ThreatFox IOCs for 2026-03-30
ThreatFox IOCs for 2026-03-30
AI Analysis
Technical Summary
This threat report from the ThreatFox MISP feed provides a collection of Indicators of Compromise (IOCs) related to malware activity as of March 30, 2026. The information is categorized under OSINT (Open Source Intelligence), network activity, and payload delivery, suggesting these IOCs are intended to help security analysts detect malicious network behavior and identify malware payloads during investigations. The absence of specific affected software versions or known exploits in the wild indicates that this is not a newly discovered vulnerability but rather a set of intelligence data for detection purposes. No patches or remediation links are provided, reinforcing that this is not a vulnerability requiring immediate patching but a threat intelligence update. The threat level is medium, reflecting moderate concern based on the available data. The technical details include a threat level rating of 2 and distribution rating of 3, which implies some degree of dissemination but limited active exploitation. The lack of CWE identifiers and exploit evidence suggests this is primarily a monitoring and detection resource rather than an active attack vector. The IOCs can be integrated into security monitoring tools, SIEMs, and threat hunting workflows to improve detection of related malware activity. Overall, this feed supports proactive defense by providing timely intelligence on potential malware indicators without indicating an urgent or critical vulnerability.
Potential Impact
The impact of this threat intelligence is primarily on an organization's ability to detect and respond to malware-related network activity. Since no active exploits or vulnerabilities are reported, the direct risk of compromise from this specific data is low. However, failure to incorporate these IOCs into security monitoring could result in missed detection opportunities, allowing malware infections or payload deliveries to go unnoticed. Organizations worldwide that rely on OSINT and network monitoring tools stand to benefit from this intelligence to enhance situational awareness and incident response. The medium severity rating reflects that while the threat is not immediately critical, it represents a meaningful contribution to defense-in-depth strategies. Without patches or active exploits, the impact is limited to detection capabilities rather than direct system compromise or data loss. The threat intelligence can help reduce dwell time of malware infections and improve overall security posture by enabling earlier identification of malicious activity.
Mitigation Recommendations
To effectively leverage this threat intelligence, organizations should integrate the provided IOCs into their existing security infrastructure, including SIEM platforms, intrusion detection/prevention systems (IDS/IPS), endpoint detection and response (EDR) tools, and network monitoring solutions. Regularly updating threat feeds and correlating these IOCs with internal logs will enhance detection accuracy. Security teams should conduct threat hunting exercises using these indicators to identify any latent or ongoing malware activity. Since no patches are available, focus should be on detection, containment, and remediation of infections. Implementing network segmentation and strict egress filtering can limit payload delivery and lateral movement. Additionally, organizations should maintain robust incident response plans to quickly address any malware detections. Training security analysts on interpreting OSINT-based IOCs and understanding their context will improve response effectiveness. Finally, sharing findings and feedback with threat intelligence communities can help refine and expand the quality of future IOCs.
Affected Countries
United States, Germany, United Kingdom, France, Canada, Australia, Netherlands, Japan, South Korea, Israel
Indicators of Compromise
- domain: true-presents-thereafter-und.trycloudflare.com
- domain: apparatus-contributions-understood-accommodation.trycloudflare.com
- domain: essayajewelry.com
- domain: detailingoff.com
- domain: scott-spring-netscape-monica.trycloudflare.com
- domain: dreambigworkharddomore.com
- domain: permission-resident-lots-ebooks.trycloudflare.com
- domain: lbimuseum.org
- domain: dealing-economics-enrollment-firms.trycloudflare.com
- domain: globalwork.best
- domain: carsaggregator.com
- domain: pagedit.shop
- file: 194.26.192.180
- hash: 8080
- file: 20.5.49.243
- hash: 443
- domain: baggiup.cyou
- domain: florjxt.cyou
- domain: patrmpf.cyou
- domain: slenjzj.cyou
- domain: skylips.cyou
- domain: yashnei.cyou
- file: 194.26.192.248
- hash: 8080
- file: 194.26.192.248
- hash: 443
- domain: sfr-webmail.com
- domain: client-macif.com
- domain: espace-macif.com
- domain: webclient-secure.com
- domain: documentacknowledgementstatuscheck.us
- domain: mohadm.sw.so
- domain: selectahrsolutions.com
- domain: superveneza.com
- domain: matronacons.com
- domain: adaptationinternatoinal.com
- domain: akarindia.com
- domain: juruaialojas.com.br
- url: https://kwsecurity.site/
- domain: instant-msg.velocityterminal.in.net
- domain: city-monitor.metropolitangrid.in.net
- file: 172.86.91.224
- hash: 1999
- domain: street-logic.metropolitangrid.in.net
- domain: area-scanner.metropolitangrid.in.net
- domain: block-sensor.metropolitangrid.in.net
- domain: zone-portal.metropolitangrid.in.net
- domain: urban-access.metropolitangrid.in.net
- domain: traffic-api.urbanflowmetric.in.net
- domain: stream-audit.urbanflowmetric.in.net
- domain: surge-protect.urbanflowmetric.in.net
- file: 107.158.128.79
- hash: 443
- file: 192.109.200.184
- hash: 3000
- domain: pulse-check.urbanflowmetric.in.net
- domain: drift-control.urbanflowmetric.in.net
- file: 64.89.161.130
- hash: 8080
- domain: flow-master.urbanflowmetric.in.net
- domain: coord-sync.precisemapnode.in.net
- domain: point-atlas.precisemapnode.in.net
- domain: layer-stack.precisemapnode.in.net
- domain: scale-vector.precisemapnode.in.net
- domain: view-finder.precisemapnode.in.net
- domain: topo-render.precisemapnode.in.net
- file: 16.16.182.17
- hash: 80
- file: 103.182.228.91
- hash: 80
- file: 139.59.88.137
- hash: 80
- domain: local-cache.districtbuffer.in.net
- domain: temp-storage.districtbuffer.in.net
- domain: queue-manager.districtbuffer.in.net
- domain: premwork.duckdns.org
- file: 151.245.112.70
- hash: 8990
- domain: malware.xoilaczzw.tv
- domain: fnhztgxdqg.a.pinggy.link
- domain: acannaaaaa-32635.portmap.host
- domain: relay-point.districtbuffer.in.net
- domain: load-buffer.districtbuffer.in.net
- domain: site-archive.districtbuffer.in.net
- domain: admin-panel.sectoralcontrol.in.net
- domain: unit-command.sectoralcontrol.in.net
- domain: remote-desk.sectoralcontrol.in.net
- domain: system-core.sectoralcontrol.in.net
- domain: switch-gear.sectoralcontrol.in.net
- domain: task-logic.sectoralcontrol.in.net
- domain: link-secure.linearbackbone.in.net
- domain: path-bridge.linearbackbone.in.net
- domain: trunk-line.linearbackbone.in.net
- domain: fiber-route.linearbackbone.in.net
- domain: main-frame.linearbackbone.in.net
- domain: node-carrier.linearbackbone.in.net
- domain: inlet-valve.centralizedduct.in.net
- domain: outlet-node.centralizedduct.in.net
- domain: filter-proc.centralizedduct.in.net
- domain: flow-guide.centralizedduct.in.net
- domain: pressure-io.centralizedduct.in.net
- domain: tunnel-sync.centralizedduct.in.net
- domain: wide-telemetry.regionaltelemetry.in.net
- domain: field-report.regionaltelemetry.in.net
- domain: signal-box.regionaltelemetry.in.net
- domain: data-packet.regionaltelemetry.in.net
- domain: wave-form.regionaltelemetry.in.net
- domain: remote-log.regionaltelemetry.in.net
- domain: border-gate.territoriallink.in.net
- domain: proxy-edge.territoriallink.in.net
- domain: land-mark.territoriallink.in.net
- domain: site-connect.territoriallink.in.net
- file: 5.188.87.38
- hash: 443
- domain: map-anchor.territoriallink.in.net
- domain: newremc.duckdns.org
- file: 107.172.13.249
- hash: 9010
- domain: diary-learn.sa.com
- domain: dominofranchiseind.in.net
- domain: hdjjjf.za.com
- domain: iso.radio.fm
- domain: makeuseof.it.com
- domain: reprint-handbook.sa.com
- domain: syfaaf.za.com
- domain: venomrat.com
- domain: xn--eck3a9bu7cul.jp.net
- domain: bot.codeeye.in.net
- domain: childrensex.codeeye.in.net
- domain: domain.codeeye.in.net
- domain: googlemalware.codeeye.in.net
- domain: money.codeeye.in.net
- domain: namecheap.codeeye.in.net
- domain: namecheapmalwaredowload.codeeye.in.net
- domain: scan.codeeye.in.net
- domain: sex.codeeye.in.net
- file: 2.27.41.248
- hash: 5632
- domain: reach-base.territoriallink.in.net
- domain: public-serv.municipalmatrix.in.net
- domain: town-council.municipalmatrix.in.net
- file: 23.132.132.67
- hash: 8808
- file: 193.42.24.214
- hash: 16790
- file: 206.238.115.206
- hash: 8880
- file: 180.178.56.230
- hash: 80
- domain: citizen-dev.municipalmatrix.in.net
- domain: auth-trust.municipalmatrix.in.net
- domain: code-index.municipalmatrix.in.net
- domain: mybiggestjoy.bond
- url: https://mybiggestjoy.bond/cf.js
- url: https://mybiggestjoy.bond/api/index.php
- url: https://mybiggestjoy.bond/log.php
- domain: routeletters.xyz
- domain: profitfact.xyz
- domain: liquidwrench.cfd
- domain: form-builder.municipalmatrix.in.net
- url: https://djasdajnsdnjgjg.com/fdghdfgh.js
- url: https://sekolahtinta.edu.my/wp-blog-footer.php
- url: https://188.166.10.165
- url: https://49.12.3.48
- url: https://sekolahtinta.edu.my/wp-blog-footer.php?page=
- url: https://136.244.96.112/
- url: https://put.cargomanbd.com/
- url: https://epy.cargomanbd.com/
- url: https://agi.cargomanbd.com/
- url: https://pva.cargomanbd.com/
- url: https://ggv.cargomanbd.com/
- url: https://gre.cargomanbd.com/
- url: https://gre.syslic.net/
- url: https://put.elythia.online/
- url: https://epy.elythia.online/
- url: https://agi.elythia.online/
- url: https://pva.elythia.online/
- url: https://ggv.elythia.online/
- url: https://gre.elythia.online/
- url: http://jdosu.funnythings.store/
- url: https://49.12.9.171/
- url: https://95.217.125.49/
- url: https://95.217.125.50/
- url: https://151.245.121.216/
- url: https://91.99.183.16/
- domain: put.cargomanbd.com
- domain: epy.cargomanbd.com
- domain: agi.cargomanbd.com
- domain: pva.cargomanbd.com
- domain: ggv.cargomanbd.com
- domain: gre.cargomanbd.com
- domain: gre.syslic.net
- domain: put.elythia.online
- domain: epy.elythia.online
- domain: agi.elythia.online
- domain: pva.elythia.online
- domain: ggv.elythia.online
- domain: jdosu.funnythings.store
- domain: heavy-duty.infrastructurehub.in.net
- file: 136.244.96.112
- hash: 443
- file: 49.12.9.171
- hash: 443
- file: 95.217.125.49
- hash: 443
- file: 95.217.125.50
- hash: 443
- file: 151.245.121.216
- hash: 443
- file: 188.166.10.165
- hash: 443
- file: 91.99.183.16
- hash: 443
- file: 49.12.3.48
- hash: 443
- file: 20.115.57.167
- hash: 4443
- file: 141.11.76.246
- hash: 8080
- domain: solid-state.infrastructurehub.in.net
- domain: sign-in-property.com
- url: https://sign-in-property.com/start/
- file: 185.177.239.196
- hash: 443
- domain: agdosve.com
- file: 157.245.60.230
- hash: 7443
- url: https://agdosve.com
- domain: asfasfqwf.com
- domain: asdasfa.com
- domain: base-build.infrastructurehub.in.net
- domain: asset-track.infrastructurehub.in.net
- domain: power-plant.infrastructurehub.in.net
- domain: resource-api.infrastructurehub.in.net
- domain: lumvale8is.starforge.in.net
- domain: vvave3-gate.starforge.in.net
- domain: 80tlyi.starforge.in.net
- domain: icegold.starforge.in.net
- domain: zencrestal2.starforge.in.net
- domain: aftwizk.starforge.in.net
- domain: n73pw.br1ghtmere.in.net
- domain: cell-plate.br1ghtmere.in.net
- url: https://steamcommunity.com/profiles/76561198721902688
- url: https://telegram.me/p74kol
- domain: screennotify.br1ghtmere.in.net
- domain: wgyinknm.br1ghtmere.in.net
- domain: tal-venal.br1ghtmere.in.net
- domain: vmcs.br1ghtmere.in.net
- domain: runwaypublic.oakwhisper.in.net
- domain: filteglob.oakwhisper.in.net
- file: 130.12.182.112
- hash: 2404
- domain: hyper-4uth.oakwhisper.in.net
- file: 172.232.125.148
- hash: 23004
- file: 172.238.111.131
- hash: 23004
- file: 172.232.214.12
- hash: 23004
- file: 172.232.253.229
- hash: 23004
- file: 165.22.220.235
- hash: 23004
- file: 172.105.74.253
- hash: 23004
- file: 172.232.35.106
- hash: 23004
- file: 172.236.172.130
- hash: 23004
- file: 5.230.170.237
- hash: 23004
- file: 5.230.170.238
- hash: 23004
- file: 5.230.170.239
- hash: 23004
- file: 5.230.170.240
- hash: 23004
- file: 194.50.5.27
- hash: 53
- domain: riverrefine.oakwhisper.in.net
- domain: wpx3375n.oakwhisper.in.net
- domain: 11kzvq.oakwhisper.in.net
- domain: subtlsegme.foxrunet.in.net
- domain: lwvkfb.foxrunet.in.net
- domain: urbanvoya.foxrunet.in.net
- domain: refineterminal.foxrunet.in.net
- file: 178.16.54.81
- hash: 2409
- domain: malaimusic.in.net
- file: 82.192.72.181
- hash: 55615
- file: 151.245.112.70
- hash: 7007
- domain: echo-draf.foxrunet.in.net
- domain: nortideis.foxrunet.in.net
- domain: crimsonpublish.stormglade.in.net
- domain: quordra3os.stormglade.in.net
- domain: opsec-cf.com
- url: https://opsec-cf.com/api/css.js
- domain: offecargo.stormglade.in.net
- domain: ligh-stric.stormglade.in.net
- domain: we5ohkh2.stormglade.in.net
- domain: maroc-hotel.com
- url: https://maroc-hotel.com
- domain: anch0r1-route.stormglade.in.net
- domain: proto-p0rt.n0vabrook.in.net
- domain: 3d1t-node.n0vabrook.in.net
- url: https://mezcalpro.com/q
- url: https://qanivor.top/session/endpoint-parser.js
- domain: qanivor.top
- url: https://qanivor.top/session/role-pipeline.php
- url: https://qanivor.top/session/signin-component.js
- url: https://zempraxo.com/ddd/angular
- domain: decode-stead.n0vabrook.in.net
- domain: quick8-chain.n0vabrook.in.net
- domain: guarmea.n0vabrook.in.net
- url: https://nabil-gateway.thebetterappliances.com/
- domain: wu4747.n0vabrook.in.net
- domain: bzknn.starforge.in.net
- domain: meta-0rch.starforge.in.net
- domain: tranrur.starforge.in.net
- domain: geyseropti.starforge.in.net
- domain: bastroh.no-ip.org
- file: 47.76.86.151
- hash: 23157
- domain: restaurant-contacts.gl.at.ply.gg
- domain: yyin.br1ghtmere.in.net
- domain: 95abc92.br1ghtmere.in.net
- domain: runti5-flow.br1ghtmere.in.net
- domain: proto-tru5ted.br1ghtmere.in.net
- url: https://brochurehub.co.uk/
- domain: dispatchmemory.oakwhisper.in.net
- domain: 50ravelv.oakwhisper.in.net
- domain: atom-mount.oakwhisper.in.net
- domain: solline0en.oakwhisper.in.net
- domain: cybdh.foxrunet.in.net
- domain: margingene.foxrunet.in.net
- file: 165.154.224.116
- hash: 12580
- file: 80.94.95.26
- hash: 7171
- file: 150.158.120.91
- hash: 443
- file: 103.166.185.160
- hash: 3333
- file: 20.105.74.94
- hash: 3333
- file: 217.154.245.123
- hash: 3333
- file: 39.97.49.101
- hash: 9205
- file: 54.158.102.250
- hash: 443
- file: 159.69.149.148
- hash: 31337
- file: 144.126.146.139
- hash: 31337
- file: 163.245.223.46
- hash: 31337
- file: 80.96.58.80
- hash: 31337
- file: 152.32.204.91
- hash: 31337
- file: 46.175.145.133
- hash: 443
- file: 102.117.164.149
- hash: 7443
- file: 80.96.58.80
- hash: 5001
- file: 149.202.74.109
- hash: 2404
- domain: field-shoa.foxrunet.in.net
- url: http://179.43.176.73/
- domain: ksu0wokple.localto.net
- domain: gdkdiebrhmn.narxz.dpdns.org
- domain: hex.narxz.dpdns.org
- domain: hexom.narxz.dpdns.org
- domain: fauhfuhfdrga-54679.portmap.host
- domain: sceneretainer.foxrunet.in.net
- domain: dpvvgwcg.stormglade.in.net
- domain: 39vhl.stormglade.in.net
- domain: allplanetssame.cfd
- url: https://allplanetssame.cfd/cf.js
- url: https://allplanetssame.cfd/api/index.php
- domain: creekcargo.stormglade.in.net
- domain: capitclou.stormglade.in.net
- domain: hmndwk.n0vabrook.in.net
- domain: gl0ss-grid.n0vabrook.in.net
- domain: sh1f-signal.n0vabrook.in.net
- domain: yx16l.n0vabrook.in.net
- domain: vzdgys.starforge.in.net
- url: https://get.cargomanbd.com/
- url: https://get.elythia.ru/
- domain: get.cargomanbd.com
- domain: get.elythia.ru
- domain: d3ep-forge.br1ghtmere.in.net
- domain: tru37-point.oakwhisper.in.net
- domain: roy4l-node.foxrunet.in.net
- url: https://maxsulcombustiveis.com.br/
- domain: delta6-zone.stormglade.in.net
- domain: solcresten3.n0vabrook.in.net
- domain: voyageinspect.cl0verpeak.in.net
- domain: dtlxmaf.cl0verpeak.in.net
- domain: tri-coreen.cl0verpeak.in.net
- domain: zennexos5.cl0verpeak.in.net
- domain: scrip8-grid.cl0verpeak.in.net
- url: https://bruxelti.top/session/role-pipeline.php
- domain: bruxelti.top
- url: https://bruxelti.top/session/signin-component.js
- domain: handleramber.cl0verpeak.in.net
- domain: nor-lineor.mossbyte.in.net
- domain: r6cp.mossbyte.in.net
- url: http://cy97983.tw1.ru/ff413aba.php
- domain: believegodisforalllove.top
- domain: believegodislove.top
- domain: je666cs.com
- domain: je777cs.com
- domain: je888cs.com
- domain: je999cs.com
- domain: ny666luck.com
- domain: ny777luck.com
- domain: ny888luck.com
- domain: ny999luck.com
- domain: gb3r.mossbyte.in.net
- domain: wavrapi.mossbyte.in.net
- domain: wkilqh.mossbyte.in.net
- domain: falldusk.mossbyte.in.net
- domain: poster-port.cinderbay.in.net
- domain: talline1is.cinderbay.in.net
- domain: ziuyacdv.cinderbay.in.net
- domain: coralsolid.cinderbay.in.net
- domain: velvetautu.cinderbay.in.net
- domain: triforgea4.cinderbay.in.net
- domain: normesh0a.glowhaven.in.net
- url: https://github.com/charlie-60/r/raw/refs/heads/main/masonrootkit.exe
- url: https://raw.githubusercontent.com/ninhpn1337/disable-windows-defender/main/source.bat
- domain: quatrigge.glowhaven.in.net
- domain: fz01ob.glowhaven.in.net
- domain: pin3-point.glowhaven.in.net
- domain: pr1v-zone.glowhaven.in.net
- domain: meta-pur3.glowhaven.in.net
- domain: r0ug3-stack.v7lora.in.net
- domain: surnm5-route.v7lora.in.net
- domain: sswms.v7lora.in.net
- domain: tdp72.v7lora.in.net
- domain: tr4ck-frame.v7lora.in.net
- domain: loyalreel.v7lora.in.net
- domain: solforgeor4.thorncairn.in.net
- domain: carolinawri039884.duckdns.org
- domain: perezchanges2464.duckdns.org
- domain: thermsyit.duckdns.org
- url: https://204.168.160.19
- domain: vgge57l.thorncairn.in.net
- url: http://38.83.138.59:25884/nz.sh
- domain: ze2975m.thorncairn.in.net
- domain: kfem.thorncairn.in.net
- domain: clif-lagoo.thorncairn.in.net
- domain: lumlithor9.thorncairn.in.net
- domain: yvx6.sa.com
- domain: pestcontrolservices.in.net
- domain: 0kkp6fidn.localto.net
- file: 216.250.253.2
- hash: 58127
- file: 103.83.87.178
- hash: 2001
- hash: 0000000000000000000000000000000000000000000000000000000000000000
- hash: 6de95d766775a84a6683ffb116160078ca7c5a75a552cd79b748b652d151c222
- file: 91.92.240.117
- hash: 80
- url: http://91.92.240.117/privaterequest/authlongpollwindows/dumpphpuploadsbetter/wordpresstemporarywordpressdump/centraltemp/pipelinebigload/1pipesql/poll/8testmariadbsql/downloads/vmjavascript_geoupdatemultigeneratortrafficprivatedownloads.php
- domain: id-located-lphone.top
- domain: icloudubicationid.work
- domain: applesetinglost.support
- domain: serviceappleonline.shop
- domain: device-findmi.com.tr
- domain: findmi-support.com.tr
- domain: device-supportlost.com.tr
- domain: lcloud-suportecom.help
- domain: arraynarrow.fabledrift.in.net
- domain: securclea.fabledrift.in.net
- domain: tpqicucp.fabledrift.in.net
- domain: gooddogshop.click
- url: https://gooddogshop.click/cf.js
- url: https://gooddogshop.click/api/index.php
- domain: storyfros.fabledrift.in.net
- url: https://gooddogshop.click/log.php
- domain: quorspireum8.fabledrift.in.net
- domain: sub-hau1.fabledrift.in.net
- file: 192.121.246.73
- hash: 5173
- domain: cr4ft9-core.skyl1tfern.in.net
- domain: 5tud1o6-path.skyl1tfern.in.net
- domain: 89n5b.skyl1tfern.in.net
- domain: cur1o1-phase.skyl1tfern.in.net
- domain: bigboysclub.cyou
- url: https://bigboysclub.cyou/cf.js
- url: https://bigboysclub.cyou/api/index.php
- url: https://bigboysclub.cyou/log.php
- domain: po5a.skyl1tfern.in.net
- domain: arkmark4et.mistlatch.in.net
- domain: mossroad.mistlatch.in.net
- domain: fabric-plate.mistlatch.in.net
- domain: 2lripcrt.mistlatch.in.net
- domain: partnerreb.mistlatch.in.net
- domain: exp05e-crest.silvershade.in.net
- domain: wolfpas.silvershade.in.net
- domain: 5udd-glow.silvershade.in.net
- domain: social-hau.silvershade.in.net
- domain: dground.org
- url: https://dground.org/file.js
- url: https://dground.org/t
- url: https://dground.org/g
- domain: blen-reef.silvershade.in.net
- url: https://dground.org/c?tk=
- domain: leusceke.com
- domain: primemicrobe.silvershade.in.net
- url: https://leusceke.com/p/reach?tk=
- domain: erpqy89.quillspire.in.net
- domain: mer-forgeex.quillspire.in.net
- url: https://dground.org/api/stat/click
- domain: nuaeftf.quillspire.in.net
- domain: m3rg-hinge.quillspire.in.net
- domain: bin4ry-ring.quillspire.in.net
- domain: open-mesh.quillspire.in.net
- domain: arkmeshet6.ashenkite.in.net
- domain: frk9qw3pqt0dx.cfc-execute.bj.baidubce.com
- domain: uyr3.ashenkite.in.net
- domain: cr4t-flow.ashenkite.in.net
- domain: pixelsola.ashenkite.in.net
- url: https://t.me/pslruhf
- domain: 185ez3.ashenkite.in.net
- domain: rpaizy.ashenkite.in.net
- domain: core-engine.vectorforge.in.net
- domain: load-stress.vectorforge.in.net
- domain: data-pipeline.vectorforge.in.net
- domain: build-deploy.vectorforge.in.net
- domain: auth-proxy.vectorforge.in.net
- domain: servemail.exprotedsteel.pro
- domain: omnisec-33243.portmap.host
- domain: lol42647-37621.portmap.host
- domain: cloud-vault.nexushaven.in.net
- domain: guest-access.nexushaven.in.net
- domain: backup-node.nexushaven.in.net
- domain: secure-link.nexushaven.in.net
- domain: relay-server.nexushaven.in.net
- domain: wave-monitor.stellarflux.in.net
- url: https://leusceke.com/p/deal?tk=
- domain: meharsons.com
- url: https://meharsons.com/file.js
- url: https://meharsons.com/t
- url: https://meharsons.com/g
- url: https://meharsons.com/c?tk=
- url: https://leusceke.com/file.js
- url: https://leusceke.com/t
- url: https://leusceke.com/g
- url: https://leusceke.com/c?tk=
- domain: zgsjyxzx.com
- url: https://zgsjyxzx.com/file.js
- domain: pulse-gate.stellarflux.in.net
- url: https://zgsjyxzx.com/t
- url: https://zgsjyxzx.com/g
- url: https://zgsjyxzx.com/c?tk=
- domain: heethcote.com
- url: https://heethcote.com/file.js
- url: https://heethcote.com/t
- url: https://heethcote.com/g
- url: https://heethcote.com/c?tk=
- domain: luthel.com
- url: https://luthel.com/file.js
- url: https://luthel.com/t
- url: https://luthel.com/g
- url: https://luthel.com/c?tk=
- domain: drift-sensor.stellarflux.in.net
- domain: jnlysj.com
- url: https://jnlysj.com/file.js
- url: https://jnlysj.com/t
- url: https://jnlysj.com/g
- url: https://jnlysj.com/c?tk=
- domain: ion-stream.stellarflux.in.net
- domain: bio-growth.orbitbloom.in.net
- domain: eco-system.orbitbloom.in.net
- domain: green-node.orbitbloom.in.net
- domain: plant-logic.orbitbloom.in.net
- domain: root-cluster.orbitbloom.in.net
- domain: leaf-proxy.orbitbloom.in.net
- domain: logic-rule.axiomforge.in.net
- domain: proof-check.axiomforge.in.net
- domain: main-frame.axiomforge.in.net
ThreatFox IOCs for 2026-03-30
Description
ThreatFox IOCs for 2026-03-30
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat report from the ThreatFox MISP feed provides a collection of Indicators of Compromise (IOCs) related to malware activity as of March 30, 2026. The information is categorized under OSINT (Open Source Intelligence), network activity, and payload delivery, suggesting these IOCs are intended to help security analysts detect malicious network behavior and identify malware payloads during investigations. The absence of specific affected software versions or known exploits in the wild indicates that this is not a newly discovered vulnerability but rather a set of intelligence data for detection purposes. No patches or remediation links are provided, reinforcing that this is not a vulnerability requiring immediate patching but a threat intelligence update. The threat level is medium, reflecting moderate concern based on the available data. The technical details include a threat level rating of 2 and distribution rating of 3, which implies some degree of dissemination but limited active exploitation. The lack of CWE identifiers and exploit evidence suggests this is primarily a monitoring and detection resource rather than an active attack vector. The IOCs can be integrated into security monitoring tools, SIEMs, and threat hunting workflows to improve detection of related malware activity. Overall, this feed supports proactive defense by providing timely intelligence on potential malware indicators without indicating an urgent or critical vulnerability.
Potential Impact
The impact of this threat intelligence is primarily on an organization's ability to detect and respond to malware-related network activity. Since no active exploits or vulnerabilities are reported, the direct risk of compromise from this specific data is low. However, failure to incorporate these IOCs into security monitoring could result in missed detection opportunities, allowing malware infections or payload deliveries to go unnoticed. Organizations worldwide that rely on OSINT and network monitoring tools stand to benefit from this intelligence to enhance situational awareness and incident response. The medium severity rating reflects that while the threat is not immediately critical, it represents a meaningful contribution to defense-in-depth strategies. Without patches or active exploits, the impact is limited to detection capabilities rather than direct system compromise or data loss. The threat intelligence can help reduce dwell time of malware infections and improve overall security posture by enabling earlier identification of malicious activity.
Mitigation Recommendations
To effectively leverage this threat intelligence, organizations should integrate the provided IOCs into their existing security infrastructure, including SIEM platforms, intrusion detection/prevention systems (IDS/IPS), endpoint detection and response (EDR) tools, and network monitoring solutions. Regularly updating threat feeds and correlating these IOCs with internal logs will enhance detection accuracy. Security teams should conduct threat hunting exercises using these indicators to identify any latent or ongoing malware activity. Since no patches are available, focus should be on detection, containment, and remediation of infections. Implementing network segmentation and strict egress filtering can limit payload delivery and lateral movement. Additionally, organizations should maintain robust incident response plans to quickly address any malware detections. Training security analysts on interpreting OSINT-based IOCs and understanding their context will improve response effectiveness. Finally, sharing findings and feedback with threat intelligence communities can help refine and expand the quality of future IOCs.
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- dc7f1f50-9914-462e-989b-b2b964e47cc9
- Original Timestamp
- 1774915387
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaintrue-presents-thereafter-und.trycloudflare.com | EtherRAT botnet C2 domain (confidence level: 100%) | |
domainapparatus-contributions-understood-accommodation.trycloudflare.com | EtherRAT botnet C2 domain (confidence level: 100%) | |
domainessayajewelry.com | EtherRAT botnet C2 domain (confidence level: 100%) | |
domaindetailingoff.com | EtherRAT botnet C2 domain (confidence level: 100%) | |
domainscott-spring-netscape-monica.trycloudflare.com | EtherRAT botnet C2 domain (confidence level: 100%) | |
domaindreambigworkharddomore.com | EtherRAT botnet C2 domain (confidence level: 100%) | |
domainpermission-resident-lots-ebooks.trycloudflare.com | EtherRAT botnet C2 domain (confidence level: 100%) | |
domainlbimuseum.org | EtherRAT botnet C2 domain (confidence level: 100%) | |
domaindealing-economics-enrollment-firms.trycloudflare.com | EtherRAT botnet C2 domain (confidence level: 100%) | |
domainglobalwork.best | EtherRAT botnet C2 domain (confidence level: 100%) | |
domaincarsaggregator.com | EtherRAT botnet C2 domain (confidence level: 100%) | |
domainpagedit.shop | EtherRAT botnet C2 domain (confidence level: 100%) | |
domainbaggiup.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainflorjxt.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainpatrmpf.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainslenjzj.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainskylips.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainyashnei.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainsfr-webmail.com | Evilginx botnet C2 domain (confidence level: 90%) | |
domainclient-macif.com | Evilginx botnet C2 domain (confidence level: 90%) | |
domainespace-macif.com | Evilginx botnet C2 domain (confidence level: 90%) | |
domainwebclient-secure.com | Evilginx botnet C2 domain (confidence level: 90%) | |
domaindocumentacknowledgementstatuscheck.us | Evilginx botnet C2 domain (confidence level: 90%) | |
domainmohadm.sw.so | Evilginx botnet C2 domain (confidence level: 75%) | |
domainselectahrsolutions.com | Evilginx botnet C2 domain (confidence level: 75%) | |
domainsuperveneza.com | Evilginx botnet C2 domain (confidence level: 75%) | |
domainmatronacons.com | Evilginx botnet C2 domain (confidence level: 75%) | |
domainadaptationinternatoinal.com | Evilginx botnet C2 domain (confidence level: 75%) | |
domainakarindia.com | Evilginx botnet C2 domain (confidence level: 75%) | |
domainjuruaialojas.com.br | Evilginx botnet C2 domain (confidence level: 75%) | |
domaininstant-msg.velocityterminal.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincity-monitor.metropolitangrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainstreet-logic.metropolitangrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainarea-scanner.metropolitangrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainblock-sensor.metropolitangrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainzone-portal.metropolitangrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainurban-access.metropolitangrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintraffic-api.urbanflowmetric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainstream-audit.urbanflowmetric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsurge-protect.urbanflowmetric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpulse-check.urbanflowmetric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindrift-control.urbanflowmetric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainflow-master.urbanflowmetric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincoord-sync.precisemapnode.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpoint-atlas.precisemapnode.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlayer-stack.precisemapnode.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainscale-vector.precisemapnode.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainview-finder.precisemapnode.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintopo-render.precisemapnode.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlocal-cache.districtbuffer.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintemp-storage.districtbuffer.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainqueue-manager.districtbuffer.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpremwork.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainmalware.xoilaczzw.tv | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainfnhztgxdqg.a.pinggy.link | XWorm botnet C2 domain (confidence level: 100%) | |
domainacannaaaaa-32635.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainrelay-point.districtbuffer.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainload-buffer.districtbuffer.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsite-archive.districtbuffer.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainadmin-panel.sectoralcontrol.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainunit-command.sectoralcontrol.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainremote-desk.sectoralcontrol.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsystem-core.sectoralcontrol.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainswitch-gear.sectoralcontrol.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintask-logic.sectoralcontrol.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlink-secure.linearbackbone.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpath-bridge.linearbackbone.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintrunk-line.linearbackbone.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfiber-route.linearbackbone.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmain-frame.linearbackbone.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnode-carrier.linearbackbone.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaininlet-valve.centralizedduct.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainoutlet-node.centralizedduct.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfilter-proc.centralizedduct.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainflow-guide.centralizedduct.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpressure-io.centralizedduct.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintunnel-sync.centralizedduct.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwide-telemetry.regionaltelemetry.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfield-report.regionaltelemetry.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsignal-box.regionaltelemetry.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindata-packet.regionaltelemetry.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwave-form.regionaltelemetry.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainremote-log.regionaltelemetry.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainborder-gate.territoriallink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainproxy-edge.territoriallink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainland-mark.territoriallink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsite-connect.territoriallink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmap-anchor.territoriallink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnewremc.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domaindiary-learn.sa.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domaindominofranchiseind.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainhdjjjf.za.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainiso.radio.fm | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainmakeuseof.it.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainreprint-handbook.sa.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainsyfaaf.za.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainvenomrat.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainxn--eck3a9bu7cul.jp.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainbot.codeeye.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainchildrensex.codeeye.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domaindomain.codeeye.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domaingooglemalware.codeeye.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainmoney.codeeye.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainnamecheap.codeeye.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainnamecheapmalwaredowload.codeeye.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainscan.codeeye.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainsex.codeeye.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainreach-base.territoriallink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpublic-serv.municipalmatrix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintown-council.municipalmatrix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincitizen-dev.municipalmatrix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainauth-trust.municipalmatrix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincode-index.municipalmatrix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmybiggestjoy.bond | Unknown malware payload delivery domain (confidence level: 100%) | |
domainrouteletters.xyz | Unknown Loader botnet C2 domain (confidence level: 100%) | |
domainprofitfact.xyz | Unknown Loader botnet C2 domain (confidence level: 100%) | |
domainliquidwrench.cfd | Unknown Loader botnet C2 domain (confidence level: 100%) | |
domainform-builder.municipalmatrix.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainput.cargomanbd.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainepy.cargomanbd.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainagi.cargomanbd.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainpva.cargomanbd.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainggv.cargomanbd.com | Vidar botnet C2 domain (confidence level: 100%) | |
domaingre.cargomanbd.com | Vidar botnet C2 domain (confidence level: 100%) | |
domaingre.syslic.net | Vidar botnet C2 domain (confidence level: 100%) | |
domainput.elythia.online | Vidar botnet C2 domain (confidence level: 100%) | |
domainepy.elythia.online | Vidar botnet C2 domain (confidence level: 100%) | |
domainagi.elythia.online | Vidar botnet C2 domain (confidence level: 100%) | |
domainpva.elythia.online | Vidar botnet C2 domain (confidence level: 100%) | |
domainggv.elythia.online | Vidar botnet C2 domain (confidence level: 100%) | |
domainjdosu.funnythings.store | Vidar botnet C2 domain (confidence level: 100%) | |
domainheavy-duty.infrastructurehub.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsolid-state.infrastructurehub.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsign-in-property.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainagdosve.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainasfasfqwf.com | NetSupportManager RAT payload delivery domain (confidence level: 100%) | |
domainasdasfa.com | NetSupportManager RAT payload delivery domain (confidence level: 100%) | |
domainbase-build.infrastructurehub.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainasset-track.infrastructurehub.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpower-plant.infrastructurehub.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainresource-api.infrastructurehub.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlumvale8is.starforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvvave3-gate.starforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain80tlyi.starforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainicegold.starforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainzencrestal2.starforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainaftwizk.starforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainn73pw.br1ghtmere.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincell-plate.br1ghtmere.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainscreennotify.br1ghtmere.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwgyinknm.br1ghtmere.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintal-venal.br1ghtmere.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvmcs.br1ghtmere.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainrunwaypublic.oakwhisper.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfilteglob.oakwhisper.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainhyper-4uth.oakwhisper.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainriverrefine.oakwhisper.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwpx3375n.oakwhisper.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain11kzvq.oakwhisper.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsubtlsegme.foxrunet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlwvkfb.foxrunet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainurbanvoya.foxrunet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainrefineterminal.foxrunet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmalaimusic.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainecho-draf.foxrunet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnortideis.foxrunet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincrimsonpublish.stormglade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainquordra3os.stormglade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainopsec-cf.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainoffecargo.stormglade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainligh-stric.stormglade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwe5ohkh2.stormglade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmaroc-hotel.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainanch0r1-route.stormglade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainproto-p0rt.n0vabrook.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain3d1t-node.n0vabrook.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainqanivor.top | SmartApeSG payload delivery domain (confidence level: 100%) | |
domaindecode-stead.n0vabrook.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainquick8-chain.n0vabrook.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainguarmea.n0vabrook.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwu4747.n0vabrook.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbzknn.starforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmeta-0rch.starforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintranrur.starforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaingeyseropti.starforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbastroh.no-ip.org | NjRAT botnet C2 domain (confidence level: 100%) | |
domainrestaurant-contacts.gl.at.ply.gg | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domainyyin.br1ghtmere.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain95abc92.br1ghtmere.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainrunti5-flow.br1ghtmere.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainproto-tru5ted.br1ghtmere.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindispatchmemory.oakwhisper.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain50ravelv.oakwhisper.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainatom-mount.oakwhisper.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsolline0en.oakwhisper.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincybdh.foxrunet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmargingene.foxrunet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfield-shoa.foxrunet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainksu0wokple.localto.net | DarkComet botnet C2 domain (confidence level: 50%) | |
domaingdkdiebrhmn.narxz.dpdns.org | Mirai botnet C2 domain (confidence level: 50%) | |
domainhex.narxz.dpdns.org | Mirai botnet C2 domain (confidence level: 50%) | |
domainhexom.narxz.dpdns.org | Mirai botnet C2 domain (confidence level: 50%) | |
domainfauhfuhfdrga-54679.portmap.host | Quasar RAT botnet C2 domain (confidence level: 50%) | |
domainsceneretainer.foxrunet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindpvvgwcg.stormglade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain39vhl.stormglade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainallplanetssame.cfd | Unknown malware payload delivery domain (confidence level: 100%) | |
domaincreekcargo.stormglade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincapitclou.stormglade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainhmndwk.n0vabrook.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaingl0ss-grid.n0vabrook.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsh1f-signal.n0vabrook.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainyx16l.n0vabrook.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvzdgys.starforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainget.cargomanbd.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainget.elythia.ru | Vidar botnet C2 domain (confidence level: 100%) | |
domaind3ep-forge.br1ghtmere.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintru37-point.oakwhisper.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainroy4l-node.foxrunet.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindelta6-zone.stormglade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsolcresten3.n0vabrook.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvoyageinspect.cl0verpeak.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindtlxmaf.cl0verpeak.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintri-coreen.cl0verpeak.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainzennexos5.cl0verpeak.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainscrip8-grid.cl0verpeak.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbruxelti.top | SmartApeSG payload delivery domain (confidence level: 100%) | |
domainhandleramber.cl0verpeak.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnor-lineor.mossbyte.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainr6cp.mossbyte.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbelievegodisforalllove.top | Remcos botnet C2 domain (confidence level: 75%) | |
domainbelievegodislove.top | Remcos botnet C2 domain (confidence level: 75%) | |
domainje666cs.com | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domainje777cs.com | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domainje888cs.com | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domainje999cs.com | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domainny666luck.com | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domainny777luck.com | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domainny888luck.com | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domainny999luck.com | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domaingb3r.mossbyte.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwavrapi.mossbyte.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwkilqh.mossbyte.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfalldusk.mossbyte.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainposter-port.cinderbay.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintalline1is.cinderbay.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainziuyacdv.cinderbay.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincoralsolid.cinderbay.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvelvetautu.cinderbay.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintriforgea4.cinderbay.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnormesh0a.glowhaven.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainquatrigge.glowhaven.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfz01ob.glowhaven.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpin3-point.glowhaven.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpr1v-zone.glowhaven.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmeta-pur3.glowhaven.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainr0ug3-stack.v7lora.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsurnm5-route.v7lora.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsswms.v7lora.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintdp72.v7lora.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintr4ck-frame.v7lora.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainloyalreel.v7lora.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsolforgeor4.thorncairn.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincarolinawri039884.duckdns.org | Remcos botnet C2 domain (confidence level: 75%) | |
domainperezchanges2464.duckdns.org | Remcos botnet C2 domain (confidence level: 75%) | |
domainthermsyit.duckdns.org | Remcos botnet C2 domain (confidence level: 75%) | |
domainvgge57l.thorncairn.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainze2975m.thorncairn.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainkfem.thorncairn.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainclif-lagoo.thorncairn.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlumlithor9.thorncairn.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainyvx6.sa.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainpestcontrolservices.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domain0kkp6fidn.localto.net | XWorm botnet C2 domain (confidence level: 100%) | |
domainid-located-lphone.top | DCRat botnet C2 domain (confidence level: 75%) | |
domainicloudubicationid.work | DCRat botnet C2 domain (confidence level: 75%) | |
domainapplesetinglost.support | DCRat botnet C2 domain (confidence level: 75%) | |
domainserviceappleonline.shop | DCRat botnet C2 domain (confidence level: 75%) | |
domaindevice-findmi.com.tr | DCRat botnet C2 domain (confidence level: 75%) | |
domainfindmi-support.com.tr | DCRat botnet C2 domain (confidence level: 75%) | |
domaindevice-supportlost.com.tr | DCRat botnet C2 domain (confidence level: 75%) | |
domainlcloud-suportecom.help | DCRat botnet C2 domain (confidence level: 75%) | |
domainarraynarrow.fabledrift.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsecurclea.fabledrift.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintpqicucp.fabledrift.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaingooddogshop.click | Unknown malware payload delivery domain (confidence level: 100%) | |
domainstoryfros.fabledrift.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainquorspireum8.fabledrift.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsub-hau1.fabledrift.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincr4ft9-core.skyl1tfern.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain5tud1o6-path.skyl1tfern.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain89n5b.skyl1tfern.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincur1o1-phase.skyl1tfern.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbigboysclub.cyou | Unknown malware payload delivery domain (confidence level: 100%) | |
domainpo5a.skyl1tfern.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainarkmark4et.mistlatch.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmossroad.mistlatch.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfabric-plate.mistlatch.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain2lripcrt.mistlatch.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpartnerreb.mistlatch.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainexp05e-crest.silvershade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolfpas.silvershade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain5udd-glow.silvershade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsocial-hau.silvershade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindground.org | Unknown malware payload delivery domain (confidence level: 100%) | |
domainblen-reef.silvershade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainleusceke.com | Unknown malware payload delivery domain (confidence level: 50%) | |
domainprimemicrobe.silvershade.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainerpqy89.quillspire.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmer-forgeex.quillspire.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnuaeftf.quillspire.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainm3rg-hinge.quillspire.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbin4ry-ring.quillspire.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainopen-mesh.quillspire.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainarkmeshet6.ashenkite.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfrk9qw3pqt0dx.cfc-execute.bj.baidubce.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainuyr3.ashenkite.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincr4t-flow.ashenkite.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpixelsola.ashenkite.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain185ez3.ashenkite.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainrpaizy.ashenkite.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincore-engine.vectorforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainload-stress.vectorforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindata-pipeline.vectorforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbuild-deploy.vectorforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainauth-proxy.vectorforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainservemail.exprotedsteel.pro | Remcos botnet C2 domain (confidence level: 100%) | |
domainomnisec-33243.portmap.host | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainlol42647-37621.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domaincloud-vault.nexushaven.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainguest-access.nexushaven.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbackup-node.nexushaven.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsecure-link.nexushaven.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainrelay-server.nexushaven.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwave-monitor.stellarflux.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmeharsons.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainzgsjyxzx.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainpulse-gate.stellarflux.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainheethcote.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainluthel.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domaindrift-sensor.stellarflux.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainjnlysj.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainion-stream.stellarflux.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbio-growth.orbitbloom.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaineco-system.orbitbloom.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaingreen-node.orbitbloom.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainplant-logic.orbitbloom.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainroot-cluster.orbitbloom.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainleaf-proxy.orbitbloom.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlogic-rule.axiomforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainproof-check.axiomforge.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmain-frame.axiomforge.in.net | ClearFake payload delivery domain (confidence level: 100%) |
File
| Value | Description | Copy |
|---|---|---|
file194.26.192.180 | Unidentified 001 botnet C2 server (confidence level: 75%) | |
file20.5.49.243 | Unidentified 001 botnet C2 server (confidence level: 75%) | |
file194.26.192.248 | Evilginx botnet C2 server (confidence level: 90%) | |
file194.26.192.248 | Evilginx botnet C2 server (confidence level: 90%) | |
file172.86.91.224 | Mirai botnet C2 server (confidence level: 80%) | |
file107.158.128.79 | Rshell botnet C2 server (confidence level: 100%) | |
file192.109.200.184 | Rshell botnet C2 server (confidence level: 75%) | |
file64.89.161.130 | Mirai botnet C2 server (confidence level: 100%) | |
file16.16.182.17 | WhiteSnake Stealer payload delivery server (confidence level: 90%) | |
file103.182.228.91 | p0wnyshell payload delivery server (confidence level: 90%) | |
file139.59.88.137 | p0wnyshell payload delivery server (confidence level: 75%) | |
file151.245.112.70 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file5.188.87.38 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file107.172.13.249 | Remcos botnet C2 server (confidence level: 100%) | |
file2.27.41.248 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file23.132.132.67 | ValleyRAT botnet C2 server (confidence level: 75%) | |
file193.42.24.214 | ValleyRAT botnet C2 server (confidence level: 75%) | |
file206.238.115.206 | ValleyRAT botnet C2 server (confidence level: 75%) | |
file180.178.56.230 | ValleyRAT botnet C2 server (confidence level: 75%) | |
file136.244.96.112 | Vidar botnet C2 server (confidence level: 100%) | |
file49.12.9.171 | Vidar botnet C2 server (confidence level: 100%) | |
file95.217.125.49 | Vidar botnet C2 server (confidence level: 100%) | |
file95.217.125.50 | Vidar botnet C2 server (confidence level: 100%) | |
file151.245.121.216 | Vidar botnet C2 server (confidence level: 100%) | |
file188.166.10.165 | Vidar botnet C2 server (confidence level: 100%) | |
file91.99.183.16 | Vidar botnet C2 server (confidence level: 100%) | |
file49.12.3.48 | Vidar botnet C2 server (confidence level: 100%) | |
file20.115.57.167 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file141.11.76.246 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file185.177.239.196 | ACR Stealer botnet C2 server (confidence level: 100%) | |
file157.245.60.230 | Unknown malware botnet C2 server (confidence level: 100%) | |
file130.12.182.112 | Remcos botnet C2 server (confidence level: 75%) | |
file172.232.125.148 | Mirai botnet C2 server (confidence level: 50%) | |
file172.238.111.131 | Mirai botnet C2 server (confidence level: 50%) | |
file172.232.214.12 | Mirai botnet C2 server (confidence level: 50%) | |
file172.232.253.229 | Mirai botnet C2 server (confidence level: 50%) | |
file165.22.220.235 | Mirai botnet C2 server (confidence level: 50%) | |
file172.105.74.253 | Mirai botnet C2 server (confidence level: 50%) | |
file172.232.35.106 | Mirai botnet C2 server (confidence level: 50%) | |
file172.236.172.130 | Mirai botnet C2 server (confidence level: 50%) | |
file5.230.170.237 | Mirai botnet C2 server (confidence level: 50%) | |
file5.230.170.238 | Mirai botnet C2 server (confidence level: 50%) | |
file5.230.170.239 | Mirai botnet C2 server (confidence level: 50%) | |
file5.230.170.240 | Mirai botnet C2 server (confidence level: 50%) | |
file194.50.5.27 | Mirai botnet C2 server (confidence level: 75%) | |
file178.16.54.81 | Remcos botnet C2 server (confidence level: 100%) | |
file82.192.72.181 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
file151.245.112.70 | XWorm botnet C2 server (confidence level: 100%) | |
file47.76.86.151 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file165.154.224.116 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file80.94.95.26 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file150.158.120.91 | Unknown malware botnet C2 server (confidence level: 50%) | |
file103.166.185.160 | Unknown malware botnet C2 server (confidence level: 50%) | |
file20.105.74.94 | Unknown malware botnet C2 server (confidence level: 50%) | |
file217.154.245.123 | Unknown malware botnet C2 server (confidence level: 50%) | |
file39.97.49.101 | Unknown malware botnet C2 server (confidence level: 50%) | |
file54.158.102.250 | Unknown malware botnet C2 server (confidence level: 50%) | |
file159.69.149.148 | Sliver botnet C2 server (confidence level: 50%) | |
file144.126.146.139 | Sliver botnet C2 server (confidence level: 50%) | |
file163.245.223.46 | Sliver botnet C2 server (confidence level: 50%) | |
file80.96.58.80 | Sliver botnet C2 server (confidence level: 50%) | |
file152.32.204.91 | Sliver botnet C2 server (confidence level: 50%) | |
file46.175.145.133 | Havoc botnet C2 server (confidence level: 50%) | |
file102.117.164.149 | Unknown malware botnet C2 server (confidence level: 50%) | |
file80.96.58.80 | AdaptixC2 botnet C2 server (confidence level: 50%) | |
file149.202.74.109 | Remcos botnet C2 server (confidence level: 50%) | |
file216.250.253.2 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
file103.83.87.178 | XWorm botnet C2 server (confidence level: 100%) | |
file91.92.240.117 | DCRat botnet C2 server (confidence level: 100%) | |
file192.121.246.73 | Unknown Stealer botnet C2 server (confidence level: 75%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash8080 | Unidentified 001 botnet C2 server (confidence level: 75%) | |
hash443 | Unidentified 001 botnet C2 server (confidence level: 75%) | |
hash8080 | Evilginx botnet C2 server (confidence level: 90%) | |
hash443 | Evilginx botnet C2 server (confidence level: 90%) | |
hash1999 | Mirai botnet C2 server (confidence level: 80%) | |
hash443 | Rshell botnet C2 server (confidence level: 100%) | |
hash3000 | Rshell botnet C2 server (confidence level: 75%) | |
hash8080 | Mirai botnet C2 server (confidence level: 100%) | |
hash80 | WhiteSnake Stealer payload delivery server (confidence level: 90%) | |
hash80 | p0wnyshell payload delivery server (confidence level: 90%) | |
hash80 | p0wnyshell payload delivery server (confidence level: 75%) | |
hash8990 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash443 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash9010 | Remcos botnet C2 server (confidence level: 100%) | |
hash5632 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash8808 | ValleyRAT botnet C2 server (confidence level: 75%) | |
hash16790 | ValleyRAT botnet C2 server (confidence level: 75%) | |
hash8880 | ValleyRAT botnet C2 server (confidence level: 75%) | |
hash80 | ValleyRAT botnet C2 server (confidence level: 75%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash4443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | ACR Stealer botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 75%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash23004 | Mirai botnet C2 server (confidence level: 50%) | |
hash53 | Mirai botnet C2 server (confidence level: 75%) | |
hash2409 | Remcos botnet C2 server (confidence level: 100%) | |
hash55615 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
hash7007 | XWorm botnet C2 server (confidence level: 100%) | |
hash23157 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash12580 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash7171 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash9205 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash443 | Havoc botnet C2 server (confidence level: 50%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash5001 | AdaptixC2 botnet C2 server (confidence level: 50%) | |
hash2404 | Remcos botnet C2 server (confidence level: 50%) | |
hash58127 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
hash2001 | XWorm botnet C2 server (confidence level: 100%) | |
hash0000000000000000000000000000000000000000000000000000000000000000 | DCRat payload (confidence level: 100%) | |
hash6de95d766775a84a6683ffb116160078ca7c5a75a552cd79b748b652d151c222 | DCRat payload (confidence level: 100%) | |
hash80 | DCRat botnet C2 server (confidence level: 100%) | |
hash5173 | Unknown Stealer botnet C2 server (confidence level: 75%) |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://kwsecurity.site/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://mybiggestjoy.bond/cf.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mybiggestjoy.bond/api/index.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mybiggestjoy.bond/log.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://djasdajnsdnjgjg.com/fdghdfgh.js | IClickFix payload delivery URL (confidence level: 100%) | |
urlhttps://sekolahtinta.edu.my/wp-blog-footer.php | IClickFix payload delivery URL (confidence level: 100%) | |
urlhttps://188.166.10.165 | Vidar botnet C2 (confidence level: 75%) | |
urlhttps://49.12.3.48 | Vidar botnet C2 (confidence level: 75%) | |
urlhttps://sekolahtinta.edu.my/wp-blog-footer.php?page= | IClickFix payload delivery URL (confidence level: 100%) | |
urlhttps://136.244.96.112/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://put.cargomanbd.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://epy.cargomanbd.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://agi.cargomanbd.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://pva.cargomanbd.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://ggv.cargomanbd.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://gre.cargomanbd.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://gre.syslic.net/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://put.elythia.online/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://epy.elythia.online/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://agi.elythia.online/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://pva.elythia.online/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://ggv.elythia.online/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://gre.elythia.online/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttp://jdosu.funnythings.store/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://49.12.9.171/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://95.217.125.49/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://95.217.125.50/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://151.245.121.216/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://91.99.183.16/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://sign-in-property.com/start/ | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://agdosve.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://steamcommunity.com/profiles/76561198721902688 | Vidar botnet C2 (confidence level: 75%) | |
urlhttps://telegram.me/p74kol | Vidar botnet C2 (confidence level: 75%) | |
urlhttps://opsec-cf.com/api/css.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://maroc-hotel.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mezcalpro.com/q | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://qanivor.top/session/endpoint-parser.js | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://qanivor.top/session/role-pipeline.php | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://qanivor.top/session/signin-component.js | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://zempraxo.com/ddd/angular | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://nabil-gateway.thebetterappliances.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://brochurehub.co.uk/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttp://179.43.176.73/ | Vidar botnet C2 (confidence level: 50%) | |
urlhttps://allplanetssame.cfd/cf.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://allplanetssame.cfd/api/index.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://get.cargomanbd.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://get.elythia.ru/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://maxsulcombustiveis.com.br/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://bruxelti.top/session/role-pipeline.php | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://bruxelti.top/session/signin-component.js | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttp://cy97983.tw1.ru/ff413aba.php | DCRat botnet C2 (confidence level: 100%) | |
urlhttps://github.com/charlie-60/r/raw/refs/heads/main/masonrootkit.exe | Unknown RAT payload delivery URL (confidence level: 100%) | |
urlhttps://raw.githubusercontent.com/ninhpn1337/disable-windows-defender/main/source.bat | Unknown RAT payload delivery URL (confidence level: 100%) | |
urlhttps://204.168.160.19 | Vidar botnet C2 (confidence level: 75%) | |
urlhttp://38.83.138.59:25884/nz.sh | Unknown malware payload delivery URL (confidence level: 75%) | |
urlhttp://91.92.240.117/privaterequest/authlongpollwindows/dumpphpuploadsbetter/wordpresstemporarywordpressdump/centraltemp/pipelinebigload/1pipesql/poll/8testmariadbsql/downloads/vmjavascript_geoupdatemultigeneratortrafficprivatedownloads.php | DCRat botnet C2 (confidence level: 100%) | |
urlhttps://gooddogshop.click/cf.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://gooddogshop.click/api/index.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://gooddogshop.click/log.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://bigboysclub.cyou/cf.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://bigboysclub.cyou/api/index.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://bigboysclub.cyou/log.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dground.org/file.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dground.org/t | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dground.org/g | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dground.org/c?tk= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://leusceke.com/p/reach?tk= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dground.org/api/stat/click | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://t.me/pslruhf | Vidar botnet C2 (confidence level: 75%) | |
urlhttps://leusceke.com/p/deal?tk= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://meharsons.com/file.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://meharsons.com/t | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://meharsons.com/g | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://meharsons.com/c?tk= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://leusceke.com/file.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://leusceke.com/t | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://leusceke.com/g | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://leusceke.com/c?tk= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://zgsjyxzx.com/file.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://zgsjyxzx.com/t | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://zgsjyxzx.com/g | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://zgsjyxzx.com/c?tk= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://heethcote.com/file.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://heethcote.com/t | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://heethcote.com/g | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://heethcote.com/c?tk= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://luthel.com/file.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://luthel.com/t | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://luthel.com/g | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://luthel.com/c?tk= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://jnlysj.com/file.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://jnlysj.com/t | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://jnlysj.com/g | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://jnlysj.com/c?tk= | Unknown malware payload delivery URL (confidence level: 100%) |
Threat ID: 69cb1068e6bfc5ba1d83cbdb
Added to database: 3/31/2026, 12:08:08 AM
Last enriched: 3/31/2026, 12:23:34 AM
Last updated: 3/31/2026, 6:30:11 AM
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.