Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-02-19

0
Medium
Published: Thu Feb 19 2026 (02/19/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-02-19

AI-Powered Analysis

AILast updated: 02/20/2026, 00:16:23 UTC

Technical Analysis

The provided information describes a malware-related threat entry from the ThreatFox MISP feed dated February 19, 2026. This entry is primarily an OSINT (Open Source Intelligence) artifact that catalogs indicators of compromise (IOCs) associated with network activity and payload delivery. However, the entry lacks specific details such as affected software versions, concrete technical indicators, or exploit mechanisms. No known exploits in the wild have been reported, and no patches or remediation links are available. The threat level is marked as medium, reflecting a moderate risk based on the limited data. The technical details include a low threat level (2 out of an unspecified scale), minimal analysis (1), and moderate distribution (3), suggesting some dissemination but limited confirmed impact. The absence of CWEs and specific indicators implies this is an intelligence-sharing record rather than a direct vulnerability or active exploit. This type of entry is typically used by security teams to enhance situational awareness and prepare defenses against potential payload delivery attempts that may emerge from the observed network activity patterns. The lack of detailed technical data restricts deeper analysis but highlights the importance of continuous monitoring of OSINT feeds and network traffic for early detection of emerging threats.

Potential Impact

Given the limited information and absence of known exploits or patches, the immediate impact on organizations is likely low to medium. However, the presence of payload delivery and network activity tags indicates potential risks of malware infections if related IOCs are encountered in operational environments. Organizations relying heavily on OSINT tools or integrating ThreatFox feeds into their security operations may be better positioned to detect and respond to such threats. The lack of specific affected versions or vulnerabilities suggests this is not a targeted exploit but rather a general malware campaign or intelligence artifact. If payload delivery attempts succeed, impacts could include data compromise, system disruption, or lateral movement within networks. The medium severity rating suggests a moderate risk that warrants attention but does not indicate an imminent critical threat. Overall, the impact is contingent on the ability of organizations to detect and mitigate suspicious network activity and payloads associated with these IOCs.

Mitigation Recommendations

1. Integrate ThreatFox and other OSINT feeds into Security Information and Event Management (SIEM) systems to enable real-time detection of related IOCs. 2. Enhance network monitoring to identify unusual payload delivery attempts or suspicious network activity patterns. 3. Employ endpoint detection and response (EDR) tools to detect and block malware payloads early in the infection chain. 4. Conduct regular threat hunting exercises focusing on network traffic anomalies and payload signatures associated with the shared IOCs. 5. Maintain updated and comprehensive incident response plans that include procedures for handling malware infections and network intrusions. 6. Educate security teams on interpreting OSINT threat intelligence and correlating it with internal telemetry for proactive defense. 7. Since no patches are available, focus on hardening network segmentation and access controls to limit potential malware spread. 8. Validate and tune intrusion detection/prevention systems (IDS/IPS) to recognize patterns consistent with the described threat activity. These steps go beyond generic advice by emphasizing the operational integration of OSINT feeds and proactive network and endpoint monitoring tailored to the threat characteristics.

Need more detailed analysis?Upgrade to Pro Console

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
f2105172-eac8-48e8-879c-29e61ead3d19
Original Timestamp
1771545787

Indicators of Compromise

File

ValueDescriptionCopy
file8.162.5.187
XWorm botnet C2 server (confidence level: 100%)
file193.161.193.99
NjRAT botnet C2 server (confidence level: 100%)
file45.150.32.124
Stealc botnet C2 server (confidence level: 100%)
file45.94.31.178
DoublePulsar botnet C2 server (confidence level: 100%)
file206.123.132.224
Quasar RAT botnet C2 server (confidence level: 100%)
file198.244.201.139
XWorm botnet C2 server (confidence level: 100%)
file172.105.85.143
XWorm botnet C2 server (confidence level: 100%)
file89.167.52.86
Mirai botnet C2 server (confidence level: 100%)
file146.70.181.238
Remcos botnet C2 server (confidence level: 100%)
file172.111.162.252
Remcos botnet C2 server (confidence level: 100%)
file23.26.129.38
Remcos botnet C2 server (confidence level: 100%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 100%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 100%)
file87.242.106.13
NonEuclid RAT botnet C2 server (confidence level: 100%)
file107.152.32.98
DoublePulsar botnet C2 server (confidence level: 100%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 100%)
file157.15.98.138
MooBot botnet C2 server (confidence level: 100%)
file54.89.163.179
Meterpreter botnet C2 server (confidence level: 100%)
file43.209.225.147
Meterpreter botnet C2 server (confidence level: 100%)
file78.12.9.38
Meterpreter botnet C2 server (confidence level: 100%)
file128.90.102.133
XWorm botnet C2 server (confidence level: 100%)
file112.68.47.218
Mirai botnet C2 server (confidence level: 100%)
file147.185.221.181
XWorm botnet C2 server (confidence level: 100%)
file165.232.45.1
AsyncRAT botnet C2 server (confidence level: 100%)
file156.246.95.51
MooBot botnet C2 server (confidence level: 100%)
file3.81.3.110
Havoc botnet C2 server (confidence level: 100%)
file130.164.164.220
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file38.127.8.3
AdaptixC2 botnet C2 server (confidence level: 100%)
file45.89.140.80
Empire Downloader botnet C2 server (confidence level: 100%)
file45.89.140.78
Empire Downloader botnet C2 server (confidence level: 100%)
file137.184.61.113
Aisuru botnet C2 server (confidence level: 75%)
file159.65.252.42
Aisuru botnet C2 server (confidence level: 75%)
file165.22.193.95
Aisuru botnet C2 server (confidence level: 75%)
file174.138.15.64
Aisuru botnet C2 server (confidence level: 75%)
file157.245.86.38
Aisuru botnet C2 server (confidence level: 75%)
file178.128.247.58
Aisuru botnet C2 server (confidence level: 75%)
file142.93.137.168
Aisuru botnet C2 server (confidence level: 75%)
file104.131.8.3
Aisuru botnet C2 server (confidence level: 75%)
file165.232.80.66
Aisuru botnet C2 server (confidence level: 75%)
file143.110.139.54
Aisuru botnet C2 server (confidence level: 75%)
file94.73.17.125
XWorm botnet C2 server (confidence level: 100%)
file134.209.55.29
Aisuru botnet C2 server (confidence level: 75%)
file101.132.167.9
Cobalt Strike botnet C2 server (confidence level: 100%)
file144.172.108.230
Bashlite botnet C2 server (confidence level: 75%)
file167.172.48.226
Aisuru botnet C2 server (confidence level: 75%)
file165.227.115.71
AsyncRAT botnet C2 server (confidence level: 100%)
file122.225.30.226
Xtreme RAT botnet C2 server (confidence level: 100%)
file84.38.133.182
Remcos botnet C2 server (confidence level: 100%)
file138.91.32.183
Sliver botnet C2 server (confidence level: 75%)
file165.245.130.101
Sliver botnet C2 server (confidence level: 75%)
file172.86.91.226
Havoc botnet C2 server (confidence level: 75%)
file185.179.189.122
DeimosC2 botnet C2 server (confidence level: 75%)
file24.20.225.162
DeimosC2 botnet C2 server (confidence level: 75%)
file52.146.70.84
DeimosC2 botnet C2 server (confidence level: 75%)
file172.233.46.113
Unknown malware botnet C2 server (confidence level: 75%)
file209.54.103.184
XWorm botnet C2 server (confidence level: 100%)
file138.199.59.6
Remcos botnet C2 server (confidence level: 100%)
file158.94.211.76
Unknown malware botnet C2 server (confidence level: 50%)
file172.94.100.227
Remcos botnet C2 server (confidence level: 100%)
file158.94.210.95
AsyncRAT botnet C2 server (confidence level: 100%)
file83.228.224.244
Unknown malware botnet C2 server (confidence level: 100%)
file62.102.148.154
Remcos botnet C2 server (confidence level: 100%)
file183.2.143.61
Xtreme RAT botnet C2 server (confidence level: 100%)
file183.2.143.61
Xtreme RAT botnet C2 server (confidence level: 100%)
file223.109.90.98
Xtreme RAT botnet C2 server (confidence level: 100%)
file178.16.53.96
Remcos botnet C2 server (confidence level: 100%)
file94.237.58.158
MimiKatz botnet C2 server (confidence level: 100%)
file65.87.7.237
AdaptixC2 botnet C2 server (confidence level: 100%)
file80.71.235.24
AdaptixC2 botnet C2 server (confidence level: 100%)
file168.245.203.52
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.203.54
Meterpreter botnet C2 server (confidence level: 100%)
file213.152.161.162
XWorm botnet C2 server (confidence level: 100%)
file134.122.140.89
XWorm botnet C2 server (confidence level: 100%)
file134.122.152.135
XWorm botnet C2 server (confidence level: 100%)
file134.122.154.171
XWorm botnet C2 server (confidence level: 100%)
file202.95.17.184
XWorm botnet C2 server (confidence level: 100%)
file202.95.18.16
XWorm botnet C2 server (confidence level: 100%)
file103.163.219.252
XWorm botnet C2 server (confidence level: 100%)
file141.11.213.91
XWorm botnet C2 server (confidence level: 100%)
file147.45.45.110
XWorm botnet C2 server (confidence level: 100%)
file193.233.113.137
XWorm botnet C2 server (confidence level: 100%)
file5.230.159.62
XWorm botnet C2 server (confidence level: 100%)
file20.234.151.26
XWorm botnet C2 server (confidence level: 100%)
file45.61.149.192
XWorm botnet C2 server (confidence level: 100%)
file45.137.98.189
XWorm botnet C2 server (confidence level: 100%)
file45.141.26.201
XWorm botnet C2 server (confidence level: 100%)
file82.26.104.128
XWorm botnet C2 server (confidence level: 100%)
file91.208.197.30
XWorm botnet C2 server (confidence level: 100%)
file149.28.151.106
Sliver botnet C2 server (confidence level: 90%)
file89.125.50.65
Unknown malware botnet C2 server (confidence level: 100%)
file103.109.234.117
Quasar RAT botnet C2 server (confidence level: 100%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 100%)
file37.4.250.173
XWorm botnet C2 server (confidence level: 100%)
file69.5.189.249
Remcos botnet C2 server (confidence level: 100%)
file15.229.32.243
AdaptixC2 botnet C2 server (confidence level: 100%)
file136.0.157.17
Quasar RAT botnet C2 server (confidence level: 100%)
file195.177.94.71
Loda botnet C2 server (confidence level: 100%)
file39.101.174.60
VShell botnet C2 server (confidence level: 100%)
file119.45.214.169
VShell botnet C2 server (confidence level: 100%)
file103.83.86.162
XWorm botnet C2 server (confidence level: 100%)
file172.86.68.38
VShell botnet C2 server (confidence level: 100%)
file178.116.38.74
RedLine Stealer botnet C2 server (confidence level: 100%)
file95.156.205.13
SpyNote botnet C2 server (confidence level: 100%)
file117.187.252.19
DeimosC2 botnet C2 server (confidence level: 75%)
file149.28.151.106
Sliver botnet C2 server (confidence level: 75%)
file178.236.252.109
Unknown malware botnet C2 server (confidence level: 75%)
file44.198.60.243
Havoc botnet C2 server (confidence level: 100%)
file107.189.27.83
Havoc botnet C2 server (confidence level: 100%)
file95.85.239.201
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file192.227.219.80
Remcos botnet C2 server (confidence level: 100%)
file181.235.2.89
Remcos botnet C2 server (confidence level: 100%)
file87.106.187.97
Sliver botnet C2 server (confidence level: 100%)
file18.221.223.195
Sliver botnet C2 server (confidence level: 100%)
file159.203.79.29
Sliver botnet C2 server (confidence level: 100%)
file3.148.25.195
Unknown malware botnet C2 server (confidence level: 100%)
file155.117.40.221
Unknown malware botnet C2 server (confidence level: 100%)
file20.39.130.27
Unknown malware botnet C2 server (confidence level: 100%)
file178.236.252.109
Unknown malware botnet C2 server (confidence level: 100%)
file3.140.254.73
Havoc botnet C2 server (confidence level: 100%)
file18.236.192.145
Havoc botnet C2 server (confidence level: 100%)
file51.84.9.169
Meterpreter botnet C2 server (confidence level: 100%)
file51.92.40.130
Meterpreter botnet C2 server (confidence level: 100%)
file54.91.209.10
Meterpreter botnet C2 server (confidence level: 100%)
file89.58.25.125
Unknown malware botnet C2 server (confidence level: 100%)
file156.225.19.99
ValleyRAT botnet C2 server (confidence level: 75%)
file176.108.250.50
Cobalt Strike botnet C2 server (confidence level: 90%)
file154.219.97.70
Ghost RAT botnet C2 server (confidence level: 75%)
file154.219.97.142
Ghost RAT botnet C2 server (confidence level: 75%)
file154.219.97.206
Ghost RAT botnet C2 server (confidence level: 75%)
file155.138.162.127
Sliver botnet C2 server (confidence level: 90%)
file165.232.45.1
AsyncRAT botnet C2 server (confidence level: 100%)
file16.58.121.239
Unknown malware botnet C2 server (confidence level: 100%)
file3.148.25.195
Havoc botnet C2 server (confidence level: 100%)
file75.119.151.20
Havoc botnet C2 server (confidence level: 100%)
file3.85.107.177
Havoc botnet C2 server (confidence level: 100%)
file209.74.82.76
Unknown malware botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash14701
XWorm botnet C2 server (confidence level: 100%)
hash44688
NjRAT botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash8990
DoublePulsar botnet C2 server (confidence level: 100%)
hash39558
Quasar RAT botnet C2 server (confidence level: 100%)
hash7181
XWorm botnet C2 server (confidence level: 100%)
hash20809
XWorm botnet C2 server (confidence level: 100%)
hash853
Mirai botnet C2 server (confidence level: 100%)
hash5675
Remcos botnet C2 server (confidence level: 100%)
hash2620
Remcos botnet C2 server (confidence level: 100%)
hash24024
Remcos botnet C2 server (confidence level: 100%)
hash25340
XWorm botnet C2 server (confidence level: 100%)
hash51173
XWorm botnet C2 server (confidence level: 100%)
hash64370
NonEuclid RAT botnet C2 server (confidence level: 100%)
hash2491
DoublePulsar botnet C2 server (confidence level: 100%)
hash61682
XWorm botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash179
Meterpreter botnet C2 server (confidence level: 100%)
hash44819
Meterpreter botnet C2 server (confidence level: 100%)
hash59161
Meterpreter botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash2323
Mirai botnet C2 server (confidence level: 100%)
hash17288
XWorm botnet C2 server (confidence level: 100%)
hash7000
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash443
AdaptixC2 botnet C2 server (confidence level: 100%)
hash80
Empire Downloader botnet C2 server (confidence level: 100%)
hash80
Empire Downloader botnet C2 server (confidence level: 100%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8088
XWorm botnet C2 server (confidence level: 100%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9000
Bashlite botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash5505
AsyncRAT botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash41000
Remcos botnet C2 server (confidence level: 100%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash9090
Sliver botnet C2 server (confidence level: 75%)
hash443
Havoc botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash8080
DeimosC2 botnet C2 server (confidence level: 75%)
hash8013
DeimosC2 botnet C2 server (confidence level: 75%)
hash6667
Unknown malware botnet C2 server (confidence level: 75%)
hash1909
XWorm botnet C2 server (confidence level: 100%)
hash60736
Remcos botnet C2 server (confidence level: 100%)
hash3232
Unknown malware botnet C2 server (confidence level: 50%)
hash29811
Remcos botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash3066
Remcos botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash43350
Xtreme RAT botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash888
Remcos botnet C2 server (confidence level: 100%)
hash8000
MimiKatz botnet C2 server (confidence level: 100%)
hash8888
AdaptixC2 botnet C2 server (confidence level: 100%)
hash8888
AdaptixC2 botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash5103
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash8282
XWorm botnet C2 server (confidence level: 100%)
hash7777
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash6000
XWorm botnet C2 server (confidence level: 100%)
hash6000
XWorm botnet C2 server (confidence level: 100%)
hash6666
XWorm botnet C2 server (confidence level: 100%)
hash6000
XWorm botnet C2 server (confidence level: 100%)
hash6000
XWorm botnet C2 server (confidence level: 100%)
hash1605
XWorm botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 90%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash63603
XWorm botnet C2 server (confidence level: 100%)
hash63603
XWorm botnet C2 server (confidence level: 100%)
hash7701
Remcos botnet C2 server (confidence level: 100%)
hash1234
AdaptixC2 botnet C2 server (confidence level: 100%)
hash9304
Quasar RAT botnet C2 server (confidence level: 100%)
hash4000
Loda botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash8443
VShell botnet C2 server (confidence level: 100%)
hash1985
XWorm botnet C2 server (confidence level: 100%)
hash28886
VShell botnet C2 server (confidence level: 100%)
hash1912
RedLine Stealer botnet C2 server (confidence level: 100%)
hash55575
SpyNote botnet C2 server (confidence level: 100%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash8443
Havoc botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3000
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash80
Havoc botnet C2 server (confidence level: 100%)
hash9999
Meterpreter botnet C2 server (confidence level: 100%)
hash1234
Meterpreter botnet C2 server (confidence level: 100%)
hash16930
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash2324
ValleyRAT botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 90%)
hash5758
Ghost RAT botnet C2 server (confidence level: 75%)
hash5758
Ghost RAT botnet C2 server (confidence level: 75%)
hash5758
Ghost RAT botnet C2 server (confidence level: 75%)
hash443
Sliver botnet C2 server (confidence level: 90%)
hash8088
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Havoc botnet C2 server (confidence level: 100%)
hash80
Havoc botnet C2 server (confidence level: 100%)
hash8443
Havoc botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://www.gorscts.shop/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://hodorit.com/identity/route-sandbox.php
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://hodorit.com/identity/rate-util.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://cirealci.com/froute1
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://185.33.87.29/zipp2
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://74.0.48.206/
Vidar botnet C2 (confidence level: 100%)
urlhttps://mieyabi.com/5j1s.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://mieyabi.com/js.php
KongTuke payload delivery URL (confidence level: 100%)
urlhttp://91.92.243.29/klob
Phorpiex payload delivery URL (confidence level: 100%)
urlhttps://polygon.qbetfhwz.xyz/gate/health
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://rss.gadgetwalabd.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://rss.alpinematters.com/
Vidar botnet C2 (confidence level: 100%)
urlhttp://158.94.211.76:3232/ceoznp
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://bra.gadgetwalabd.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://bra.alpinematters.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://trofeyincs.top/login/middleware-json.php
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://trofeyincs.top/login/auth-response.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://trombolistic.com/111-file-r
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://79.141.163.163/320-zip
SmartApeSG payload delivery URL (confidence level: 100%)

Domain

ValueDescriptionCopy
domainsystemcore.murta46unprin.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainhodorit.com
SmartApeSG payload delivery domain (confidence level: 100%)
domain3mi05cn7h7k4ecsb.frostapi.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainbotnet.exiled.fit
Mirai botnet C2 domain (confidence level: 100%)
domainmieyabi.com
KongTuke payload delivery domain (confidence level: 100%)
domainstonepath.rockwood.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainsolidleaf.rockwood.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainfruitcase.plum63box.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainredplum.plum63box.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainboxstore.plum63box.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainsweetstock.plum63box.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaincoldbreeze.snowwind.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainwintertrack.snowwind.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainpurewhite.snowwind.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainchillstream.snowwind.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainquickpath.fastlane.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainroadrunner.fastlane.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaindrivelogic.fastlane.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainshiftpoint.fastlane.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainshipfresh.mint5ship.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaingreenleaf.mint5ship.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainswiftcore.cloudbridge.city
ClearFake payload delivery domain (confidence level: 100%)
domainlinkflow.cloudbridge.city
ClearFake payload delivery domain (confidence level: 100%)
domainopenport.cloudbridge.city
ClearFake payload delivery domain (confidence level: 100%)
domain21.yunduans.com
ValleyRAT botnet C2 domain (confidence level: 75%)
domainfastgate.cloudbridge.city
ClearFake payload delivery domain (confidence level: 100%)
domaingreenleaf.natureway.city
ClearFake payload delivery domain (confidence level: 100%)
domainnexit-53294.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainnexit-62461.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domain26068482b66202d6ca29e1bb210288c8.444ef3f25893ae427338085e576fa9fb.traefik.default
Cobalt Strike botnet C2 domain (confidence level: 50%)
domainearthmap.natureway.city
ClearFake payload delivery domain (confidence level: 100%)
domainwildtrack.natureway.city
ClearFake payload delivery domain (confidence level: 100%)
domainriverflow.natureway.city
ClearFake payload delivery domain (confidence level: 100%)
domainsmartstep.urbanlab.city
ClearFake payload delivery domain (confidence level: 100%)
domainpulseview.urbanlab.city
ClearFake payload delivery domain (confidence level: 100%)
domaingridlock.urbanlab.city
ClearFake payload delivery domain (confidence level: 100%)
domain52wyvwc0.cabinetslyuka.digital
ClearFake payload delivery domain (confidence level: 100%)
domainpxkpoxt8.cabinetslyuka.digital
ClearFake payload delivery domain (confidence level: 100%)
domainbrightsky.starpoint.city
ClearFake payload delivery domain (confidence level: 100%)
domaingoldlight.goldstar.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainbrightsky.goldstar.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainshinepoint.goldstar.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainnext-dance.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainspacecore.goldstar.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainboxlayer.box1fig7.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainpolygon.qbetfhwz.xyz
Unknown RAT botnet C2 domain (confidence level: 100%)
domainfigstore.box1fig7.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainroundpack.box1fig7.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainbaseflow.box1fig7.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaindesertroad.sandwave.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainraterake.cfd
Unknown Loader botnet C2 domain (confidence level: 100%)
domaindrywind.sandwave.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainrss.gadgetwalabd.com
Vidar botnet C2 domain (confidence level: 100%)
domainrss.alpinematters.com
Vidar botnet C2 domain (confidence level: 100%)
domaindonothg.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainfrancek.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaingoldensand.sandwave.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainhoustongaragedoorinstallers.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainbiopranica.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainpressureulcerlawyer.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainusedteslabuyers.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainwarmtrack.sandwave.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainpearbox.pack12pear.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainfruitpack.pack12pear.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainlocalstore.pack12pear.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainwww.safebrowse.io
ClearFake payload delivery domain (confidence level: 100%)
domaingreenlabel.pack12pear.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainironcore.ironstar.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainsteelsync.ironstar.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainpowerbeat.ironstar.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainhardlink.ironstar.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainmoonlight.eastmoon.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaindarksky.eastmoon.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaineastorbit.eastmoon.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainglowpoint.eastmoon.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaingsm.ftp.sh
Unknown malware botnet C2 domain (confidence level: 100%)
domainplm.ftp.sh
Unknown malware botnet C2 domain (confidence level: 100%)
domainmintbase.ship48mint.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaincoldship.ship48mint.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainxxblessingswealths.duckdns.org
XWorm botnet C2 domain (confidence level: 75%)
domainyupangco.com
Snake botnet C2 domain (confidence level: 100%)
domainfreshroute.ship48mint.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainfastpack.ship48mint.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainkiwitalk.ship46kiwi.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaingreenbird.ship46kiwi.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainfastkiwi.ship46kiwi.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainskyline.ship46kiwi.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaincolaba.ru.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainwsc.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainhg0088.co.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domain789f.br.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainbertran.ru.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainfrunglewump.gb.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainhcolaba.ru.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainwwn.uk.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindaroughgan1.com
Remcos botnet C2 domain (confidence level: 100%)
domaindaroughgan8hajous30.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domaindaroughgan8hajous40.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domaindaroughgan8hajous50.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domaindawdawf-45472.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainbra.gadgetwalabd.com
Vidar botnet C2 domain (confidence level: 100%)
domainbra.alpinematters.com
Vidar botnet C2 domain (confidence level: 100%)
domainwestcoast.westwind.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainstrongblow.westwind.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainopenfield.westwind.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainapiv4.frostapi.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainvelvet-parrot.com
SantaStealer botnet C2 domain (confidence level: 100%)
domainapi-metadata-v6.is
XOR DDoS botnet C2 domain (confidence level: 100%)
domainstormtrack.westwind.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainpearline.pear7pack.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainsweetfruit.pear7pack.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainbrotherspizza.kozow.com
AsyncRAT botnet C2 domain (confidence level: 75%)
domainpizzashop.kozow.com
AsyncRAT botnet C2 domain (confidence level: 75%)
domaingoldpack.pear7pack.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaintrofeyincs.top
SmartApeSG payload delivery domain (confidence level: 100%)
domainfarmfresh.pear7pack.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainblackfire.darkfire.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainsys-kernel-update.to
XOR DDoS botnet C2 domain (confidence level: 100%)
domaintelemetry-pipe.sh
XOR DDoS botnet C2 domain (confidence level: 100%)
domainhotelement.darkfire.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainsmoketrace.darkfire.coupons
ClearFake payload delivery domain (confidence level: 100%)
domaincoalpoint.darkfire.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainfigbranch.fig08box.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainsmallbox.fig08box.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainvirtualspeechtherapists.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmegafilehub1.baby
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainkys.li
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainfreshfig.fig08box.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainmegafilehub2.baby
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmegafilehub3.baby
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmegafilehub4.baby
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainboxflow.fig08box.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainabnewszamanpaper72.sa.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainp-93kketo.ru.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainwww.lighter500.com
Remcos botnet C2 domain (confidence level: 100%)
domainvnwns-188-163-102-33.a.free.pinggy.link
Quasar RAT botnet C2 domain (confidence level: 100%)
domainplumfield.box671plum.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainheavybox.box671plum.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainblueplum.box671plum.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainstockhub.box671plum.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainkiwitransit.kiwi9ship3.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainoceanbird.kiwi9ship3.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainportside.kiwi9ship3.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainglobalfruit.kiwi9ship3.coupons
ClearFake payload delivery domain (confidence level: 100%)
domainbluecloud.skyrain.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhighwind.skyrain.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainclearair.skyrain.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsoftmist.skyrain.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainblueocean.deepwave.in.net
ClearFake payload delivery domain (confidence level: 100%)
domain92lottery.coach
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindarkwater.deepwave.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainseacurrent.deepwave.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsaltreef.deepwave.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhotstone.firepath.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainashcloud.firepath.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainglowtrace.firepath.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincoalbase.firepath.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfreezepoint.coldwind.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwinterblast.coldwind.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsnowtrack.coldwind.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnorthgale.coldwind.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlightbeam.brightstar.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspacecore.brightstar.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhuntpack.graywolf.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwildstep.graywolf.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingreytrack.graywolf.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainforestnode.graywolf.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbluehunt.bluewolf.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnightrun.bluewolf.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainleadpulse.bluewolf.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlightcore.coolstar.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbrightpoint.coolstar.in.net
ClearFake payload delivery domain (confidence level: 100%)
domain423vlwlb.blue128cinder.digital
ClearFake payload delivery domain (confidence level: 100%)
domainy5d9oidj.blue128cinder.digital
ClearFake payload delivery domain (confidence level: 100%)
domainspaceview.coolstar.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmanager.3utilities.com
Remcos botnet C2 domain (confidence level: 100%)
domainbkn-partr.com
Havoc botnet C2 domain (confidence level: 100%)
domainjuandaza2025pu.camdvr.org
Remcos botnet C2 domain (confidence level: 100%)
domaincoldbeam.coolstar.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsteelsync.ironwave.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhardflow.ironwave.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpowerlink.ironwave.in.net
ClearFake payload delivery domain (confidence level: 100%)

Threat ID: 6997a7c9d7880ec89b3e18d1

Added to database: 2/20/2026, 12:16:09 AM

Last enriched: 2/20/2026, 12:16:23 AM

Last updated: 2/20/2026, 4:09:06 AM

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats