ThreatFox IOCs for 2026-03-09
ThreatFox IOCs for 2026-03-09
AI Analysis
Technical Summary
The entry titled 'ThreatFox IOCs for 2026-03-09' originates from the ThreatFox MISP feed, which is a platform for sharing threat intelligence, particularly Indicators of Compromise (IOCs). The threat is classified as malware related to OSINT (Open Source Intelligence), payload delivery, and network activity. Despite being labeled as a medium severity threat, the record contains no specific affected software versions, no CVEs or CWEs, no known exploits in the wild, and no patch availability. The technical details include a low threat level (2 out of an unspecified scale), minimal analysis (1), and moderate distribution (3), but no concrete indicators or payload descriptions are provided. The tags and categories suggest this entry is more of an intelligence update or a collection of IOCs rather than a detailed vulnerability or active exploit. The lack of actionable technical data limits the ability to perform a deep technical analysis or to understand the exact nature of the malware or its delivery mechanisms.
Potential Impact
Due to the absence of detailed information on the malware's capabilities, affected systems, or exploitation methods, the potential impact remains unclear. The medium severity rating suggests some risk, but without specifics, it is difficult to assess the threat's effect on confidentiality, integrity, or availability. Organizations worldwide could theoretically be impacted if the malware targets widely used systems or networks, but no evidence supports active exploitation or widespread distribution. The lack of known exploits and patches indicates this may be an emerging or low-activity threat, or simply an intelligence collection without immediate operational impact.
Mitigation Recommendations
Given the limited information, organizations should focus on general best practices for malware defense and OSINT monitoring: 1) Maintain updated endpoint protection and network monitoring tools capable of detecting unusual payload delivery and network activity. 2) Integrate ThreatFox and other threat intelligence feeds into security information and event management (SIEM) systems to enhance detection capabilities. 3) Conduct regular threat hunting exercises focusing on network anomalies and suspicious payloads. 4) Educate security teams on interpreting and leveraging OSINT-based threat intelligence. 5) Maintain robust incident response plans to quickly address any emerging threats identified through updated intelligence. Since no patches or specific exploits are known, no targeted remediation is currently possible.
Affected Countries
United States, Germany, United Kingdom, France, Canada, Australia, Japan, South Korea, Netherlands, Sweden
Indicators of Compromise
- domain: good-gate.goodtime.in.net
- url: https://www.ulfhedinnvikings.com/
- domain: kirk-service.live
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/mzcxijwx2zg9e7w
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/ejk52zwt2js16ro
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/6v0tazc5mboxujs
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/q7cherolivolejk
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/iro9a3cp6zsd230
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/ujgti3g12f45y74
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/m3o1azkhufs1enk
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/y74habwtyvsxarw
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/a7k56jotufo5ab4
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/2vk56j8h27whyzg
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/6v4de3o1yz0du7k
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/yzc5yj81yv0h2fw
- url: http://kirk-service.live/6e07a7147a15224446034debd2d1288b/ufcx6bc1ef45e7g
- url: http://kirk-service.live/reconcile
- domain: crispy-rusty.com
- url: https://crispy-rusty.com/
- domain: ford-sync.ironford.in.net
- domain: gate-v05.lakegate.in.net
- url: http://83.142.209.47/x
- domain: gennods.cyou
- domain: brocaez.club
- domain: familbg.club
- domain: mobbyyt.club
- file: 31.57.216.128
- hash: 2404
- file: 5.206.227.239
- hash: 2404
- file: 146.103.106.71
- hash: 443
- file: 38.242.144.218
- hash: 7755
- file: 102.117.160.235
- hash: 7443
- file: 79.135.160.20
- hash: 7443
- file: 8.138.0.148
- hash: 7443
- file: 144.31.164.198
- hash: 80
- file: 45.158.196.14
- hash: 4321
- file: 196.75.62.145
- hash: 2222
- file: 168.245.203.193
- hash: 3790
- file: 188.137.228.57
- hash: 1337
- domain: nbdeco.fr
- domain: clay-logic.redclay.in.net
- domain: red-v09.redclay.in.net
- domain: clay-gate.redclay.in.net
- domain: red-unit.redclay.in.net
- domain: bend-ref.oakbend.in.net
- domain: nearchos-akte.gr
- domain: oak-v11.oakbend.in.net
- domain: bend-base.oakbend.in.net
- domain: oak-net.oakbend.in.net
- domain: neckaralb.digital
- domain: neighborhoodroofingllc.com
- domain: vult-node.nexoris.in.net
- domain: nex-v01.nexoris.in.net
- domain: nekoamerikaheiku.info
- domain: vult-sync.nexoris.in.net
- domain: nex-base.nexoris.in.net
- domain: alt-hub.zenithra.in.net
- domain: neuroconsultas.pt
- domain: new.avtograf.ee
- domain: zen-v12.zenithra.in.net
- domain: new.tsypin.partners
- domain: alt-net.zenithra.in.net
- domain: zen-flow.zenithra.in.net
- domain: ops-gate.lumitron.in.net
- domain: newenergypartnership.com
- domain: lumi-v3.lumitron.in.net
- domain: newlinekitchens.hdps.co.za
- domain: mpt.pedagogiai-tarsasag.hu
- domain: ops-unit.lumitron.in.net
- domain: naosagioulouka.gr
- domain: lumi-edge.lumitron.in.net
- domain: dist-core.veloxis.in.net
- domain: nevikup.com
- domain: auraplay.vip
- file: 101.32.36.2
- hash: 80
- file: 101.34.203.51
- hash: 8007
- url: https://cdn-us-cloudflare-services.t3.storage.dev/follow/index.html?x-amz-algorithm=aws4-hmac-sha256&x-amz-credential=tid_ydatdzfwt_hunghpsgltcegtzeeiwhetiouwdibgulkrrlknws%2f20260308%2fauto%2fs3%2faws4_request&x-amz-date=20260308t175148z&x-amz-expires=172800&x-amz-signedheaders=host&x-amz-signature=ffdb4b5c5e00d0d24ba730369686eba47c5bf55f2d83780482e67a0b03ebe2c0
- file: 45.74.48.72
- hash: 443
- file: 178.16.52.36
- hash: 2121
- file: 38.54.6.205
- hash: 8888
- file: 136.0.213.192
- hash: 8808
- file: 138.197.35.236
- hash: 443
- domain: avlc2.westus2.cloudapp.azure.com
- file: 151.240.151.123
- hash: 80
- file: 103.177.47.49
- hash: 3790
- domain: newproject1.dashop.tech
- domain: news.mohitrathi.in
- domain: newsite.lbgresearch.org
- domain: vel-v44.veloxis.in.net
- url: http://85.28.47.152
- domain: newtli.theteambuilderadrc.com
- url: http://192.168.2.53:80/am8w
- domain: dist-sync.veloxis.in.net
- domain: newvermont.fairgoseo.com.au
- domain: vel-data.veloxis.in.net
- url: https://next-step-n4.t3.storage.dev/index.html?x-amz-algorithm=aws4-hmac-sha256&x-amz-credential=tid_wnnisps__tskokdg_uwkaghhuvhbcshbutgbmxtaqtxsqtrdfy/20260308/auto/s3/aws4_request&x-amz-date=20260308t012517z&x-amz-expires=2160000&x-amz-signedhe
- domain: bit-vault.cryptixy.in.net
- file: 195.24.237.47
- hash: 80
- domain: nexoeasy-88.com
- domain: cryp-v05.cryptixy.in.net
- file: 91.219.239.7
- hash: 8080
- domain: bit-hub.cryptixy.in.net
- domain: nexxusmanagement.com
- domain: cryp-node.cryptixy.in.net
- domain: main-peak.solarisx.in.net
- domain: nflug.com
- domain: sol-v6.solarisx.in.net
- domain: main-sys.solarisx.in.net
- domain: sol-base.solarisx.in.net
- domain: bigbrainsholdings.com
- domain: debank-api.cc
- domain: magnusworkspace.com
- domain: node2-py-store.com
- domain: py-installer.cc
- domain: s1-rarlab.com
- domain: s3-python.cc
- domain: updateservice1-telegramweb.com
- domain: web3-walletnotify.cc
- file: 64.225.39.118
- hash: 8443
- file: 178.16.55.119
- hash: 9000
- file: 94.72.122.1
- hash: 7443
- file: 40.233.14.199
- hash: 7443
- file: 41.216.188.35
- hash: 4782
- file: 103.177.47.97
- hash: 3790
- file: 103.177.47.109
- hash: 3790
- file: 103.177.47.121
- hash: 3790
- file: 103.177.47.73
- hash: 3790
- domain: ngoaithatnhatban.vn
- domain: site-node.terravia.in.net
- file: 123.56.52.156
- hash: 8888
- file: 172.245.126.52
- hash: 443
- domain: terr-v77.terravia.in.net
- domain: site-net.terravia.in.net
- domain: terr-run.terravia.in.net
- domain: 11uttaq1.bitterfisherm.digital
- domain: ovbfopy8.bitterfisherm.digital
- url: http://45.156.87.17/reg
- domain: term-way.niventa.in.net
- domain: niv-v08.niventa.in.net
- domain: term-sync.niventa.in.net
- domain: mullenpalimpseststudio.com
- domain: niv-flow.niventa.in.net
- domain: wriconsult.com
- domain: link-logic.astronis.in.net
- domain: oakumsnarrowboats.com
- url: https://64.95.10.115:23011/update.sh
- url: https://temp.sh/tqtss/storm.exe
- domain: arlingtonheightsgaragedoors.com
- file: 179.43.166.147
- hash: 8084
- file: 64.95.10.115
- hash: 23011
- domain: invitoenergypartners.com
- hash: 9f431d5549a03aee92cfd2bdbbe90f1c91e965c99e90a0c9ad5a001f4e80c350
- hash: 98a7b0900a9072bb40af579ec372da7b27af12b15868394df51fefe290ab176b
- hash: 66cceb2c2f1d9988b501832fd3b559775982e2fce4ab38fc4ffe71b74eafc726
- hash: 679ee05d92a858b6fe70aeb6072eb804548f1732e18b6c181af122b833386afb
- hash: 4762e944a0ce1f9aef243e11538f84f16b6f36560ed6e32dfd9a5f99e17e8e50
- hash: 98442387d466f27357d727b3706037a4df12a78602b93df973b063462a677761
- hash: cc2bc3750cc5125a50466f66ae4f2bedf1cac0e43477a78ed2fd88f3e987a292
- hash: cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce
- hash: 0ecc867ce916d01640d76ec03de24d1d23585eb582e9c48a0364c62a590548ac
- domain: fraziewealthmanagement.com
- file: 134.122.13.34
- hash: 8979
- file: 138.197.14.95
- hash: 80
- domain: northernvirginiapainting.com
- url: http://vrf.cldvrfd.click/u323245/local3.txt
- domain: vrf.cldvrfd.click
- domain: tkmfinancialservices.com
- domain: astro-v09.astronis.in.net
- domain: newyorkcitybrandingagency.com
- domain: link-gate.astronis.in.net
- domain: astro-unit.astronis.in.net
- domain: tech-ref.moxura.in.net
- domain: mox-v11.moxura.in.net
- file: 45.32.113.200
- hash: 8084
- file: 182.16.76.2
- hash: 8001
- domain: tech-base.moxura.in.net
- file: 107.189.16.142
- hash: 443
- domain: mentaorb.com
- domain: mox-net.moxura.in.net
- domain: jaxfamilylawyers.com
- url: https://steamcommunity.com/profiles/76561198732393960
- url: https://telegram.me/k33dro
- url: https://ooe.myserver.com.bd/
- url: https://ooe.digitalmatters360.com/
- url: https://del.nexs.com.bd/
- url: https://ftx.nexs.com.bd/
- url: https://gpa.nexs.com.bd/
- url: https://grc.nexs.com.bd/
- url: https://eah.nexs.com.bd/
- url: https://ooe.nexs.com.bd/
- url: https://del.kindnessbrand.com/
- url: https://ftx.kindnessbrand.com/
- url: https://gpa.jamesbreese.com/
- url: https://grc.jamesbreese.com/
- url: https://eah.jamesbreese.com/
- url: https://ooe.jamesbreese.com/
- url: https://74.0.48.207/
- url: https://74.0.48.36/
- url: https://74.0.32.159/
- url: https://107.148.158.43/
- url: https://74.0.32.113/
- url: https://148.251.39.121/
- url: https://148.251.39.122/
- url: https://165.22.76.254/
- domain: ooe.myserver.com.bd
- domain: del.nexs.com.bd
- domain: ftx.nexs.com.bd
- domain: gpa.nexs.com.bd
- domain: grc.nexs.com.bd
- domain: eah.nexs.com.bd
- domain: ooe.nexs.com.bd
- domain: del.kindnessbrand.com
- domain: ftx.kindnessbrand.com
- domain: gpa.jamesbreese.com
- domain: grc.jamesbreese.com
- domain: eah.jamesbreese.com
- domain: ooe.jamesbreese.com
- file: 74.0.48.207
- hash: 443
- file: 74.0.48.36
- hash: 443
- file: 74.0.32.159
- hash: 443
- file: 107.148.158.43
- hash: 443
- file: 74.0.32.113
- hash: 443
- file: 148.251.39.121
- hash: 443
- file: 148.251.39.122
- hash: 443
- file: 165.22.76.254
- hash: 443
- domain: res2erch-sl0ut.com
- domain: syncryp.bestink.in.net
- domain: jwalb.bestink.in.net
- domain: alt-d0ck.bestink.in.net
- domain: ch3c-line.bestink.in.net
- domain: dev-moral.askloop.in.net
- domain: bineress.shop
- domain: serdraix4.askloop.in.net
- domain: tri-fluxor.askloop.in.net
- domain: jfjoj.askloop.in.net
- url: http://cr404896.tw1.ru/cf893288.php
- file: 38.76.193.60
- hash: 5554
- domain: carrierstream.toolbend.in.net
- file: 154.86.19.38
- hash: 9001
- file: 108.187.4.192
- hash: 448
- file: 8.217.149.107
- hash: 8888
- domain: niceonefashion.com
- file: 38.76.193.60
- hash: 80
- domain: prrnftoa.toolbend.in.net
- domain: guardtrans.toolbend.in.net
- domain: reel-mount.toolbend.in.net
- domain: fvj7.blackford.in.net
- domain: oute2-grid.blackford.in.net
- domain: nick.olesak.com
- domain: mossoak.blackford.in.net
- domain: 1ago-plate.blackford.in.net
- domain: nickis-reinigungsservice.de
- domain: hyrfnqqh.fullgate.in.net
- domain: queuemarsh.fullgate.in.net
- domain: nickleger.com
- domain: tr-official.shop
- url: https://tr-official.shop
- file: 216.250.249.222
- hash: 443
- file: 216.250.249.222
- hash: 80
- domain: skin-greece.gl.at.ply.gg
- domain: shown-mario.gl.at.ply.gg
- domain: dreem-45850.portmap.host
- domain: nice-off.shop
- domain: gaydkonx.fullgate.in.net
- url: https://nice-off.shop
- domain: winterque.fullgate.in.net
- domain: ognbb.rollbend.in.net
- domain: b74nufw.rollbend.in.net
- domain: velline5en.rollbend.in.net
- domain: neo-gu1de.rollbend.in.net
- domain: valu-crest.spinpath.in.net
- domain: quorlithix3.spinpath.in.net
- file: 194.59.30.158
- hash: 6699
- file: 5.101.86.17
- hash: 2428
- file: 68.183.182.113
- hash: 8443
- file: 77.91.96.232
- hash: 7777
- file: 3.101.115.146
- hash: 42544
- file: 35.177.92.190
- hash: 7576
- file: 161.248.87.175
- hash: 7777
- file: 8.219.93.253
- hash: 5201
- domain: repairdefend.spinpath.in.net
- domain: stri5-reach.spinpath.in.net
- domain: nikita.vn
- domain: r3nder-switch.windright.in.net
- domain: loader.dojiner.at
- file: 213.176.79.236
- hash: 80
- domain: lknz.windright.in.net
- domain: nikosstratakis.com
- domain: 6h76gr0n.diagnosfirst.digital
- domain: 9mha5mm1.diagnosfirst.digital
- domain: unload-bridge.windright.in.net
- domain: letcurre.windright.in.net
- domain: zztzqouw.redflat.in.net
- file: 31.57.216.28
- hash: 416
- file: 31.57.216.27
- hash: 416
- file: 130.12.180.119
- hash: 416
- file: 46.151.182.245
- hash: 416
- file: 130.12.182.175
- hash: 416
- file: 130.12.180.85
- hash: 416
- file: 130.12.180.144
- hash: 416
- domain: meta-p4stur.redflat.in.net
- domain: palemicro.redflat.in.net
- domain: xxhigsz.redflat.in.net
- domain: warmgrim.slowbend.in.net
- domain: s0lid-leaf.slowbend.in.net
- domain: iqdrq.slowbend.in.net
- domain: ninjaflix-ead.bloco101.com
- file: 178.104.35.103
- hash: 29078
- domain: columnreel.slowbend.in.net
- domain: prim-node.veritax.in.net
- domain: veri-v01.veritax.in.net
- domain: prim-sync.veritax.in.net
- domain: veri-base.veritax.in.net
- url: http://134.122.152.210:8888/supershell/login/
- domain: alt-hub.kronosis.in.net
- domain: kron-v12.kronosis.in.net
- domain: alt-net.kronosis.in.net
- domain: kron-flow.kronosis.in.net
- domain: ops-gate.dynastis.in.net
- domain: dyna-v3.dynastis.in.net
- domain: ops-unit.dynastis.in.net
- domain: eo4quhil.cheesechubary.digital
- domain: dyna-edge.dynastis.in.net
- domain: 8r6d1s3j.cheesechubary.digital
- domain: dist-core.nexulon.in.net
- domain: nexu-v44.nexulon.in.net
- url: http://venom-stealer.com/api/upload
- url: http://venom-stealer.com/api/upload-json
- url: http://venom-stealer.com/api/upload-complete
- domain: venom-stealer.com
- domain: espace.servebeer.com
- file: 185.242.3.40
- hash: 4444
- domain: dist-sync.nexulon.in.net
- domain: kampf.huehnchenfarm.ru
- file: 45.141.119.34
- hash: 8443
- file: 45.141.119.34
- hash: 56001
- file: 103.83.86.16
- hash: 15098
- file: 103.83.86.16
- hash: 15099
- domain: nexu-data.nexulon.in.net
- domain: nlp.edu.sofine.ua
- domain: bit-vault.zentalis.in.net
- domain: files.jeaniescott.digital
- domain: zent-v05.zentalis.in.net
- domain: bit-hub.zentalis.in.net
- file: 212.118.41.7
- hash: 443
- file: 89.167.47.162
- hash: 443
- domain: zent-node.zentalis.in.net
- domain: main-peak.orbisura.in.net
- url: https://mcdns-imager.click/api/css.js
- file: 150.241.64.21
- hash: 8888
- domain: nfkavn.bond
- url: https://polygon-cnd-stats.sbs/api/css.js
- file: 95.85.224.14
- hash: 8000
- url: https://llc-image-ico.click/api/css.js
- domain: orbi-v6.orbisura.in.net
- file: 62.164.177.35
- hash: 8088
- domain: nero-ns-cdns.sbs
- url: https://nero-ns-cdns.sbs/api/css.js
- file: 193.221.201.170
- hash: 8088
- url: https://llc-image-ico.click/api/index.php
- url: https://nero-ns-cdns.sbs/api/index.php
- file: 103.121.48.141
- hash: 8443
- url: https://polygon-cnd-stats.sbs/api/index.php
- url: https://mcdns-imager.click/api/index.php
- domain: adcdn.ster.nl
- domain: main-sys.orbisura.in.net
- file: 46.149.73.60
- hash: 80
- url: https://api-server-cdn.sbs/api/css.js
- domain: api-server-cdn.sbs
- domain: orbi-base.orbisura.in.net
- url: http://sys32.cc/mir8s4zzzru/index.php
- domain: noa360.com
- domain: site-node.fluxoris.in.net
- domain: api-imager-host.beer
- url: https://api-imager-host.beer/api/css.js
- file: 8.138.39.67
- hash: 80
- file: 154.9.26.175
- hash: 443
- file: 31.57.187.149
- hash: 1604
- file: 209.74.86.135
- hash: 2850
- domain: ns-server-isdjs-icons.sbs
- file: 103.245.231.207
- hash: 4444
- url: https://ns-server-isdjs-icons.sbs/api/css.js
- domain: flux-v77.fluxoris.in.net
- domain: ns-cyber-server.sbs
- url: https://ns-cyber-server.sbs/api/css.js
- domain: site-net.fluxoris.in.net
- domain: flux-run.fluxoris.in.net
- file: 45.141.119.34
- hash: 39002
- file: 141.98.6.14
- hash: 5563
- domain: term-way.vibrante.in.net
- file: 45.83.31.39
- hash: 5173
- domain: vibr-v08.vibrante.in.net
- domain: term-sync.vibrante.in.net
- domain: vibr-flow.vibrante.in.net
- domain: link-logic.spectris.in.net
- domain: spec-v09.spectris.in.net
- domain: link-gate.spectris.in.net
- domain: spec-unit.spectris.in.net
- domain: tech-ref.quintura.in.net
- domain: quin-v11.quintura.in.net
- domain: tech-base.quintura.in.net
- domain: quin-net.quintura.in.net
- domain: transmfield.wayton.in.net
- domain: faitdem.wayton.in.net
- domain: render5-line.wayton.in.net
- domain: va1u-node.wayton.in.net
- domain: nomorchaos.com
- domain: guid-route.greentea.in.net
- domain: deal1-point.greentea.in.net
- domain: glossapi.greentea.in.net
- domain: sdk9-pulse.greentea.in.net
- domain: tax-fc.gl.at.ply.gg
- domain: bui13-well.costfee.in.net
- file: 85.235.75.90
- hash: 25565
- file: 161.248.87.157
- hash: 4499
- file: 119.28.70.225
- hash: 80
- file: 119.28.70.225
- hash: 5860
- file: 119.28.70.225
- hash: 983
- domain: reel-tok.costfee.in.net
- domain: pa5s7-signal.costfee.in.net
- domain: road-layer.droplast.in.net
- domain: sub-ca1m.droplast.in.net
- domain: dark-shi.droplast.in.net
- domain: northoflajollapublishing.com.quickcooldesign.com
- domain: eaec4m.droplast.in.net
- domain: mars-sort.lookback.in.net
- domain: sp4rrow-phase.lookback.in.net
- domain: 3zwcexo.lookback.in.net
- domain: u1tr5-bridge.lookback.in.net
- domain: notepad.promadesign.com
- domain: syst-node.centurionix.in.net
- domain: cent-v01.centurionix.in.net
- domain: alti-v12.altimetrica.in.net
- domain: infra-net.altimetrica.in.net
- file: 87.106.216.140
- hash: 80
- file: 156.234.21.209
- hash: 30502
- file: 101.32.36.2
- hash: 443
- file: 185.239.69.238
- hash: 2083
- file: 103.82.24.104
- hash: 80
- file: 93.113.25.85
- hash: 443
- file: 34.154.84.183
- hash: 443
- domain: www.kludt8zn.shop
- domain: www.r15p5l5b.shop
- domain: www.nlmz602h.shop
- domain: www.7dk5l721.shop
- file: 85.137.253.58
- hash: 9000
- file: 47.129.168.50
- hash: 389
- file: 47.129.168.50
- hash: 8389
- file: 16.170.165.141
- hash: 80
- domain: alti-flow.altimetrica.in.net
- domain: data-gate.quantovault.in.net
- domain: quan-v3.quantovault.in.net
- domain: data-unit.quantovault.in.net
- domain: quan-edge.quantovault.in.net
- domain: logic-core.primordialis.in.net
- domain: prim-v44.primordialis.in.net
- domain: logic-sync.primordialis.in.net
- domain: novikon.nikolaev.ua
- domain: prim-data.primordialis.in.net
- domain: novo.blockerbrasil.com.br
- domain: vult-vault.spectrometric.in.net
- domain: spec-v05.spectrometric.in.net
- domain: yhcy21oo.demogsystemat.digital
- domain: f0fjv96k.demogsystemat.digital
- domain: vult-hub.spectrometric.in.net
- domain: spec-node.spectrometric.in.net
- domain: main-peak.obsidianix.in.net
- domain: obsi-v6.obsidianix.in.net
- domain: main-sys.obsidianix.in.net
- domain: obsi-base.obsidianix.in.net
- domain: term-way.vibratronic.in.net
- domain: www.cloudflara.xyz
- file: 172.86.107.2
- hash: 443
- file: 193.42.25.65
- hash: 1444
- domain: vibr-v08.vibratronic.in.net
- file: 38.147.170.252
- hash: 7777
- domain: term-sync.vibratronic.in.net
- domain: vibr-flow.vibratronic.in.net
- domain: flow-logic.synchromesh.in.net
- domain: sync-v09.synchromesh.in.net
- domain: flow-gate.synchromesh.in.net
- domain: npj.app
- domain: sync-unit.synchromesh.in.net
- domain: tech-ref.galactoview.in.net
- domain: gala-v11.galactoview.in.net
- file: 77.221.149.33
- hash: 80
- file: 91.231.222.220
- hash: 5620
- file: 103.65.230.86
- hash: 443
- domain: tech-base.galactoview.in.net
- domain: gala-net.galactoview.in.net
- domain: link-node.structovista.in.net
- domain: dytdttyhhmjfjtydukytdtdrtrtjrttgyuttfdtd.duckdns.org
- file: 172.245.4.221
- hash: 2406
- domain: stru-v77.structovista.in.net
- domain: nsgpara.com
- domain: link-net.structovista.in.net
- domain: nslwzqa.org
- domain: stru-run.structovista.in.net
- domain: nuevaimagen.esnaj.com
ThreatFox IOCs for 2026-03-09
Description
ThreatFox IOCs for 2026-03-09
AI-Powered Analysis
Technical Analysis
The entry titled 'ThreatFox IOCs for 2026-03-09' originates from the ThreatFox MISP feed, which is a platform for sharing threat intelligence, particularly Indicators of Compromise (IOCs). The threat is classified as malware related to OSINT (Open Source Intelligence), payload delivery, and network activity. Despite being labeled as a medium severity threat, the record contains no specific affected software versions, no CVEs or CWEs, no known exploits in the wild, and no patch availability. The technical details include a low threat level (2 out of an unspecified scale), minimal analysis (1), and moderate distribution (3), but no concrete indicators or payload descriptions are provided. The tags and categories suggest this entry is more of an intelligence update or a collection of IOCs rather than a detailed vulnerability or active exploit. The lack of actionable technical data limits the ability to perform a deep technical analysis or to understand the exact nature of the malware or its delivery mechanisms.
Potential Impact
Due to the absence of detailed information on the malware's capabilities, affected systems, or exploitation methods, the potential impact remains unclear. The medium severity rating suggests some risk, but without specifics, it is difficult to assess the threat's effect on confidentiality, integrity, or availability. Organizations worldwide could theoretically be impacted if the malware targets widely used systems or networks, but no evidence supports active exploitation or widespread distribution. The lack of known exploits and patches indicates this may be an emerging or low-activity threat, or simply an intelligence collection without immediate operational impact.
Mitigation Recommendations
Given the limited information, organizations should focus on general best practices for malware defense and OSINT monitoring: 1) Maintain updated endpoint protection and network monitoring tools capable of detecting unusual payload delivery and network activity. 2) Integrate ThreatFox and other threat intelligence feeds into security information and event management (SIEM) systems to enhance detection capabilities. 3) Conduct regular threat hunting exercises focusing on network anomalies and suspicious payloads. 4) Educate security teams on interpreting and leveraging OSINT-based threat intelligence. 5) Maintain robust incident response plans to quickly address any emerging threats identified through updated intelligence. Since no patches or specific exploits are known, no targeted remediation is currently possible.
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- db05c214-0ade-4028-910e-19a55ce855ab
- Original Timestamp
- 1773100987
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaingood-gate.goodtime.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainkirk-service.live | MaskGramStealer botnet C2 domain (confidence level: 100%) | |
domaincrispy-rusty.com | SantaStealer botnet C2 domain (confidence level: 100%) | |
domainford-sync.ironford.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaingate-v05.lakegate.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaingennods.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainbrocaez.club | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainfamilbg.club | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainmobbyyt.club | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainnbdeco.fr | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainclay-logic.redclay.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainred-v09.redclay.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainclay-gate.redclay.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainred-unit.redclay.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbend-ref.oakbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnearchos-akte.gr | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainoak-v11.oakbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbend-base.oakbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainoak-net.oakbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainneckaralb.digital | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainneighborhoodroofingllc.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainvult-node.nexoris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnex-v01.nexoris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnekoamerikaheiku.info | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainvult-sync.nexoris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnex-base.nexoris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainalt-hub.zenithra.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainneuroconsultas.pt | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainnew.avtograf.ee | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainzen-v12.zenithra.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnew.tsypin.partners | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainalt-net.zenithra.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainzen-flow.zenithra.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainops-gate.lumitron.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnewenergypartnership.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainlumi-v3.lumitron.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnewlinekitchens.hdps.co.za | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainmpt.pedagogiai-tarsasag.hu | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainops-unit.lumitron.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnaosagioulouka.gr | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainlumi-edge.lumitron.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindist-core.veloxis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnevikup.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainauraplay.vip | Cobalt Strike botnet C2 domain (confidence level: 50%) | |
domainavlc2.westus2.cloudapp.azure.com | Havoc botnet C2 domain (confidence level: 100%) | |
domainnewproject1.dashop.tech | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainnews.mohitrathi.in | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainnewsite.lbgresearch.org | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainvel-v44.veloxis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnewtli.theteambuilderadrc.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domaindist-sync.veloxis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnewvermont.fairgoseo.com.au | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainvel-data.veloxis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbit-vault.cryptixy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnexoeasy-88.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domaincryp-v05.cryptixy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbit-hub.cryptixy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnexxusmanagement.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domaincryp-node.cryptixy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmain-peak.solarisx.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnflug.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainsol-v6.solarisx.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmain-sys.solarisx.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsol-base.solarisx.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbigbrainsholdings.com | CountLoader payload delivery domain (confidence level: 100%) | |
domaindebank-api.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainmagnusworkspace.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainnode2-py-store.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainpy-installer.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domains1-rarlab.com | CountLoader payload delivery domain (confidence level: 100%) | |
domains3-python.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainupdateservice1-telegramweb.com | CountLoader payload delivery domain (confidence level: 100%) | |
domainweb3-walletnotify.cc | CountLoader payload delivery domain (confidence level: 100%) | |
domainngoaithatnhatban.vn | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainsite-node.terravia.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainterr-v77.terravia.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsite-net.terravia.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainterr-run.terravia.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain11uttaq1.bitterfisherm.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainovbfopy8.bitterfisherm.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainterm-way.niventa.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainniv-v08.niventa.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainterm-sync.niventa.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmullenpalimpseststudio.com | HijackLoader botnet C2 domain (confidence level: 100%) | |
domainniv-flow.niventa.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwriconsult.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainlink-logic.astronis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainoakumsnarrowboats.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainarlingtonheightsgaragedoors.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domaininvitoenergypartners.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainfraziewealthmanagement.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainnorthernvirginiapainting.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainvrf.cldvrfd.click | Unknown malware payload delivery domain (confidence level: 100%) | |
domaintkmfinancialservices.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainastro-v09.astronis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnewyorkcitybrandingagency.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainlink-gate.astronis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainastro-unit.astronis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintech-ref.moxura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmox-v11.moxura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintech-base.moxura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmentaorb.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainmox-net.moxura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainjaxfamilylawyers.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainooe.myserver.com.bd | Vidar botnet C2 domain (confidence level: 100%) | |
domaindel.nexs.com.bd | Vidar botnet C2 domain (confidence level: 100%) | |
domainftx.nexs.com.bd | Vidar botnet C2 domain (confidence level: 100%) | |
domaingpa.nexs.com.bd | Vidar botnet C2 domain (confidence level: 100%) | |
domaingrc.nexs.com.bd | Vidar botnet C2 domain (confidence level: 100%) | |
domaineah.nexs.com.bd | Vidar botnet C2 domain (confidence level: 100%) | |
domainooe.nexs.com.bd | Vidar botnet C2 domain (confidence level: 100%) | |
domaindel.kindnessbrand.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainftx.kindnessbrand.com | Vidar botnet C2 domain (confidence level: 100%) | |
domaingpa.jamesbreese.com | Vidar botnet C2 domain (confidence level: 100%) | |
domaingrc.jamesbreese.com | Vidar botnet C2 domain (confidence level: 100%) | |
domaineah.jamesbreese.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainooe.jamesbreese.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainres2erch-sl0ut.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainsyncryp.bestink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainjwalb.bestink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainalt-d0ck.bestink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainch3c-line.bestink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindev-moral.askloop.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbineress.shop | Vidar botnet C2 domain (confidence level: 100%) | |
domainserdraix4.askloop.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintri-fluxor.askloop.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainjfjoj.askloop.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincarrierstream.toolbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainniceonefashion.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainprrnftoa.toolbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainguardtrans.toolbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainreel-mount.toolbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfvj7.blackford.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainoute2-grid.blackford.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnick.olesak.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainmossoak.blackford.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain1ago-plate.blackford.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnickis-reinigungsservice.de | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainhyrfnqqh.fullgate.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainqueuemarsh.fullgate.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnickleger.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domaintr-official.shop | Unknown malware payload delivery domain (confidence level: 100%) | |
domainskin-greece.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainshown-mario.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domaindreem-45850.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainnice-off.shop | Unknown malware payload delivery domain (confidence level: 100%) | |
domaingaydkonx.fullgate.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwinterque.fullgate.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainognbb.rollbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainb74nufw.rollbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvelline5en.rollbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainneo-gu1de.rollbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvalu-crest.spinpath.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainquorlithix3.spinpath.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainrepairdefend.spinpath.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainstri5-reach.spinpath.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnikita.vn | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainr3nder-switch.windright.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainloader.dojiner.at | ArcaneStealer botnet C2 domain (confidence level: 100%) | |
domainlknz.windright.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnikosstratakis.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domain6h76gr0n.diagnosfirst.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domain9mha5mm1.diagnosfirst.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainunload-bridge.windright.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainletcurre.windright.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainzztzqouw.redflat.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmeta-p4stur.redflat.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpalemicro.redflat.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainxxhigsz.redflat.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwarmgrim.slowbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domains0lid-leaf.slowbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainiqdrq.slowbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainninjaflix-ead.bloco101.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domaincolumnreel.slowbend.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainprim-node.veritax.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainveri-v01.veritax.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainprim-sync.veritax.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainveri-base.veritax.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainalt-hub.kronosis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainkron-v12.kronosis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainalt-net.kronosis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainkron-flow.kronosis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainops-gate.dynastis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindyna-v3.dynastis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainops-unit.dynastis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaineo4quhil.cheesechubary.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domaindyna-edge.dynastis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain8r6d1s3j.cheesechubary.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domaindist-core.nexulon.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnexu-v44.nexulon.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvenom-stealer.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainespace.servebeer.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domaindist-sync.nexulon.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainkampf.huehnchenfarm.ru | PureRAT botnet C2 domain (confidence level: 100%) | |
domainnexu-data.nexulon.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnlp.edu.sofine.ua | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainbit-vault.zentalis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfiles.jeaniescott.digital | FAKEUPDATES botnet C2 domain (confidence level: 100%) | |
domainzent-v05.zentalis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbit-hub.zentalis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainzent-node.zentalis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmain-peak.orbisura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnfkavn.bond | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainorbi-v6.orbisura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnero-ns-cdns.sbs | Unknown malware payload delivery domain (confidence level: 100%) | |
domainadcdn.ster.nl | Amatera botnet C2 domain (confidence level: 100%) | |
domainmain-sys.orbisura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainapi-server-cdn.sbs | Unknown malware payload delivery domain (confidence level: 100%) | |
domainorbi-base.orbisura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnoa360.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainsite-node.fluxoris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainapi-imager-host.beer | Unknown malware payload delivery domain (confidence level: 100%) | |
domainns-server-isdjs-icons.sbs | Unknown malware payload delivery domain (confidence level: 100%) | |
domainflux-v77.fluxoris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainns-cyber-server.sbs | Unknown malware payload delivery domain (confidence level: 100%) | |
domainsite-net.fluxoris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainflux-run.fluxoris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainterm-way.vibrante.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvibr-v08.vibrante.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainterm-sync.vibrante.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvibr-flow.vibrante.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlink-logic.spectris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainspec-v09.spectris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlink-gate.spectris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainspec-unit.spectris.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintech-ref.quintura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainquin-v11.quintura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintech-base.quintura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainquin-net.quintura.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintransmfield.wayton.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfaitdem.wayton.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainrender5-line.wayton.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainva1u-node.wayton.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnomorchaos.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainguid-route.greentea.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindeal1-point.greentea.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainglossapi.greentea.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsdk9-pulse.greentea.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintax-fc.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainbui13-well.costfee.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainreel-tok.costfee.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpa5s7-signal.costfee.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainroad-layer.droplast.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsub-ca1m.droplast.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindark-shi.droplast.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnorthoflajollapublishing.com.quickcooldesign.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domaineaec4m.droplast.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmars-sort.lookback.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsp4rrow-phase.lookback.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain3zwcexo.lookback.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainu1tr5-bridge.lookback.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnotepad.promadesign.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainsyst-node.centurionix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincent-v01.centurionix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainalti-v12.altimetrica.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaininfra-net.altimetrica.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwww.kludt8zn.shop | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainwww.r15p5l5b.shop | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainwww.nlmz602h.shop | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainwww.7dk5l721.shop | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainalti-flow.altimetrica.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindata-gate.quantovault.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainquan-v3.quantovault.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindata-unit.quantovault.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainquan-edge.quantovault.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlogic-core.primordialis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainprim-v44.primordialis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlogic-sync.primordialis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnovikon.nikolaev.ua | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainprim-data.primordialis.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnovo.blockerbrasil.com.br | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainvult-vault.spectrometric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainspec-v05.spectrometric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainyhcy21oo.demogsystemat.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainf0fjv96k.demogsystemat.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainvult-hub.spectrometric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainspec-node.spectrometric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmain-peak.obsidianix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainobsi-v6.obsidianix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmain-sys.obsidianix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainobsi-base.obsidianix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainterm-way.vibratronic.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwww.cloudflara.xyz | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainvibr-v08.vibratronic.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainterm-sync.vibratronic.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvibr-flow.vibratronic.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainflow-logic.synchromesh.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsync-v09.synchromesh.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainflow-gate.synchromesh.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnpj.app | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainsync-unit.synchromesh.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintech-ref.galactoview.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaingala-v11.galactoview.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintech-base.galactoview.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaingala-net.galactoview.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlink-node.structovista.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindytdttyhhmjfjtydukytdtdrtrtjrttgyuttfdtd.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainstru-v77.structovista.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnsgpara.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainlink-net.structovista.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnslwzqa.org | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainstru-run.structovista.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnuevaimagen.esnaj.com | StrelaStealer payload delivery domain (confidence level: 100%) |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://www.ulfhedinnvikings.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/mzcxijwx2zg9e7w | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/ejk52zwt2js16ro | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/6v0tazc5mboxujs | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/q7cherolivolejk | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/iro9a3cp6zsd230 | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/ujgti3g12f45y74 | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/m3o1azkhufs1enk | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/y74habwtyvsxarw | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/a7k56jotufo5ab4 | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/2vk56j8h27whyzg | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/6v4de3o1yz0du7k | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/yzc5yj81yv0h2fw | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/ufcx6bc1ef45e7g | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttp://kirk-service.live/reconcile | MaskGramStealer botnet C2 (confidence level: 100%) | |
urlhttps://crispy-rusty.com/ | SantaStealer botnet C2 (confidence level: 100%) | |
urlhttp://83.142.209.47/x | Unknown malware payload delivery URL (confidence level: 75%) | |
urlhttps://cdn-us-cloudflare-services.t3.storage.dev/follow/index.html?x-amz-algorithm=aws4-hmac-sha256&x-amz-credential=tid_ydatdzfwt_hunghpsgltcegtzeeiwhetiouwdibgulkrrlknws%2f20260308%2fauto%2fs3%2faws4_request&x-amz-date=20260308t175148z&x-amz-expires=172800&x-amz-signedheaders=host&x-amz-signature=ffdb4b5c5e00d0d24ba730369686eba47c5bf55f2d83780482e67a0b03ebe2c0 | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttp://85.28.47.152 | Stealc botnet C2 (confidence level: 100%) | |
urlhttp://192.168.2.53:80/am8w | Cobalt Strike botnet C2 (confidence level: 75%) | |
urlhttps://next-step-n4.t3.storage.dev/index.html?x-amz-algorithm=aws4-hmac-sha256&x-amz-credential=tid_wnnisps__tskokdg_uwkaghhuvhbcshbutgbmxtaqtxsqtrdfy/20260308/auto/s3/aws4_request&x-amz-date=20260308t012517z&x-amz-expires=2160000&x-amz-signedhe | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttp://45.156.87.17/reg | Unidentified PS 001 payload delivery URL (confidence level: 100%) | |
urlhttps://64.95.10.115:23011/update.sh | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://temp.sh/tqtss/storm.exe | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://vrf.cldvrfd.click/u323245/local3.txt | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://steamcommunity.com/profiles/76561198732393960 | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://telegram.me/k33dro | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://ooe.myserver.com.bd/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://ooe.digitalmatters360.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://del.nexs.com.bd/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://ftx.nexs.com.bd/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://gpa.nexs.com.bd/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://grc.nexs.com.bd/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://eah.nexs.com.bd/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://ooe.nexs.com.bd/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://del.kindnessbrand.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://ftx.kindnessbrand.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://gpa.jamesbreese.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://grc.jamesbreese.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://eah.jamesbreese.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://ooe.jamesbreese.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://74.0.48.207/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://74.0.48.36/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://74.0.32.159/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://107.148.158.43/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://74.0.32.113/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://148.251.39.121/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://148.251.39.122/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://165.22.76.254/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttp://cr404896.tw1.ru/cf893288.php | DCRat botnet C2 (confidence level: 100%) | |
urlhttps://tr-official.shop | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://nice-off.shop | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://134.122.152.210:8888/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttp://venom-stealer.com/api/upload | Unknown Stealer botnet C2 (confidence level: 100%) | |
urlhttp://venom-stealer.com/api/upload-json | Unknown Stealer botnet C2 (confidence level: 100%) | |
urlhttp://venom-stealer.com/api/upload-complete | Unknown Stealer botnet C2 (confidence level: 100%) | |
urlhttps://mcdns-imager.click/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://polygon-cnd-stats.sbs/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://llc-image-ico.click/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://nero-ns-cdns.sbs/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://llc-image-ico.click/api/index.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://nero-ns-cdns.sbs/api/index.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://polygon-cnd-stats.sbs/api/index.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mcdns-imager.click/api/index.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://api-server-cdn.sbs/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://sys32.cc/mir8s4zzzru/index.php | Amadey botnet C2 (confidence level: 100%) | |
urlhttps://api-imager-host.beer/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://ns-server-isdjs-icons.sbs/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://ns-cyber-server.sbs/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) |
File
| Value | Description | Copy |
|---|---|---|
file31.57.216.128 | Remcos botnet C2 server (confidence level: 100%) | |
file5.206.227.239 | Remcos botnet C2 server (confidence level: 100%) | |
file146.103.106.71 | Sliver botnet C2 server (confidence level: 100%) | |
file38.242.144.218 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file102.117.160.235 | Unknown malware botnet C2 server (confidence level: 100%) | |
file79.135.160.20 | Unknown malware botnet C2 server (confidence level: 100%) | |
file8.138.0.148 | Unknown malware botnet C2 server (confidence level: 100%) | |
file144.31.164.198 | Bashlite botnet C2 server (confidence level: 100%) | |
file45.158.196.14 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file196.75.62.145 | Meterpreter botnet C2 server (confidence level: 100%) | |
file168.245.203.193 | Meterpreter botnet C2 server (confidence level: 100%) | |
file188.137.228.57 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file101.32.36.2 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file101.34.203.51 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file45.74.48.72 | Remcos botnet C2 server (confidence level: 100%) | |
file178.16.52.36 | Remcos botnet C2 server (confidence level: 100%) | |
file38.54.6.205 | Unknown malware botnet C2 server (confidence level: 100%) | |
file136.0.213.192 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file138.197.35.236 | Unknown malware botnet C2 server (confidence level: 100%) | |
file151.240.151.123 | XWorm botnet C2 server (confidence level: 100%) | |
file103.177.47.49 | Meterpreter botnet C2 server (confidence level: 100%) | |
file195.24.237.47 | GCleaner botnet C2 server (confidence level: 75%) | |
file91.219.239.7 | Unknown malware botnet C2 server (confidence level: 75%) | |
file64.225.39.118 | Sliver botnet C2 server (confidence level: 100%) | |
file178.16.55.119 | SectopRAT botnet C2 server (confidence level: 100%) | |
file94.72.122.1 | Unknown malware botnet C2 server (confidence level: 100%) | |
file40.233.14.199 | Unknown malware botnet C2 server (confidence level: 100%) | |
file41.216.188.35 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file103.177.47.97 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.47.109 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.47.121 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.47.73 | Meterpreter botnet C2 server (confidence level: 100%) | |
file123.56.52.156 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file172.245.126.52 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file179.43.166.147 | Unknown malware botnet C2 server (confidence level: 75%) | |
file64.95.10.115 | Unknown malware botnet C2 server (confidence level: 75%) | |
file134.122.13.34 | SparkRAT botnet C2 server (confidence level: 75%) | |
file138.197.14.95 | SparkRAT botnet C2 server (confidence level: 75%) | |
file45.32.113.200 | VShell botnet C2 server (confidence level: 100%) | |
file182.16.76.2 | VShell botnet C2 server (confidence level: 100%) | |
file107.189.16.142 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file74.0.48.207 | Vidar botnet C2 server (confidence level: 100%) | |
file74.0.48.36 | Vidar botnet C2 server (confidence level: 100%) | |
file74.0.32.159 | Vidar botnet C2 server (confidence level: 100%) | |
file107.148.158.43 | Vidar botnet C2 server (confidence level: 100%) | |
file74.0.32.113 | Vidar botnet C2 server (confidence level: 100%) | |
file148.251.39.121 | Vidar botnet C2 server (confidence level: 100%) | |
file148.251.39.122 | Vidar botnet C2 server (confidence level: 100%) | |
file165.22.76.254 | Vidar botnet C2 server (confidence level: 100%) | |
file38.76.193.60 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file154.86.19.38 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file108.187.4.192 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file8.217.149.107 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file38.76.193.60 | ValleyRAT botnet C2 server (confidence level: 75%) | |
file216.250.249.222 | Remcos botnet C2 server (confidence level: 100%) | |
file216.250.249.222 | Remcos botnet C2 server (confidence level: 100%) | |
file194.59.30.158 | Remcos botnet C2 server (confidence level: 100%) | |
file5.101.86.17 | Remcos botnet C2 server (confidence level: 100%) | |
file68.183.182.113 | Havoc botnet C2 server (confidence level: 100%) | |
file77.91.96.232 | DCRat botnet C2 server (confidence level: 100%) | |
file3.101.115.146 | Meterpreter botnet C2 server (confidence level: 100%) | |
file35.177.92.190 | Meterpreter botnet C2 server (confidence level: 100%) | |
file161.248.87.175 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file8.219.93.253 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file213.176.79.236 | ArcaneStealer botnet C2 server (confidence level: 100%) | |
file31.57.216.28 | Tofsee botnet C2 server (confidence level: 75%) | |
file31.57.216.27 | Tofsee botnet C2 server (confidence level: 75%) | |
file130.12.180.119 | Tofsee botnet C2 server (confidence level: 75%) | |
file46.151.182.245 | Tofsee botnet C2 server (confidence level: 75%) | |
file130.12.182.175 | Tofsee botnet C2 server (confidence level: 75%) | |
file130.12.180.85 | Tofsee botnet C2 server (confidence level: 75%) | |
file130.12.180.144 | Tofsee botnet C2 server (confidence level: 75%) | |
file178.104.35.103 | Unknown malware botnet C2 server (confidence level: 100%) | |
file185.242.3.40 | Unknown malware botnet C2 server (confidence level: 75%) | |
file45.141.119.34 | PureRAT botnet C2 server (confidence level: 75%) | |
file45.141.119.34 | PureRAT botnet C2 server (confidence level: 75%) | |
file103.83.86.16 | Remcos botnet C2 server (confidence level: 100%) | |
file103.83.86.16 | Remcos botnet C2 server (confidence level: 100%) | |
file212.118.41.7 | ACR Stealer botnet C2 server (confidence level: 75%) | |
file89.167.47.162 | ACR Stealer botnet C2 server (confidence level: 75%) | |
file150.241.64.21 | Unknown malware botnet C2 server (confidence level: 75%) | |
file95.85.224.14 | Unknown malware botnet C2 server (confidence level: 75%) | |
file62.164.177.35 | Unknown malware botnet C2 server (confidence level: 75%) | |
file193.221.201.170 | Unknown malware botnet C2 server (confidence level: 75%) | |
file103.121.48.141 | Unknown malware botnet C2 server (confidence level: 75%) | |
file46.149.73.60 | Amatera botnet C2 server (confidence level: 75%) | |
file8.138.39.67 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file154.9.26.175 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file31.57.187.149 | Venom RAT botnet C2 server (confidence level: 100%) | |
file209.74.86.135 | Unknown malware botnet C2 server (confidence level: 100%) | |
file103.245.231.207 | Meterpreter botnet C2 server (confidence level: 100%) | |
file45.141.119.34 | PureRAT botnet C2 server (confidence level: 75%) | |
file141.98.6.14 | Unknown malware botnet C2 server (confidence level: 75%) | |
file45.83.31.39 | Unknown malware botnet C2 server (confidence level: 75%) | |
file85.235.75.90 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file161.248.87.157 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file119.28.70.225 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file119.28.70.225 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file119.28.70.225 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file87.106.216.140 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file156.234.21.209 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file101.32.36.2 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file185.239.69.238 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file103.82.24.104 | Remcos botnet C2 server (confidence level: 100%) | |
file93.113.25.85 | Sliver botnet C2 server (confidence level: 100%) | |
file34.154.84.183 | Unknown malware botnet C2 server (confidence level: 100%) | |
file85.137.253.58 | XWorm botnet C2 server (confidence level: 100%) | |
file47.129.168.50 | Meterpreter botnet C2 server (confidence level: 100%) | |
file47.129.168.50 | Meterpreter botnet C2 server (confidence level: 100%) | |
file16.170.165.141 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file172.86.107.2 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file193.42.25.65 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file38.147.170.252 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file77.221.149.33 | Unknown Loader botnet C2 server (confidence level: 100%) | |
file91.231.222.220 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file103.65.230.86 | Unknown RAT botnet C2 server (confidence level: 100%) | |
file172.245.4.221 | Remcos botnet C2 server (confidence level: 100%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash7755 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Bashlite botnet C2 server (confidence level: 100%) | |
hash4321 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash2222 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash1337 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8007 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Remcos botnet C2 server (confidence level: 100%) | |
hash2121 | Remcos botnet C2 server (confidence level: 100%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | XWorm botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash80 | GCleaner botnet C2 server (confidence level: 75%) | |
hash8080 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash8443 | Sliver botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash4782 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8084 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash23011 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash9f431d5549a03aee92cfd2bdbbe90f1c91e965c99e90a0c9ad5a001f4e80c350 | Unknown malware payload (confidence level: 100%) | |
hash98a7b0900a9072bb40af579ec372da7b27af12b15868394df51fefe290ab176b | Unknown malware payload (confidence level: 100%) | |
hash66cceb2c2f1d9988b501832fd3b559775982e2fce4ab38fc4ffe71b74eafc726 | Unknown malware payload (confidence level: 100%) | |
hash679ee05d92a858b6fe70aeb6072eb804548f1732e18b6c181af122b833386afb | Unknown malware payload (confidence level: 100%) | |
hash4762e944a0ce1f9aef243e11538f84f16b6f36560ed6e32dfd9a5f99e17e8e50 | Unknown malware payload (confidence level: 100%) | |
hash98442387d466f27357d727b3706037a4df12a78602b93df973b063462a677761 | Unknown malware payload (confidence level: 100%) | |
hashcc2bc3750cc5125a50466f66ae4f2bedf1cac0e43477a78ed2fd88f3e987a292 | Unknown malware payload (confidence level: 100%) | |
hashcf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce | Unknown malware payload (confidence level: 100%) | |
hash0ecc867ce916d01640d76ec03de24d1d23585eb582e9c48a0364c62a590548ac | Unknown malware payload (confidence level: 100%) | |
hash8979 | SparkRAT botnet C2 server (confidence level: 75%) | |
hash80 | SparkRAT botnet C2 server (confidence level: 75%) | |
hash8084 | VShell botnet C2 server (confidence level: 100%) | |
hash8001 | VShell botnet C2 server (confidence level: 100%) | |
hash443 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash5554 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash9001 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash448 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash8888 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash80 | ValleyRAT botnet C2 server (confidence level: 75%) | |
hash443 | Remcos botnet C2 server (confidence level: 100%) | |
hash80 | Remcos botnet C2 server (confidence level: 100%) | |
hash6699 | Remcos botnet C2 server (confidence level: 100%) | |
hash2428 | Remcos botnet C2 server (confidence level: 100%) | |
hash8443 | Havoc botnet C2 server (confidence level: 100%) | |
hash7777 | DCRat botnet C2 server (confidence level: 100%) | |
hash42544 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash7576 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash7777 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash5201 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash80 | ArcaneStealer botnet C2 server (confidence level: 100%) | |
hash416 | Tofsee botnet C2 server (confidence level: 75%) | |
hash416 | Tofsee botnet C2 server (confidence level: 75%) | |
hash416 | Tofsee botnet C2 server (confidence level: 75%) | |
hash416 | Tofsee botnet C2 server (confidence level: 75%) | |
hash416 | Tofsee botnet C2 server (confidence level: 75%) | |
hash416 | Tofsee botnet C2 server (confidence level: 75%) | |
hash416 | Tofsee botnet C2 server (confidence level: 75%) | |
hash29078 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash4444 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash8443 | PureRAT botnet C2 server (confidence level: 75%) | |
hash56001 | PureRAT botnet C2 server (confidence level: 75%) | |
hash15098 | Remcos botnet C2 server (confidence level: 100%) | |
hash15099 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | ACR Stealer botnet C2 server (confidence level: 75%) | |
hash443 | ACR Stealer botnet C2 server (confidence level: 75%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash8000 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash8088 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash8088 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash8443 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash80 | Amatera botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash1604 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash2850 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash4444 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash39002 | PureRAT botnet C2 server (confidence level: 75%) | |
hash5563 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash5173 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash25565 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash4499 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash80 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash5860 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash983 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash30502 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2083 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash9000 | XWorm botnet C2 server (confidence level: 100%) | |
hash389 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash8389 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash80 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash1444 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash7777 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Unknown Loader botnet C2 server (confidence level: 100%) | |
hash5620 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown RAT botnet C2 server (confidence level: 100%) | |
hash2406 | Remcos botnet C2 server (confidence level: 100%) |
Threat ID: 69af634bea502d3aa8dad08d
Added to database: 3/10/2026, 12:18:19 AM
Last enriched: 3/10/2026, 12:18:30 AM
Last updated: 3/14/2026, 3:14:00 AM
Views: 203
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.