Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-03-09

0
Medium
Published: Mon Mar 09 2026 (03/09/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-03-09

AI-Powered Analysis

AILast updated: 03/10/2026, 00:18:30 UTC

Technical Analysis

The entry titled 'ThreatFox IOCs for 2026-03-09' originates from the ThreatFox MISP feed, which is a platform for sharing threat intelligence, particularly Indicators of Compromise (IOCs). The threat is classified as malware related to OSINT (Open Source Intelligence), payload delivery, and network activity. Despite being labeled as a medium severity threat, the record contains no specific affected software versions, no CVEs or CWEs, no known exploits in the wild, and no patch availability. The technical details include a low threat level (2 out of an unspecified scale), minimal analysis (1), and moderate distribution (3), but no concrete indicators or payload descriptions are provided. The tags and categories suggest this entry is more of an intelligence update or a collection of IOCs rather than a detailed vulnerability or active exploit. The lack of actionable technical data limits the ability to perform a deep technical analysis or to understand the exact nature of the malware or its delivery mechanisms.

Potential Impact

Due to the absence of detailed information on the malware's capabilities, affected systems, or exploitation methods, the potential impact remains unclear. The medium severity rating suggests some risk, but without specifics, it is difficult to assess the threat's effect on confidentiality, integrity, or availability. Organizations worldwide could theoretically be impacted if the malware targets widely used systems or networks, but no evidence supports active exploitation or widespread distribution. The lack of known exploits and patches indicates this may be an emerging or low-activity threat, or simply an intelligence collection without immediate operational impact.

Mitigation Recommendations

Given the limited information, organizations should focus on general best practices for malware defense and OSINT monitoring: 1) Maintain updated endpoint protection and network monitoring tools capable of detecting unusual payload delivery and network activity. 2) Integrate ThreatFox and other threat intelligence feeds into security information and event management (SIEM) systems to enhance detection capabilities. 3) Conduct regular threat hunting exercises focusing on network anomalies and suspicious payloads. 4) Educate security teams on interpreting and leveraging OSINT-based threat intelligence. 5) Maintain robust incident response plans to quickly address any emerging threats identified through updated intelligence. Since no patches or specific exploits are known, no targeted remediation is currently possible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
db05c214-0ade-4028-910e-19a55ce855ab
Original Timestamp
1773100987

