Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-04-08

0
Medium
Published: Wed Apr 08 2026 (04/08/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-04-08

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 04/09/2026, 00:05:49 UTC

Technical Analysis

The report details malware-related IOCs collected on 2026-04-08 from the ThreatFox MISP feed. It focuses on OSINT data concerning network activity and payload delivery but lacks detailed technical indicators or affected software versions. No exploits are currently known in the wild, and no patches apply since this is an intelligence feed rather than a software vulnerability. The threat level and analysis scores are low to moderate, with distribution rated higher, suggesting some spread or prevalence of the observed activity.

Potential Impact

The impact is limited to the presence of malware-related network activity and payload delivery as indicated by the IOCs. There is no direct evidence of exploitation or compromise of specific software or systems. Without known exploits or affected versions, the immediate risk to organizations is informational, supporting detection and response efforts rather than indicating an active vulnerability.

Mitigation Recommendations

No patch or official remediation is available or applicable. Security teams should use the provided IOCs to enhance detection capabilities and monitor network activity for related indicators. Since this is an OSINT report, no direct action is mandated beyond integrating threat intelligence into existing security monitoring processes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
78c39a73-1159-47a5-967c-13c111bdf09b
Original Timestamp
1775692986

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttp://150.241.230.16:7777/debug
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://150.241.230.16:7777/system-info
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://150.241.230.16:7777/dcinjection-send
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://venergymomentum.com/calculate/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://193.233.113.199
Unknown Stealer botnet C2 (confidence level: 50%)
urlhttp://77.91.97.186
Unknown Stealer botnet C2 (confidence level: 50%)
urlhttps://joyfulvoice.org/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://vescel.es/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://ieedn.org/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://smarterfeds.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://api.telegram.org/bot8746632348:aahnc3uyti38jz0mes9mlnqvelaiybwqs_s/
Unknown malware botnet C2 (confidence level: 50%)
urlhttps://zixxalor.top/verify/principal-css.php
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://zixxalor.top/verify/trace-deploy.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://wtp.msalifenterprise.net/
Vidar botnet C2 (confidence level: 100%)
urlhttps://wtp.expertcs.au/
Vidar botnet C2 (confidence level: 100%)
urlhttps://sec3viewing.live/install-guide.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://sec3viewing.live/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ew-masagroup.com/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ew-masagroup.com/invite.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://zoom-in.pages.dev/install-guide
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://zoom-in.pages.dev/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://zoom-i.pages.dev/install-guide
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://zoom-i.pages.dev/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://googlemeet.emilychart.xyz/invite.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://googlemeet.emilychart.xyz/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://simplicity-w.pages.dev/downloads/zoomworkspace.clientsetup.msi
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://simplicity-w.pages.dev/installation-guide
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://zoominviteeees.de/downloads/zoomworkspace.clientsetup.msi
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://zoominviteeees.de/installation-guide
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://fritchat.xyz/googlemeet/invite.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://fritchat.xyz/googlemeet/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://googlemeetinterview.help
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://googlomeetings.com/windows/invite.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://qkltt28zm3bxw.live/567/windows/invite.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://qkltt28zm3bxw.live/567/windows/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://googlemeet-meetings.us/update.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://usz00mczyiee.store/h7j3gm9g4jsp9/windows/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://usz00mczyiee.store/h7j3gm9g4jsp9/windows/invite.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://usz00mczyiee.store/h7j3gm9g4jsp9/windows/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://usz00mczyiee.store/h7j3gm9g4jsp9/windows/files/zoomworkspace.exe
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://usz00mczyiee.store/z8hj7ske6l9/windows/invite.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://usz00mczyiee.store/z8hj7ske6l9/windows/install-guide.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://usz00mczyiee.store/z8hj7ske6l9/windows/files/zoomworkspace.exe
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ggoooglemeettinggninvit.click/meets/567/windows/invite.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ggoooglemeettinggninvit.click/meets/567/windows/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://googgleemeetinginterviiew.live/invite.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://googgleemeetinginterviiew.live/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://goggllemmeettiingnc.com/join/invite.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://goggllemmeettiingnc.com/join/microsoft-store.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://193.143.1.21/fakeurl.htm
NetSupportManager RAT botnet C2 (confidence level: 100%)
urlhttp://193.143.1.21:443/fakeurl.htm
NetSupportManager RAT botnet C2 (confidence level: 100%)
urlhttps://prennixo.com/react
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://prennixo.com/pnpm
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://clfckhitriver.com/api/data
SmartApeSG payload delivery URL (confidence level: 75%)
urlhttps://stromao.com/file.js
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://clnsdns.beer/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://jsframeworkns.beer/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://nsservclod.beer/api/css.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://bestwebchlen.cyou/cf.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://bestwebchlen.cyou/api/index.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://bestwebchlen.cyou/log.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://stromao.com/t
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://stromao.com/g
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://142.248.80.144/lol.sh
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://135.181.233.232
Vidar botnet C2 (confidence level: 75%)
urlhttps://vittaro.ws/1/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://74.0.42.84
Vidar botnet C2 (confidence level: 75%)
urlhttps://xhx.msalifenterprise.net/
Vidar botnet C2 (confidence level: 100%)
urlhttps://xhx.expertcs.au/
Vidar botnet C2 (confidence level: 100%)
urlhttps://rbb.msalifenterprise.net/
Vidar botnet C2 (confidence level: 100%)
urlhttps://rbb.hbway.com.au/
Vidar botnet C2 (confidence level: 100%)
urlhttps://74.0.48.39/
Vidar botnet C2 (confidence level: 100%)
urlhttps://project-ms50192kd15.pages.dev
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://download-version.1-5-8.com/claude.msixbundle
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://jpbassin.com/curl/45b34232b6c839a6383c73bd2acf07117229211b67986d817a4b35b4beb73902
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://jpbassin.com/n8n/update
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://152.32.191.249:23803/ca
Cobalt Strike botnet C2 (confidence level: 75%)
urlhttp://152.32.191.249:23803/ysih
Cobalt Strike botnet C2 (confidence level: 75%)
urlhttps://new.importletterofcredit.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://cegmester.hellodevs.dev
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://conseilsst.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ameublement.bcd-adventures.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://deepsight.icu/t.188cfd3975db.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://deepsight.icu/ext-b.5211fbb3d30f.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://deepsight.icu/t.js?site=
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://deepsight.icu/ext.ec6c3fd8b3fb.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://logicvault.icu/ext.ec6c3fd8b3fb.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://logicvault.icu/ext-b.5211fbb3d30f.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://logicvault.icu/t.js?site=
Unknown malware payload delivery URL (confidence level: 100%)

Domain

ValueDescriptionCopy
domainpeakship.exceptionpong.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainplay67.cc
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmicroscall.com
WAVESHAPER payload delivery domain (confidence level: 100%)
domainmicroscell.com
WAVESHAPER payload delivery domain (confidence level: 100%)
domainmicrosmeet.xyz
WAVESHAPER payload delivery domain (confidence level: 100%)
domainopenclaw-cli.gr.com
IClickFix payload delivery domain (confidence level: 100%)
domaingetmonero.gr.com
IClickFix payload delivery domain (confidence level: 100%)
domainelectrum-wallet.gr.com
IClickFix payload delivery domain (confidence level: 100%)
domainelectrum.us.com
IClickFix payload delivery domain (confidence level: 100%)
domainfeatherwallet.us.com
IClickFix payload delivery domain (confidence level: 100%)
domainmymonero.us.com
IClickFix payload delivery domain (confidence level: 100%)
domainmicrosmeet.com
WAVESHAPER payload delivery domain (confidence level: 100%)
domaincertif.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainroot-source.ontogenesiscore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaineu03live.us
WAVESHAPER payload delivery domain (confidence level: 75%)
domainmsmeet.us
WAVESHAPER payload delivery domain (confidence level: 75%)
domaininteams.us
WAVESHAPER payload delivery domain (confidence level: 75%)
domaindencall.xyz
WAVESHAPER payload delivery domain (confidence level: 75%)
domaindentmt.us
WAVESHAPER payload delivery domain (confidence level: 75%)
domaincoinlistnetwork.com
WAVESHAPER payload delivery domain (confidence level: 75%)
domainsense-node.noeticstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlogic-api.noeticstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstream-gate.noeticstream.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainroot-vault.gnoseologiccore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbase-audit.gnoseologiccore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainknow-logic.gnoseologiccore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincore-secure.gnoseologiccore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsource-hub.gnoseologiccore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintruth-svc.gnoseologiccore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmesh-point.epistematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincell-logic.epistematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmatrix-api.epistematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsync-node.epistematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindata-vault.epistematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingrid-portal.epistematrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainflux-gate.ontofluxion.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainreal-io.ontofluxion.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbeing-log.ontofluxion.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainshift-node.ontofluxion.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindrift-svc.ontofluxion.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainentity-hub.ontofluxion.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmrcrystallized-56006.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainsphere-api.axiomaticsphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlaw-check.axiomaticsphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfixed-point.axiomaticsphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbase-logic.axiomaticsphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainunit-vault.axiomaticsphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainorder-node.axiomaticsphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainforge-svc.dialectonforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsynth-io.dialectonforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstep-check.dialectonforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindebate-hub.dialectonforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainthesis-log.dialectonforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlogic-gate.dialectonforge.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainzixxalor.top
SmartApeSG payload delivery domain (confidence level: 100%)
domaininfer-unit.inferenciumgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintrace-node.inferenciumgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindata-mesh.inferenciumgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingrid-api.inferenciumgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstep-wise.inferenciumgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlogic-vault.inferenciumgrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhub-secure.theoriconhub.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmodel-check.theoriconhub.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainabstract-io.theoriconhub.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainview-port.theoriconhub.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspace-unit.theoriconhub.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintheory-log.theoriconhub.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlayer-check.systemicitylayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfile-stack.systemicitylayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainarchive-hub.systemicitylayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrank-index.systemicitylayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmarketing.gundf.de
StrelaStealer payload delivery domain (confidence level: 100%)
domainorder-svc.systemicitylayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmain-route.systemicitylayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsmart-point.cognitrixvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainthink-node.cognitrixvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainneural-io.cognitrixvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsense-api.cognitrixvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainvector-svc.cognitrixvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbrain-log.cognitrixvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbase-point.ministobelisk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintower-sync.ministobelisk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstone-api.ministobelisk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpillar-node.ministobelisk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsite-vault.ministobelisk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmark-svc.ministobelisk.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainkelvin654.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainerapersona.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmsn.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.ladyhawkemusic.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilaczzzf.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilaczth.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilacztg.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilacztd.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilacxyo.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilacxyf.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilacxye.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilackf.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilackd.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainskin-check.pairingreptile.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainxoilackc.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilackc.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domaintooteko.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.tooteko.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainseacritterscafe.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.seacritterscafe.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmschicafe.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.mschicafe.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainheeiastatepark.org
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.heeiastatepark.org
Quasar RAT botnet C2 domain (confidence level: 100%)
domainfulltextreports.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.fulltextreports.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainfoxclinicwholesale.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.foxclinicwholesale.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domaincomingofage.org
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.comingofage.org
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.coinsource.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domaincakhiaao.cc
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.cakhiaao.cc
Quasar RAT botnet C2 domain (confidence level: 100%)
domainweblog-kidsenzo.nl
Quasar RAT botnet C2 domain (confidence level: 100%)
domainaccelrobotics.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.accelrobotics.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmallorca.myftp.org
Revenge RAT botnet C2 domain (confidence level: 100%)
domainmbvd.hopto.org
Revenge RAT botnet C2 domain (confidence level: 100%)
domaingreen-node.pairingreptile.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincold-api.pairingreptile.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainegg-vault.pairingreptile.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainscale-svc.pairingreptile.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintrack-hub.pairingreptile.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstep-io.naminkaprocess.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwtp.msalifenterprise.net
Vidar botnet C2 domain (confidence level: 100%)
domainwtp.expertcs.au
Vidar botnet C2 domain (confidence level: 100%)
domainwork-flow.naminkaprocess.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrun-log.naminkaprocess.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaineepaulz.ansmtpariba.com
Remcos botnet C2 domain (confidence level: 75%)
domainbtc23556gvbvc.icu
ValleyRAT botnet C2 domain (confidence level: 100%)
domaintask-api.naminkaprocess.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbtc23556gvbvc.cyou
ValleyRAT botnet C2 domain (confidence level: 100%)
domainsy336556254c.cyou
ValleyRAT botnet C2 domain (confidence level: 100%)
domainsy336556254c.qpon
ValleyRAT botnet C2 domain (confidence level: 100%)
domainxn1256165xn.qpon
ValleyRAT botnet C2 domain (confidence level: 100%)
domainwy29d68v.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domainuser-hub.naminkaprocess.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmain-svc.naminkaprocess.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmt27u19t.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domainforce-point.dynamismjuply.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincu39d76p.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domaintd49t43g.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domainur89t27d.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domaintd49t44g.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domainqd8jh2n.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domainpishjdaagd.cn
ValleyRAT botnet C2 domain (confidence level: 100%)
domainpower-api.dynamismjuply.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsec3viewing.live
Unknown malware payload delivery domain (confidence level: 100%)
domainshift-svc.dynamismjuply.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainew-masagroup.com
Unknown malware payload delivery domain (confidence level: 100%)
domainzoom-in.pages.dev
Unknown malware payload delivery domain (confidence level: 100%)
domaindrive-node.dynamismjuply.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainzoom-i.pages.dev
Unknown malware payload delivery domain (confidence level: 100%)
domaingooglemeet.emilychart.xyz
Unknown malware payload delivery domain (confidence level: 100%)
domainkinetic-io.dynamismjuply.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsimplicity-w.pages.dev
Unknown malware payload delivery domain (confidence level: 100%)
domainfast-log.dynamismjuply.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainzoominviteeees.de
Unknown malware payload delivery domain (confidence level: 100%)
domainokfuck001.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domainjdhajkba.cn
ValleyRAT botnet C2 domain (confidence level: 100%)
domainrosklun.cn
ValleyRAT botnet C2 domain (confidence level: 100%)
domainkoeuisg.cn
ValleyRAT botnet C2 domain (confidence level: 100%)
domainqaloucndh.cn
ValleyRAT botnet C2 domain (confidence level: 100%)
domainfmngirhbonpe.cn
ValleyRAT botnet C2 domain (confidence level: 100%)
domainzljjjfgr.cyou
ValleyRAT botnet C2 domain (confidence level: 100%)
domainmk65yui45876l.cyou
ValleyRAT botnet C2 domain (confidence level: 100%)
domainfritchat.xyz
Unknown malware payload delivery domain (confidence level: 100%)
domainscan-gate.boredistascan.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingooglemeetinterview.help
Unknown malware payload delivery domain (confidence level: 100%)
domainread-api.boredistascan.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingooglomeetings.com
Unknown malware payload delivery domain (confidence level: 100%)
domainqkltt28zm3bxw.live
Unknown malware payload delivery domain (confidence level: 100%)
domainview-hub.boredistascan.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingooglemeet-meetings.us
Unknown malware payload delivery domain (confidence level: 100%)
domainusz00mczyiee.store
Unknown malware payload delivery domain (confidence level: 100%)
domainfile-node.boredistascan.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintrace-svc.boredistascan.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainopen-log.boredistascan.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlab-check.sciencestupids.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainggoooglemeettinggninvit.click
Unknown malware payload delivery domain (confidence level: 100%)
domaintest-api.sciencestupids.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingooggleemeetinginterviiew.live
Unknown malware payload delivery domain (confidence level: 100%)
domaingoggllemmeettiingnc.com
Unknown malware payload delivery domain (confidence level: 100%)
domainstudy-node.sciencestupids.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfact-vault.sciencestupids.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsmart-io.sciencestupids.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindata-svc.sciencestupids.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfarm-logic.ranchitro.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincrop-api.ranchitro.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfield-node.ranchitro.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainland-vault.ranchitro.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainranch-hub.ranchitro.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlive-svc.ranchitro.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainword-check.dictatessullen.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintext-api.dictatessullen.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindark-node.dictatessullen.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainiridia.me
Unknown malware payload delivery domain (confidence level: 100%)
domainmood-log.dictatessullen.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainiridiacheats.dev
Unknown malware payload delivery domain (confidence level: 100%)
domainkssaprraemdda.com
NetSupportManager RAT botnet C2 domain (confidence level: 100%)
domainhard-svc.dictatessullen.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainline-vault.dictatessullen.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmesh-static.fastidmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincakhiaaj.cc
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.cakhiaaj.cc
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilacke.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainbase-point.fastidmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincore-api.fastidmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainunit-node.fastidmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainquick-io.fastidmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmatrix-svc.fastidmatrix.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincoat-check.selzovestments.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwear-api.selzovestments.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainshop-hub.selzovestments.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstock-node.selzovestments.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainitem-svc.selzovestments.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstyle-log.selzovestments.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainprennixo.com
SmartApeSG payload delivery domain (confidence level: 100%)
domainlink.mundonerdassistencia.com
StrelaStealer payload delivery domain (confidence level: 100%)
domaingrande-luna.top
KongTuke payload delivery domain (confidence level: 100%)
domainoeannon.com
KongTuke payload delivery domain (confidence level: 100%)
domainpixel-trace.iconoguroque.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainimage-api.iconoguroque.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainview-hub.iconoguroque.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindraw-node.iconoguroque.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainart-svc.iconoguroque.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsign-gate.iconoguroque.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfreserat.gb.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainform-check.shapeprimrose.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincpiprinting.us.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domaingegehhe-64692.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilaczzzzc.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainrexblade.sa.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domaingtv.uk.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainfkgohw.za.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainhghehg-51578.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainkx5official.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.kx5official.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainhiamego-36241.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainbase-point.shapeprimrose.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincompat.plenarykcg.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domaingeo-api.shapeprimrose.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmesh-node.shapeprimrose.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsolid-svc.shapeprimrose.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainframe-hub.shapeprimrose.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainclnsdns.beer
Unknown malware payload delivery domain (confidence level: 100%)
domainjsframeworkns.beer
Unknown malware payload delivery domain (confidence level: 100%)
domainnsservclod.beer
Unknown malware payload delivery domain (confidence level: 100%)
domaintalk-sync.dialectdozing.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbestwebchlen.cyou
Unknown malware payload delivery domain (confidence level: 100%)
domainstromao.com
Unknown malware payload delivery domain (confidence level: 100%)
domainword-api.dialectdozing.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainterm-log.dialectdozing.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainquiet-node.dialectdozing.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspeech-svc.dialectdozing.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrest-gate.dialectdozing.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwrap-logic.covercotehour.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintime-check.covercotehour.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfriendjewel.cfd
Unknown Loader botnet C2 domain (confidence level: 100%)
domainumbrellaquestion.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainvittaro.ws
Unknown malware botnet C2 domain (confidence level: 100%)
domainslot-api.covercotehour.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsxhangtie.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainsafe-node.covercotehour.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincoat-svc.covercotehour.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainport-hub.covercotehour.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsend-relay.emissarysooth.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlink-api.emissarysooth.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintruth-node.emissarysooth.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsoft-svc.emissarysooth.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainclear-gate.emissarysooth.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmessage-hub.emissarysooth.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainking-logic.monarchold.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpast-api.monarchold.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrule-check.monarchold.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincrown-node.monarchold.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhist-svc.monarchold.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbase-vault.monarchold.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbest-pair.goodtwain.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindual-api.goodtwain.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstep-node.goodtwain.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainitem-svc.goodtwain.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrbb.msalifenterprise.net
Vidar botnet C2 domain (confidence level: 100%)
domainrbb.hbway.com.au
Vidar botnet C2 domain (confidence level: 100%)
domainxhx.msalifenterprise.net
Vidar botnet C2 domain (confidence level: 100%)
domainxhx.expertcs.au
Vidar botnet C2 domain (confidence level: 100%)
domainmatch-gate.goodtwain.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlink-hub.goodtwain.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintop-logic.apotheosbring.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintake-api.apotheosbring.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainupdate35630.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 75%)
domainshift-node.apotheosbring.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpeak-svc.apotheosbring.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincore-gate.apotheosbring.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainload-hub.apotheosbring.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainwin-point.excellsadarma.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincdn.network-sync.online
Remcos botnet C2 domain (confidence level: 100%)
domain4thguy.ooguy.com
Remcos botnet C2 domain (confidence level: 100%)
domainshroom010.duckdns.org
Quasar RAT botnet C2 domain (confidence level: 100%)
domainwww.xn--eck4dzdq88wogxb.jpn.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domaincomplainprocess.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainflagship.jp.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainsunwin66.us.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmalware.xoilacxyi.tv
Quasar RAT botnet C2 domain (confidence level: 100%)
domainall.ddnsskey.com
XWorm botnet C2 domain (confidence level: 100%)
domainartesvisuais.us.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domaincure.uk.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainwoad.sa.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainbholauclonline.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domaindata-api.excellsadarma.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainamor11.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 75%)
domainbest-node.excellsadarma.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintest-svc.excellsadarma.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmark-gate.excellsadarma.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainroot-hub.excellsadarma.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmyth-logic.assyrfantasy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindream-api.assyrfantasy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfair-node.assyrfantasy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintale-svc.assyrfantasy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstory-gate.assyrfantasy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmagic-hub.assyrfantasy.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmind-sync.noospherecore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainglobal-io.noospherecore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainthought-api.noospherecore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincore-vault.noospherecore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlogic-node.noospherecore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainshell-svc.noospherecore.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainproject-ms50192kd15.pages.dev
Unknown malware payload delivery domain (confidence level: 100%)
domaindownload-version.1-5-8.com
Unknown malware payload delivery domain (confidence level: 100%)
domaintrace-point.gnosticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsmart-api.gnosticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainvector-hub.gnosticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainknow-node.gnosticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpath-svc.gnosticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainbase-gate.gnosticvector.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainflow-data.epistemiconflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmesh-api.epistemiconflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsync-vault.epistemiconflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainjpetrade.com
StrelaStealer payload delivery domain (confidence level: 100%)
domaintruth-node.epistemiconflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainshift-svc.epistemiconflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindrift-gate.epistemiconflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaingrid-core.ontoversegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainworld-api.ontoversegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmap-log.ontoversegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainentity-node.ontoversegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainverse-svc.ontoversegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspace-gate.ontoversegrid.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainengine-io.axiomorphengine.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlaw-check.axiomorphengine.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainnew.importletterofcredit.com
Unknown malware payload delivery domain (confidence level: 100%)
domainfixed-node.axiomorphengine.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaincegmester.hellodevs.dev
Unknown malware payload delivery domain (confidence level: 100%)
domainconseilsst.com
Unknown malware payload delivery domain (confidence level: 100%)
domainameublement.bcd-adventures.com
Unknown malware payload delivery domain (confidence level: 100%)
domainunit-vault.axiomorphengine.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrule-svc.axiomorphengine.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmatrix-hub.axiomorphengine.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainsphere-api.dialectosphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintalk-node.dialectosphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainescoclar.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainmohmusremcos.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domaindeepsight.icu
Unknown malware payload delivery domain (confidence level: 100%)
domainthesis-log.dialectosphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlogicvault.icu
Unknown malware payload delivery domain (confidence level: 100%)
domainstate-svc.dialectosphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindebate-hub.dialectosphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlogic-gate.dialectosphere.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaininfer-unit.inferentialisflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstep-api.inferentialisflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaintrace-log.inferentialisflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainflux-node.inferentialisflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domaindata-svc.inferentialisflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainpoint-gate.inferentialisflux.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainlayer-io.theorexuslayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmodel-api.theorexuslayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainabstract-log.theorexuslayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainspace-node.theorexuslayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainview-svc.theorexuslayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainhub-gate.theorexuslayer.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainmatrix-flow.systematrixflow.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainorder-api.systematrixflow.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainrank-node.systematrixflow.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainstream-svc.systematrixflow.in.net
ClearFake payload delivery domain (confidence level: 100%)
domainfile-hub.systematrixflow.in.net
ClearFake payload delivery domain (confidence level: 100%)

File

ValueDescriptionCopy
file121.4.21.197
Cobalt Strike botnet C2 server (confidence level: 100%)
file62.204.35.187
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.41.194.61
Xtreme RAT botnet C2 server (confidence level: 100%)
file122.225.30.87
Xtreme RAT botnet C2 server (confidence level: 100%)
file38.127.138.208
Xtreme RAT botnet C2 server (confidence level: 100%)
file50.61.162.66
Xtreme RAT botnet C2 server (confidence level: 100%)
file151.59.114.197
SectopRAT botnet C2 server (confidence level: 100%)
file85.239.147.3
Remcos botnet C2 server (confidence level: 100%)
file47.239.118.14
GobRAT botnet C2 server (confidence level: 100%)
file142.11.206.73
WAVESHAPER botnet C2 server (confidence level: 75%)
file108.187.42.200
FatalRat botnet C2 server (confidence level: 100%)
file31.56.209.80
XWorm botnet C2 server (confidence level: 100%)
file110.137.37.67
RedLine Stealer botnet C2 server (confidence level: 100%)
file46.151.182.19
Tofsee botnet C2 server (confidence level: 75%)
file204.76.203.165
Tofsee botnet C2 server (confidence level: 75%)
file156.245.234.13
ValleyRAT botnet C2 server (confidence level: 75%)
file84.247.150.177
Unknown malware botnet C2 server (confidence level: 100%)
file91.84.99.84
Unknown malware botnet C2 server (confidence level: 100%)
file43.240.29.37
ValleyRAT botnet C2 server (confidence level: 75%)
file38.190.198.153
ValleyRAT botnet C2 server (confidence level: 75%)
file18.197.149.125
Cobalt Strike botnet C2 server (confidence level: 100%)
file3.87.231.239
Cobalt Strike botnet C2 server (confidence level: 100%)
file180.97.221.231
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.162.251
Cobalt Strike botnet C2 server (confidence level: 100%)
file77.91.97.244
ACR Stealer botnet C2 server (confidence level: 100%)
file18.167.248.64
ValleyRAT botnet C2 server (confidence level: 75%)
file38.47.218.228
ValleyRAT botnet C2 server (confidence level: 75%)
file104.143.38.60
ValleyRAT botnet C2 server (confidence level: 75%)
file103.235.46.40
ValleyRAT botnet C2 server (confidence level: 50%)
file103.27.79.47
ValleyRAT botnet C2 server (confidence level: 50%)
file104.21.27.90
ValleyRAT botnet C2 server (confidence level: 50%)
file111.229.63.154
ValleyRAT botnet C2 server (confidence level: 50%)
file13.114.145.229
ValleyRAT botnet C2 server (confidence level: 50%)
file13.115.16.99
ValleyRAT botnet C2 server (confidence level: 50%)
file150.138.84.116
ValleyRAT botnet C2 server (confidence level: 50%)
file154.12.62.211
ValleyRAT botnet C2 server (confidence level: 50%)
file154.23.181.179
ValleyRAT botnet C2 server (confidence level: 50%)
file154.44.28.40
ValleyRAT botnet C2 server (confidence level: 50%)
file154.82.84.197
ValleyRAT botnet C2 server (confidence level: 50%)
file154.91.84.224
ValleyRAT botnet C2 server (confidence level: 50%)
file154.91.90.58
ValleyRAT botnet C2 server (confidence level: 50%)
file154.94.233.61
ValleyRAT botnet C2 server (confidence level: 50%)
file156.248.77.219
ValleyRAT botnet C2 server (confidence level: 50%)
file156.251.17.126
ValleyRAT botnet C2 server (confidence level: 50%)
file16.162.119.198
ValleyRAT botnet C2 server (confidence level: 50%)
file16.162.177.72
ValleyRAT botnet C2 server (confidence level: 50%)
file16.162.59.119
ValleyRAT botnet C2 server (confidence level: 50%)
file16.163.219.121
ValleyRAT botnet C2 server (confidence level: 50%)
file178.255.244.147
ValleyRAT botnet C2 server (confidence level: 50%)
file18.162.240.37
ValleyRAT botnet C2 server (confidence level: 50%)
file18.166.34.146
ValleyRAT botnet C2 server (confidence level: 50%)
file18.167.147.125
ValleyRAT botnet C2 server (confidence level: 50%)
file18.167.223.205
ValleyRAT botnet C2 server (confidence level: 50%)
file18.167.75.187
ValleyRAT botnet C2 server (confidence level: 50%)
file18.167.81.101
ValleyRAT botnet C2 server (confidence level: 50%)
file188.114.97.12
ValleyRAT botnet C2 server (confidence level: 50%)
file198.176.61.77
ValleyRAT botnet C2 server (confidence level: 50%)
file202.95.11.103
ValleyRAT botnet C2 server (confidence level: 50%)
file206.238.196.153
ValleyRAT botnet C2 server (confidence level: 50%)
file206.238.199.8
ValleyRAT botnet C2 server (confidence level: 50%)
file43.155.75.248
ValleyRAT botnet C2 server (confidence level: 50%)
file43.198.140.40
ValleyRAT botnet C2 server (confidence level: 50%)
file43.198.5.54
ValleyRAT botnet C2 server (confidence level: 50%)
file43.199.122.69
ValleyRAT botnet C2 server (confidence level: 50%)
file43.199.179.9
ValleyRAT botnet C2 server (confidence level: 50%)
file43.199.220.21
ValleyRAT botnet C2 server (confidence level: 50%)
file43.199.234.212
ValleyRAT botnet C2 server (confidence level: 50%)
file54.46.19.123
ValleyRAT botnet C2 server (confidence level: 50%)
file54.46.23.169
ValleyRAT botnet C2 server (confidence level: 50%)
file54.46.33.136
ValleyRAT botnet C2 server (confidence level: 50%)
file54.46.39.110
ValleyRAT botnet C2 server (confidence level: 50%)
file54.46.9.213
ValleyRAT botnet C2 server (confidence level: 50%)
file91.103.253.163
ValleyRAT botnet C2 server (confidence level: 50%)
file99.97.147.200
Unknown malware botnet C2 server (confidence level: 100%)
file171.244.28.167
Unknown malware botnet C2 server (confidence level: 100%)
file187.237.154.137
Unknown malware botnet C2 server (confidence level: 100%)
file143.92.32.25
ValleyRAT botnet C2 server (confidence level: 100%)
file111.124.203.18
Cobalt Strike botnet C2 server (confidence level: 75%)
file54.36.237.92
Unknown RAT payload delivery server (confidence level: 100%)
file154.211.104.6
ValleyRAT botnet C2 server (confidence level: 100%)
file89.110.115.141
SectopRAT botnet C2 server (confidence level: 100%)
file158.160.75.185
Quasar RAT botnet C2 server (confidence level: 99%)
file104.225.129.185
SmartApeSG payload delivery server (confidence level: 75%)
file193.161.193.99
RatonRAT botnet C2 server (confidence level: 100%)
file74.0.48.39
Vidar botnet C2 server (confidence level: 100%)
file31.57.38.176
Remcos botnet C2 server (confidence level: 100%)
file178.16.55.23
Quasar RAT botnet C2 server (confidence level: 100%)
file178.16.55.23
Quasar RAT botnet C2 server (confidence level: 100%)
file38.87.116.37
XWorm botnet C2 server (confidence level: 100%)
file45.153.34.27
XWorm botnet C2 server (confidence level: 100%)
file2.27.59.8
Quasar RAT botnet C2 server (confidence level: 100%)
file38.45.125.58
ValleyRAT botnet C2 server (confidence level: 100%)
file152.32.191.249
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.151.81.138
Remcos botnet C2 server (confidence level: 100%)
file144.31.169.191
NjRAT botnet C2 server (confidence level: 100%)
file216.250.253.125
Remcos botnet C2 server (confidence level: 100%)
file88.98.223.82
Quasar RAT botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash139
Xtreme RAT botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash139
Xtreme RAT botnet C2 server (confidence level: 100%)
hash40000
Xtreme RAT botnet C2 server (confidence level: 100%)
hash8080
SectopRAT botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash8443
GobRAT botnet C2 server (confidence level: 100%)
hash8000
WAVESHAPER botnet C2 server (confidence level: 75%)
hash1080
FatalRat botnet C2 server (confidence level: 100%)
hash1996
XWorm botnet C2 server (confidence level: 100%)
hash1912
RedLine Stealer botnet C2 server (confidence level: 100%)
hash428
Tofsee botnet C2 server (confidence level: 75%)
hash428
Tofsee botnet C2 server (confidence level: 75%)
hash80
ValleyRAT botnet C2 server (confidence level: 75%)
hash8000
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash886
ValleyRAT botnet C2 server (confidence level: 75%)
hash886
ValleyRAT botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9100
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7025
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash8880
ValleyRAT botnet C2 server (confidence level: 75%)
hash55662
ValleyRAT botnet C2 server (confidence level: 75%)
hash80
ValleyRAT botnet C2 server (confidence level: 75%)
hash80
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8880
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8443
ValleyRAT botnet C2 server (confidence level: 50%)
hash8670
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash90
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash80
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8880
ValleyRAT botnet C2 server (confidence level: 50%)
hash8670
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8443
ValleyRAT botnet C2 server (confidence level: 50%)
hash3333
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8880
ValleyRAT botnet C2 server (confidence level: 50%)
hash58676
ValleyRAT botnet C2 server (confidence level: 50%)
hash80
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8880
ValleyRAT botnet C2 server (confidence level: 50%)
hash80
ValleyRAT botnet C2 server (confidence level: 50%)
hash8082
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8443
ValleyRAT botnet C2 server (confidence level: 50%)
hash8443
ValleyRAT botnet C2 server (confidence level: 50%)
hash8443
ValleyRAT botnet C2 server (confidence level: 50%)
hash8443
ValleyRAT botnet C2 server (confidence level: 50%)
hash8670
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8443
ValleyRAT botnet C2 server (confidence level: 50%)
hash8670
ValleyRAT botnet C2 server (confidence level: 50%)
hash8080
ValleyRAT botnet C2 server (confidence level: 50%)
hash8443
ValleyRAT botnet C2 server (confidence level: 50%)
hash8443
ValleyRAT botnet C2 server (confidence level: 50%)
hash9000
ValleyRAT botnet C2 server (confidence level: 50%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8443
Unknown RAT payload delivery server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash40435
Quasar RAT botnet C2 server (confidence level: 99%)
hash443
SmartApeSG payload delivery server (confidence level: 75%)
hash64692
RatonRAT botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash2029
Remcos botnet C2 server (confidence level: 100%)
hash1602
Quasar RAT botnet C2 server (confidence level: 100%)
hash1605
Quasar RAT botnet C2 server (confidence level: 100%)
hash2137
XWorm botnet C2 server (confidence level: 100%)
hash443
XWorm botnet C2 server (confidence level: 100%)
hash6000
Quasar RAT botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash23803
Cobalt Strike botnet C2 server (confidence level: 100%)
hash24053
Remcos botnet C2 server (confidence level: 100%)
hash666
NjRAT botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash50051
Quasar RAT botnet C2 server (confidence level: 100%)

Threat ID: 69d6ed521cc7ad14dac65b97

Added to database: 4/9/2026, 12:05:38 AM

Last enriched: 4/9/2026, 12:05:49 AM

Last updated: 4/9/2026, 5:47:52 AM

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses