Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-04-06

0
Medium
Published: Mon Apr 06 2026 (04/06/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-04-06

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 04/07/2026, 00:30:27 UTC

Technical Analysis

The ThreatFox IOCs for 2026-04-06 represent a collection of malware-related indicators intended for open-source intelligence (OSINT) purposes. The data includes network activity and payload delivery aspects but lacks detailed technical specifics or affected software versions. There are no known exploits in the wild, and no remediation patches exist. The threat level and analysis scores are low to moderate, indicating limited immediate impact or exploitation evidence.

Potential Impact

The threat involves malware-related indicators that could be used to detect or analyze malicious payload delivery and network activity. However, no direct exploitation or active attacks have been confirmed. The absence of known exploits and patches suggests this is primarily intelligence for detection rather than an active vulnerability or ongoing attack campaign.

Mitigation Recommendations

No patches are available for this threat. Since this is an OSINT feed providing IOCs rather than a vulnerability with a fix, mitigation should focus on integrating these IOCs into detection and monitoring tools as appropriate. No urgent remediation actions are indicated based on the current information.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
d3cb8b3d-a27b-493d-aa37-00bb428b38c6
Original Timestamp
1775520187

Indicators of Compromise

Domain

ValueDescriptionCopy
domaindowindexsp.com
TransferLoader payload delivery domain (confidence level: 100%)
domainbulbous-bouffant.metalseed.net
Unknown malware botnet C2 domain (confidence level: 90%)
domainbottube.ai
Unknown malware botnet C2 domain (confidence level: 90%)
domainrustchain.org
Unknown malware botnet C2 domain (confidence level: 90%)
domainr3v13wd0s.com
Unknown RAT botnet C2 domain (confidence level: 100%)
domaina55doc6.com
Unknown RAT botnet C2 domain (confidence level: 100%)
domainzleishitestttg.store
Unknown RAT botnet C2 domain (confidence level: 100%)
domainextended-king-tone-polar.trycloudflare.com
EtherRAT botnet C2 domain (confidence level: 100%)
domainfluxnet.life
EtherRAT botnet C2 domain (confidence level: 100%)
domaincerumo.shop
EtherRAT botnet C2 domain (confidence level: 100%)
domainzonasteni.com
EtherRAT botnet C2 domain (confidence level: 100%)
domainmillersteel.digital
EtherRAT botnet C2 domain (confidence level: 100%)
domainpublisherresolution.com
EtherRAT botnet C2 domain (confidence level: 100%)
domainnastilka.com
EtherRAT botnet C2 domain (confidence level: 100%)
domainterminal-labels-fan-witness.trycloudflare.com
EtherRAT botnet C2 domain (confidence level: 100%)
domainnorthcroft.digital
EtherRAT botnet C2 domain (confidence level: 100%)
domainimported-spread-amplifier-chemicals.trycloudflare.com
EtherRAT botnet C2 domain (confidence level: 100%)
domainkde-blink-buried-flower.trycloudflare.com
EtherRAT botnet C2 domain (confidence level: 100%)
domainicq-flooring-procedure-rap.trycloudflare.com
EtherRAT botnet C2 domain (confidence level: 100%)
domainmight-tribute-christina-vacuum.trycloudflare.com
EtherRAT botnet C2 domain (confidence level: 100%)
domaincorp-embassy-finds-marked.trycloudflare.com
EtherRAT botnet C2 domain (confidence level: 100%)
domaindepot-reunion-listings-targets.trycloudflare.com
EtherRAT botnet C2 domain (confidence level: 100%)
domaincdnlivechatinc.com
magecart botnet C2 domain (confidence level: 100%)
domainbot.cdnlivechatinc.com
magecart botnet C2 domain (confidence level: 100%)
domainbunnycraft.online
Unknown Stealer payload delivery domain (confidence level: 100%)
domaincherriecraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domaincutiecraft.network
Unknown Stealer payload delivery domain (confidence level: 100%)
domaincutiemc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domaincutiesmc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domaincuttiescraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domaincuttiesmp.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domaingreatsmp.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainhellocraft.online
Unknown Stealer payload delivery domain (confidence level: 100%)
domainhellokittycraft.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainhellokittymc.online
Unknown Stealer payload delivery domain (confidence level: 100%)
domainhellopink.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkitllycraft.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkitlycraft.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkitseramc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkitten-smp.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittenclient.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittenmc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittensmc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittiemc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittieslandmc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittiysmc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittlycraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittlycraft.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittycraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittycraft.online
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittycraft.site
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittypinkiecraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittypixel.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittyscrafts.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittysmp.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkuromicraft.online
Unknown Stealer payload delivery domain (confidence level: 100%)
domainlanchemc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainminicraft.world
Unknown Stealer payload delivery domain (confidence level: 100%)
domainmysticraftsmp.fun
Unknown Stealer payload delivery domain (confidence level: 100%)
domainneekocraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainowocraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainpinkcraftmc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainpinkiecraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainplaypinkycraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainplaysweetcraft.site
Unknown Stealer payload delivery domain (confidence level: 100%)
domainponyrise.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainragnacook.site
Unknown Stealer payload delivery domain (confidence level: 100%)
domainsanriocraft.online
Unknown Stealer payload delivery domain (confidence level: 100%)
domainsanriomc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainsanriomc.online
Unknown Stealer payload delivery domain (confidence level: 100%)
domainsoftiecraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainsugarsmp.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainsweetcraft.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainsweetiecraft.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainuwucraft.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainsweet-craft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainsweetkittycraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainpurfall.games
Unknown Stealer payload delivery domain (confidence level: 100%)
domainyagiz.art
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittenscraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainsweetcraft.site
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittiescraft.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittiesmc.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittyescraft.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainarcadegard.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainadorecraft.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domaincutycraft.fr
Unknown Stealer payload delivery domain (confidence level: 100%)
domaincuttieslauncher.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkittien-smp.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainadamrat.lol
Unknown RAT botnet C2 domain (confidence level: 100%)
domaindatawebsync-lvmv.onrender.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainplush-topaz.space
Unknown malware botnet C2 domain (confidence level: 100%)
domainwww.koenighaus-infrarot.de
Unknown malware payload delivery domain (confidence level: 100%)
domaingymacademie.ddns.net
Remcos botnet C2 domain (confidence level: 100%)
domainremcosmonitor.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainbossgsaghdh-62973.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainmegansmousepops.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainremcos2025rem.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainclaude-code-main.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainsmokecar.space
Unknown Loader botnet C2 domain (confidence level: 100%)
domainforkmice.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainproject-ms0419431ks13.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domaintheorylaugh.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainlightef.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainpertur.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainpodiat.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainbeing-node.ontologicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainreal-time-io.ontologicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsource-data.ontologicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstats-checking.com
Unknown malware payload delivery domain (confidence level: 100%)
domainexist-api.ontologicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrule-set.axiomaticgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincore-logic.axiomaticgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmesh-static.axiomaticgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmsgrouppolicy.vg
CountLoader botnet C2 domain (confidence level: 100%)
domainfixed-point.axiomaticgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbase-matrix.axiomaticgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainjftolsa.ws
SmokeLoader botnet C2 domain (confidence level: 100%)
domainnicetolosv.xyz
SmokeLoader botnet C2 domain (confidence level: 100%)
domainlaw-check.axiomaticgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainthesis-sync.dialecticflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainanti-node.dialecticflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintnt.unguidedfreewill.co
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainai.latitudeprevalent.cfd
ACR Stealer botnet C2 domain (confidence level: 100%)
domainsynth-portal.dialecticflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintabbysbakescodes.ws
Unknown malware botnet C2 domain (confidence level: 100%)
domainbifa668.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domaindebate-log.dialecticflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainshift-point.dialecticflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainreceiver.cy
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmotion-svc.dialecticflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaininfer-unit.inferentialcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstatementtouch.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainlead-trace.inferentialcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlogic-vault.inferentialcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwww.aa88.blog
Quasar RAT botnet C2 domain (confidence level: 100%)
domainhint-api.inferentialcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhomecub.cfd
Unknown Loader botnet C2 domain (confidence level: 100%)
domainguess-node.inferentialcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstep-wise.inferentialcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainabstract-io.theoreticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhvaaac.casacam.net
PureRAT botnet C2 domain (confidence level: 100%)
domainntpfix.online
Unknown malware botnet C2 domain (confidence level: 100%)
domainmodel-check.theoreticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmap-project.theoreticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainideal-node.theoreticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspace-time.theoreticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainframe-api.theoreticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainorder-logic.systematiclayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstep-monitor.systematiclayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrank-index.systematiclayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfile-stack.systematiclayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainarchive-hub.systematiclayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainline-secure.systematiclayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincw.compactedtightness.cfd
ACR Stealer botnet C2 domain (confidence level: 100%)
domainbruvqqex.top
SmartApeSG payload delivery domain (confidence level: 100%)
domainomarinjakuzzii.com
NetSupportManager RAT botnet C2 domain (confidence level: 100%)
domainlusnyak.xyz
NetSupportManager RAT botnet C2 domain (confidence level: 100%)