Indicators of Compromise

Domain

ValueDescriptionCopy
domaingood-gate.goodtime.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainkirk-service.live
MaskGramStealer botnet C2 domain (confidence level: 100%)
domaincrispy-rusty.com
SantaStealer botnet C2 domain (confidence level: 100%)
domainford-sync.ironford.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingate-v05.lakegate.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingennods.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainbrocaez.club
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainfamilbg.club
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainmobbyyt.club
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainnbdeco.fr
StrelaStealer payload delivery domain (confidence level: 100%)
domainclay-logic.redclay.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainred-v09.redclay.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainclay-gate.redclay.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainred-unit.redclay.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbend-ref.oakbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnearchos-akte.gr
StrelaStealer payload delivery domain (confidence level: 100%)
domainoak-v11.oakbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbend-base.oakbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainoak-net.oakbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainneckaralb.digital
StrelaStealer payload delivery domain (confidence level: 100%)
domainneighborhoodroofingllc.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainvult-node.nexoris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnex-v01.nexoris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnekoamerikaheiku.info
StrelaStealer payload delivery domain (confidence level: 100%)
domainvult-sync.nexoris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnex-base.nexoris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainalt-hub.zenithra.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainneuroconsultas.pt
StrelaStealer payload delivery domain (confidence level: 100%)
domainnew.avtograf.ee
StrelaStealer payload delivery domain (confidence level: 100%)
domainzen-v12.zenithra.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnew.tsypin.partners
StrelaStealer payload delivery domain (confidence level: 100%)
domainalt-net.zenithra.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainzen-flow.zenithra.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainops-gate.lumitron.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnewenergypartnership.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainlumi-v3.lumitron.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnewlinekitchens.hdps.co.za
StrelaStealer payload delivery domain (confidence level: 100%)
domainmpt.pedagogiai-tarsasag.hu
StrelaStealer payload delivery domain (confidence level: 100%)
domainops-unit.lumitron.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnaosagioulouka.gr
StrelaStealer payload delivery domain (confidence level: 100%)
domainlumi-edge.lumitron.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindist-core.veloxis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnevikup.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainauraplay.vip
Cobalt Strike botnet C2 domain (confidence level: 50%)
domainavlc2.westus2.cloudapp.azure.com
Havoc botnet C2 domain (confidence level: 100%)
domainnewproject1.dashop.tech
StrelaStealer payload delivery domain (confidence level: 100%)
domainnews.mohitrathi.in
StrelaStealer payload delivery domain (confidence level: 100%)
domainnewsite.lbgresearch.org
StrelaStealer payload delivery domain (confidence level: 100%)
domainvel-v44.veloxis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnewtli.theteambuilderadrc.com
StrelaStealer payload delivery domain (confidence level: 100%)
domaindist-sync.veloxis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnewvermont.fairgoseo.com.au
StrelaStealer payload delivery domain (confidence level: 100%)
domainvel-data.veloxis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbit-vault.cryptixy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnexoeasy-88.com
StrelaStealer payload delivery domain (confidence level: 100%)
domaincryp-v05.cryptixy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbit-hub.cryptixy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnexxusmanagement.com
StrelaStealer payload delivery domain (confidence level: 100%)
domaincryp-node.cryptixy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmain-peak.solarisx.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnflug.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainsol-v6.solarisx.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmain-sys.solarisx.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsol-base.solarisx.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbigbrainsholdings.com
CountLoader payload delivery domain (confidence level: 100%)
domaindebank-api.cc
CountLoader payload delivery domain (confidence level: 100%)
domainmagnusworkspace.com
CountLoader payload delivery domain (confidence level: 100%)
domainnode2-py-store.com
CountLoader payload delivery domain (confidence level: 100%)
domainpy-installer.cc
CountLoader payload delivery domain (confidence level: 100%)
domains1-rarlab.com
CountLoader payload delivery domain (confidence level: 100%)
domains3-python.cc
CountLoader payload delivery domain (confidence level: 100%)
domainupdateservice1-telegramweb.com
CountLoader payload delivery domain (confidence level: 100%)
domainweb3-walletnotify.cc
CountLoader payload delivery domain (confidence level: 100%)
domainngoaithatnhatban.vn
StrelaStealer payload delivery domain (confidence level: 100%)
domainsite-node.terravia.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainterr-v77.terravia.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsite-net.terravia.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainterr-run.terravia.in.net
ClearFake payload delivery domain (confidence level: 100%)
domain11uttaq1.bitterfisherm.digital
ClearFake payload delivery domain (confidence level: 100%)
domainovbfopy8.bitterfisherm.digital
ClearFake payload delivery domain (confidence level: 100%)
domainterm-way.niventa.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainniv-v08.niventa.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainterm-sync.niventa.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmullenpalimpseststudio.com
HijackLoader botnet C2 domain (confidence level: 100%)
domainniv-flow.niventa.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwriconsult.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainlink-logic.astronis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainoakumsnarrowboats.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainarlingtonheightsgaragedoors.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaininvitoenergypartners.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainfraziewealthmanagement.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainnorthernvirginiapainting.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainvrf.cldvrfd.click
Unknown malware payload delivery domain (confidence level: 100%)
domaintkmfinancialservices.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainastro-v09.astronis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnewyorkcitybrandingagency.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainlink-gate.astronis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainastro-unit.astronis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintech-ref.moxura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmox-v11.moxura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintech-base.moxura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmentaorb.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmox-net.moxura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainjaxfamilylawyers.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainooe.myserver.com.bd
Vidar botnet C2 domain (confidence level: 100%)
domaindel.nexs.com.bd
Vidar botnet C2 domain (confidence level: 100%)
domainftx.nexs.com.bd
Vidar botnet C2 domain (confidence level: 100%)
domaingpa.nexs.com.bd
Vidar botnet C2 domain (confidence level: 100%)
domaingrc.nexs.com.bd
Vidar botnet C2 domain (confidence level: 100%)
domaineah.nexs.com.bd
Vidar botnet C2 domain (confidence level: 100%)
domainooe.nexs.com.bd
Vidar botnet C2 domain (confidence level: 100%)
domaindel.kindnessbrand.com
Vidar botnet C2 domain (confidence level: 100%)
domainftx.kindnessbrand.com
Vidar botnet C2 domain (confidence level: 100%)
domaingpa.jamesbreese.com
Vidar botnet C2 domain (confidence level: 100%)
domaingrc.jamesbreese.com
Vidar botnet C2 domain (confidence level: 100%)
domaineah.jamesbreese.com
Vidar botnet C2 domain (confidence level: 100%)
domainooe.jamesbreese.com
Vidar botnet C2 domain (confidence level: 100%)
domainres2erch-sl0ut.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainsyncryp.bestink.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainjwalb.bestink.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainalt-d0ck.bestink.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainch3c-line.bestink.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindev-moral.askloop.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbineress.shop
Vidar botnet C2 domain (confidence level: 100%)
domainserdraix4.askloop.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintri-fluxor.askloop.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainjfjoj.askloop.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincarrierstream.toolbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainniceonefashion.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainprrnftoa.toolbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainguardtrans.toolbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainreel-mount.toolbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfvj7.blackford.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainoute2-grid.blackford.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnick.olesak.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainmossoak.blackford.in.net
ClearFake payload delivery domain (confidence level: 100%)
domain1ago-plate.blackford.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnickis-reinigungsservice.de
StrelaStealer payload delivery domain (confidence level: 100%)
domainhyrfnqqh.fullgate.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainqueuemarsh.fullgate.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnickleger.com
StrelaStealer payload delivery domain (confidence level: 100%)
domaintr-official.shop
Unknown malware payload delivery domain (confidence level: 100%)
domainskin-greece.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainshown-mario.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domaindreem-45850.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainnice-off.shop
Unknown malware payload delivery domain (confidence level: 100%)
domaingaydkonx.fullgate.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwinterque.fullgate.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainognbb.rollbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainb74nufw.rollbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainvelline5en.rollbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainneo-gu1de.rollbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainvalu-crest.spinpath.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainquorlithix3.spinpath.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrepairdefend.spinpath.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstri5-reach.spinpath.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnikita.vn
StrelaStealer payload delivery domain (confidence level: 100%)
domainr3nder-switch.windright.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainloader.dojiner.at
ArcaneStealer botnet C2 domain (confidence level: 100%)
domainlknz.windright.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnikosstratakis.com
StrelaStealer payload delivery domain (confidence level: 100%)
domain6h76gr0n.diagnosfirst.digital
ClearFake payload delivery domain (confidence level: 100%)
domain9mha5mm1.diagnosfirst.digital
ClearFake payload delivery domain (confidence level: 100%)
domainunload-bridge.windright.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainletcurre.windright.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainzztzqouw.redflat.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmeta-p4stur.redflat.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpalemicro.redflat.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainxxhigsz.redflat.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwarmgrim.slowbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domains0lid-leaf.slowbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainiqdrq.slowbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainninjaflix-ead.bloco101.com
StrelaStealer payload delivery domain (confidence level: 100%)
domaincolumnreel.slowbend.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainprim-node.veritax.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainveri-v01.veritax.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainprim-sync.veritax.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainveri-base.veritax.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainalt-hub.kronosis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainkron-v12.kronosis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainalt-net.kronosis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainkron-flow.kronosis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainops-gate.dynastis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindyna-v3.dynastis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainops-unit.dynastis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaineo4quhil.cheesechubary.digital
ClearFake payload delivery domain (confidence level: 100%)
domaindyna-edge.dynastis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domain8r6d1s3j.cheesechubary.digital
ClearFake payload delivery domain (confidence level: 100%)
domaindist-core.nexulon.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnexu-v44.nexulon.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainvenom-stealer.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainespace.servebeer.com
Unknown malware botnet C2 domain (confidence level: 100%)
domaindist-sync.nexulon.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainkampf.huehnchenfarm.ru
PureRAT botnet C2 domain (confidence level: 100%)
domainnexu-data.nexulon.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnlp.edu.sofine.ua
StrelaStealer payload delivery domain (confidence level: 100%)
domainbit-vault.zentalis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfiles.jeaniescott.digital
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainzent-v05.zentalis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbit-hub.zentalis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainzent-node.zentalis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmain-peak.orbisura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnfkavn.bond
Unknown malware botnet C2 domain (confidence level: 100%)
domainorbi-v6.orbisura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnero-ns-cdns.sbs
Unknown malware payload delivery domain (confidence level: 100%)
domainadcdn.ster.nl
Amatera botnet C2 domain (confidence level: 100%)
domainmain-sys.orbisura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainapi-server-cdn.sbs
Unknown malware payload delivery domain (confidence level: 100%)
domainorbi-base.orbisura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnoa360.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainsite-node.fluxoris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainapi-imager-host.beer
Unknown malware payload delivery domain (confidence level: 100%)
domainns-server-isdjs-icons.sbs
Unknown malware payload delivery domain (confidence level: 100%)
domainflux-v77.fluxoris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainns-cyber-server.sbs
Unknown malware payload delivery domain (confidence level: 100%)
domainsite-net.fluxoris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainflux-run.fluxoris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainterm-way.vibrante.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainvibr-v08.vibrante.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainterm-sync.vibrante.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainvibr-flow.vibrante.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlink-logic.spectris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspec-v09.spectris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlink-gate.spectris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspec-unit.spectris.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintech-ref.quintura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainquin-v11.quintura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintech-base.quintura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainquin-net.quintura.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintransmfield.wayton.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfaitdem.wayton.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrender5-line.wayton.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainva1u-node.wayton.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnomorchaos.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainguid-route.greentea.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindeal1-point.greentea.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainglossapi.greentea.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsdk9-pulse.greentea.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintax-fc.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainbui13-well.costfee.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainreel-tok.costfee.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpa5s7-signal.costfee.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainroad-layer.droplast.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsub-ca1m.droplast.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindark-shi.droplast.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnorthoflajollapublishing.com.quickcooldesign.com
StrelaStealer payload delivery domain (confidence level: 100%)
domaineaec4m.droplast.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmars-sort.lookback.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsp4rrow-phase.lookback.in.net
ClearFake payload delivery domain (confidence level: 100%)
domain3zwcexo.lookback.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainu1tr5-bridge.lookback.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnotepad.promadesign.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainsyst-node.centurionix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincent-v01.centurionix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainalti-v12.altimetrica.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaininfra-net.altimetrica.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwww.kludt8zn.shop
Quasar RAT botnet C2 domain (confidence level: 100%)
domainwww.r15p5l5b.shop
Quasar RAT botnet C2 domain (confidence level: 100%)
domainwww.nlmz602h.shop
Quasar RAT botnet C2 domain (confidence level: 100%)
domainwww.7dk5l721.shop
Quasar RAT botnet C2 domain (confidence level: 100%)
domainalti-flow.altimetrica.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindata-gate.quantovault.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainquan-v3.quantovault.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindata-unit.quantovault.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainquan-edge.quantovault.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlogic-core.primordialis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainprim-v44.primordialis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlogic-sync.primordialis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnovikon.nikolaev.ua
StrelaStealer payload delivery domain (confidence level: 100%)
domainprim-data.primordialis.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnovo.blockerbrasil.com.br
StrelaStealer payload delivery domain (confidence level: 100%)
domainvult-vault.spectrometric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspec-v05.spectrometric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainyhcy21oo.demogsystemat.digital
ClearFake payload delivery domain (confidence level: 100%)
domainf0fjv96k.demogsystemat.digital
ClearFake payload delivery domain (confidence level: 100%)
domainvult-hub.spectrometric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspec-node.spectrometric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmain-peak.obsidianix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainobsi-v6.obsidianix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmain-sys.obsidianix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainobsi-base.obsidianix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainterm-way.vibratronic.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwww.cloudflara.xyz
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainvibr-v08.vibratronic.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainterm-sync.vibratronic.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainvibr-flow.vibratronic.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainflow-logic.synchromesh.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsync-v09.synchromesh.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainflow-gate.synchromesh.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnpj.app
StrelaStealer payload delivery domain (confidence level: 100%)
domainsync-unit.synchromesh.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintech-ref.galactoview.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingala-v11.galactoview.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintech-base.galactoview.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingala-net.galactoview.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlink-node.structovista.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindytdttyhhmjfjtydukytdtdrtrtjrttgyuttfdtd.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainstru-v77.structovista.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnsgpara.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainlink-net.structovista.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnslwzqa.org
StrelaStealer payload delivery domain (confidence level: 100%)
domainstru-run.structovista.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnuevaimagen.esnaj.com
StrelaStealer payload delivery domain (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://www.ulfhedinnvikings.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/mzcxijwx2zg9e7w
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/ejk52zwt2js16ro
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/6v0tazc5mboxujs
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/q7cherolivolejk
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/iro9a3cp6zsd230
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/ujgti3g12f45y74
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/m3o1azkhufs1enk
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/y74habwtyvsxarw
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/a7k56jotufo5ab4
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/2vk56j8h27whyzg
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/6v4de3o1yz0du7k
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/yzc5yj81yv0h2fw
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/6e07a7147a15224446034debd2d1288b/ufcx6bc1ef45e7g
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttp://kirk-service.live/reconcile
MaskGramStealer botnet C2 (confidence level: 100%)
urlhttps://crispy-rusty.com/
SantaStealer botnet C2 (confidence level: 100%)
urlhttp://83.142.209.47/x
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://cdn-us-cloudflare-services.t3.storage.dev/follow/index.html?x-amz-algorithm=aws4-hmac-sha256&x-amz-credential=tid_ydatdzfwt_hunghpsgltcegtzeeiwhetiouwdibgulkrrlknws%2f20260308%2fauto%2fs3%2faws4_request&x-amz-date=20260308t175148z&x-amz-expires=172800&x-amz-signedheaders=host&x-amz-signature=ffdb4b5c5e00d0d24ba730369686eba47c5bf55f2d83780482e67a0b03ebe2c0
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://85.28.47.152
Stealc botnet C2 (confidence level: 100%)
urlhttp://192.168.2.53:80/am8w
Cobalt Strike botnet C2 (confidence level: 75%)
urlhttps://next-step-n4.t3.storage.dev/index.html?x-amz-algorithm=aws4-hmac-sha256&x-amz-credential=tid_wnnisps__tskokdg_uwkaghhuvhbcshbutgbmxtaqtxsqtrdfy/20260308/auto/s3/aws4_request&x-amz-date=20260308t012517z&x-amz-expires=2160000&x-amz-signedhe
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://45.156.87.17/reg
Unidentified PS 001 payload delivery URL (confidence level: 100%)
urlhttps://64.95.10.115:23011/update.sh
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://temp.sh/tqtss/storm.exe
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://vrf.cldvrfd.click/u323245/local3.txt
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://steamcommunity.com/profiles/76561198732393960
Vidar botnet C2 (confidence level: 100%)
urlhttps://telegram.me/k33dro
Vidar botnet C2 (confidence level: 100%)
urlhttps://ooe.myserver.com.bd/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ooe.digitalmatters360.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://del.nexs.com.bd/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ftx.nexs.com.bd/
Vidar botnet C2 (confidence level: 100%)
urlhttps://gpa.nexs.com.bd/
Vidar botnet C2 (confidence level: 100%)
urlhttps://grc.nexs.com.bd/
Vidar botnet C2 (confidence level: 100%)
urlhttps://eah.nexs.com.bd/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ooe.nexs.com.bd/
Vidar botnet C2 (confidence level: 100%)
urlhttps://del.kindnessbrand.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ftx.kindnessbrand.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://gpa.jamesbreese.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://grc.jamesbreese.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://eah.jamesbreese.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ooe.jamesbreese.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://74.0.48.207/
Vidar botnet C2 (confidence level: 100%)
urlhttps://74.0.48.36/
Vidar botnet C2 (confidence level: 100%)
urlhttps://74.0.32.159/
Vidar botnet C2 (confidence level: 100%)
urlhttps://107.148.158.43/
Vidar botnet C2 (confidence level: 100%)
urlhttps://74.0.32.113/
Vidar botnet C2 (confidence level: 100%)
urlhttps://148.251.39.121/
Vidar botnet C2 (confidence level: 100%)
urlhttps://148.251.39.122/
Vidar botnet C2 (confidence level: 100%)
urlhttps://165.22.76.254/
Vidar botnet C2 (confidence level: 100%)
urlhttp://cr404896.tw1.ru/cf893288.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://tr-official.shop
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://nice-off.shop
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://134.122.152.210:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://venom-stealer.com/api/upload
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttp://venom-stealer.com/api/upload-json
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttp://venom-stealer.com/api/upload-complete
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://mcdns-imager.click/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://polygon-cnd-stats.sbs/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://llc-image-ico.click/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://nero-ns-cdns.sbs/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://llc-image-ico.click/api/index.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://nero-ns-cdns.sbs/api/index.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://polygon-cnd-stats.sbs/api/index.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://mcdns-imager.click/api/index.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://api-server-cdn.sbs/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://sys32.cc/mir8s4zzzru/index.php
Amadey botnet C2 (confidence level: 100%)
urlhttps://api-imager-host.beer/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ns-server-isdjs-icons.sbs/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ns-cyber-server.sbs/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)

File

ValueDescriptionCopy
file31.57.216.128
Remcos botnet C2 server (confidence level: 100%)
file5.206.227.239
Remcos botnet C2 server (confidence level: 100%)
file146.103.106.71
Sliver botnet C2 server (confidence level: 100%)
file38.242.144.218
AsyncRAT botnet C2 server (confidence level: 100%)
file102.117.160.235
Unknown malware botnet C2 server (confidence level: 100%)
file79.135.160.20
Unknown malware botnet C2 server (confidence level: 100%)
file8.138.0.148
Unknown malware botnet C2 server (confidence level: 100%)
file144.31.164.198
Bashlite botnet C2 server (confidence level: 100%)
file45.158.196.14
AdaptixC2 botnet C2 server (confidence level: 100%)
file196.75.62.145
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.203.193
Meterpreter botnet C2 server (confidence level: 100%)
file188.137.228.57
Empire Downloader botnet C2 server (confidence level: 100%)
file101.32.36.2
Cobalt Strike botnet C2 server (confidence level: 100%)
file101.34.203.51
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.74.48.72
Remcos botnet C2 server (confidence level: 100%)
file178.16.52.36
Remcos botnet C2 server (confidence level: 100%)
file38.54.6.205
Unknown malware botnet C2 server (confidence level: 100%)
file136.0.213.192
AsyncRAT botnet C2 server (confidence level: 100%)
file138.197.35.236
Unknown malware botnet C2 server (confidence level: 100%)
file151.240.151.123
XWorm botnet C2 server (confidence level: 100%)
file103.177.47.49
Meterpreter botnet C2 server (confidence level: 100%)
file195.24.237.47
GCleaner botnet C2 server (confidence level: 75%)
file91.219.239.7
Unknown malware botnet C2 server (confidence level: 75%)
file64.225.39.118
Sliver botnet C2 server (confidence level: 100%)
file178.16.55.119
SectopRAT botnet C2 server (confidence level: 100%)
file94.72.122.1
Unknown malware botnet C2 server (confidence level: 100%)
file40.233.14.199
Unknown malware botnet C2 server (confidence level: 100%)
file41.216.188.35
Quasar RAT botnet C2 server (confidence level: 100%)
file103.177.47.97
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.109
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.121
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.73
Meterpreter botnet C2 server (confidence level: 100%)
file123.56.52.156
Cobalt Strike botnet C2 server (confidence level: 100%)
file172.245.126.52
Cobalt Strike botnet C2 server (confidence level: 100%)
file179.43.166.147
Unknown malware botnet C2 server (confidence level: 75%)
file64.95.10.115
Unknown malware botnet C2 server (confidence level: 75%)
file134.122.13.34
SparkRAT botnet C2 server (confidence level: 75%)
file138.197.14.95
SparkRAT botnet C2 server (confidence level: 75%)
file45.32.113.200
VShell botnet C2 server (confidence level: 100%)
file182.16.76.2
VShell botnet C2 server (confidence level: 100%)
file107.189.16.142
AdaptixC2 botnet C2 server (confidence level: 100%)
file74.0.48.207
Vidar botnet C2 server (confidence level: 100%)
file74.0.48.36
Vidar botnet C2 server (confidence level: 100%)
file74.0.32.159
Vidar botnet C2 server (confidence level: 100%)
file107.148.158.43
Vidar botnet C2 server (confidence level: 100%)
file74.0.32.113
Vidar botnet C2 server (confidence level: 100%)
file148.251.39.121
Vidar botnet C2 server (confidence level: 100%)
file148.251.39.122
Vidar botnet C2 server (confidence level: 100%)
file165.22.76.254
Vidar botnet C2 server (confidence level: 100%)
file38.76.193.60
ValleyRAT botnet C2 server (confidence level: 100%)
file154.86.19.38
ValleyRAT botnet C2 server (confidence level: 100%)
file108.187.4.192
ValleyRAT botnet C2 server (confidence level: 100%)
file8.217.149.107
ValleyRAT botnet C2 server (confidence level: 100%)
file38.76.193.60
ValleyRAT botnet C2 server (confidence level: 75%)
file216.250.249.222
Remcos botnet C2 server (confidence level: 100%)
file216.250.249.222
Remcos botnet C2 server (confidence level: 100%)
file194.59.30.158
Remcos botnet C2 server (confidence level: 100%)
file5.101.86.17
Remcos botnet C2 server (confidence level: 100%)
file68.183.182.113
Havoc botnet C2 server (confidence level: 100%)
file77.91.96.232
DCRat botnet C2 server (confidence level: 100%)
file3.101.115.146
Meterpreter botnet C2 server (confidence level: 100%)
file35.177.92.190
Meterpreter botnet C2 server (confidence level: 100%)
file161.248.87.175
ValleyRAT botnet C2 server (confidence level: 100%)
file8.219.93.253
ValleyRAT botnet C2 server (confidence level: 100%)
file213.176.79.236
ArcaneStealer botnet C2 server (confidence level: 100%)
file31.57.216.28
Tofsee botnet C2 server (confidence level: 75%)
file31.57.216.27
Tofsee botnet C2 server (confidence level: 75%)
file130.12.180.119
Tofsee botnet C2 server (confidence level: 75%)
file46.151.182.245
Tofsee botnet C2 server (confidence level: 75%)
file130.12.182.175
Tofsee botnet C2 server (confidence level: 75%)
file130.12.180.85
Tofsee botnet C2 server (confidence level: 75%)
file130.12.180.144
Tofsee botnet C2 server (confidence level: 75%)
file178.104.35.103
Unknown malware botnet C2 server (confidence level: 100%)
file185.242.3.40
Unknown malware botnet C2 server (confidence level: 75%)
file45.141.119.34
PureRAT botnet C2 server (confidence level: 75%)
file45.141.119.34
PureRAT botnet C2 server (confidence level: 75%)
file103.83.86.16
Remcos botnet C2 server (confidence level: 100%)
file103.83.86.16
Remcos botnet C2 server (confidence level: 100%)
file212.118.41.7
ACR Stealer botnet C2 server (confidence level: 75%)
file89.167.47.162
ACR Stealer botnet C2 server (confidence level: 75%)
file150.241.64.21
Unknown malware botnet C2 server (confidence level: 75%)
file95.85.224.14
Unknown malware botnet C2 server (confidence level: 75%)
file62.164.177.35
Unknown malware botnet C2 server (confidence level: 75%)
file193.221.201.170
Unknown malware botnet C2 server (confidence level: 75%)
file103.121.48.141
Unknown malware botnet C2 server (confidence level: 75%)
file46.149.73.60
Amatera botnet C2 server (confidence level: 75%)
file8.138.39.67
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.9.26.175
Cobalt Strike botnet C2 server (confidence level: 100%)
file31.57.187.149
Venom RAT botnet C2 server (confidence level: 100%)
file209.74.86.135
Unknown malware botnet C2 server (confidence level: 100%)
file103.245.231.207
Meterpreter botnet C2 server (confidence level: 100%)
file45.141.119.34
PureRAT botnet C2 server (confidence level: 75%)
file141.98.6.14
Unknown malware botnet C2 server (confidence level: 75%)
file45.83.31.39
Unknown malware botnet C2 server (confidence level: 75%)
file85.235.75.90
Quasar RAT botnet C2 server (confidence level: 100%)
file161.248.87.157
ValleyRAT botnet C2 server (confidence level: 100%)
file119.28.70.225
ValleyRAT botnet C2 server (confidence level: 100%)
file119.28.70.225
ValleyRAT botnet C2 server (confidence level: 100%)
file119.28.70.225
ValleyRAT botnet C2 server (confidence level: 100%)
file87.106.216.140
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.21.209
Cobalt Strike botnet C2 server (confidence level: 100%)
file101.32.36.2
Cobalt Strike botnet C2 server (confidence level: 100%)
file185.239.69.238
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.82.24.104
Remcos botnet C2 server (confidence level: 100%)
file93.113.25.85
Sliver botnet C2 server (confidence level: 100%)
file34.154.84.183
Unknown malware botnet C2 server (confidence level: 100%)
file85.137.253.58
XWorm botnet C2 server (confidence level: 100%)
file47.129.168.50
Meterpreter botnet C2 server (confidence level: 100%)
file47.129.168.50
Meterpreter botnet C2 server (confidence level: 100%)
file16.170.165.141
Empire Downloader botnet C2 server (confidence level: 100%)
file172.86.107.2
Cobalt Strike botnet C2 server (confidence level: 75%)
file193.42.25.65
Cobalt Strike botnet C2 server (confidence level: 75%)
file38.147.170.252
Cobalt Strike botnet C2 server (confidence level: 75%)
file77.221.149.33
Unknown Loader botnet C2 server (confidence level: 100%)
file91.231.222.220
AsyncRAT botnet C2 server (confidence level: 100%)
file103.65.230.86
Unknown RAT botnet C2 server (confidence level: 100%)
file172.245.4.221
Remcos botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash7755
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Bashlite botnet C2 server (confidence level: 100%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 100%)
hash2222
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash1337
Empire Downloader botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8007
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash2121
Remcos botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
XWorm botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash80
GCleaner botnet C2 server (confidence level: 75%)
hash8080
Unknown malware botnet C2 server (confidence level: 75%)
hash8443
Sliver botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8084
Unknown malware botnet C2 server (confidence level: 75%)
hash23011
Unknown malware botnet C2 server (confidence level: 75%)
hash9f431d5549a03aee92cfd2bdbbe90f1c91e965c99e90a0c9ad5a001f4e80c350
Unknown malware payload (confidence level: 100%)
hash98a7b0900a9072bb40af579ec372da7b27af12b15868394df51fefe290ab176b
Unknown malware payload (confidence level: 100%)
hash66cceb2c2f1d9988b501832fd3b559775982e2fce4ab38fc4ffe71b74eafc726
Unknown malware payload (confidence level: 100%)
hash679ee05d92a858b6fe70aeb6072eb804548f1732e18b6c181af122b833386afb
Unknown malware payload (confidence level: 100%)
hash4762e944a0ce1f9aef243e11538f84f16b6f36560ed6e32dfd9a5f99e17e8e50
Unknown malware payload (confidence level: 100%)
hash98442387d466f27357d727b3706037a4df12a78602b93df973b063462a677761
Unknown malware payload (confidence level: 100%)
hashcc2bc3750cc5125a50466f66ae4f2bedf1cac0e43477a78ed2fd88f3e987a292
Unknown malware payload (confidence level: 100%)
hashcf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce
Unknown malware payload (confidence level: 100%)
hash0ecc867ce916d01640d76ec03de24d1d23585eb582e9c48a0364c62a590548ac
Unknown malware payload (confidence level: 100%)
hash8979
SparkRAT botnet C2 server (confidence level: 75%)
hash80
SparkRAT botnet C2 server (confidence level: 75%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash8001
VShell botnet C2 server (confidence level: 100%)
hash443
AdaptixC2 botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash5554
ValleyRAT botnet C2 server (confidence level: 100%)
hash9001
ValleyRAT botnet C2 server (confidence level: 100%)
hash448
ValleyRAT botnet C2 server (confidence level: 100%)
hash8888
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
ValleyRAT botnet C2 server (confidence level: 75%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash80
Remcos botnet C2 server (confidence level: 100%)
hash6699
Remcos botnet C2 server (confidence level: 100%)
hash2428
Remcos botnet C2 server (confidence level: 100%)
hash8443
Havoc botnet C2 server (confidence level: 100%)
hash7777
DCRat botnet C2 server (confidence level: 100%)
hash42544
Meterpreter botnet C2 server (confidence level: 100%)
hash7576
Meterpreter botnet C2 server (confidence level: 100%)
hash7777
ValleyRAT botnet C2 server (confidence level: 100%)
hash5201
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
ArcaneStealer botnet C2 server (confidence level: 100%)
hash416
Tofsee botnet C2 server (confidence level: 75%)
hash416
Tofsee botnet C2 server (confidence level: 75%)
hash416
Tofsee botnet C2 server (confidence level: 75%)
hash416
Tofsee botnet C2 server (confidence level: 75%)
hash416
Tofsee botnet C2 server (confidence level: 75%)
hash416
Tofsee botnet C2 server (confidence level: 75%)
hash416
Tofsee botnet C2 server (confidence level: 75%)
hash29078
Unknown malware botnet C2 server (confidence level: 100%)
hash4444
Unknown malware botnet C2 server (confidence level: 75%)
hash8443
PureRAT botnet C2 server (confidence level: 75%)
hash56001
PureRAT botnet C2 server (confidence level: 75%)
hash15098
Remcos botnet C2 server (confidence level: 100%)
hash15099
Remcos botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 75%)
hash443
ACR Stealer botnet C2 server (confidence level: 75%)
hash8888
Unknown malware botnet C2 server (confidence level: 75%)
hash8000
Unknown malware botnet C2 server (confidence level: 75%)
hash8088
Unknown malware botnet C2 server (confidence level: 75%)
hash8088
Unknown malware botnet C2 server (confidence level: 75%)
hash8443
Unknown malware botnet C2 server (confidence level: 75%)
hash80
Amatera botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash1604
Venom RAT botnet C2 server (confidence level: 100%)
hash2850
Unknown malware botnet C2 server (confidence level: 100%)
hash4444
Meterpreter botnet C2 server (confidence level: 100%)
hash39002
PureRAT botnet C2 server (confidence level: 75%)
hash5563
Unknown malware botnet C2 server (confidence level: 75%)
hash5173
Unknown malware botnet C2 server (confidence level: 75%)
hash25565
Quasar RAT botnet C2 server (confidence level: 100%)
hash4499
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
ValleyRAT botnet C2 server (confidence level: 100%)
hash5860
ValleyRAT botnet C2 server (confidence level: 100%)
hash983
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash30502
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2083
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash9000
XWorm botnet C2 server (confidence level: 100%)
hash389
Meterpreter botnet C2 server (confidence level: 100%)
hash8389
Meterpreter botnet C2 server (confidence level: 100%)
hash80
Empire Downloader botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash1444
Cobalt Strike botnet C2 server (confidence level: 75%)
hash7777
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Unknown Loader botnet C2 server (confidence level: 100%)
hash5620
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Unknown RAT botnet C2 server (confidence level: 100%)
hash2406
Remcos botnet C2 server (confidence level: 100%)

Threat ID: 69af634bea502d3aa8dad08d

Added to database: 3/10/2026, 12:18:19 AM

Last enriched: 3/10/2026, 12:18:30 AM

Last updated: 3/14/2026, 3:14:00 AM

Views: 203

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses