ThreatFox IOCs for 2026-04-04
ThreatFox IOCs for 2026-04-04
AI Analysis
Technical Summary
The threat consists of malware-related IOCs collected and shared via the ThreatFox MISP feed on 2026-04-04. It focuses on OSINT data concerning payload delivery mechanisms and network activity associated with malware. No detailed technical indicators or affected software versions are provided. The threat level and analysis scores suggest moderate concern, with distribution rated higher, indicating some spread or prevalence. No known exploits or patches are associated with this threat.
Potential Impact
The impact is limited to the presence of malware-related indicators that could aid in detection and response efforts. There is no evidence of active exploitation or specific vulnerable software versions. The threat could facilitate malware delivery or network-based malicious activity if leveraged by attackers.
Mitigation Recommendations
No patch is available for this threat. Since it relates to IOCs and OSINT data, defenders should incorporate these indicators into their detection and monitoring tools as appropriate. No vendor advisory or official fix exists. Standard malware detection and network monitoring practices aligned with these IOCs are recommended.
Indicators of Compromise
- url: https://zorpelix.top/endpoint/private-sessionstore.js
- domain: zorpelix.top
- url: https://zorpelix.top/endpoint/redirect-cookie.php
- url: https://zorpelix.top/endpoint/admin-bundle.js
- url: https://kaventur.com/angular
- url: https://qerunvax.top/endpoint/redirect-cookie.php
- domain: qerunvax.top
- url: https://qerunvax.top/endpoint/admin-bundle.js
- file: 166.88.182.64
- hash: 443
- file: 216.151.165.201
- hash: 443
- file: 212.64.201.57
- hash: 1995
- hash: f36542b449e0b164bf0927d48bd934aa0e66bd2fab483f532cf2010f3fc9d02b
- hash: 42533fbb40fe274c96a31c948ae6e84b6c103f9da6f27c9d1dc5c011f7b719d0
- hash: 9b00ce3b72371c12f93d50eba473241e0a5c8cc1050e3d9ab9fe4ec21e2f5841
- hash: 575cb7f119c0f8a403ec0db3fff8bb7f2a651c5f2501ae51ec7b6241ecdd8a72
- file: 171.22.182.231
- hash: 80
- domain: wildishadventure.com
- domain: editor.fileviewer.blog
- file: 46.246.99.110
- hash: 443
- hash: 048e374baac36d8cf68dd32e48313ef8eb517d647548b1bf5f26d2d0e2e3cdc7
- hash: 3625d068896953595e75df328676a08bc071977ac1ff95d44b745bbcb7018c6f
- domain: present.pcohenlaw.com
- file: 176.65.139.102
- hash: 8
- url: http://217.69.2.135/czw8qtplzobjpuskagebra%3d%3d
- url: http://217.69.3.51/k6iopyyvkypx6r2fd5c6%2fg%3d%3d
- url: http://217.69.2.135/get_arhive_npm/noquvjrpcd%2fsadyfqegqtq%3d%3d
- url: http://217.69.3.51/get_arhive_npm/ymlauac6b7gljurhk4vxha%3d%3d
- url: https://calendar.app.google/ccqgmlkerzv6kda28
- url: http://62.60.226.159/psd8ezaw/index.php
- file: 91.218.183.177
- hash: 4444
- file: 213.21.222.241
- hash: 7443
- file: 123.30.48.175
- hash: 8080
- file: 151.247.22.77
- hash: 54984
- file: 45.74.48.70
- hash: 443
- file: 154.41.194.170
- hash: 139
- url: https://45.154.98.13:8443/ws
- domain: veggiehomrecipe.com
- url: http://74.208.195.188:3000/download-file/464545
- domain: tridontoq.com
- domain: baadeckyarns.com
- domain: atozcleen.com
- file: 94.26.83.83
- hash: 558
- domain: thats.theywaytowin.site
- domain: odet.emoxsdontn12.publicvm.com
- domain: 2kk9d.pixelfodream.rest
- domain: git.bvmai.xyz
- domain: server04.com-2.mobi
- domain: aff.raidboss.biz.id
- domain: aff.humbleness.me
- domain: free.primewinningways.com
- file: 108.163.203.126
- hash: 443
- file: 65.60.9.236
- hash: 443
- domain: meki.google.co.ws
- file: 185.61.223.31
- hash: 443
- file: 93.177.119.25
- hash: 443
- file: 93.177.119.193
- hash: 443
- file: 85.206.169.153
- hash: 443
- file: 85.206.169.155
- hash: 443
- file: 85.206.169.157
- hash: 443
- domain: marsh.dichromatictear.com
- url: https://malibaaquaculture.com/
- domain: camel-milk.eu
- url: https://jeremeycountry-school.com/student/cd9o3jma
- domain: jeremeycountry-school.com
- file: 78.111.111.236
- hash: 4895
- file: 103.211.219.238
- hash: 4219
- file: 72.61.25.108
- hash: 3989
- file: 15.235.192.42
- hash: 48261
- file: 76.13.17.11
- hash: 6573
- file: 62.72.32.156
- hash: 6782
- file: 62.72.32.156
- hash: 5902
- file: 217.156.122.75
- hash: 1378
- domain: power-drive.infodynamics.in.net
- domain: killerboymaxilo-59859.portmap.host
- domain: notes-ease.gl.at.ply.gg
- file: 185.14.92.89
- hash: 5000
- file: 154.85.58.188
- hash: 9999
- file: 152.32.175.134
- hash: 9999
- file: 176.65.139.81
- hash: 3779
- domain: rcmpx.duckdns.org
- domain: snickerbarwithhotsauceonit-51791.portmap.host
- domain: jansuri.kozow.com
- domain: xaszxa.myftp.biz
- domain: latidodeliveries.com
- hash: 4ac3e3b1f0d054a4ed682a1d6a53ddb3
- hash: d761a6a7ae9f2254bd81ac234033a8b8
- hash: 30767275ca828ec1c9d62baccbb0cdf1
- hash: 7e521bb895d7329b7fb2b2a8736f4b19
- hash: 2dbedfba5f6bf5f69b471447e4161311
- hash: b72c2be9651ede5f337926c6b5830624
- hash: 98021dca558b69e93a20d912200f1782
- hash: 692238a56e1941b1d92df3d8dfd513eb
- domain: aquasecurtiy.org
- domain: checkmarx.zone
- domain: models.litellm.cloud
- domain: championships-peoples-point-cassette.trycloudflare.com
- domain: investigation-launches-hearings-copying.trycloudflare.com
- domain: souls-entire-defined-routes.trycloudflare.com
- domain: create-sensitivity-grad-sequence.trycloudflare.com
- domain: plug-tab-protective-relay.trycloudflare.com
- domain: tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io
- domain: ffxjhdp4aaucgrkh5jy5xb4f4lhwre7wqxteg27i24pfyb2uwlwxgoyd.onion
- file: 47.94.148.168
- hash: 8888
- file: 104.168.117.123
- hash: 7777
- file: 8.148.247.172
- hash: 8888
- url: https://www.ampkart.com/
- url: https://astepaheadpreschool.com/
- file: 176.65.139.81
- hash: 4090
- file: 86.165.21.169
- hash: 4782
- file: 52.74.12.195
- hash: 80
- file: 52.221.112.64
- hash: 80
- url: http://62.60.226.159/psd8ezaw/login.php
- domain: whatfuck000.intermediate.cyou
- domain: whatfuck000.intermediate.icu
- file: 137.220.158.170
- hash: 9001
- domain: sametcanaltindal.online
- domain: io3ld9xy.sametcanaltindal.online
- domain: 051z9t01.sametcanaltindal.online
- domain: ld2ombme.sametcanaltindal.online
- domain: n66klrdz.sametcanaltindal.online
- domain: dfdzfhyl.sametcanaltindal.online
- domain: qwi2rr26.sametcanaltindal.online
- domain: 8g05rgqx.sametcanaltindal.online
- domain: c18uskdb.sametcanaltindal.online
- domain: hj5mzm9m.sametcanaltindal.online
- domain: 1p7lhbac.sametcanaltindal.online
- domain: 88twg8ug.sametcanaltindal.online
- domain: gc72w7o0.sametcanaltindal.online
- domain: zpuf659k.sametcanaltindal.online
- domain: 0mduzija.sametcanaltindal.online
- domain: rdrkohnj.sametcanaltindal.online
- domain: sooj4mj8.sametcanaltindal.online
- domain: hde760qe.sametcanaltindal.online
- domain: 88vx07b2.sametcanaltindal.online
- domain: 2pjcqtpo.sametcanaltindal.online
- domain: so6tzwnz.sametcanaltindal.online
- domain: 0e8no9tj.sametcanaltindal.online
- domain: wl8ee0nz.sametcanaltindal.online
- domain: 638mbdnw.sametcanaltindal.online
- domain: 2anyhb8i.sametcanaltindal.online
- domain: j75dg096.sametcanaltindal.online
- domain: api.sametcanaltindal.online
- file: 78.198.121.158
- hash: 777
- domain: moy-magnit.ru.com
- domain: de-ta.us.com
- domain: shopping.uk.net
- domain: cybertronic.uk.com
- domain: qiyi.cn.com
- domain: hosac.eu.com
- domain: alktvs.ru.com
- domain: tss.eu.com
- domain: vla.uk.com
- domain: njs.in.net
- domain: xn--h1agd3a1be.ru.com
- file: 151.242.63.2
- hash: 7000
- url: https://tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io/
- url: https://hooks.slack.com/services/t011wkpusqk/b0aq40vdqq2/amcxrvrlkuexe3bchhia6fu9
- url: https://unexpected-conflicts-compiled-anymore.trycloudflare.com/api/v1/posts/exfil/comments
- domain: moltbook-health.the-l.ink
- domain: probe-worker.hugebigballs87.workers.dev
- url: https://3abilisim.com/
- domain: flyingbbird.cc
- url: https://glasstips.com/wp-blog-footer.php?page=
- domain: inasiainbd.com
- url: https://inasiainbd.com
- url: http://151.243.113.89/dasff.txt
- file: 151.243.113.89
- hash: 80
- domain: miskolopiyzf.com
- domain: lobsterrakkos.com
- file: 144.31.107.231
- hash: 9999
- file: 144.31.107.231
- hash: 4444
- url: https://djasdajnsdnjgjg.com/sdfggg.js
- domain: qaomekspdjfbdeixxjky.supabase.co
- file: 149.30.255.106
- hash: 443
- file: 3.71.73.80
- hash: 80
- file: 47.83.121.186
- hash: 8443
- file: 170.64.203.23
- hash: 31337
- file: 37.120.156.119
- hash: 4444
- file: 45.32.111.46
- hash: 443
- url: https://meherwomenshospital.com/%22>demo
- domain: marxrwonew9090.duckdns.org
- file: 104.200.72.111
- hash: 8382
- file: 93.88.203.34
- hash: 26880
- domain: girl-tries.gl.at.ply.gg
- domain: webdev.it.com
- domain: vn168aa.net
- domain: 5491.cn.com
- domain: 8421.cn.com
- domain: agrevo.us.com
- url: https://cheeerfulharbor.rest
- file: 47.96.237.48
- hash: 30204
- file: 202.95.6.233
- hash: 8888
- domain: celebration-internet.cc
- url: https://celebration-internet.cc/
- domain: paf.hugo-mapp.co
- url: https://paf.hugo-mapp.co/
- domain: smart.hugo-mapp.co
- url: https://smart.hugo-mapp.co/
- file: 162.215.170.152
- hash: 1995
- domain: cnc.xenema.vip
- domain: preziosamagazines.cc
- file: 45.61.135.109
- hash: 443
- domain: casasdeicom.cc
- file: 204.76.203.165
- hash: 430
- file: 46.151.182.19
- hash: 430
- file: 194.182.64.133
- hash: 8610
- domain: bk7pwxz9yt.localto.net
- domain: frozen-nicotine.with.playit.plus
- domain: legrugohungary.hu
- url: https://storage.googleapis.com/nodedownload/nodeserver-setup-full_t5.msi
- url: https://storage.googleapis.com/nodedownload/nodeserver-setup-full_t4.msi
- url: https://storage.googleapis.com/nodedownload/nodeserver-setup-full_t3.msi
- url: https://storage.googleapis.com/nodedownload/nodeserver-setup-full_t6.msi
- domain: sisspas.com
- url: https://sisspas.com
- domain: roaminginluxe.com
- url: https://roaminginluxe.com
- url: https://h4captcha.sbs/captcha/code-win.txt
- url: https://h4captcha.sbs/captcha/code-mac.txt
- url: http://172.94.9.250/d/xxx60399
- url: http://172.94.9.250/login
- domain: secure-key.cryptolayer.in.net
- domain: hash-store.cryptolayer.in.net
- url: http://172.94.9.250/d/xxx51278
- domain: anon-auth.cryptolayer.in.net
- domain: bit-stream.logicstream.in.net
- domain: code-gate.logicstream.in.net
- domain: packet-flow.logicstream.in.net
- domain: rule-engine.logicstream.in.net
- domain: main-frame.logicstream.in.net
- domain: step-check.logicstream.in.net
- domain: freshhomrecipes.com
- url: https://freshhomrecipes.com/home.php?security_token=be08e4c9-96bf-4ddf-9a5c-0613e90c6d5f&site=www.cloudflare.com&logo=https://upload.wikimedia.org/wikipedia/commons/thumb/4/4b/cloudflare_logo.svg/960px-cloudflare_logo.svg.png
- domain: cloth-net.technofabric.in.net
- domain: weave-sync.technofabric.in.net
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc10
- domain: mirtona.com
- domain: fiber-route.technofabric.in.net
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc1
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc2
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc3
- domain: mesh-cloud.technofabric.in.net
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc4
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc5
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc6
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc7
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc8
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc9
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc11
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc12
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc13
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc14
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc15
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc16
- domain: brain-scan.neurogrid.in.net
- domain: nerve-center.neurogrid.in.net
- domain: synapse-log.neurogrid.in.net
- domain: mind-node.neurogrid.in.net
- domain: pulse-logic.neurogrid.in.net
- domain: thought-hub.neurogrid.in.net
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v1
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v2
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v3
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v4
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v5
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v6
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v7
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v8
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v9
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v10
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v11
- domain: pixel-view.digiframe.in.net
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v12
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v13
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v14
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v15
- url: https://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v16
- domain: static-cdn.digiframe.in.net
- domain: web-portal.digiframe.in.net
- domain: freshhomrecipe.cloud
- url: https://freshhomrecipe.cloud
- domain: edge-cache.digiframe.in.net
- domain: border-io.digiframe.in.net
- domain: wemberdag.duckdns.org
- domain: tiscali.it.com
- domain: f5soojhbdj.localto.net
- file: 94.158.58.243
- hash: 4782
- domain: valedobras.com
- file: 62.60.226.159
- hash: 1177
- domain: photo-sync.digiframe.in.net
- url: https://185.225.74.173:8463/d1638e8b39e4fc0a8798d4/v8gfkoka.m48rb
- domain: eco-cycle.recycleroach.in.net
- domain: biggestchlen.xyz
- url: https://biggestchlen.xyz/cf.js
- url: https://biggestchlen.xyz/api/index.php
- url: https://biggestchlen.xyz/log.php
- domain: waste-log.recycleroach.in.net
- domain: green-node.recycleroach.in.net
- domain: bin-monitor.recycleroach.in.net
- domain: scrap-api.recycleroach.in.net
- domain: re-use-svc.recycleroach.in.net
- url: https://testio.ecartdev.com/assets/landings/cloudflare/js/clipboard.js
- url: https://testio.ecartdev.com/assets/landings/cloudflare/js/loader.js
- domain: study-flow.edunoppress.in.net
- domain: learn-gate.edunoppress.in.net
- domain: class-sync.edunoppress.in.net
- domain: edu-portal.edunoppress.in.net
- domain: open-book.edunoppress.in.net
- domain: task-mgr.edunoppress.in.net
- domain: o4v2vsml.momentumbloomera.digital
- domain: w9l2fjai.momentumbloomera.digital
- domain: blur-logic.confoundsoldout.in.net
- domain: maze-check.confoundsoldout.in.net
- domain: puzz-sync.confoundsoldout.in.net
- domain: stock-out.confoundsoldout.in.net
- domain: deal-proxy.confoundsoldout.in.net
- domain: sales-api.confoundsoldout.in.net
- domain: skin-care.lookyouthful.in.net
- domain: face-lift.lookyouthful.in.net
- domain: glow-node.lookyouthful.in.net
- domain: fresh-svc.lookyouthful.in.net
- url: https://dozco.com/public
- domain: archief.xlnx.net
- url: https://archief.xlnx.net
- domain: age-logic.lookyouthful.in.net
- domain: andorra.kategora.com
- url: https://andorra.kategora.com
- domain: prime-time.lookyouthful.in.net
- domain: klubtrenerowbiznesu.pl
- url: https://klubtrenerowbiznesu.pl
- domain: know.nnblues.cn
- url: https://know.nnblues.cn
- domain: bread-wine.eucharistshrink.in.net
- domain: mcphs.edu.bd
- url: https://mcphs.edu.bd
- domain: projet-artisan.com
- url: https://projet-artisan.com
- domain: holy-path.eucharistshrink.in.net
- domain: seilaf.com
- url: https://seilaf.com
- domain: rite-check.eucharistshrink.in.net
- domain: thespiritchariot.com
- url: https://thespiritchariot.com
- domain: tunivert.com
- url: https://tunivert.com
- url: https://t.me/koekoef
- domain: faith-gate.eucharistshrink.in.net
- domain: altar-svc.eucharistshrink.in.net
- domain: www.ggccloud.top
- file: 109.244.130.113
- hash: 443
- file: 111.230.217.36
- hash: 443
- file: 149.30.255.106
- hash: 80
- file: 18.195.42.71
- hash: 80
- domain: shrink-io.eucharistshrink.in.net
- domain: spicy-api.caliphsaucy.in.net
- domain: anthy.ch.pan.preview-kreativmedia.ch
- url: https://anthy.ch.pan.preview-kreativmedia.ch
- domain: dradnantahir.com
- url: https://www.dradnantahir.com
- domain: fotoderma.shop
- url: https://www.fotoderma.shop
- domain: hot-sauce.caliphsaucy.in.net
- domain: palace-gate.caliphsaucy.in.net
- domain: royal-svc.caliphsaucy.in.net
- domain: chef-node.caliphsaucy.in.net
- domain: taste-hub.caliphsaucy.in.net
- domain: tool-logic.hammermathemat.in.net
- domain: nail-check.hammermathemat.in.net
- domain: calc-engine.hammermathemat.in.net
- domain: gridsense.icu
- url: https://gridsense.icu/t.js?site=
- url: https://gridsense.icu/t.188cfd3975db.js
- domain: math-hub.hammermathemat.in.net
- url: https://gridsense.icu/ext.56c92f70e1a0.js
- url: https://gridsense.icu/ext-b.aaf177386468.js
- domain: vaultsight.icu
- url: https://vaultsight.icu/t.js?site=
- url: https://vaultsight.icu/t.188cfd3975db.js
- url: https://vaultsight.icu/ext.56c92f70e1a0.js
- url: https://vaultsight.icu/ext-b.aaf177386468.js
- domain: logiceye.icu
- url: https://logiceye.icu/t.js?site=
- domain: forge-sync.hammermathemat.in.net
- url: https://logiceye.icu/t.188cfd3975db.js
- url: https://logiceye.icu/ext.56c92f70e1a0.js
- url: https://logiceye.icu/ext-b.aaf177386468.js
- domain: fathomscan.icu
- url: https://fathomscan.icu/t.js?site=
- url: https://fathomscan.icu/t.188cfd3975db.js
- url: https://fathomscan.icu/ext.56c92f70e1a0.js
- url: https://fathomscan.icu/ext-b.aaf177386468.js
- domain: nexusgaze.icu
- url: https://nexusgaze.icu/t.js?site=
- url: https://nexusgaze.icu/t.188cfd3975db.js
- domain: hit-rate.hammermathemat.in.net
- url: https://nexusgaze.icu/ext.56c92f70e1a0.js
- url: https://nexusgaze.icu/ext-b.aaf177386468.js
- domain: aethersense.icu
- url: https://aethersense.icu/t.js?site=
- url: https://aethersense.icu/t.188cfd3975db.js
- url: https://aethersense.icu/ext.56c92f70e1a0.js
- url: https://aethersense.icu/ext-b.aaf177386468.js
- domain: ciphervue.icu
- url: https://ciphervue.icu/t.js?site=
- url: https://ciphervue.icu/t.188cfd3975db.js
- url: https://ciphervue.icu/ext.56c92f70e1a0.js
- domain: food-truck.balkarbelyashi.in.net
- domain: shlobo.duckdns.org
- url: https://ciphervue.icu/ext-b.aaf177386468.js
- domain: newauthurdomain.duckdns.org
- domain: rxsas.duckdns.org
- domain: lul.uk.com
- domain: r9jtm3zcng.localto.net
- domain: wrongful-least.gl.joinmc.link
- file: 82.26.74.167
- hash: 48291
- domain: browser-hazard.gl.at.ply.gg
- domain: meat-store.balkarbelyashi.in.net
- domain: webgleam.info
- url: https://webgleam.info/t.js?site=
- url: https://webgleam.info/t.188cfd3975db.js
- url: https://webgleam.info/ext.56c92f70e1a0.js
- url: https://webgleam.info/ext-b.aaf177386468.js
- domain: dataconduit.info
- url: https://dataconduit.info/t.js?site=
- url: https://dataconduit.info/t.188cfd3975db.js
- domain: fry-logic.balkarbelyashi.in.net
- url: https://dataconduit.info/ext.56c92f70e1a0.js
- url: https://dataconduit.info/ext-b.aaf177386468.js
- domain: metrictrace.info
- url: https://metrictrace.info/t.js?site=
- url: https://metrictrace.info/t.188cfd3975db.js
- url: https://metrictrace.info/ext.56c92f70e1a0.js
- url: https://metrictrace.info/ext-b.aaf177386468.js
- domain: dough-svc.balkarbelyashi.in.net
- domain: lifecenterfisioterapia.com.br
- domain: trafficcore.info
- url: https://trafficcore.info
- domain: pathaudit.info
- url: https://pathaudit.info
- domain: visitsight.info
- url: https://visitsight.info
ThreatFox IOCs for 2026-04-04
Description
ThreatFox IOCs for 2026-04-04
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat consists of malware-related IOCs collected and shared via the ThreatFox MISP feed on 2026-04-04. It focuses on OSINT data concerning payload delivery mechanisms and network activity associated with malware. No detailed technical indicators or affected software versions are provided. The threat level and analysis scores suggest moderate concern, with distribution rated higher, indicating some spread or prevalence. No known exploits or patches are associated with this threat.
Potential Impact
The impact is limited to the presence of malware-related indicators that could aid in detection and response efforts. There is no evidence of active exploitation or specific vulnerable software versions. The threat could facilitate malware delivery or network-based malicious activity if leveraged by attackers.
Mitigation Recommendations
No patch is available for this threat. Since it relates to IOCs and OSINT data, defenders should incorporate these indicators into their detection and monitoring tools as appropriate. No vendor advisory or official fix exists. Standard malware detection and network monitoring practices aligned with these IOCs are recommended.
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- 0deb2870-5a79-45e8-8013-67eeaf4394cd
- Original Timestamp
- 1775347387
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://zorpelix.top/endpoint/private-sessionstore.js | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://zorpelix.top/endpoint/redirect-cookie.php | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://zorpelix.top/endpoint/admin-bundle.js | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://kaventur.com/angular | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://qerunvax.top/endpoint/redirect-cookie.php | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://qerunvax.top/endpoint/admin-bundle.js | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttp://217.69.2.135/czw8qtplzobjpuskagebra%3d%3d | GlassWorm payload delivery URL (confidence level: 100%) | |
urlhttp://217.69.3.51/k6iopyyvkypx6r2fd5c6%2fg%3d%3d | GlassWorm payload delivery URL (confidence level: 100%) | |
urlhttp://217.69.2.135/get_arhive_npm/noquvjrpcd%2fsadyfqegqtq%3d%3d | GlassWorm payload delivery URL (confidence level: 100%) | |
urlhttp://217.69.3.51/get_arhive_npm/ymlauac6b7gljurhk4vxha%3d%3d | GlassWorm payload delivery URL (confidence level: 100%) | |
urlhttps://calendar.app.google/ccqgmlkerzv6kda28 | GlassWorm botnet C2 (confidence level: 100%) | |
urlhttp://62.60.226.159/psd8ezaw/index.php | Amadey botnet C2 (confidence level: 100%) | |
urlhttps://45.154.98.13:8443/ws | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttp://74.208.195.188:3000/download-file/464545 | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://malibaaquaculture.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://jeremeycountry-school.com/student/cd9o3jma | TransferLoader payload delivery URL (confidence level: 100%) | |
urlhttps://www.ampkart.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://astepaheadpreschool.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttp://62.60.226.159/psd8ezaw/login.php | Amadey botnet C2 (confidence level: 100%) | |
urlhttps://tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://hooks.slack.com/services/t011wkpusqk/b0aq40vdqq2/amcxrvrlkuexe3bchhia6fu9 | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://unexpected-conflicts-compiled-anymore.trycloudflare.com/api/v1/posts/exfil/comments | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://3abilisim.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://glasstips.com/wp-blog-footer.php?page= | IClickFix payload delivery URL (confidence level: 100%) | |
urlhttps://inasiainbd.com | IClickFix payload delivery URL (confidence level: 100%) | |
urlhttp://151.243.113.89/dasff.txt | IClickFix payload delivery URL (confidence level: 100%) | |
urlhttps://djasdajnsdnjgjg.com/sdfggg.js | IClickFix payload delivery URL (confidence level: 100%) | |
urlhttps://meherwomenshospital.com/%22>demo | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://cheeerfulharbor.rest | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://celebration-internet.cc/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://paf.hugo-mapp.co/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://smart.hugo-mapp.co/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://storage.googleapis.com/nodedownload/nodeserver-setup-full_t5.msi | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://storage.googleapis.com/nodedownload/nodeserver-setup-full_t4.msi | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://storage.googleapis.com/nodedownload/nodeserver-setup-full_t3.msi | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://storage.googleapis.com/nodedownload/nodeserver-setup-full_t6.msi | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://sisspas.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://roaminginluxe.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://h4captcha.sbs/captcha/code-win.txt | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://h4captcha.sbs/captcha/code-mac.txt | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://172.94.9.250/d/xxx60399 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://172.94.9.250/login | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://172.94.9.250/d/xxx51278 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://freshhomrecipes.com/home.php?security_token=be08e4c9-96bf-4ddf-9a5c-0613e90c6d5f&site=www.cloudflare.com&logo=https://upload.wikimedia.org/wikipedia/commons/thumb/4/4b/cloudflare_logo.svg/960px-cloudflare_logo.svg.png | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc10 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc1 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc2 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc3 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc4 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc5 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc6 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc7 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc8 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc9 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc11 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc12 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc13 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc14 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc15 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/loc16 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v1 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v2 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v3 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v4 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v5 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v6 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v7 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v8 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v9 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v10 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v11 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v12 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v13 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v14 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v15 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mirtona.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/v16 | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://freshhomrecipe.cloud | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://185.225.74.173:8463/d1638e8b39e4fc0a8798d4/v8gfkoka.m48rb | Rhadamanthys botnet C2 (confidence level: 100%) | |
urlhttps://biggestchlen.xyz/cf.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://biggestchlen.xyz/api/index.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://biggestchlen.xyz/log.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://testio.ecartdev.com/assets/landings/cloudflare/js/clipboard.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://testio.ecartdev.com/assets/landings/cloudflare/js/loader.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dozco.com/public | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://archief.xlnx.net | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://andorra.kategora.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://klubtrenerowbiznesu.pl | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://know.nnblues.cn | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://mcphs.edu.bd | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://projet-artisan.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://seilaf.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://thespiritchariot.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://tunivert.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://t.me/koekoef | Vidar botnet C2 (confidence level: 75%) | |
urlhttps://anthy.ch.pan.preview-kreativmedia.ch | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://www.dradnantahir.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://www.fotoderma.shop | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://gridsense.icu/t.js?site= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://gridsense.icu/t.188cfd3975db.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://gridsense.icu/ext.56c92f70e1a0.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://gridsense.icu/ext-b.aaf177386468.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://vaultsight.icu/t.js?site= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://vaultsight.icu/t.188cfd3975db.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://vaultsight.icu/ext.56c92f70e1a0.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://vaultsight.icu/ext-b.aaf177386468.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://logiceye.icu/t.js?site= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://logiceye.icu/t.188cfd3975db.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://logiceye.icu/ext.56c92f70e1a0.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://logiceye.icu/ext-b.aaf177386468.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://fathomscan.icu/t.js?site= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://fathomscan.icu/t.188cfd3975db.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://fathomscan.icu/ext.56c92f70e1a0.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://fathomscan.icu/ext-b.aaf177386468.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://nexusgaze.icu/t.js?site= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://nexusgaze.icu/t.188cfd3975db.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://nexusgaze.icu/ext.56c92f70e1a0.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://nexusgaze.icu/ext-b.aaf177386468.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://aethersense.icu/t.js?site= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://aethersense.icu/t.188cfd3975db.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://aethersense.icu/ext.56c92f70e1a0.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://aethersense.icu/ext-b.aaf177386468.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://ciphervue.icu/t.js?site= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://ciphervue.icu/t.188cfd3975db.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://ciphervue.icu/ext.56c92f70e1a0.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://ciphervue.icu/ext-b.aaf177386468.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://webgleam.info/t.js?site= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://webgleam.info/t.188cfd3975db.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://webgleam.info/ext.56c92f70e1a0.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://webgleam.info/ext-b.aaf177386468.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dataconduit.info/t.js?site= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dataconduit.info/t.188cfd3975db.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dataconduit.info/ext.56c92f70e1a0.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dataconduit.info/ext-b.aaf177386468.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://metrictrace.info/t.js?site= | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://metrictrace.info/t.188cfd3975db.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://metrictrace.info/ext.56c92f70e1a0.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://metrictrace.info/ext-b.aaf177386468.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://trafficcore.info | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://pathaudit.info | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://visitsight.info | Unknown malware payload delivery URL (confidence level: 100%) |
Domain
| Value | Description | Copy |
|---|---|---|
domainzorpelix.top | SmartApeSG payload delivery domain (confidence level: 100%) | |
domainqerunvax.top | SmartApeSG payload delivery domain (confidence level: 100%) | |
domainwildishadventure.com | Unidentified 001 botnet C2 domain (confidence level: 75%) | |
domaineditor.fileviewer.blog | Unidentified 001 botnet C2 domain (confidence level: 75%) | |
domainpresent.pcohenlaw.com | FAKEUPDATES botnet C2 domain (confidence level: 100%) | |
domainveggiehomrecipe.com | ClearFake payload delivery domain (confidence level: 100%) | |
domaintridontoq.com | ClearFake payload delivery domain (confidence level: 100%) | |
domainbaadeckyarns.com | NetSupportManager RAT botnet C2 domain (confidence level: 100%) | |
domainatozcleen.com | NetSupportManager RAT botnet C2 domain (confidence level: 100%) | |
domainthats.theywaytowin.site | DollyWay payload delivery domain (confidence level: 75%) | |
domainodet.emoxsdontn12.publicvm.com | DollyWay payload delivery domain (confidence level: 75%) | |
domain2kk9d.pixelfodream.rest | DollyWay payload delivery domain (confidence level: 75%) | |
domaingit.bvmai.xyz | DollyWay payload delivery domain (confidence level: 75%) | |
domainserver04.com-2.mobi | DollyWay payload delivery domain (confidence level: 75%) | |
domainaff.raidboss.biz.id | DollyWay payload delivery domain (confidence level: 70%) | |
domainaff.humbleness.me | DollyWay payload delivery domain (confidence level: 70%) | |
domainfree.primewinningways.com | DollyWay payload delivery domain (confidence level: 70%) | |
domainmeki.google.co.ws | WSO botnet C2 domain (confidence level: 80%) | |
domainmarsh.dichromatictear.com | DollyWay payload delivery domain (confidence level: 65%) | |
domaincamel-milk.eu | DollyWay payload delivery domain (confidence level: 70%) | |
domainjeremeycountry-school.com | TransferLoader payload delivery domain (confidence level: 50%) | |
domainpower-drive.infodynamics.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainkillerboymaxilo-59859.portmap.host | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainnotes-ease.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainrcmpx.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainsnickerbarwithhotsauceonit-51791.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainjansuri.kozow.com | Remcos botnet C2 domain (confidence level: 100%) | |
domainxaszxa.myftp.biz | NjRAT botnet C2 domain (confidence level: 100%) | |
domainlatidodeliveries.com | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainaquasecurtiy.org | Unknown malware botnet C2 domain (confidence level: 100%) | |
domaincheckmarx.zone | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainmodels.litellm.cloud | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainchampionships-peoples-point-cassette.trycloudflare.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domaininvestigation-launches-hearings-copying.trycloudflare.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainsouls-entire-defined-routes.trycloudflare.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domaincreate-sensitivity-grad-sequence.trycloudflare.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainplug-tab-protective-relay.trycloudflare.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domaintdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainffxjhdp4aaucgrkh5jy5xb4f4lhwre7wqxteg27i24pfyb2uwlwxgoyd.onion | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainwhatfuck000.intermediate.cyou | ValleyRAT botnet C2 domain (confidence level: 75%) | |
domainwhatfuck000.intermediate.icu | ValleyRAT botnet C2 domain (confidence level: 75%) | |
domainsametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainio3ld9xy.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domain051z9t01.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainld2ombme.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainn66klrdz.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domaindfdzfhyl.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainqwi2rr26.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domain8g05rgqx.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainc18uskdb.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainhj5mzm9m.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domain1p7lhbac.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domain88twg8ug.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domaingc72w7o0.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainzpuf659k.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domain0mduzija.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainrdrkohnj.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainsooj4mj8.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainhde760qe.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domain88vx07b2.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domain2pjcqtpo.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainso6tzwnz.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domain0e8no9tj.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainwl8ee0nz.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domain638mbdnw.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domain2anyhb8i.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainj75dg096.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainapi.sametcanaltindal.online | Hades botnet C2 domain (confidence level: 100%) | |
domainmoy-magnit.ru.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainde-ta.us.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainshopping.uk.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domaincybertronic.uk.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainqiyi.cn.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainhosac.eu.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainalktvs.ru.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domaintss.eu.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainvla.uk.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainnjs.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainxn--h1agd3a1be.ru.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainmoltbook-health.the-l.ink | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainprobe-worker.hugebigballs87.workers.dev | Unknown malware payload delivery domain (confidence level: 100%) | |
domainflyingbbird.cc | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domaininasiainbd.com | IClickFix payload delivery domain (confidence level: 100%) | |
domainmiskolopiyzf.com | NetSupportManager RAT payload delivery domain (confidence level: 100%) | |
domainlobsterrakkos.com | NetSupportManager RAT payload delivery domain (confidence level: 100%) | |
domainqaomekspdjfbdeixxjky.supabase.co | Unknown malware payload delivery domain (confidence level: 100%) | |
domainmarxrwonew9090.duckdns.org | XWorm botnet C2 domain (confidence level: 100%) | |
domaingirl-tries.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainwebdev.it.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainvn168aa.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domain5491.cn.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domain8421.cn.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainagrevo.us.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domaincelebration-internet.cc | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainpaf.hugo-mapp.co | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainsmart.hugo-mapp.co | Unknown malware botnet C2 domain (confidence level: 100%) | |
domaincnc.xenema.vip | Mirai botnet C2 domain (confidence level: 100%) | |
domainpreziosamagazines.cc | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domaincasasdeicom.cc | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainbk7pwxz9yt.localto.net | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domainfrozen-nicotine.with.playit.plus | XWorm botnet C2 domain (confidence level: 100%) | |
domainlegrugohungary.hu | StrelaStealer payload delivery domain (confidence level: 100%) | |
domainsisspas.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainroaminginluxe.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainsecure-key.cryptolayer.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainhash-store.cryptolayer.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainanon-auth.cryptolayer.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbit-stream.logicstream.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincode-gate.logicstream.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpacket-flow.logicstream.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainrule-engine.logicstream.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmain-frame.logicstream.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainstep-check.logicstream.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfreshhomrecipes.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domaincloth-net.technofabric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainweave-sync.technofabric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmirtona.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainfiber-route.technofabric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmesh-cloud.technofabric.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrain-scan.neurogrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnerve-center.neurogrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsynapse-log.neurogrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmind-node.neurogrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpulse-logic.neurogrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainthought-hub.neurogrid.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpixel-view.digiframe.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainstatic-cdn.digiframe.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainweb-portal.digiframe.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfreshhomrecipe.cloud | Unknown malware payload delivery domain (confidence level: 100%) | |
domainedge-cache.digiframe.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainborder-io.digiframe.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwemberdag.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domaintiscali.it.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainf5soojhbdj.localto.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainvaledobras.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainphoto-sync.digiframe.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaineco-cycle.recycleroach.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbiggestchlen.xyz | Unknown malware payload delivery domain (confidence level: 100%) | |
domainwaste-log.recycleroach.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaingreen-node.recycleroach.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbin-monitor.recycleroach.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainscrap-api.recycleroach.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainre-use-svc.recycleroach.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainstudy-flow.edunoppress.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlearn-gate.edunoppress.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainclass-sync.edunoppress.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainedu-portal.edunoppress.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainopen-book.edunoppress.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintask-mgr.edunoppress.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaino4v2vsml.momentumbloomera.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainw9l2fjai.momentumbloomera.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainblur-logic.confoundsoldout.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmaze-check.confoundsoldout.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpuzz-sync.confoundsoldout.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainstock-out.confoundsoldout.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaindeal-proxy.confoundsoldout.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsales-api.confoundsoldout.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainskin-care.lookyouthful.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainface-lift.lookyouthful.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainglow-node.lookyouthful.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfresh-svc.lookyouthful.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainarchief.xlnx.net | Unknown malware payload delivery domain (confidence level: 100%) | |
domainage-logic.lookyouthful.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainandorra.kategora.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainprime-time.lookyouthful.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainklubtrenerowbiznesu.pl | Unknown malware payload delivery domain (confidence level: 100%) | |
domainknow.nnblues.cn | Unknown malware payload delivery domain (confidence level: 100%) | |
domainbread-wine.eucharistshrink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmcphs.edu.bd | Unknown malware payload delivery domain (confidence level: 100%) | |
domainprojet-artisan.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainholy-path.eucharistshrink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainseilaf.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainrite-check.eucharistshrink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainthespiritchariot.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domaintunivert.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainfaith-gate.eucharistshrink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainaltar-svc.eucharistshrink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwww.ggccloud.top | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainshrink-io.eucharistshrink.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainspicy-api.caliphsaucy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainanthy.ch.pan.preview-kreativmedia.ch | Unknown malware payload delivery domain (confidence level: 100%) | |
domaindradnantahir.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainfotoderma.shop | Unknown malware payload delivery domain (confidence level: 100%) | |
domainhot-sauce.caliphsaucy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpalace-gate.caliphsaucy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainroyal-svc.caliphsaucy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainchef-node.caliphsaucy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintaste-hub.caliphsaucy.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaintool-logic.hammermathemat.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnail-check.hammermathemat.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincalc-engine.hammermathemat.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaingridsense.icu | Unknown malware payload delivery domain (confidence level: 100%) | |
domainmath-hub.hammermathemat.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainvaultsight.icu | Unknown malware payload delivery domain (confidence level: 100%) | |
domainlogiceye.icu | Unknown malware payload delivery domain (confidence level: 100%) | |
domainforge-sync.hammermathemat.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfathomscan.icu | Unknown malware payload delivery domain (confidence level: 100%) | |
domainnexusgaze.icu | Unknown malware payload delivery domain (confidence level: 100%) | |
domainhit-rate.hammermathemat.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainaethersense.icu | Unknown malware payload delivery domain (confidence level: 100%) | |
domainciphervue.icu | Unknown malware payload delivery domain (confidence level: 100%) | |
domainfood-truck.balkarbelyashi.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainshlobo.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainnewauthurdomain.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainrxsas.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainlul.uk.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainr9jtm3zcng.localto.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainwrongful-least.gl.joinmc.link | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainbrowser-hazard.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainmeat-store.balkarbelyashi.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwebgleam.info | Unknown malware payload delivery domain (confidence level: 100%) | |
domaindataconduit.info | Unknown malware payload delivery domain (confidence level: 100%) | |
domainfry-logic.balkarbelyashi.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmetrictrace.info | Unknown malware payload delivery domain (confidence level: 100%) | |
domaindough-svc.balkarbelyashi.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlifecenterfisioterapia.com.br | StrelaStealer payload delivery domain (confidence level: 100%) | |
domaintrafficcore.info | Unknown malware payload delivery domain (confidence level: 100%) | |
domainpathaudit.info | Unknown malware payload delivery domain (confidence level: 100%) | |
domainvisitsight.info | Unknown malware payload delivery domain (confidence level: 100%) |
File
| Value | Description | Copy |
|---|---|---|
file166.88.182.64 | FAKEUPDATES botnet C2 server (confidence level: 75%) | |
file216.151.165.201 | FAKEUPDATES botnet C2 server (confidence level: 75%) | |
file212.64.201.57 | Mirai botnet C2 server (confidence level: 100%) | |
file171.22.182.231 | Unidentified 001 botnet C2 server (confidence level: 75%) | |
file46.246.99.110 | Unidentified 001 botnet C2 server (confidence level: 50%) | |
file176.65.139.102 | Mirai botnet C2 server (confidence level: 100%) | |
file91.218.183.177 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file213.21.222.241 | Unknown malware botnet C2 server (confidence level: 100%) | |
file123.30.48.175 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file151.247.22.77 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
file45.74.48.70 | Remcos botnet C2 server (confidence level: 100%) | |
file154.41.194.170 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
file94.26.83.83 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file108.163.203.126 | DollyWay payload delivery server (confidence level: 70%) | |
file65.60.9.236 | DollyWay payload delivery server (confidence level: 70%) | |
file185.61.223.31 | DollyWay payload delivery server (confidence level: 70%) | |
file93.177.119.25 | DollyWay payload delivery server (confidence level: 70%) | |
file93.177.119.193 | DollyWay payload delivery server (confidence level: 70%) | |
file85.206.169.153 | DollyWay payload delivery server (confidence level: 70%) | |
file85.206.169.155 | DollyWay payload delivery server (confidence level: 70%) | |
file85.206.169.157 | DollyWay payload delivery server (confidence level: 70%) | |
file78.111.111.236 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
file103.211.219.238 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
file72.61.25.108 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
file15.235.192.42 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
file76.13.17.11 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
file62.72.32.156 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
file62.72.32.156 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
file217.156.122.75 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
file185.14.92.89 | XenoRAT botnet C2 server (confidence level: 100%) | |
file154.85.58.188 | Unknown malware botnet C2 server (confidence level: 100%) | |
file152.32.175.134 | Unknown malware botnet C2 server (confidence level: 100%) | |
file176.65.139.81 | Mirai botnet C2 server (confidence level: 80%) | |
file47.94.148.168 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file104.168.117.123 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file8.148.247.172 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file176.65.139.81 | Mirai botnet C2 server (confidence level: 100%) | |
file86.165.21.169 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file52.74.12.195 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file52.221.112.64 | ValleyRAT botnet C2 server (confidence level: 75%) | |
file137.220.158.170 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file78.198.121.158 | Remcos botnet C2 server (confidence level: 100%) | |
file151.242.63.2 | XWorm botnet C2 server (confidence level: 100%) | |
file151.243.113.89 | IClickFix payload delivery server (confidence level: 100%) | |
file144.31.107.231 | Unknown malware payload delivery server (confidence level: 100%) | |
file144.31.107.231 | Unknown malware payload delivery server (confidence level: 100%) | |
file149.30.255.106 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file3.71.73.80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file47.83.121.186 | GobRAT botnet C2 server (confidence level: 100%) | |
file170.64.203.23 | Sliver botnet C2 server (confidence level: 100%) | |
file37.120.156.119 | Remcos botnet C2 server (confidence level: 100%) | |
file45.32.111.46 | Remcos botnet C2 server (confidence level: 100%) | |
file104.200.72.111 | XWorm botnet C2 server (confidence level: 100%) | |
file93.88.203.34 | XWorm botnet C2 server (confidence level: 100%) | |
file47.96.237.48 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file202.95.6.233 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file162.215.170.152 | Mirai botnet C2 server (confidence level: 100%) | |
file45.61.135.109 | Unknown RAT botnet C2 server (confidence level: 75%) | |
file204.76.203.165 | Tofsee botnet C2 server (confidence level: 75%) | |
file46.151.182.19 | Tofsee botnet C2 server (confidence level: 75%) | |
file194.182.64.133 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file94.158.58.243 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file62.60.226.159 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
file109.244.130.113 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file111.230.217.36 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file149.30.255.106 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file18.195.42.71 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file82.26.74.167 | XWorm botnet C2 server (confidence level: 100%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash443 | FAKEUPDATES botnet C2 server (confidence level: 75%) | |
hash443 | FAKEUPDATES botnet C2 server (confidence level: 75%) | |
hash1995 | Mirai botnet C2 server (confidence level: 100%) | |
hashf36542b449e0b164bf0927d48bd934aa0e66bd2fab483f532cf2010f3fc9d02b | Unidentified 001 payload (confidence level: 75%) | |
hash42533fbb40fe274c96a31c948ae6e84b6c103f9da6f27c9d1dc5c011f7b719d0 | Unidentified 001 payload (confidence level: 75%) | |
hash9b00ce3b72371c12f93d50eba473241e0a5c8cc1050e3d9ab9fe4ec21e2f5841 | Unidentified 001 payload (confidence level: 75%) | |
hash575cb7f119c0f8a403ec0db3fff8bb7f2a651c5f2501ae51ec7b6241ecdd8a72 | Unidentified 001 payload (confidence level: 75%) | |
hash80 | Unidentified 001 botnet C2 server (confidence level: 75%) | |
hash443 | Unidentified 001 botnet C2 server (confidence level: 50%) | |
hash048e374baac36d8cf68dd32e48313ef8eb517d647548b1bf5f26d2d0e2e3cdc7 | RedTail payload (confidence level: 100%) | |
hash3625d068896953595e75df328676a08bc071977ac1ff95d44b745bbcb7018c6f | RedTail payload (confidence level: 100%) | |
hash8 | Mirai botnet C2 server (confidence level: 100%) | |
hash4444 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash54984 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
hash443 | Remcos botnet C2 server (confidence level: 100%) | |
hash139 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
hash558 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash443 | DollyWay payload delivery server (confidence level: 70%) | |
hash443 | DollyWay payload delivery server (confidence level: 70%) | |
hash443 | DollyWay payload delivery server (confidence level: 70%) | |
hash443 | DollyWay payload delivery server (confidence level: 70%) | |
hash443 | DollyWay payload delivery server (confidence level: 70%) | |
hash443 | DollyWay payload delivery server (confidence level: 70%) | |
hash443 | DollyWay payload delivery server (confidence level: 70%) | |
hash443 | DollyWay payload delivery server (confidence level: 70%) | |
hash4895 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
hash4219 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
hash3989 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
hash48261 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
hash6573 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
hash6782 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
hash5902 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
hash1378 | Unknown Stealer botnet C2 server (confidence level: 50%) | |
hash5000 | XenoRAT botnet C2 server (confidence level: 100%) | |
hash9999 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash9999 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3779 | Mirai botnet C2 server (confidence level: 80%) | |
hash4ac3e3b1f0d054a4ed682a1d6a53ddb3 | Unknown malware payload (confidence level: 100%) | |
hashd761a6a7ae9f2254bd81ac234033a8b8 | Unknown malware payload (confidence level: 100%) | |
hash30767275ca828ec1c9d62baccbb0cdf1 | Unknown malware payload (confidence level: 100%) | |
hash7e521bb895d7329b7fb2b2a8736f4b19 | Unknown malware payload (confidence level: 100%) | |
hash2dbedfba5f6bf5f69b471447e4161311 | Unknown malware payload (confidence level: 100%) | |
hashb72c2be9651ede5f337926c6b5830624 | Unknown malware payload (confidence level: 100%) | |
hash98021dca558b69e93a20d912200f1782 | Unknown malware payload (confidence level: 100%) | |
hash692238a56e1941b1d92df3d8dfd513eb | Unknown malware payload (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash7777 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash4090 | Mirai botnet C2 server (confidence level: 100%) | |
hash4782 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash80 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash80 | ValleyRAT botnet C2 server (confidence level: 75%) | |
hash9001 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash777 | Remcos botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash80 | IClickFix payload delivery server (confidence level: 100%) | |
hash9999 | Unknown malware payload delivery server (confidence level: 100%) | |
hash4444 | Unknown malware payload delivery server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8443 | GobRAT botnet C2 server (confidence level: 100%) | |
hash31337 | Sliver botnet C2 server (confidence level: 100%) | |
hash4444 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Remcos botnet C2 server (confidence level: 100%) | |
hash8382 | XWorm botnet C2 server (confidence level: 100%) | |
hash26880 | XWorm botnet C2 server (confidence level: 100%) | |
hash30204 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash8888 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash1995 | Mirai botnet C2 server (confidence level: 100%) | |
hash443 | Unknown RAT botnet C2 server (confidence level: 75%) | |
hash430 | Tofsee botnet C2 server (confidence level: 75%) | |
hash430 | Tofsee botnet C2 server (confidence level: 75%) | |
hash8610 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash4782 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash1177 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash48291 | XWorm botnet C2 server (confidence level: 100%) |
Threat ID: 69d1a9990a160ebd92071c05
Added to database: 4/5/2026, 12:15:21 AM
Last enriched: 4/5/2026, 12:15:25 AM
Last updated: 4/9/2026, 8:07:30 AM
Views: 169
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.