domainbrain-weave.cognitivefabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainthought-api.cognitivefabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainneural-link.cognitivefabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmind-web.cognitivefabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsense-data.cognitivefabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainperception-svc.cognitivefabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainratio-point.rationalmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsmart-node.rationalmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhautstark-konzept.de.bms69.com
Unknown malware payload delivery domain (confidence level: 100%)
domainthink-tank.rationalmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwp.gameph.net
Unknown malware payload delivery domain (confidence level: 100%)
domaintesthaazskzka.hoststronger.site
Unknown malware payload delivery domain (confidence level: 100%)
domainclear-head.rationalmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbelowthelines.news
Unknown malware payload delivery domain (confidence level: 100%)
domaincoachingaccelerator.com
Unknown malware payload delivery domain (confidence level: 100%)
domaincalc-logic.rationalmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindecision-svc.rationalmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbreak-down.analyticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainprintertechs.com
Unknown malware payload delivery domain (confidence level: 100%)
domainstat-render.analyticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainxvideos-th.com
Unknown malware payload delivery domain (confidence level: 100%)
domainpoint-scan.analyticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindata-split.analyticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmeta-track.analyticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingfz.uk.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainlukewards.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domaintrace-result.analyticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstep-sync.methodicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainqxazzilo.top
SmartApeSG payload delivery domain (confidence level: 100%)
domainflow-order.methodicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainjjbgasang.com
Unknown malware payload delivery domain (confidence level: 100%)
domaintrace-audit.methodicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpath-logic.methodicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrule-monitor.methodicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainroyalsystemsforyou.com
Unknown malware payload delivery domain (confidence level: 100%)
domainskydive-dubai.live
Unknown malware payload delivery domain (confidence level: 100%)
domainseq-manager.methodicstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstrict-code.formalisticcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainyourtube.lol
Unknown malware payload delivery domain (confidence level: 100%)
domaindenegnet.click
Unknown malware payload delivery domain (confidence level: 100%)
domainbase-syntax.formalisticcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainghdnsserverns.beer
Unknown malware payload delivery domain (confidence level: 100%)
domaingdelogi.lol
Unknown malware payload delivery domain (confidence level: 100%)
domainproof-vault.formalisticcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainteam-hf.com
Unknown malware payload delivery domain (confidence level: 100%)
domainteam-na.xyz
Unknown malware payload delivery domain (confidence level: 100%)
domaincheck-point.formalisticcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainteam.limo
Unknown malware payload delivery domain (confidence level: 100%)
domainuc.team-in.xyz
Unknown malware payload delivery domain (confidence level: 100%)
domainnorm-engine.formalisticcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainteam-nt.com
Unknown malware payload delivery domain (confidence level: 100%)
domainaxis-portal.formalisticcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfaceit-na.com
Unknown malware payload delivery domain (confidence level: 100%)
domaintop-down-io.deductivegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainresult-node.deductivegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainproof-static.deductivegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainanydomen.info
Unknown Stealer payload delivery domain (confidence level: 100%)
domainparalegalmustang.icu
Unknown Stealer payload delivery domain (confidence level: 100%)
domainlaw-verify.deductivegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainanydomen.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainbase-extract.deductivegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbiglights.net
Unknown Stealer payload delivery domain (confidence level: 100%)
domainclevergeriatric.icu
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkettlewhisper.icu
Unknown Stealer payload delivery domain (confidence level: 100%)
domaintubestore.digital
Unknown Stealer payload delivery domain (confidence level: 100%)
domainunit-logic.deductivegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpattern-dev.inductiveflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindata-guess.inductiveflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintrend-sensor.inductiveflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlikely-hood.inductiveflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainflux-scan.inductiveflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpoint-drift.inductiveflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbit-weave.logicalfabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmueleer.com
Unknown malware payload delivery domain (confidence level: 100%)
domaingate-secure.logicalfabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainweissnat.org
Unknown malware payload delivery domain (confidence level: 100%)
domainmesh-router.logicalfabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainthread-svc.logicalfabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstitch-api.logicalfabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincore-net.logicalfabric.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmind-stack.cognitivematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainthought-hub.cognitivematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainst-images.socalpocis.org
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainneural-io.cognitivematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsense-gate.cognitivematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbrain-api.cognitivematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainvision-node.cognitivematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainword-map.semanticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainterm-index.semanticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmeaning-svc.semanticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintag-portal.semanticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlink-trace.semanticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmeta-point.semanticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainchrisbekner001.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainstinosa.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainpaialspailas.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainpaialspailas22.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainfvqro5kllu.localto.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainrustomjeeaden.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainaib.it.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domain38sprosnowmeprona.za.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainthe-rehab.us.org
Quasar RAT botnet C2 domain (confidence level: 100%)
domainframe-build.structuralcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbeam-logic.structuralcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsolid-store.structuralcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbase-support.structuralcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainroboticsxp.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainusadigitizer.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainstress-node.structuralcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainload-api.structuralcore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainidea-vault.abstractlogic.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmodel-check.abstractlogic.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainblank-space.abstractlogic.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpure-node.abstractlogic.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintheory-svc.abstractlogic.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainghost-api.abstractlogic.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainentity-hub.conceptmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainroot-source.conceptmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincloud-draft.conceptmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainview-port.conceptmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsketch-node.conceptmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmaster-index.conceptmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincall-center.exhortshelk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainadminreservation.com
Unknown malware payload delivery domain (confidence level: 100%)
domainvoice-api.exhortshelk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainexteroavx.com
Unknown malware payload delivery domain (confidence level: 100%)
domainjskeowgo.com
Unknown malware payload delivery domain (confidence level: 100%)
domainpush-notify.exhortshelk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainqwlkfsfa.com
Unknown malware payload delivery domain (confidence level: 100%)
domainbnlfosf.com
Unknown malware payload delivery domain (confidence level: 100%)
domainsfnfpopq.com
Unknown malware payload delivery domain (confidence level: 100%)
domaingaowvdoxh.com
Unknown malware payload delivery domain (confidence level: 100%)
domainalert-node.exhortshelk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsfqwfq.com
Unknown malware payload delivery domain (confidence level: 100%)
domainsync-logic.exhortshelk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrelay-svc.exhortshelk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingloss-check.enameledtack.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainproject-stor129585.pages.dev
Unknown Stealer payload delivery domain (confidence level: 100%)
domainjpbassin.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainhard-point.enameledtack.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpin-storage.enameledtack.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsurface-api.enameledtack.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincoat-logic.enameledtack.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfix-node.enameledtack.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainquery-hub.howaskfor.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrequest-io.howaskfor.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhelp-desk.howaskfor.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsearch-svc.howaskfor.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainclient-gate.howaskfor.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindata-form.howaskfor.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainblast-zone.explosionjunip.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfire-wall.explosionjunip.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwood-trace.explosionjunip.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingreen-core.explosionjunip.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainplant-api.explosionjunip.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmiexpedientefavorito.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainboom-logic.explosionjunip.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainblessgod1903-60577.portmap.host
Remcos botnet C2 domain (confidence level: 100%)
domainlewisham1122.ddnsking.com
Remcos botnet C2 domain (confidence level: 100%)
domainaprilfreshremsshot.ddns.net
Remcos botnet C2 domain (confidence level: 100%)
domainforbacjskdfred.accesscam.org
Remcos botnet C2 domain (confidence level: 100%)
domainfreewetremdsgft54.ddns.net
Remcos botnet C2 domain (confidence level: 100%)
domainhhufhtwest2887.ddns.net
Remcos botnet C2 domain (confidence level: 100%)
domainletkepwinbudgt.accesscam.org
Remcos botnet C2 domain (confidence level: 100%)
domainmyfresapril2025remi.accesscam.org
Remcos botnet C2 domain (confidence level: 100%)
domainprinceremi25fr.accesscam.org
Remcos botnet C2 domain (confidence level: 100%)
domainwinnersderwestrem.ddns.net
Remcos botnet C2 domain (confidence level: 100%)
domainjaylenbro-44553.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainhiamego-47630.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainhstco.co.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainwaste-node.kokotkasquand.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainloss-monitor.kokotkasquand.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspend-api.kokotkasquand.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintrack-hub.kokotkasquand.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlimit-gate.kokotkasquand.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainuser-pool.kokotkasquand.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwave-point.beckonuncert.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrisk-check.beckonuncert.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincall-sign.beckonuncert.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhint-node.beckonuncert.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainguess-api.beckonuncert.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainopen-end.beckonuncert.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrule-block.drillobjection.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbase-audit.drillobjection.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhard-check.drillobjection.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintest-engine.drillobjection.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstop-logic.drillobjection.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpoint-api.drillobjection.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbio-trace.bactergreat.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincell-logic.bactergreat.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingrowth-hub.bactergreat.in.net
ClearFake payload delivery domain (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://h4captcha.sbs/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://bulbous-bouffant.metalseed.net/api/miners
Unknown malware botnet C2 (confidence level: 90%)
urlhttps://bulbous-bouffant.metalseed.net/attest/challenge
Unknown malware botnet C2 (confidence level: 90%)
urlhttps://bulbous-bouffant.metalseed.net/attest/submit
Unknown malware botnet C2 (confidence level: 90%)
urlhttps://bulbous-bouffant.metalseed.net/epoch/enroll
Unknown malware botnet C2 (confidence level: 90%)
urlhttps://bottube.ai/api/telemetry/install
Unknown malware botnet C2 (confidence level: 90%)
urlhttps://50.28.86.131/api/miners
Unknown malware botnet C2 (confidence level: 90%)
urlhttps://rustchain.org/attest/challenge
Unknown malware botnet C2 (confidence level: 90%)
urlhttps://rustchain.org/attest/submit
Unknown malware botnet C2 (confidence level: 90%)
urlhttps://rustchain.org/epoch/enroll
Unknown malware botnet C2 (confidence level: 90%)
urlhttps://uscdka.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://creditcapitol.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://lareic.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.rxnursing.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.musictoyourhome.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://extended-king-tone-polar.trycloudflare.com
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://fluxnet.life
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://cerumo.shop
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://zonasteni.com
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://millersteel.digital
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://publisherresolution.com
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://nastilka.com
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://terminal-labels-fan-witness.trycloudflare.com
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://northcroft.digital
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://imported-spread-amplifier-chemicals.trycloudflare.com
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://kde-blink-buried-flower.trycloudflare.com
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://icq-flooring-procedure-rap.trycloudflare.com
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://might-tribute-christina-vacuum.trycloudflare.com
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://corp-embassy-finds-marked.trycloudflare.com
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://depot-reunion-listings-targets.trycloudflare.com
EtherRAT botnet C2 (confidence level: 100%)
urlhttps://syndicatesecurity.co.uk/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://meninno-events.ch/
Unknown malware payload delivery URL (confidence level: 90%)
urlwss://cdnlivechatinc.com/ws
magecart botnet C2 (confidence level: 100%)
urlhttps://cdnlivechatinc.com/ws
magecart botnet C2 (confidence level: 100%)
urlhttps://dtpp.digitalindustry.mn/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://noakhalihomeservice.xyz/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.10estate.com.au/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.esmartway.com.my/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.koenighaus-infrarot.de/
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://89.169.32.161/ec8c42534104783f?force=1
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://89.169.32.161/59b88608?force=1
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://89.169.32.161/28434d80fdf?force=1
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://45.32.150.251/gafer0had88vn1dltvutxa%3d%3d
GlassWorm payload delivery URL (confidence level: 100%)
urlhttp://45.32.150.251/m%2f7usvz%2f5igfbdblnpcxwa%3d%3d
GlassWorm payload delivery URL (confidence level: 100%)
urlhttp://45.32.150.251/g/gafer0had88vn1dltvutxa%3d%3d
GlassWorm payload delivery URL (confidence level: 100%)
urlhttp://45.32.150.251/get_arhive_npm/7st9zwaqyqi0lm82yt8jdg%3d%3d
GlassWorm payload delivery URL (confidence level: 100%)
urlhttp://45.32.150.251/get_arhive_npm/qdij1z4aktfclzs540axfa%3d%3d
GlassWorm payload delivery URL (confidence level: 100%)
urlhttp://217.69.2.135/xg%2fyg77dioro%2bettihymnw%3d%3d
GlassWorm payload delivery URL (confidence level: 100%)
urlhttp://217.69.3.51/wcke9mpy8bmesgj8eqjpxg%3d%3d
GlassWorm payload delivery URL (confidence level: 100%)
urlhttp://217.69.2.135/get_arhive_npm/eidilpgbftrk%2bvnoocnxwa%3d%3d
GlassWorm payload delivery URL (confidence level: 100%)
urlhttp://217.69.3.51/get_arhive_npm/lmtnivulatw34rqi2jrf1q%3d%3d
GlassWorm payload delivery URL (confidence level: 100%)
urlhttp://a1251124.xsph.ru/l1nc0in.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://graalconsult.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://cerebe.cyou
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://zoomaudits.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://claude-code-main.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://project-ms0419431ks13.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://107.148.158.208
Vidar botnet C2 (confidence level: 75%)
urlhttps://31.57.201.12
Vidar botnet C2 (confidence level: 75%)
urlhttps://stats-checking.com/config
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://stats-checking.com/stats
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://stats-checking.com/js/tds.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://msgrouppolicy.vg/
CountLoader botnet C2 (confidence level: 100%)
urlhttps://tnt.unguidedfreewill.co/
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttp://109.158.183.30:5000
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://receiver.cy/files/jar/module
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://receiver.cy/files/jar/component
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://receiver.cy/api/component/lastmodified
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://weedhack.cy/files/jar/module
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://weedhack.cy/files/jar/component
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://weedhack.cy/api/component/lastmodified
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://fundacioportal.org/ca/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://taxi-amsterdamservice.nl/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://bruvqqex.top/realm/rate-effect.php
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://bruvqqex.top/realm/legacy-validator.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://zexxario.com/tcp/protocol
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://cv327205.tw1.ru/l1nc0in.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://hautstark-konzept.de.bms69.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://wp.gameph.net
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://testhaazskzka.hoststronger.site
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://belowthelines.news
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://coachingaccelerator.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://www.printertechs.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://xvideos-th.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://bruvqqex.top/realm/session-header.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://qxazzilo.top/realm/rate-effect.php
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://qxazzilo.top/realm/legacy-validator.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://jjbgasang.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://gasangmanual.com/files/jejugasang2.txt
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://gasangmanual.com/files/jejugasang.txt
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://gasangmanual.com/files/test1.txt
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://gasangmanual.com/files/small.bat
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://gasangmanual.com/files/gasangmenual2.txt
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://gasangmanual.com/files/gasangmenual1.txt
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://gasangmanual.com/files/32d2f4e573292bd132cfff234d2a059a.exe
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://royalsystemsforyou.com/lyks.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://skydive-dubai.live
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://yourtube.lol
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://85.11.161.35:3861/quas.msi
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://denegnet.click/cf.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://denegnet.click/api/index.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://denegnet.click/cf.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://denegnet.click/log.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ghdnsserverns.beer/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://team-hf.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://team-na.xyz
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://www.team.limo
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://uc.team-in.xyz
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://team-in.xyz
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://zexxario.com/health/check
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://team-nt.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://faceit-na.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://printertechs.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://anydomen.info
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://paralegalmustang.icu/script.sh
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://anydomen.net
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://biglights.net
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://clevergeriatric.icu/script.sh
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://kettlewhisper.icu
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://tubestore.digital
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://mueleer.com/t
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://mueleer.com/file.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://mueleer.com/g
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://weissnat.org/file.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://weissnat.org/t
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://weissnat.org/g
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://217.69.2.135/jy0fbn0y0pcv2yq0wtgg9w%3d%3d
GlassWorm botnet C2 (confidence level: 100%)
urlhttp://217.69.3.51/ix%2b3aqbulxmclyylbqld7q%3d%3d
GlassWorm botnet C2 (confidence level: 100%)
urlhttp://45.32.150.251/l9u0rbkrgjy0qqierebnaw%3d%3d
GlassWorm botnet C2 (confidence level: 100%)
urlhttp://45.32.150.251/g/l9u0rbkrgjy0qqierebnaw%3d%3d
GlassWorm botnet C2 (confidence level: 100%)
urlhttp://217.69.3.51/g/ix%2b3aqbulxmclyylbqld7q%3d%3d
GlassWorm botnet C2 (confidence level: 100%)
urlhttp://45.32.150.251/get_arhive_npm/0tffcixhat5smmpj2raolg%3d%3d
GlassWorm botnet C2 (confidence level: 100%)
urlhttp://217.69.2.135/get_arhive_npm/gxsonk0cybwd7yuhpxcg0q%3d%3d
GlassWorm botnet C2 (confidence level: 100%)
urlhttp://217.69.3.51/get_arhive_npm/wa3yshw6zuam8nls3ryd5g%3d%3d
GlassWorm botnet C2 (confidence level: 100%)
urlhttps://flo-nowak.de/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://team.limo/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://kartacpa.co.il/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://atomiy.cyou
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://dcdivas.com/wp-includes/pomo/orkapo.exe
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://a1159717.xsph.ru/34d86416.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://adminreservation.com/start/
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://77.91.97.92/032.txt
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://exteroavx.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://jskeowgo.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://qwlkfsfa.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://bnlfosf.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://sfnfpopq.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://gaowvdoxh.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://sfqwfq.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://project-stor129585.pages.dev
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://jpbassin.com/curl/8a7770426690f0afbeefa643c00e5e47330c82653bf0606234c1566069b68787
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://jpbassin.com/cleaner3/update
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://cu603691.tw1.ru/l1nc0in.php
DCRat botnet C2 (confidence level: 100%)

File

ValueDescriptionCopy
file39.105.213.45
Cobalt Strike botnet C2 server (confidence level: 100%)
file50.28.86.131
Unknown malware botnet C2 server (confidence level: 90%)
file171.233.27.46
Venom RAT botnet C2 server (confidence level: 100%)
file176.65.139.81
Mirai botnet C2 server (confidence level: 80%)
file193.46.218.171
magecart botnet C2 server (confidence level: 100%)
file185.218.16.112
magecart botnet C2 server (confidence level: 100%)
file194.87.238.14
magecart botnet C2 server (confidence level: 100%)
file176.65.139.25
Mirai botnet C2 server (confidence level: 80%)
file103.130.214.71
Mirai botnet C2 server (confidence level: 80%)
file193.233.19.233
XWorm botnet C2 server (confidence level: 100%)
file47.76.96.68
Cobalt Strike botnet C2 server (confidence level: 75%)
file192.252.181.74
ValleyRAT botnet C2 server (confidence level: 100%)
file192.252.181.74
ValleyRAT botnet C2 server (confidence level: 75%)
file185.244.31.212
Remcos botnet C2 server (confidence level: 100%)
file203.161.41.129
Cobalt Strike botnet C2 server (confidence level: 100%)
file116.99.191.53
DCRat botnet C2 server (confidence level: 100%)
file172.105.0.126
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.148.194.157
Cobalt Strike botnet C2 server (confidence level: 100%)
file217.156.66.151
CountLoader botnet C2 server (confidence level: 75%)
file143.92.63.179
ValleyRAT botnet C2 server (confidence level: 75%)
file108.181.218.60
PureRAT botnet C2 server (confidence level: 75%)
file185.208.159.210
PureRAT botnet C2 server (confidence level: 75%)
file176.65.132.185
CountLoader botnet C2 server (confidence level: 75%)
file89.125.50.217
Unknown malware botnet C2 server (confidence level: 100%)
file61.111.250.139
ValleyRAT botnet C2 server (confidence level: 75%)
file91.84.106.109
ACR Stealer botnet C2 server (confidence level: 75%)
file198.46.178.137
PureRAT botnet C2 server (confidence level: 75%)
file130.12.182.175
Tofsee botnet C2 server (confidence level: 75%)
file46.151.182.19
Tofsee botnet C2 server (confidence level: 75%)
file130.12.180.119
Tofsee botnet C2 server (confidence level: 75%)
file31.57.216.27
Tofsee botnet C2 server (confidence level: 75%)
file31.57.216.28
Tofsee botnet C2 server (confidence level: 75%)
file204.76.203.165
Tofsee botnet C2 server (confidence level: 75%)
file94.26.83.20
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file91.92.241.142
PureRAT botnet C2 server (confidence level: 75%)
file78.153.149.211
Unknown malware botnet C2 server (confidence level: 75%)
file176.65.150.63
Mirai botnet C2 server (confidence level: 80%)
file176.65.144.110
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file176.65.144.30
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file173.205.83.196
XWorm botnet C2 server (confidence level: 100%)
file103.204.79.99
ValleyRAT botnet C2 server (confidence level: 100%)
file103.204.79.99
ValleyRAT botnet C2 server (confidence level: 100%)
file43.226.125.85
ValleyRAT botnet C2 server (confidence level: 100%)
file206.238.180.235
ValleyRAT botnet C2 server (confidence level: 100%)
file134.122.173.209
ValleyRAT botnet C2 server (confidence level: 100%)
file38.14.248.232
Unknown malware botnet C2 server (confidence level: 75%)
file91.236.186.56
XWorm botnet C2 server (confidence level: 100%)
file5.101.82.22
Unknown RAT botnet C2 server (confidence level: 75%)
file101.132.195.54
Cobalt Strike botnet C2 server (confidence level: 75%)
file85.11.161.35
Unknown malware payload delivery server (confidence level: 100%)
file47.112.182.218
Cobalt Strike botnet C2 server (confidence level: 75%)
file84.21.189.244
Unknown malware botnet C2 server (confidence level: 100%)
file51.195.109.77
XWorm botnet C2 server (confidence level: 100%)
file71.188.123.108
Quasar RAT botnet C2 server (confidence level: 100%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 100%)
file43.160.222.50
ValleyRAT botnet C2 server (confidence level: 100%)
file43.160.222.50
ValleyRAT botnet C2 server (confidence level: 100%)
file43.160.222.50
ValleyRAT botnet C2 server (confidence level: 100%)
file43.165.167.122
ValleyRAT botnet C2 server (confidence level: 100%)
file43.165.167.122
ValleyRAT botnet C2 server (confidence level: 100%)
file43.165.167.122
ValleyRAT botnet C2 server (confidence level: 100%)
file43.139.108.161
Cobalt Strike botnet C2 server (confidence level: 100%)
file38.76.199.164
Cobalt Strike botnet C2 server (confidence level: 100%)
file38.127.138.248
Xtreme RAT botnet C2 server (confidence level: 100%)
file83.142.209.196
Socks5 Systemz botnet C2 server (confidence level: 100%)
file38.244.156.247
Socks5 Systemz botnet C2 server (confidence level: 100%)
file207.174.0.44
Remcos botnet C2 server (confidence level: 100%)
file45.151.81.138
Remcos botnet C2 server (confidence level: 100%)
file193.161.193.99
Quasar RAT botnet C2 server (confidence level: 100%)
file71.188.123.108
Quasar RAT botnet C2 server (confidence level: 75%)
file80.66.75.51
Remcos botnet C2 server (confidence level: 100%)
file80.66.75.51
Remcos botnet C2 server (confidence level: 100%)
file80.66.75.51
Remcos botnet C2 server (confidence level: 100%)
file100.76.160.96
Remcos botnet C2 server (confidence level: 100%)
file188.90.75.98
Remcos botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash9999
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 90%)
hash5001
Venom RAT botnet C2 server (confidence level: 100%)
hash4961
Mirai botnet C2 server (confidence level: 80%)
hash443
magecart botnet C2 server (confidence level: 100%)
hash443
magecart botnet C2 server (confidence level: 100%)
hash443
magecart botnet C2 server (confidence level: 100%)
hash0f95f1168d151dcea5aa2a5dc2de5721984d10fc2c5095d7e2ea8d46f0496510
magecart payload (confidence level: 100%)
hash0ad7daf901779b5b9639c77662e21a97dc029c125dffd992fbf1419e1e38b464
magecart payload (confidence level: 100%)
hash7e715c846f7ec6f892450fc5e6c36ce030da130defd7d6545358c291ec1145a3
magecart payload (confidence level: 100%)
hash2ba01d4141fce7342a7f0cc330e6c08da83cfe5d4bfd1a79b69f20d2b1f4f7e5
GlassWorm payload (confidence level: 100%)
hash3778
Mirai botnet C2 server (confidence level: 80%)
hash9506
Mirai botnet C2 server (confidence level: 80%)
hash5552
XWorm botnet C2 server (confidence level: 100%)
hash5555
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
ValleyRAT botnet C2 server (confidence level: 100%)
hash433
ValleyRAT botnet C2 server (confidence level: 75%)
hash4321
Remcos botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8889
DCRat botnet C2 server (confidence level: 100%)
hash808
Cobalt Strike botnet C2 server (confidence level: 100%)
hash6443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
CountLoader botnet C2 server (confidence level: 75%)
hash443
ValleyRAT botnet C2 server (confidence level: 75%)
hash1238
PureRAT botnet C2 server (confidence level: 75%)
hash56006
PureRAT botnet C2 server (confidence level: 75%)
hash443
CountLoader botnet C2 server (confidence level: 75%)
hashcf0eed666d4a468cec802c3cd8289dce3d4b318c17233c3b40370ce2ded75ec7
Unknown malware payload (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash9899
ValleyRAT botnet C2 server (confidence level: 75%)
hash443
ACR Stealer botnet C2 server (confidence level: 75%)
hash2d3d236f5f2a41f8e00d2c4545b501406e98ce66ba013e177c496df540d12e3b
Unknown malware payload (confidence level: 100%)
hash3268
PureRAT botnet C2 server (confidence level: 75%)
hash419
Tofsee botnet C2 server (confidence level: 75%)
hash419
Tofsee botnet C2 server (confidence level: 75%)
hash419
Tofsee botnet C2 server (confidence level: 75%)
hash419
Tofsee botnet C2 server (confidence level: 75%)
hash419
Tofsee botnet C2 server (confidence level: 75%)
hash419
Tofsee botnet C2 server (confidence level: 75%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash56001
PureRAT botnet C2 server (confidence level: 75%)
hash443
Unknown malware botnet C2 server (confidence level: 75%)
hash1312
Mirai botnet C2 server (confidence level: 80%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash3210
XWorm botnet C2 server (confidence level: 100%)
hash22011
ValleyRAT botnet C2 server (confidence level: 100%)
hash22012
ValleyRAT botnet C2 server (confidence level: 100%)
hash442
ValleyRAT botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash443
ValleyRAT botnet C2 server (confidence level: 100%)
hash7000
Unknown malware botnet C2 server (confidence level: 75%)
hash23306
XWorm botnet C2 server (confidence level: 100%)
hash8041
Unknown RAT botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash3861
Unknown malware payload delivery server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash4433
Unknown malware botnet C2 server (confidence level: 100%)
hash2137
XWorm botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash7777
XWorm botnet C2 server (confidence level: 100%)
hash12341
ValleyRAT botnet C2 server (confidence level: 100%)
hash12342
ValleyRAT botnet C2 server (confidence level: 100%)
hash808
ValleyRAT botnet C2 server (confidence level: 100%)
hash12341
ValleyRAT botnet C2 server (confidence level: 100%)
hash12342
ValleyRAT botnet C2 server (confidence level: 100%)
hash808
ValleyRAT botnet C2 server (confidence level: 100%)
hash8192
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash139
Xtreme RAT botnet C2 server (confidence level: 100%)
hash80
Socks5 Systemz botnet C2 server (confidence level: 100%)
hash443
Socks5 Systemz botnet C2 server (confidence level: 100%)
hash8997
Remcos botnet C2 server (confidence level: 100%)
hash24052
Remcos botnet C2 server (confidence level: 100%)
hash44553
Quasar RAT botnet C2 server (confidence level: 100%)
hash25340
Quasar RAT botnet C2 server (confidence level: 75%)
hash13334
Remcos botnet C2 server (confidence level: 100%)
hash15624
Remcos botnet C2 server (confidence level: 100%)
hash55554
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)

Threat ID: 69d44c990a160ebd92ef4b3d

Added to database: 4/7/2026, 12:15:21 AM

Last enriched: 4/7/2026, 12:30:27 AM

Last updated: 4/7/2026, 3:24:21 AM

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses