ThreatFox IOCs for 2026-02-22
ThreatFox IOCs for 2026-02-22
AI Analysis
Technical Summary
This entry from the ThreatFox MISP feed provides a collection of Indicators of Compromise (IOCs) related to malware activities focusing on OSINT (Open Source Intelligence), payload delivery mechanisms, and network activity. The data lacks specific affected software versions or detailed technical descriptions of the malware or attack vectors. No known exploits are reported in the wild, and no patches or remediation links are available, indicating this is likely an intelligence update rather than a newly discovered vulnerability or active attack campaign. The threat level is medium, suggesting moderate risk primarily from detection and response perspectives rather than immediate exploitation. The feed is tagged with TLP:WHITE, indicating the information is intended for public sharing and broad dissemination. The absence of CWEs and technical specifics limits the ability to perform deep technical analysis, but the presence of IOCs can assist security teams in enhancing their detection and monitoring capabilities for related malicious activity.
Potential Impact
Given the lack of specific exploit details or active attacks, the immediate impact on organizations worldwide is limited. However, the presence of new IOCs related to malware payload delivery and network activity indicates potential reconnaissance or preparatory stages of cyber threats. Organizations that do not incorporate updated threat intelligence feeds may miss early signs of emerging threats, potentially leading to delayed detection and response. The medium severity suggests that while the threat is not critical, it could contribute to successful attacks if combined with other vulnerabilities or social engineering tactics. The impact is primarily on security monitoring and incident response effectiveness rather than direct system compromise at this stage.
Mitigation Recommendations
Organizations should integrate ThreatFox and similar OSINT feeds into their Security Information and Event Management (SIEM) and threat detection platforms to leverage the provided IOCs for enhanced monitoring. Regularly updating detection rules and signatures based on these feeds can improve early warning capabilities. Conduct proactive network traffic analysis focusing on payload delivery patterns and suspicious network activity aligned with the IOCs. Employ threat hunting exercises to identify any signs of compromise related to the indicators. Maintain robust incident response plans to quickly address any alerts triggered by these IOCs. Since no patches are available, focus on detection and containment strategies rather than remediation. Collaboration with threat intelligence communities can provide additional context and updates.
Affected Countries
United States, United Kingdom, Germany, France, Canada, Australia, Japan, South Korea, India, Brazil
Indicators of Compromise
- domain: tightfeather.condenfeather.ru
- domain: clearscript.purecode.in.net
- file: 206.123.145.26
- hash: 1999
- url: https://mac-os-helper.com/
- domain: dutycourier.servantakeaway.ru
- file: 168.245.203.177
- hash: 3790
- file: 16.63.109.40
- hash: 3445
- file: 13.221.157.7
- hash: 15443
- file: 108.130.208.104
- hash: 44818
- domain: mildnode.mildtech.in.net
- domain: brightflash.neondata.in.net
- domain: glowbase.neondata.in.net
- domain: citypulse.neondata.in.net
- url: https://aiselfie.cam/
- domain: neonlink.neondata.in.net
- url: http://eyota.com.sg/group/panelnew/gate.php
- domain: dcenevinew.duckdns.org
- file: 8.131.77.227
- hash: 817
- file: 94.242.52.79
- hash: 443
- file: 46.246.86.9
- hash: 2003
- file: 79.107.150.203
- hash: 995
- file: 193.161.193.99
- hash: 40701
- domain: xoeyxsife-33031.portmap.host
- file: 192.227.219.75
- hash: 54301
- file: 198.135.54.85
- hash: 2404
- file: 149.50.96.57
- hash: 443
- file: 103.83.86.58
- hash: 80
- file: 102.98.95.49
- hash: 443
- file: 202.61.137.217
- hash: 4444
- file: 103.177.47.64
- hash: 3790
- file: 85.11.167.122
- hash: 443
- domain: quickpath.fastlink.in.net
- domain: speednode.fastlink.in.net
- domain: rapidcore.fastlink.in.net
- domain: fastexchange.fastlink.in.net
- domain: highrange.ultranet.in.net
- domain: superlink.ultranet.in.net
- domain: megastream.ultranet.in.net
- domain: amsholdings.ddns.net
- domain: swgtcampus0101.duckdns.org
- domain: toleskiki.ddnsgeek.com
- domain: egtwax65c.localto.net
- domain: resinwood.callresined.ru
- domain: mi9h8uf4.ironrock.digital
- domain: ojqxtq3l.ironrock.digital
- domain: ringplank.callresined.ru
- domain: desertwander.nomadsuppurat.ru
- domain: tribalpath.nomadsuppurat.ru
- domain: cheapnfljerseys-fromchina.us.com
- file: 1.94.40.59
- hash: 65534
- file: 5.89.184.32
- hash: 49151
- file: 150.139.136.86
- hash: 10001
- file: 122.225.30.63
- hash: 10001
- domain: steppejourney.nomadsuppurat.ru
- domain: yhhpswoa.forward3cross.digital
- domain: 0uwsxbye.forward3cross.digital
- file: 172.111.213.101
- hash: 1962
- file: 91.219.237.71
- hash: 80
- domain: wazuh.kokanddu.uz
- file: 103.177.47.91
- hash: 3790
- file: 103.177.47.96
- hash: 3790
- file: 18.212.63.218
- hash: 9142
- file: 58.244.42.108
- hash: 10001
- file: 103.177.47.99
- hash: 3790
- file: 54.147.162.161
- hash: 1911
- domain: oprc9zre.upgrade4file.digital
- domain: odbsasjd.upgrade4file.digital
- file: 47.57.1.21
- hash: 443
- file: 91.92.241.12
- hash: 6969
- domain: thespacemachines.st
- url: https://store-image.shop/api/css.js
- domain: store-image.shop
- url: https://vaer-cdn-3.sbs/api/css.js
- domain: vaer-cdn-3.sbs
- url: https://image-hoster11.sbs/api/css.js
- domain: image-hoster11.sbs
- url: https://nstv-css-styles-19.sbs/api/css.js
- domain: nstv-css-styles-19.sbs
- domain: dltucra.com
- url: https://dltucra.com/data.php
- url: https://dltucra.com/data.zip
- url: https://dltucra.com/test.php
- url: https://dltucra.com/configpack.zip
- url: https://dltucra.com/helpu.php
- domain: ldveriz.com
- url: https://ldveriz.com/server.php
- url: https://dlderi.com/data.zip
- url: https://dlderi.com/configpack.zip
- domain: 366kf0hf.up12file.digital
- domain: stormpanel.batenshutter.ru
- domain: thunderray.sa.com
- domain: slot-indonesia.jp.net
- domain: tbh.uk.com
- domain: vub.us.com
- file: 165.232.45.1
- hash: 6000
- file: 62.102.148.130
- hash: 42830
- file: 45.90.163.37
- hash: 56999
- domain: woodenlatch.batenshutter.ru
- domain: rainbarrier.batenshutter.ru
- domain: goldflake.orichsnow.ru
- file: 2.56.109.9
- hash: 777
- file: 4.193.136.158
- hash: 808
- file: 172.111.232.241
- hash: 5671
- file: 102.117.162.31
- hash: 7443
- file: 54.177.211.190
- hash: 1335
- domain: maxalaprod-64489.portmap.host
- domain: richfrost.orichsnow.ru
- domain: bozqk0kq.novacode.digital
- domain: r8ada0zp.novacode.digital
- domain: snowcrown.orichsnow.ru
- domain: pathfinder.exploratsinyuk.ru
- domain: trailquest.exploratsinyuk.ru
- file: 5.189.140.26
- hash: 443
- file: 34.253.217.85
- hash: 80
- file: 172.86.121.104
- hash: 443
- file: 123.31.11.7
- hash: 443
- file: 4.247.145.101
- hash: 31337
- file: 46.225.85.130
- hash: 31337
- file: 118.122.8.155
- hash: 9308
- file: 38.60.220.157
- hash: 80
- url: http://83.142.209.9/
- file: 147.45.245.42
- hash: 20325
- url: http://139.59.119.89/ohshit.sh
- domain: mapseeker.exploratsinyuk.ru
- domain: coreformula.inherentrecip.ru
- domain: innaterecipe.inherentrecip.ru
- domain: baseportion.inherentrecip.ru
- domain: graincontrol.brannysuppress.ru
- domain: maltguard.brannysuppress.ru
- domain: brewshield.brannysuppress.ru
- domain: minihouse.koreansmall.ru
- domain: littlemarket.koreansmall.ru
- file: 193.161.193.99
- hash: 40515
- domain: compactvillage.koreansmall.ru
- domain: 59xgjeq2.hexalink.digital
- domain: joieshk7.hexalink.digital
- domain: checktone.auditsounder.ru
- domain: verifyecho.auditsounder.ru
- domain: soundreview.auditsounder.ru
- domain: corenumber.arithmethair.in.net
- domain: digitflow.arithmethair.in.net
- domain: mathlogic.arithmethair.in.net
- domain: calcunit.arithmethair.in.net
- domain: darkport.detachfrigate.in.net
- domain: vesselhub.detachfrigate.in.net
- domain: oceanpoint.detachfrigate.in.net
- domain: autofinder.in.net
- file: 47.238.234.29
- hash: 443
- domain: xswdeu.za.com
- file: 185.196.8.208
- hash: 8000
- file: 198.135.54.88
- hash: 7000
- file: 194.169.160.12
- hash: 7832
- domain: cursednetwork.ru
- domain: povermnebrat.ru
- domain: shipnode.detachfrigate.in.net
- domain: heropath.shratsurvivor.in.net
- file: 176.65.148.52
- hash: 1999
- domain: 176.65.148.52.ptr.pfcloud.network
- file: 176.65.148.52
- hash: 1914
- domain: hardlife.shratsurvivor.in.net
- domain: wildhunt.shratsurvivor.in.net
- domain: laststand.shratsurvivor.in.net
- domain: oldcore.solidyears.in.net
- domain: basepoint.solidyears.in.net
- domain: longroad.solidyears.in.net
- domain: hardrock.solidyears.in.net
- domain: finalgate.afterlifetap.in.net
- domain: spiritlink.afterlifetap.in.net
- domain: beyondbase.afterlifetap.in.net
- domain: soultrack.afterlifetap.in.net
- domain: daytrace.hourillusion.in.net
- url: http://143.92.60.26:8888/supershell/login/
- file: 74.118.172.190
- hash: 5938
- domain: bkns-prtner.com
- domain: shiftview.hourillusion.in.net
- file: 3.104.47.154
- hash: 11613
- file: 168.119.50.34
- hash: 4444
- file: 51.85.37.194
- hash: 35005
- file: 196.75.55.17
- hash: 2222
- domain: immortal-service.cc
- domain: critical-service.cc
- domain: fileless-market.cc
- domain: indeanapolice.cc
- domain: globalsnn2-new.cc
- domain: globalsnn10-new.cc
- domain: globalsnn1-new.cc
- domain: globalsnn3-new.cc
- domain: globalsnn4-new.cc
- domain: globalsnn5-new.cc
- domain: globalsnn6-new.cc
- domain: globalsnn7-new.cc
- domain: globalsnn8-new.cc
- domain: globalsnn9-new.cc
- domain: globalsnn-new.cc
- domain: api-microservice-us1.com
- domain: api-microservice-us10.com
- domain: api-microservice-us2.com
- domain: api-microservice-us3.com
- domain: api-microservice-us4.com
- domain: api-microservice-us5.com
- domain: api-microservice-us6.com
- domain: api-microservice-us7.com
- domain: api-microservice-us8.com
- domain: api-microservice-us9.com
- domain: alphazero10-endscape.cc
- domain: alphazero1-endscape.cc
- domain: alphazero2-endscape.cc
- domain: alphazero3-endscape.cc
- domain: alphazero4-endscape.cc
- domain: alphazero5-endscape.cc
- domain: alphazero6-endscape.cc
- domain: alphazero7-endscape.cc
- domain: alphazero8-endscape.cc
- domain: alphazero9-endscape.cc
- domain: alphazero-endscape.cc
- domain: watchpoint.hourillusion.in.net
- url: https://eroticaforfree.com/nfront.php
- url: https://eroticaforfree.com/nback.php
- domain: timeloop.hourillusion.in.net
- domain: tasknode.baskadubutil.in.net
- domain: maintool.baskadubutil.in.net
- domain: servicedesk.baskadubutil.in.net
- domain: utilsync.baskadubutil.in.net
- domain: leadgroup.chelnperson.in.net
- domain: humanunit.chelnperson.in.net
- domain: workforce.chelnperson.in.net
- domain: staffbase.chelnperson.in.net
- file: 144.31.203.91
- hash: 6703
- file: 172.96.14.105
- hash: 1312
- domain: bot.1756520.xyz
- domain: authpoint.approvkrup.in.net
- domain: magiablackgold.com
- domain: finalstep.approvkrup.in.net
- domain: applynow.approvkrup.in.net
- domain: checkstatus.approvkrup.in.net
- domain: ultranode.ultranet.in.net
- domain: money.bullishcoder.com
- domain: centralcloudservice.lubginany.in.net
- domain: networkdatamanager.lubginany.in.net
- domain: idk123456789012-51385.portmap.host
- domain: secureaccesspoint.lubginany.in.net
- domain: 5z6y8mkfe.localto.net
- domain: internalnodepoint.lubginany.in.net
- domain: mananta.es
- domain: complexlogicstream.intricessaucy.in.net
- domain: advancedsystrace.intricessaucy.in.net
- file: 144.7.95.161
- hash: 10250
- file: 18.253.110.70
- hash: 443
- file: 185.45.195.85
- hash: 443
- file: 65.153.151.164
- hash: 10011
- file: 91.202.3.5
- hash: 443
- domain: globalsynchandler.intricessaucy.in.net
- domain: win-system-update.me
- file: 45.93.31.198
- hash: 53084
- domain: godisgreatmygood.duckdns.org
- domain: greatmindworkingunison.duckdns.org
- domain: revlonducussdmg.duckdns.org
- file: 69.167.10.201
- hash: 443
- file: 72.61.158.123
- hash: 3001
- domain: remotedatachannel.intricessaucy.in.net
- domain: flightcontrolcenter.aircraftmodel.in.net
- domain: maniariup.com
- domain: aerospaceviewport.aircraftmodel.in.net
- domain: manolocorretora.com.br
- domain: navigationsysunit.aircraftmodel.in.net
- domain: technicalsupportbox.aircraftmodel.in.net
- file: 20.173.41.169
- hash: 4443
- file: 143.92.60.13
- hash: 8888
- file: 141.140.0.147
- hash: 8808
- domain: auth.mercadolivreshop.shop
- file: 165.245.186.179
- hash: 2222
- domain: activestatushub.snoozetrap.in.net
- domain: silenttriggerbase.snoozetrap.in.net
- domain: manutecaowebsites.creativexspot.com
- domain: backgroundprocess.snoozetrap.in.net
- domain: monitoringservice.snoozetrap.in.net
- domain: deploymentsystems.implementnega.in.net
- domain: applicationbackup.implementnega.in.net
- domain: coreintegratednode.implementnega.in.net
- domain: processvalidation.implementnega.in.net
- domain: infrastructure-service.urbanlake.ru
- domain: xlyxmzlj2.localto.net
- domain: kugo.it.com
- domain: analytics.qzz.io
- file: 45.64.52.154
- hash: 8080
- domain: tahtam.dynv6.net
- file: 185.199.52.247
- hash: 8081
- file: 83.142.209.3
- hash: 8089
- domain: bbb.mercadolivreshop.shop
- file: 212.3.142.177
- hash: 1912
- domain: city-management-portal.urbanlake.ru
- domain: central-hub-access.urbanlake.ru
- domain: public-gateway-alpha.urbanlake.ru
ThreatFox IOCs for 2026-02-22
Description
ThreatFox IOCs for 2026-02-22
AI-Powered Analysis
Technical Analysis
This entry from the ThreatFox MISP feed provides a collection of Indicators of Compromise (IOCs) related to malware activities focusing on OSINT (Open Source Intelligence), payload delivery mechanisms, and network activity. The data lacks specific affected software versions or detailed technical descriptions of the malware or attack vectors. No known exploits are reported in the wild, and no patches or remediation links are available, indicating this is likely an intelligence update rather than a newly discovered vulnerability or active attack campaign. The threat level is medium, suggesting moderate risk primarily from detection and response perspectives rather than immediate exploitation. The feed is tagged with TLP:WHITE, indicating the information is intended for public sharing and broad dissemination. The absence of CWEs and technical specifics limits the ability to perform deep technical analysis, but the presence of IOCs can assist security teams in enhancing their detection and monitoring capabilities for related malicious activity.
Potential Impact
Given the lack of specific exploit details or active attacks, the immediate impact on organizations worldwide is limited. However, the presence of new IOCs related to malware payload delivery and network activity indicates potential reconnaissance or preparatory stages of cyber threats. Organizations that do not incorporate updated threat intelligence feeds may miss early signs of emerging threats, potentially leading to delayed detection and response. The medium severity suggests that while the threat is not critical, it could contribute to successful attacks if combined with other vulnerabilities or social engineering tactics. The impact is primarily on security monitoring and incident response effectiveness rather than direct system compromise at this stage.
Mitigation Recommendations
Organizations should integrate ThreatFox and similar OSINT feeds into their Security Information and Event Management (SIEM) and threat detection platforms to leverage the provided IOCs for enhanced monitoring. Regularly updating detection rules and signatures based on these feeds can improve early warning capabilities. Conduct proactive network traffic analysis focusing on payload delivery patterns and suspicious network activity aligned with the IOCs. Employ threat hunting exercises to identify any signs of compromise related to the indicators. Maintain robust incident response plans to quickly address any alerts triggered by these IOCs. Since no patches are available, focus on detection and containment strategies rather than remediation. Collaboration with threat intelligence communities can provide additional context and updates.
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- b30f6cd0-7820-48cc-bd33-2995468a9dfc
- Original Timestamp
- 1771804987
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaintightfeather.condenfeather.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainclearscript.purecode.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindutycourier.servantakeaway.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmildnode.mildtech.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrightflash.neondata.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainglowbase.neondata.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincitypulse.neondata.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainneonlink.neondata.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindcenevinew.duckdns.org | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainxoeyxsife-33031.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainquickpath.fastlink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainspeednode.fastlink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainrapidcore.fastlink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfastexchange.fastlink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainhighrange.ultranet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsuperlink.ultranet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmegastream.ultranet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainamsholdings.ddns.net | Remcos botnet C2 domain (confidence level: 75%) | |
domainswgtcampus0101.duckdns.org | Remcos botnet C2 domain (confidence level: 75%) | |
domaintoleskiki.ddnsgeek.com | Remcos botnet C2 domain (confidence level: 75%) | |
domainegtwax65c.localto.net | XWorm botnet C2 domain (confidence level: 100%) | |
domainresinwood.callresined.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmi9h8uf4.ironrock.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainojqxtq3l.ironrock.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainringplank.callresined.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindesertwander.nomadsuppurat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintribalpath.nomadsuppurat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincheapnfljerseys-fromchina.us.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainsteppejourney.nomadsuppurat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainyhhpswoa.forward3cross.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domain0uwsxbye.forward3cross.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainwazuh.kokanddu.uz | Havoc botnet C2 domain (confidence level: 100%) | |
domainoprc9zre.upgrade4file.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainodbsasjd.upgrade4file.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainthespacemachines.st | Mirai botnet C2 domain (confidence level: 100%) | |
domainstore-image.shop | Unknown malware payload delivery domain (confidence level: 100%) | |
domainvaer-cdn-3.sbs | Unknown malware payload delivery domain (confidence level: 100%) | |
domainimage-hoster11.sbs | Unknown malware payload delivery domain (confidence level: 100%) | |
domainnstv-css-styles-19.sbs | Unknown malware payload delivery domain (confidence level: 100%) | |
domaindltucra.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainldveriz.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domain366kf0hf.up12file.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainstormpanel.batenshutter.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainthunderray.sa.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainslot-indonesia.jp.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaintbh.uk.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainvub.us.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainwoodenlatch.batenshutter.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrainbarrier.batenshutter.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingoldflake.orichsnow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmaxalaprod-64489.portmap.host | Nanocore RAT botnet C2 domain (confidence level: 100%) | |
domainrichfrost.orichsnow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbozqk0kq.novacode.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainr8ada0zp.novacode.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainsnowcrown.orichsnow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpathfinder.exploratsinyuk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintrailquest.exploratsinyuk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmapseeker.exploratsinyuk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincoreformula.inherentrecip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaininnaterecipe.inherentrecip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbaseportion.inherentrecip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingraincontrol.brannysuppress.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmaltguard.brannysuppress.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrewshield.brannysuppress.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainminihouse.koreansmall.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlittlemarket.koreansmall.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincompactvillage.koreansmall.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain59xgjeq2.hexalink.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainjoieshk7.hexalink.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainchecktone.auditsounder.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainverifyecho.auditsounder.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsoundreview.auditsounder.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincorenumber.arithmethair.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindigitflow.arithmethair.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmathlogic.arithmethair.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincalcunit.arithmethair.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindarkport.detachfrigate.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvesselhub.detachfrigate.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainoceanpoint.detachfrigate.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainautofinder.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainxswdeu.za.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaincursednetwork.ru | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainpovermnebrat.ru | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainshipnode.detachfrigate.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainheropath.shratsurvivor.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain176.65.148.52.ptr.pfcloud.network | Mirai botnet C2 domain (confidence level: 80%) | |
domainhardlife.shratsurvivor.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwildhunt.shratsurvivor.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlaststand.shratsurvivor.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainoldcore.solidyears.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbasepoint.solidyears.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlongroad.solidyears.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainhardrock.solidyears.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfinalgate.afterlifetap.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainspiritlink.afterlifetap.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbeyondbase.afterlifetap.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsoultrack.afterlifetap.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindaytrace.hourillusion.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbkns-prtner.com | Havoc botnet C2 domain (confidence level: 100%) | |
domainshiftview.hourillusion.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainimmortal-service.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domaincritical-service.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainfileless-market.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainindeanapolice.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainglobalsnn2-new.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainglobalsnn10-new.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainglobalsnn1-new.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainglobalsnn3-new.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainglobalsnn4-new.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainglobalsnn5-new.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainglobalsnn6-new.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainglobalsnn7-new.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainglobalsnn8-new.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainglobalsnn9-new.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainglobalsnn-new.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainapi-microservice-us1.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainapi-microservice-us10.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainapi-microservice-us2.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainapi-microservice-us3.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainapi-microservice-us4.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainapi-microservice-us5.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainapi-microservice-us6.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainapi-microservice-us7.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainapi-microservice-us8.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainapi-microservice-us9.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainalphazero10-endscape.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainalphazero1-endscape.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainalphazero2-endscape.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainalphazero3-endscape.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainalphazero4-endscape.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainalphazero5-endscape.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainalphazero6-endscape.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainalphazero7-endscape.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainalphazero8-endscape.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainalphazero9-endscape.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainalphazero-endscape.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainwatchpoint.hourillusion.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintimeloop.hourillusion.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintasknode.baskadubutil.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmaintool.baskadubutil.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainservicedesk.baskadubutil.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainutilsync.baskadubutil.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainleadgroup.chelnperson.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainhumanunit.chelnperson.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainworkforce.chelnperson.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainstaffbase.chelnperson.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbot.1756520.xyz | Mirai botnet C2 domain (confidence level: 100%) | |
domainauthpoint.approvkrup.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmagiablackgold.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainfinalstep.approvkrup.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainapplynow.approvkrup.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincheckstatus.approvkrup.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainultranode.ultranet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoney.bullishcoder.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domaincentralcloudservice.lubginany.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnetworkdatamanager.lubginany.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainidk123456789012-51385.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainsecureaccesspoint.lubginany.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain5z6y8mkfe.localto.net | SpyNote botnet C2 domain (confidence level: 100%) | |
domaininternalnodepoint.lubginany.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmananta.es | StrelaStealer payload delivery domain (confidence level: 100%) | |
domaincomplexlogicstream.intricessaucy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainadvancedsystrace.intricessaucy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainglobalsynchandler.intricessaucy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwin-system-update.me | Cobalt Strike botnet C2 domain (confidence level: 100%) | |
domaingodisgreatmygood.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domaingreatmindworkingunison.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainrevlonducussdmg.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainremotedatachannel.intricessaucy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainflightcontrolcenter.aircraftmodel.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmaniariup.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainaerospaceviewport.aircraftmodel.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmanolocorretora.com.br | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainnavigationsysunit.aircraftmodel.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintechnicalsupportbox.aircraftmodel.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainauth.mercadolivreshop.shop | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainactivestatushub.snoozetrap.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsilenttriggerbase.snoozetrap.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmanutecaowebsites.creativexspot.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainbackgroundprocess.snoozetrap.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmonitoringservice.snoozetrap.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindeploymentsystems.implementnega.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainapplicationbackup.implementnega.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincoreintegratednode.implementnega.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainprocessvalidation.implementnega.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaininfrastructure-service.urbanlake.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxlyxmzlj2.localto.net | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domainkugo.it.com | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domainanalytics.qzz.io | Cobalt Strike botnet C2 domain (confidence level: 100%) | |
domaintahtam.dynv6.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainbbb.mercadolivreshop.shop | Unknown malware botnet C2 domain (confidence level: 100%) | |
domaincity-management-portal.urbanlake.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincentral-hub-access.urbanlake.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpublic-gateway-alpha.urbanlake.ru | ClearFake payload delivery domain (confidence level: 100%) |
File
| Value | Description | Copy |
|---|---|---|
file206.123.145.26 | Mirai botnet C2 server (confidence level: 80%) | |
file168.245.203.177 | Meterpreter botnet C2 server (confidence level: 100%) | |
file16.63.109.40 | Meterpreter botnet C2 server (confidence level: 100%) | |
file13.221.157.7 | Meterpreter botnet C2 server (confidence level: 100%) | |
file108.130.208.104 | Meterpreter botnet C2 server (confidence level: 100%) | |
file8.131.77.227 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file94.242.52.79 | Unknown malware botnet C2 server (confidence level: 100%) | |
file46.246.86.9 | DCRat botnet C2 server (confidence level: 100%) | |
file79.107.150.203 | QakBot botnet C2 server (confidence level: 100%) | |
file193.161.193.99 | XWorm botnet C2 server (confidence level: 100%) | |
file192.227.219.75 | Remcos botnet C2 server (confidence level: 100%) | |
file198.135.54.85 | Remcos botnet C2 server (confidence level: 100%) | |
file149.50.96.57 | Remcos botnet C2 server (confidence level: 100%) | |
file103.83.86.58 | Remcos botnet C2 server (confidence level: 100%) | |
file102.98.95.49 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file202.61.137.217 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file103.177.47.64 | Meterpreter botnet C2 server (confidence level: 100%) | |
file85.11.167.122 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file1.94.40.59 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file5.89.184.32 | Unknown malware botnet C2 server (confidence level: 100%) | |
file150.139.136.86 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
file122.225.30.63 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
file172.111.213.101 | Remcos botnet C2 server (confidence level: 100%) | |
file91.219.237.71 | Sliver botnet C2 server (confidence level: 100%) | |
file103.177.47.91 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.47.96 | Meterpreter botnet C2 server (confidence level: 100%) | |
file18.212.63.218 | Meterpreter botnet C2 server (confidence level: 100%) | |
file58.244.42.108 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.47.99 | Meterpreter botnet C2 server (confidence level: 100%) | |
file54.147.162.161 | Meterpreter botnet C2 server (confidence level: 100%) | |
file47.57.1.21 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file91.92.241.12 | Mirai botnet C2 server (confidence level: 100%) | |
file165.232.45.1 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file62.102.148.130 | Remcos botnet C2 server (confidence level: 100%) | |
file45.90.163.37 | Mirai botnet C2 server (confidence level: 80%) | |
file2.56.109.9 | Unknown Stealer botnet C2 server (confidence level: 100%) | |
file4.193.136.158 | Remcos botnet C2 server (confidence level: 100%) | |
file172.111.232.241 | Remcos botnet C2 server (confidence level: 100%) | |
file102.117.162.31 | Unknown malware botnet C2 server (confidence level: 100%) | |
file54.177.211.190 | Meterpreter botnet C2 server (confidence level: 100%) | |
file5.189.140.26 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file34.253.217.85 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file172.86.121.104 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file123.31.11.7 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file4.247.145.101 | Sliver botnet C2 server (confidence level: 50%) | |
file46.225.85.130 | Sliver botnet C2 server (confidence level: 50%) | |
file118.122.8.155 | NetSupportManager RAT botnet C2 server (confidence level: 50%) | |
file38.60.220.157 | Kimsuky botnet C2 server (confidence level: 50%) | |
file147.45.245.42 | AsyncRAT botnet C2 server (confidence level: 50%) | |
file193.161.193.99 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
file47.238.234.29 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file185.196.8.208 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file198.135.54.88 | Venom RAT botnet C2 server (confidence level: 100%) | |
file194.169.160.12 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file176.65.148.52 | Mirai botnet C2 server (confidence level: 80%) | |
file176.65.148.52 | Mirai botnet C2 server (confidence level: 80%) | |
file74.118.172.190 | Remcos botnet C2 server (confidence level: 100%) | |
file3.104.47.154 | Meterpreter botnet C2 server (confidence level: 100%) | |
file168.119.50.34 | Meterpreter botnet C2 server (confidence level: 100%) | |
file51.85.37.194 | Meterpreter botnet C2 server (confidence level: 100%) | |
file196.75.55.17 | Meterpreter botnet C2 server (confidence level: 100%) | |
file144.31.203.91 | Mirai botnet C2 server (confidence level: 100%) | |
file172.96.14.105 | Mirai botnet C2 server (confidence level: 100%) | |
file144.7.95.161 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file18.253.110.70 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file185.45.195.85 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file65.153.151.164 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file91.202.3.5 | DanaBot botnet C2 server (confidence level: 75%) | |
file45.93.31.198 | Sliver botnet C2 server (confidence level: 90%) | |
file69.167.10.201 | DCRat botnet C2 server (confidence level: 100%) | |
file72.61.158.123 | Unknown malware botnet C2 server (confidence level: 100%) | |
file20.173.41.169 | Sliver botnet C2 server (confidence level: 100%) | |
file143.92.60.13 | Unknown malware botnet C2 server (confidence level: 100%) | |
file141.140.0.147 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file165.245.186.179 | Unknown malware botnet C2 server (confidence level: 100%) | |
file45.64.52.154 | Ghost RAT botnet C2 server (confidence level: 75%) | |
file185.199.52.247 | Unknown malware botnet C2 server (confidence level: 100%) | |
file83.142.209.3 | Hook botnet C2 server (confidence level: 100%) | |
file212.3.142.177 | RedLine Stealer botnet C2 server (confidence level: 100%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash1999 | Mirai botnet C2 server (confidence level: 80%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3445 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash15443 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash44818 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash817 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash2003 | DCRat botnet C2 server (confidence level: 100%) | |
hash995 | QakBot botnet C2 server (confidence level: 100%) | |
hash40701 | XWorm botnet C2 server (confidence level: 100%) | |
hash54301 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Remcos botnet C2 server (confidence level: 100%) | |
hash80 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash4444 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash443 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash65534 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash49151 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash10001 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
hash10001 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
hash1962 | Remcos botnet C2 server (confidence level: 100%) | |
hash80 | Sliver botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash9142 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash10001 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash1911 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash6969 | Mirai botnet C2 server (confidence level: 100%) | |
hash6000 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash42830 | Remcos botnet C2 server (confidence level: 100%) | |
hash56999 | Mirai botnet C2 server (confidence level: 80%) | |
hash777 | Unknown Stealer botnet C2 server (confidence level: 100%) | |
hash808 | Remcos botnet C2 server (confidence level: 100%) | |
hash5671 | Remcos botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash1335 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash9308 | NetSupportManager RAT botnet C2 server (confidence level: 50%) | |
hash80 | Kimsuky botnet C2 server (confidence level: 50%) | |
hash20325 | AsyncRAT botnet C2 server (confidence level: 50%) | |
hash40515 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8000 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash7000 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash7832 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash1999 | Mirai botnet C2 server (confidence level: 80%) | |
hash1914 | Mirai botnet C2 server (confidence level: 80%) | |
hash5938 | Remcos botnet C2 server (confidence level: 100%) | |
hash11613 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash4444 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash35005 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash2222 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash6703 | Mirai botnet C2 server (confidence level: 100%) | |
hash1312 | Mirai botnet C2 server (confidence level: 100%) | |
hash10250 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash10011 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | DanaBot botnet C2 server (confidence level: 75%) | |
hash53084 | Sliver botnet C2 server (confidence level: 90%) | |
hash443 | DCRat botnet C2 server (confidence level: 100%) | |
hash3001 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash4443 | Sliver botnet C2 server (confidence level: 100%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash2222 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8080 | Ghost RAT botnet C2 server (confidence level: 75%) | |
hash8081 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8089 | Hook botnet C2 server (confidence level: 100%) | |
hash1912 | RedLine Stealer botnet C2 server (confidence level: 100%) |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://mac-os-helper.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://aiselfie.cam/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttp://eyota.com.sg/group/panelnew/gate.php | Pony botnet C2 (confidence level: 100%) | |
urlhttps://store-image.shop/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://vaer-cdn-3.sbs/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://image-hoster11.sbs/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://nstv-css-styles-19.sbs/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dltucra.com/data.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dltucra.com/data.zip | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dltucra.com/test.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dltucra.com/configpack.zip | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dltucra.com/helpu.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://ldveriz.com/server.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dlderi.com/data.zip | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dlderi.com/configpack.zip | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://83.142.209.9/ | Hook botnet C2 (confidence level: 50%) | |
urlhttp://139.59.119.89/ohshit.sh | Unknown malware payload delivery URL (confidence level: 75%) | |
urlhttp://143.92.60.26:8888/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://eroticaforfree.com/nfront.php | Satacom botnet C2 (confidence level: 100%) | |
urlhttps://eroticaforfree.com/nback.php | Satacom botnet C2 (confidence level: 100%) |
Threat ID: 699b9c51be58cf853bc9aa6a
Added to database: 2/23/2026, 12:16:17 AM
Last enriched: 2/23/2026, 12:16:26 AM
Last updated: 2/23/2026, 8:13:57 AM
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.