Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-02-22

0
Medium
Published: Sun Feb 22 2026 (02/22/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-02-22

AI-Powered Analysis

AILast updated: 02/23/2026, 00:16:26 UTC

Technical Analysis

This entry from the ThreatFox MISP feed provides a collection of Indicators of Compromise (IOCs) related to malware activities focusing on OSINT (Open Source Intelligence), payload delivery mechanisms, and network activity. The data lacks specific affected software versions or detailed technical descriptions of the malware or attack vectors. No known exploits are reported in the wild, and no patches or remediation links are available, indicating this is likely an intelligence update rather than a newly discovered vulnerability or active attack campaign. The threat level is medium, suggesting moderate risk primarily from detection and response perspectives rather than immediate exploitation. The feed is tagged with TLP:WHITE, indicating the information is intended for public sharing and broad dissemination. The absence of CWEs and technical specifics limits the ability to perform deep technical analysis, but the presence of IOCs can assist security teams in enhancing their detection and monitoring capabilities for related malicious activity.

Potential Impact

Given the lack of specific exploit details or active attacks, the immediate impact on organizations worldwide is limited. However, the presence of new IOCs related to malware payload delivery and network activity indicates potential reconnaissance or preparatory stages of cyber threats. Organizations that do not incorporate updated threat intelligence feeds may miss early signs of emerging threats, potentially leading to delayed detection and response. The medium severity suggests that while the threat is not critical, it could contribute to successful attacks if combined with other vulnerabilities or social engineering tactics. The impact is primarily on security monitoring and incident response effectiveness rather than direct system compromise at this stage.

Mitigation Recommendations

Organizations should integrate ThreatFox and similar OSINT feeds into their Security Information and Event Management (SIEM) and threat detection platforms to leverage the provided IOCs for enhanced monitoring. Regularly updating detection rules and signatures based on these feeds can improve early warning capabilities. Conduct proactive network traffic analysis focusing on payload delivery patterns and suspicious network activity aligned with the IOCs. Employ threat hunting exercises to identify any signs of compromise related to the indicators. Maintain robust incident response plans to quickly address any alerts triggered by these IOCs. Since no patches are available, focus on detection and containment strategies rather than remediation. Collaboration with threat intelligence communities can provide additional context and updates.

Need more detailed analysis?Upgrade to Pro Console

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
b30f6cd0-7820-48cc-bd33-2995468a9dfc
Original Timestamp
1771804987

Indicators of Compromise

Domain

ValueDescriptionCopy
domaintightfeather.condenfeather.ru
ClearFake payload delivery domain (confidence level: 100%)
domainclearscript.purecode.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindutycourier.servantakeaway.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmildnode.mildtech.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbrightflash.neondata.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainglowbase.neondata.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincitypulse.neondata.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainneonlink.neondata.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindcenevinew.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 100%)
domainxoeyxsife-33031.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainquickpath.fastlink.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspeednode.fastlink.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrapidcore.fastlink.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfastexchange.fastlink.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhighrange.ultranet.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsuperlink.ultranet.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmegastream.ultranet.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainamsholdings.ddns.net
Remcos botnet C2 domain (confidence level: 75%)
domainswgtcampus0101.duckdns.org
Remcos botnet C2 domain (confidence level: 75%)
domaintoleskiki.ddnsgeek.com
Remcos botnet C2 domain (confidence level: 75%)
domainegtwax65c.localto.net
XWorm botnet C2 domain (confidence level: 100%)
domainresinwood.callresined.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmi9h8uf4.ironrock.digital
ClearFake payload delivery domain (confidence level: 100%)
domainojqxtq3l.ironrock.digital
ClearFake payload delivery domain (confidence level: 100%)
domainringplank.callresined.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindesertwander.nomadsuppurat.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintribalpath.nomadsuppurat.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincheapnfljerseys-fromchina.us.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainsteppejourney.nomadsuppurat.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyhhpswoa.forward3cross.digital
ClearFake payload delivery domain (confidence level: 100%)
domain0uwsxbye.forward3cross.digital
ClearFake payload delivery domain (confidence level: 100%)
domainwazuh.kokanddu.uz
Havoc botnet C2 domain (confidence level: 100%)
domainoprc9zre.upgrade4file.digital
ClearFake payload delivery domain (confidence level: 100%)
domainodbsasjd.upgrade4file.digital
ClearFake payload delivery domain (confidence level: 100%)
domainthespacemachines.st
Mirai botnet C2 domain (confidence level: 100%)
domainstore-image.shop
Unknown malware payload delivery domain (confidence level: 100%)
domainvaer-cdn-3.sbs
Unknown malware payload delivery domain (confidence level: 100%)
domainimage-hoster11.sbs
Unknown malware payload delivery domain (confidence level: 100%)
domainnstv-css-styles-19.sbs
Unknown malware payload delivery domain (confidence level: 100%)
domaindltucra.com
Unknown malware payload delivery domain (confidence level: 100%)
domainldveriz.com
Unknown malware payload delivery domain (confidence level: 100%)
domain366kf0hf.up12file.digital
ClearFake payload delivery domain (confidence level: 100%)
domainstormpanel.batenshutter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainthunderray.sa.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainslot-indonesia.jp.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domaintbh.uk.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainvub.us.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainwoodenlatch.batenshutter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrainbarrier.batenshutter.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingoldflake.orichsnow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmaxalaprod-64489.portmap.host
Nanocore RAT botnet C2 domain (confidence level: 100%)
domainrichfrost.orichsnow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbozqk0kq.novacode.digital
ClearFake payload delivery domain (confidence level: 100%)
domainr8ada0zp.novacode.digital
ClearFake payload delivery domain (confidence level: 100%)
domainsnowcrown.orichsnow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpathfinder.exploratsinyuk.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintrailquest.exploratsinyuk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmapseeker.exploratsinyuk.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincoreformula.inherentrecip.ru
ClearFake payload delivery domain (confidence level: 100%)
domaininnaterecipe.inherentrecip.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbaseportion.inherentrecip.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingraincontrol.brannysuppress.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmaltguard.brannysuppress.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbrewshield.brannysuppress.ru
ClearFake payload delivery domain (confidence level: 100%)
domainminihouse.koreansmall.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlittlemarket.koreansmall.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincompactvillage.koreansmall.ru
ClearFake payload delivery domain (confidence level: 100%)
domain59xgjeq2.hexalink.digital
ClearFake payload delivery domain (confidence level: 100%)
domainjoieshk7.hexalink.digital
ClearFake payload delivery domain (confidence level: 100%)
domainchecktone.auditsounder.ru
ClearFake payload delivery domain (confidence level: 100%)
domainverifyecho.auditsounder.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsoundreview.auditsounder.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincorenumber.arithmethair.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindigitflow.arithmethair.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmathlogic.arithmethair.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincalcunit.arithmethair.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindarkport.detachfrigate.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainvesselhub.detachfrigate.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainoceanpoint.detachfrigate.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainautofinder.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainxswdeu.za.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaincursednetwork.ru
Quasar RAT botnet C2 domain (confidence level: 100%)
domainpovermnebrat.ru
Quasar RAT botnet C2 domain (confidence level: 100%)
domainshipnode.detachfrigate.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainheropath.shratsurvivor.in.net
ClearFake payload delivery domain (confidence level: 100%)
domain176.65.148.52.ptr.pfcloud.network
Mirai botnet C2 domain (confidence level: 80%)
domainhardlife.shratsurvivor.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwildhunt.shratsurvivor.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlaststand.shratsurvivor.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainoldcore.solidyears.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbasepoint.solidyears.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlongroad.solidyears.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhardrock.solidyears.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfinalgate.afterlifetap.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspiritlink.afterlifetap.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbeyondbase.afterlifetap.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsoultrack.afterlifetap.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindaytrace.hourillusion.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbkns-prtner.com
Havoc botnet C2 domain (confidence level: 100%)
domainshiftview.hourillusion.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainimmortal-service.cc
CountLoader payload delivery domain (confidence level: 100%)
domaincritical-service.cc
CountLoader payload delivery domain (confidence level: 100%)
domainfileless-market.cc
CountLoader payload delivery domain (confidence level: 100%)
domainindeanapolice.cc
CountLoader payload delivery domain (confidence level: 100%)
domainglobalsnn2-new.cc
CountLoader payload delivery domain (confidence level: 100%)
domainglobalsnn10-new.cc
CountLoader payload delivery domain (confidence level: 100%)
domainglobalsnn1-new.cc
CountLoader payload delivery domain (confidence level: 100%)
domainglobalsnn3-new.cc
CountLoader payload delivery domain (confidence level: 100%)
domainglobalsnn4-new.cc
CountLoader payload delivery domain (confidence level: 100%)
domainglobalsnn5-new.cc
CountLoader payload delivery domain (confidence level: 100%)
domainglobalsnn6-new.cc
CountLoader payload delivery domain (confidence level: 100%)
domainglobalsnn7-new.cc
CountLoader payload delivery domain (confidence level: 100%)
domainglobalsnn8-new.cc
CountLoader payload delivery domain (confidence level: 100%)
domainglobalsnn9-new.cc
CountLoader payload delivery domain (confidence level: 100%)
domainglobalsnn-new.cc
CountLoader payload delivery domain (confidence level: 100%)
domainapi-microservice-us1.com
CountLoader payload delivery domain (confidence level: 100%)
domainapi-microservice-us10.com
CountLoader payload delivery domain (confidence level: 100%)
domainapi-microservice-us2.com
CountLoader payload delivery domain (confidence level: 100%)
domainapi-microservice-us3.com
CountLoader payload delivery domain (confidence level: 100%)
domainapi-microservice-us4.com
CountLoader payload delivery domain (confidence level: 100%)
domainapi-microservice-us5.com
CountLoader payload delivery domain (confidence level: 100%)
domainapi-microservice-us6.com
CountLoader payload delivery domain (confidence level: 100%)
domainapi-microservice-us7.com
CountLoader payload delivery domain (confidence level: 100%)
domainapi-microservice-us8.com
CountLoader payload delivery domain (confidence level: 100%)
domainapi-microservice-us9.com
CountLoader payload delivery domain (confidence level: 100%)
domainalphazero10-endscape.cc
CountLoader payload delivery domain (confidence level: 100%)
domainalphazero1-endscape.cc
CountLoader payload delivery domain (confidence level: 100%)
domainalphazero2-endscape.cc
CountLoader payload delivery domain (confidence level: 100%)
domainalphazero3-endscape.cc
CountLoader payload delivery domain (confidence level: 100%)
domainalphazero4-endscape.cc
CountLoader payload delivery domain (confidence level: 100%)
domainalphazero5-endscape.cc
CountLoader payload delivery domain (confidence level: 100%)
domainalphazero6-endscape.cc
CountLoader payload delivery domain (confidence level: 100%)
domainalphazero7-endscape.cc
CountLoader payload delivery domain (confidence level: 100%)
domainalphazero8-endscape.cc
CountLoader payload delivery domain (confidence level: 100%)
domainalphazero9-endscape.cc
CountLoader payload delivery domain (confidence level: 100%)
domainalphazero-endscape.cc
CountLoader payload delivery domain (confidence level: 100%)
domainwatchpoint.hourillusion.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintimeloop.hourillusion.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintasknode.baskadubutil.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmaintool.baskadubutil.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainservicedesk.baskadubutil.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainutilsync.baskadubutil.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainleadgroup.chelnperson.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhumanunit.chelnperson.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainworkforce.chelnperson.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstaffbase.chelnperson.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbot.1756520.xyz
Mirai botnet C2 domain (confidence level: 100%)
domainauthpoint.approvkrup.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmagiablackgold.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainfinalstep.approvkrup.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainapplynow.approvkrup.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincheckstatus.approvkrup.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainultranode.ultranet.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmoney.bullishcoder.com
StrelaStealer payload delivery domain (confidence level: 100%)
domaincentralcloudservice.lubginany.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnetworkdatamanager.lubginany.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainidk123456789012-51385.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainsecureaccesspoint.lubginany.in.net
ClearFake payload delivery domain (confidence level: 100%)
domain5z6y8mkfe.localto.net
SpyNote botnet C2 domain (confidence level: 100%)
domaininternalnodepoint.lubginany.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmananta.es
StrelaStealer payload delivery domain (confidence level: 100%)
domaincomplexlogicstream.intricessaucy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainadvancedsystrace.intricessaucy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainglobalsynchandler.intricessaucy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwin-system-update.me
Cobalt Strike botnet C2 domain (confidence level: 100%)
domaingodisgreatmygood.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domaingreatmindworkingunison.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainrevlonducussdmg.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainremotedatachannel.intricessaucy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainflightcontrolcenter.aircraftmodel.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmaniariup.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainaerospaceviewport.aircraftmodel.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmanolocorretora.com.br
StrelaStealer payload delivery domain (confidence level: 100%)
domainnavigationsysunit.aircraftmodel.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintechnicalsupportbox.aircraftmodel.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainauth.mercadolivreshop.shop
Unknown malware botnet C2 domain (confidence level: 100%)
domainactivestatushub.snoozetrap.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsilenttriggerbase.snoozetrap.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmanutecaowebsites.creativexspot.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainbackgroundprocess.snoozetrap.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmonitoringservice.snoozetrap.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindeploymentsystems.implementnega.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainapplicationbackup.implementnega.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincoreintegratednode.implementnega.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainprocessvalidation.implementnega.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaininfrastructure-service.urbanlake.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxlyxmzlj2.localto.net
AsyncRAT botnet C2 domain (confidence level: 75%)
domainkugo.it.com
AsyncRAT botnet C2 domain (confidence level: 75%)
domainanalytics.qzz.io
Cobalt Strike botnet C2 domain (confidence level: 100%)
domaintahtam.dynv6.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainbbb.mercadolivreshop.shop
Unknown malware botnet C2 domain (confidence level: 100%)
domaincity-management-portal.urbanlake.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincentral-hub-access.urbanlake.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpublic-gateway-alpha.urbanlake.ru
ClearFake payload delivery domain (confidence level: 100%)

File

ValueDescriptionCopy
file206.123.145.26
Mirai botnet C2 server (confidence level: 80%)
file168.245.203.177
Meterpreter botnet C2 server (confidence level: 100%)
file16.63.109.40
Meterpreter botnet C2 server (confidence level: 100%)
file13.221.157.7
Meterpreter botnet C2 server (confidence level: 100%)
file108.130.208.104
Meterpreter botnet C2 server (confidence level: 100%)
file8.131.77.227
Cobalt Strike botnet C2 server (confidence level: 100%)
file94.242.52.79
Unknown malware botnet C2 server (confidence level: 100%)
file46.246.86.9
DCRat botnet C2 server (confidence level: 100%)
file79.107.150.203
QakBot botnet C2 server (confidence level: 100%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 100%)
file192.227.219.75
Remcos botnet C2 server (confidence level: 100%)
file198.135.54.85
Remcos botnet C2 server (confidence level: 100%)
file149.50.96.57
Remcos botnet C2 server (confidence level: 100%)
file103.83.86.58
Remcos botnet C2 server (confidence level: 100%)
file102.98.95.49
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file202.61.137.217
AdaptixC2 botnet C2 server (confidence level: 100%)
file103.177.47.64
Meterpreter botnet C2 server (confidence level: 100%)
file85.11.167.122
Empire Downloader botnet C2 server (confidence level: 100%)
file1.94.40.59
Cobalt Strike botnet C2 server (confidence level: 100%)
file5.89.184.32
Unknown malware botnet C2 server (confidence level: 100%)
file150.139.136.86
Xtreme RAT botnet C2 server (confidence level: 100%)
file122.225.30.63
Xtreme RAT botnet C2 server (confidence level: 100%)
file172.111.213.101
Remcos botnet C2 server (confidence level: 100%)
file91.219.237.71
Sliver botnet C2 server (confidence level: 100%)
file103.177.47.91
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.96
Meterpreter botnet C2 server (confidence level: 100%)
file18.212.63.218
Meterpreter botnet C2 server (confidence level: 100%)
file58.244.42.108
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.99
Meterpreter botnet C2 server (confidence level: 100%)
file54.147.162.161
Meterpreter botnet C2 server (confidence level: 100%)
file47.57.1.21
DeimosC2 botnet C2 server (confidence level: 75%)
file91.92.241.12
Mirai botnet C2 server (confidence level: 100%)
file165.232.45.1
AsyncRAT botnet C2 server (confidence level: 100%)
file62.102.148.130
Remcos botnet C2 server (confidence level: 100%)
file45.90.163.37
Mirai botnet C2 server (confidence level: 80%)
file2.56.109.9
Unknown Stealer botnet C2 server (confidence level: 100%)
file4.193.136.158
Remcos botnet C2 server (confidence level: 100%)
file172.111.232.241
Remcos botnet C2 server (confidence level: 100%)
file102.117.162.31
Unknown malware botnet C2 server (confidence level: 100%)
file54.177.211.190
Meterpreter botnet C2 server (confidence level: 100%)
file5.189.140.26
Cobalt Strike botnet C2 server (confidence level: 50%)
file34.253.217.85
Cobalt Strike botnet C2 server (confidence level: 50%)
file172.86.121.104
Cobalt Strike botnet C2 server (confidence level: 50%)
file123.31.11.7
Cobalt Strike botnet C2 server (confidence level: 50%)
file4.247.145.101
Sliver botnet C2 server (confidence level: 50%)
file46.225.85.130
Sliver botnet C2 server (confidence level: 50%)
file118.122.8.155
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file38.60.220.157
Kimsuky botnet C2 server (confidence level: 50%)
file147.45.245.42
AsyncRAT botnet C2 server (confidence level: 50%)
file193.161.193.99
Nanocore RAT botnet C2 server (confidence level: 100%)
file47.238.234.29
Cobalt Strike botnet C2 server (confidence level: 100%)
file185.196.8.208
Quasar RAT botnet C2 server (confidence level: 100%)
file198.135.54.88
Venom RAT botnet C2 server (confidence level: 100%)
file194.169.160.12
Quasar RAT botnet C2 server (confidence level: 100%)
file176.65.148.52
Mirai botnet C2 server (confidence level: 80%)
file176.65.148.52
Mirai botnet C2 server (confidence level: 80%)
file74.118.172.190
Remcos botnet C2 server (confidence level: 100%)
file3.104.47.154
Meterpreter botnet C2 server (confidence level: 100%)
file168.119.50.34
Meterpreter botnet C2 server (confidence level: 100%)
file51.85.37.194
Meterpreter botnet C2 server (confidence level: 100%)
file196.75.55.17
Meterpreter botnet C2 server (confidence level: 100%)
file144.31.203.91
Mirai botnet C2 server (confidence level: 100%)
file172.96.14.105
Mirai botnet C2 server (confidence level: 100%)
file144.7.95.161
DeimosC2 botnet C2 server (confidence level: 75%)
file18.253.110.70
DeimosC2 botnet C2 server (confidence level: 75%)
file185.45.195.85
DeimosC2 botnet C2 server (confidence level: 75%)
file65.153.151.164
DeimosC2 botnet C2 server (confidence level: 75%)
file91.202.3.5
DanaBot botnet C2 server (confidence level: 75%)
file45.93.31.198
Sliver botnet C2 server (confidence level: 90%)
file69.167.10.201
DCRat botnet C2 server (confidence level: 100%)
file72.61.158.123
Unknown malware botnet C2 server (confidence level: 100%)
file20.173.41.169
Sliver botnet C2 server (confidence level: 100%)
file143.92.60.13
Unknown malware botnet C2 server (confidence level: 100%)
file141.140.0.147
AsyncRAT botnet C2 server (confidence level: 100%)
file165.245.186.179
Unknown malware botnet C2 server (confidence level: 100%)
file45.64.52.154
Ghost RAT botnet C2 server (confidence level: 75%)
file185.199.52.247
Unknown malware botnet C2 server (confidence level: 100%)
file83.142.209.3
Hook botnet C2 server (confidence level: 100%)
file212.3.142.177
RedLine Stealer botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash1999
Mirai botnet C2 server (confidence level: 80%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3445
Meterpreter botnet C2 server (confidence level: 100%)
hash15443
Meterpreter botnet C2 server (confidence level: 100%)
hash44818
Meterpreter botnet C2 server (confidence level: 100%)
hash817
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash2003
DCRat botnet C2 server (confidence level: 100%)
hash995
QakBot botnet C2 server (confidence level: 100%)
hash40701
XWorm botnet C2 server (confidence level: 100%)
hash54301
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash80
Remcos botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash4444
AdaptixC2 botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Empire Downloader botnet C2 server (confidence level: 100%)
hash65534
Cobalt Strike botnet C2 server (confidence level: 100%)
hash49151
Unknown malware botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash1962
Remcos botnet C2 server (confidence level: 100%)
hash80
Sliver botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash9142
Meterpreter botnet C2 server (confidence level: 100%)
hash10001
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash1911
Meterpreter botnet C2 server (confidence level: 100%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash6969
Mirai botnet C2 server (confidence level: 100%)
hash6000
AsyncRAT botnet C2 server (confidence level: 100%)
hash42830
Remcos botnet C2 server (confidence level: 100%)
hash56999
Mirai botnet C2 server (confidence level: 80%)
hash777
Unknown Stealer botnet C2 server (confidence level: 100%)
hash808
Remcos botnet C2 server (confidence level: 100%)
hash5671
Remcos botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash1335
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash9308
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash80
Kimsuky botnet C2 server (confidence level: 50%)
hash20325
AsyncRAT botnet C2 server (confidence level: 50%)
hash40515
Nanocore RAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8000
Quasar RAT botnet C2 server (confidence level: 100%)
hash7000
Venom RAT botnet C2 server (confidence level: 100%)
hash7832
Quasar RAT botnet C2 server (confidence level: 100%)
hash1999
Mirai botnet C2 server (confidence level: 80%)
hash1914
Mirai botnet C2 server (confidence level: 80%)
hash5938
Remcos botnet C2 server (confidence level: 100%)
hash11613
Meterpreter botnet C2 server (confidence level: 100%)
hash4444
Meterpreter botnet C2 server (confidence level: 100%)
hash35005
Meterpreter botnet C2 server (confidence level: 100%)
hash2222
Meterpreter botnet C2 server (confidence level: 100%)
hash6703
Mirai botnet C2 server (confidence level: 100%)
hash1312
Mirai botnet C2 server (confidence level: 100%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash10011
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DanaBot botnet C2 server (confidence level: 75%)
hash53084
Sliver botnet C2 server (confidence level: 90%)
hash443
DCRat botnet C2 server (confidence level: 100%)
hash3001
Unknown malware botnet C2 server (confidence level: 100%)
hash4443
Sliver botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash2222
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Ghost RAT botnet C2 server (confidence level: 75%)
hash8081
Unknown malware botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash1912
RedLine Stealer botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://mac-os-helper.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://aiselfie.cam/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://eyota.com.sg/group/panelnew/gate.php
Pony botnet C2 (confidence level: 100%)
urlhttps://store-image.shop/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://vaer-cdn-3.sbs/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://image-hoster11.sbs/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://nstv-css-styles-19.sbs/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dltucra.com/data.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dltucra.com/data.zip
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dltucra.com/test.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dltucra.com/configpack.zip
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dltucra.com/helpu.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ldveriz.com/server.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dlderi.com/data.zip
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dlderi.com/configpack.zip
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://83.142.209.9/
Hook botnet C2 (confidence level: 50%)
urlhttp://139.59.119.89/ohshit.sh
Unknown malware payload delivery URL (confidence level: 75%)
urlhttp://143.92.60.26:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://eroticaforfree.com/nfront.php
Satacom botnet C2 (confidence level: 100%)
urlhttps://eroticaforfree.com/nback.php
Satacom botnet C2 (confidence level: 100%)

Threat ID: 699b9c51be58cf853bc9aa6a

Added to database: 2/23/2026, 12:16:17 AM

Last enriched: 2/23/2026, 12:16:26 AM

Last updated: 2/23/2026, 8:13:57 AM

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats