Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-04-05

0
Medium
Published: Sun Apr 05 2026 (04/05/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-04-05

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 04/06/2026, 00:30:29 UTC

Technical Analysis

The data represents a collection of malware-related IOCs published on 2026-04-05 from the ThreatFox MISP feed. It is classified under OSINT and involves network activity and payload delivery. There are no affected product versions or specific vulnerabilities detailed. No patches or fixes are available, and no active exploitation has been reported. The threat level is moderate, with limited technical analysis and distribution information provided.

Potential Impact

The impact is currently limited due to the absence of known exploits in the wild and no specific affected software versions. The threat indicates potential malware activity that could involve network-based payload delivery, but without further details, the exact impact cannot be fully assessed.

Mitigation Recommendations

No patch or official remediation is available for this threat. Since no active exploitation is known, monitoring for related indicators and applying general malware defense best practices is advisable. Specific mitigation actions cannot be recommended due to lack of detailed technical information.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
b996c45a-44f0-44de-8d3a-f152875082d4
Original Timestamp
1775433787

Indicators of Compromise

Domain

ValueDescriptionCopy
domaintfxgjy8d4r.localto.net
Quasar RAT botnet C2 domain (confidence level: 75%)
domainsost1213.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainghfjfgj57765r67ghght-56660.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainlivewithrelief.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainsnack-api.balkarbelyashi.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhot-belyash.balkarbelyashi.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainchhidden.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainhiddenhost.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainscdoorco.co.uk
Quasar RAT botnet C2 domain (confidence level: 100%)
domaindrink-sync.okiselwhiten.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainberry-mix.okiselwhiten.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbright-node.okiselwhiten.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainclean-svc.okiselwhiten.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwash-logic.okiselwhiten.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainclear-sky.okiselwhiten.in.net
ClearFake payload delivery domain (confidence level: 100%)
domain051516xx.vectorprospera.digital
ClearFake payload delivery domain (confidence level: 100%)
domain5x0raip5.vectorprospera.digital
ClearFake payload delivery domain (confidence level: 100%)
domainfly8889.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainwelcome2amway.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainbj88-daga.online
Quasar RAT botnet C2 domain (confidence level: 100%)
domainbj88-games.us
Quasar RAT botnet C2 domain (confidence level: 100%)
domainbj8826.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainbj88a.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainbj88s.zone
Quasar RAT botnet C2 domain (confidence level: 100%)
domaingokulmimrot.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainnohonhaisou.co.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainshallowwaterboutique.gb.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainsteep-hill.sa.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainvmn.uk.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainxn--d1aizef8e.ru.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainxn--tck0gq19hs5p9fqf00a.jpn.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainanayaghma.sa.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainproject-stor51092.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainftduk.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainqpxd3gb5z.localto.net
AsyncRAT botnet C2 domain (confidence level: 75%)
domainclaude-docs.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainlowtrap.mom
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkj51-weathj-dsjka.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domaindownload-version.1-8-3.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainlate-pond-d4f2.david-taylor87.workers.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domaingkkma-glcaks-summ.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainhb8uu38hbx872bv28dbh29.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainnhb227nbx872bd6723g4d.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainproject-msg510901kja.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainclaufua.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainfdfwasrgwrhfdgvwr.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainejecen.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domaindownload-version.4-1-7.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkrempie.xyz
Unknown malware payload delivery domain (confidence level: 100%)
domainmeblor.ru
StrelaStealer payload delivery domain (confidence level: 100%)
domainhedj.sa.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainp6zunv.ru.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainxn--hyup2pp3bi2g.jpn.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainxn--lckh3dvdtc8ib0962hxmwd.jp.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainkaalsarpshantitrimbakeshwar.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainlegaseas.us.org
Quasar RAT botnet C2 domain (confidence level: 100%)
domain9elmharbor.ru
Unknown Stealer payload delivery domain (confidence level: 100%)
domainhacelu.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkjkgsi-gsjgkan-wintersga.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainproject-hidd501921.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainproject-usb392891.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainryandp-63686.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domaini8pknbadf4.localto.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainoa8naf3lih.localto.net
NjRAT botnet C2 domain (confidence level: 100%)
domainclaude-code-info.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainproject-clau05192.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainart-studio.gouachesoror.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpaint-job.gouachesoror.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbrush-api.gouachesoror.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsister-hub.gouachesoror.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincolor-set.gouachesoror.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindraw-sync.gouachesoror.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintruth-verify.epistemicforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlogic-audit.epistemicforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainproof-engine.epistemicforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbase-theory.epistemicforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmind-vault.epistemicforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstudy-sync.epistemicforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainentity-map.ontologicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainflow-object.ontologicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainembargogo2377.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainrem.pushswroller.eu
Remcos botnet C2 domain (confidence level: 100%)
domainrun.rollerswpush.eu
Remcos botnet C2 domain (confidence level: 100%)
domainswre.remwavesw.com
Remcos botnet C2 domain (confidence level: 100%)
domaindcratyprograma.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domain2sasprosnowmeprona.za.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainhx3k851.uk.com
Quasar RAT botnet C2 domain (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttp://196.251.107.130/h84jjfar/index.php
Amadey botnet C2 (confidence level: 100%)
urlhttps://project-stor51092.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://ftduk.com/curl/34979832a7c24b00a2bf21f5aa53a5025b08c497a9400c403602ac08e434d033
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://ftduk.com/cleaner3/update
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://178.16.52.29
Stealc botnet C2 (confidence level: 100%)
urlhttps://claude-docs.com
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://lowtrap.mom/loader.sh
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://lowtrap.mom/payload.applescript
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://lowtrap.mom/api/bot/heartbeat
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://ftduk.com/curl/59b62772b3fd5584013342c0d9741befd73af0701ae0409d3cc7c3546680906c
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://kj51-weathj-dsjka.pages.dev
Unknown Stealer payload delivery URL (confidence level: 50%)
urlhttps://download-version.1-8-3.com/claude
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://late-pond-d4f2.david-taylor87.workers.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://gkkma-glcaks-summ.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://hb8uu38hbx872bv28dbh29.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://nhb227nbx872bd6723g4d.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://project-msg510901kja.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://claufua.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://213.165.45.120/kukawul
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://213.165.45.120/wogaxu
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://213.165.45.120/jigabedac
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://213.165.45.120/jinibode
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://213.165.45.120/kahege
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://213.165.45.120/modeceli
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://213.165.45.120/nogate
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://213.165.45.120/xogiri
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://213.165.45.120/newone
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://fdfwasrgwrhfdgvwr.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://ejecen.com/curl/3227dad68cb21941c33d3e74126b73f0d66eea79996b1be70aed733e813c3de9
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://download-version.4-1-7.com/claude
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://krempie.xyz/cf.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://krempie.xyz/api/index.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://krempie.xyz/log.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://pertur.cyou
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://ftduk.com/n8n/update
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://hacelu.com/curl/f083ead083d7766164c4aea88a0fbd6f105b8a5a91fab6336882aa49b1694812
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://kjkgsi-gsjgkan-wintersga.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://hacelu.com/cleaner3/update
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://project-hidd501921.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://hacelu.com/curl/f269fe69501e3f5e3a40fc84f21da46df3fc7c5a62b796b110ec84f995a4d8e3
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://hacelu.com/hiddenfix/update
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://project-usb392891.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://hacelu.com/curl/7856125165158b06b00d0acf49c34ea26cbc0b250103a48c746c0eb23b31cbc5
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://hacelu.com/usbfix/update
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://claude-code-info.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://project-clau05192.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)

File

ValueDescriptionCopy
file116.193.134.6
RedLine Stealer botnet C2 server (confidence level: 100%)
file172.65.185.109
Ghost RAT botnet C2 server (confidence level: 100%)
file95.70.183.89
XWorm botnet C2 server (confidence level: 100%)
file213.165.45.120
Unknown Stealer payload delivery server (confidence level: 100%)
file8.148.5.193
XWorm botnet C2 server (confidence level: 75%)
file179.118.199.252
XWorm botnet C2 server (confidence level: 100%)
file5.42.92.37
XWorm botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash1912
RedLine Stealer botnet C2 server (confidence level: 100%)
hash83
Ghost RAT botnet C2 server (confidence level: 100%)
hash90
XWorm botnet C2 server (confidence level: 100%)
hash80
Unknown Stealer payload delivery server (confidence level: 100%)
hash12748
XWorm botnet C2 server (confidence level: 75%)
hash7771
XWorm botnet C2 server (confidence level: 100%)
hash7777
XWorm botnet C2 server (confidence level: 100%)

Threat ID: 69d2fb190a160ebd9229a5af

Added to database: 4/6/2026, 12:15:21 AM

Last enriched: 4/6/2026, 12:30:29 AM

Last updated: 4/6/2026, 5:16:00 AM

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses