Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-05-12

0
Medium
Published: Tue May 12 2026 (05/12/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-05-12

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/13/2026, 00:21:19 UTC

Technical Analysis

The report details malware-related Indicators of Compromise (IOCs) collected on 2026-05-12 by ThreatFox, an OSINT source. It highlights network activity and payload delivery associated with this malware but does not specify affected software versions or known active exploits. The threat level is moderate, reflecting observed distribution but limited analysis and exploitation data.

Potential Impact

The impact is primarily informational, providing threat intelligence on malware activity and associated network indicators. There is no direct evidence of active exploitation or specific vulnerable products. This intelligence can aid detection and response but does not describe a vulnerability or exploit with direct impact on systems.

Mitigation Recommendations

No patches or direct remediation actions are applicable as this is an OSINT report of IOCs rather than a vulnerability. Security teams should integrate these IOCs into detection tools and monitoring systems as appropriate. Patch status is not applicable. No vendor advisory or official fix exists for this intelligence data.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
fc9cb20c-d3f1-4292-bb77-c5844aea3d6e
Original Timestamp
1778630588

Indicators of Compromise

File

ValueDescriptionCopy
file172.233.43.225
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.43.151
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.43.176
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.43.136
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.43.94
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.43.144
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.43.254
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.43.193
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.43.198
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.43.234
Kimwolf botnet C2 server (confidence level: 100%)
file204.168.207.15
Unknown malware botnet C2 server (confidence level: 50%)
file172.235.189.92
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.160
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.85
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.128
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.38.5
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.19
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.167
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.38.211
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.171
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.38.38
Kimwolf botnet C2 server (confidence level: 100%)
file167.99.42.187
Kimwolf botnet C2 server (confidence level: 100%)
file146.190.21.60
Kimwolf botnet C2 server (confidence level: 100%)
file161.35.156.86
Kimwolf botnet C2 server (confidence level: 100%)
file159.223.236.216
Kimwolf botnet C2 server (confidence level: 100%)
file167.71.4.59
Kimwolf botnet C2 server (confidence level: 100%)
file188.166.91.46
Kimwolf botnet C2 server (confidence level: 100%)
file164.90.194.88
Kimwolf botnet C2 server (confidence level: 100%)
file167.172.33.114
Kimwolf botnet C2 server (confidence level: 100%)
file188.166.95.66
Kimwolf botnet C2 server (confidence level: 100%)
file134.122.49.151
Kimwolf botnet C2 server (confidence level: 100%)
file52.15.149.177
Cobalt Strike botnet C2 server (confidence level: 50%)
file91.197.97.122
Cobalt Strike botnet C2 server (confidence level: 50%)
file43.132.129.236
Cobalt Strike botnet C2 server (confidence level: 50%)
file18.221.198.1
Meterpreter botnet C2 server (confidence level: 50%)
file35.152.145.168
Meterpreter botnet C2 server (confidence level: 50%)
file3.110.138.170
Meterpreter botnet C2 server (confidence level: 50%)
file209.99.191.194
Unknown malware botnet C2 server (confidence level: 75%)
file193.233.113.45
Unknown malware botnet C2 server (confidence level: 75%)
file206.189.9.152
Kimwolf botnet C2 server (confidence level: 100%)
file209.38.46.60
Kimwolf botnet C2 server (confidence level: 100%)
file104.248.95.144
Kimwolf botnet C2 server (confidence level: 100%)
file209.38.35.250
Kimwolf botnet C2 server (confidence level: 100%)
file68.183.8.89
Kimwolf botnet C2 server (confidence level: 100%)
file64.225.70.117
Kimwolf botnet C2 server (confidence level: 100%)
file165.232.92.190
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.108
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.146
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.209
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.157
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.253
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.7
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.42
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.189.14
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.175.45
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.175.205
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.175.147
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.175.202
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.175.188
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.175.185
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.175.117
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.175.197
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.168.34
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.168.206
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.168.86
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.168.9
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.168.119
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.190.108
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.57.11
Kimwolf botnet C2 server (confidence level: 100%)
file103.48.133.153
Cobalt Strike botnet C2 server (confidence level: 50%)
file23.235.186.175
Cobalt Strike botnet C2 server (confidence level: 50%)
file103.48.133.143
Cobalt Strike botnet C2 server (confidence level: 50%)
file103.48.133.145
Cobalt Strike botnet C2 server (confidence level: 50%)
file42.193.244.172
Cobalt Strike botnet C2 server (confidence level: 50%)
file156.234.65.182
Cobalt Strike botnet C2 server (confidence level: 50%)
file156.234.20.19
Cobalt Strike botnet C2 server (confidence level: 50%)
file103.48.133.143
Cobalt Strike botnet C2 server (confidence level: 50%)
file103.48.133.145
Cobalt Strike botnet C2 server (confidence level: 50%)
file177.22.88.133
Sliver botnet C2 server (confidence level: 50%)
file177.22.88.133
Sliver botnet C2 server (confidence level: 50%)
file177.22.88.133
Sliver botnet C2 server (confidence level: 50%)
file177.22.88.133
Sliver botnet C2 server (confidence level: 50%)
file177.22.88.133
Sliver botnet C2 server (confidence level: 50%)
file177.22.88.133
Sliver botnet C2 server (confidence level: 50%)
file177.22.88.133
Sliver botnet C2 server (confidence level: 50%)
file54.254.223.245
Sliver botnet C2 server (confidence level: 50%)
file143.198.142.73
Sliver botnet C2 server (confidence level: 50%)
file139.59.75.111
Sliver botnet C2 server (confidence level: 50%)
file159.89.25.242
Sliver botnet C2 server (confidence level: 50%)
file134.122.31.17
Sliver botnet C2 server (confidence level: 50%)
file20.244.14.203
Sliver botnet C2 server (confidence level: 50%)
file63.178.31.141
Sliver botnet C2 server (confidence level: 50%)
file18.135.60.110
Sliver botnet C2 server (confidence level: 50%)
file143.198.106.101
Sliver botnet C2 server (confidence level: 50%)
file64.23.222.19
Sliver botnet C2 server (confidence level: 50%)
file54.187.229.58
Sliver botnet C2 server (confidence level: 50%)
file103.75.118.29
Meterpreter botnet C2 server (confidence level: 50%)
file85.217.248.191
Quasar RAT botnet C2 server (confidence level: 50%)
file52.254.91.238
Sliver botnet C2 server (confidence level: 50%)
file217.11.63.202
Sliver botnet C2 server (confidence level: 50%)
file98.89.112.9
Sliver botnet C2 server (confidence level: 50%)
file52.45.107.143
Sliver botnet C2 server (confidence level: 50%)
file197.144.116.119
AsyncRAT botnet C2 server (confidence level: 50%)
file188.166.69.11
Sliver botnet C2 server (confidence level: 50%)
file85.198.70.219
Sliver botnet C2 server (confidence level: 50%)
file3.139.13.90
Sliver botnet C2 server (confidence level: 50%)
file63.141.255.205
Sliver botnet C2 server (confidence level: 50%)
file190.255.90.152
AsyncRAT botnet C2 server (confidence level: 50%)
file161.35.137.162
Sliver botnet C2 server (confidence level: 50%)
file54.65.46.61
Brute Ratel C4 botnet C2 server (confidence level: 50%)
file199.101.111.64
Meterpreter botnet C2 server (confidence level: 50%)
file59.19.73.104
Quasar RAT botnet C2 server (confidence level: 50%)
file150.107.31.116
Sliver botnet C2 server (confidence level: 50%)
file45.113.226.187
Sliver botnet C2 server (confidence level: 50%)
file109.123.253.45
AsyncRAT botnet C2 server (confidence level: 50%)
file144.76.33.44
Sliver botnet C2 server (confidence level: 50%)
file202.95.8.97
Quasar RAT botnet C2 server (confidence level: 50%)
file165.227.46.205
Sliver botnet C2 server (confidence level: 50%)
file174.138.32.236
AsyncRAT botnet C2 server (confidence level: 50%)
file63.182.244.34
Sliver botnet C2 server (confidence level: 50%)
file77.110.119.103
Quasar RAT botnet C2 server (confidence level: 50%)
file52.211.131.104
Sliver botnet C2 server (confidence level: 50%)
file34.79.100.34
Sliver botnet C2 server (confidence level: 50%)
file54.237.98.166
Sliver botnet C2 server (confidence level: 50%)
file34.76.168.156
Sliver botnet C2 server (confidence level: 50%)
file79.72.77.73
Sliver botnet C2 server (confidence level: 50%)
file202.155.8.170
Sliver botnet C2 server (confidence level: 50%)
file44.247.75.6
Sliver botnet C2 server (confidence level: 50%)
file108.131.78.238
Sliver botnet C2 server (confidence level: 50%)
file3.65.255.43
Sliver botnet C2 server (confidence level: 50%)
file3.79.216.26
Sliver botnet C2 server (confidence level: 50%)
file54.195.183.174
Sliver botnet C2 server (confidence level: 50%)
file13.59.22.162
Sliver botnet C2 server (confidence level: 50%)
file18.158.198.90
Sliver botnet C2 server (confidence level: 50%)
file185.193.126.141
Sliver botnet C2 server (confidence level: 50%)
file185.234.69.58
Sliver botnet C2 server (confidence level: 50%)
file3.135.82.100
Sliver botnet C2 server (confidence level: 50%)
file3.105.89.29
Sliver botnet C2 server (confidence level: 50%)
file212.34.142.145
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file167.99.220.224
Kimwolf botnet C2 server (confidence level: 100%)
file134.209.200.130
Kimwolf botnet C2 server (confidence level: 100%)
file146.190.21.63
Kimwolf botnet C2 server (confidence level: 100%)
file64.225.68.89
Kimwolf botnet C2 server (confidence level: 100%)
file164.92.219.1
Kimwolf botnet C2 server (confidence level: 100%)
file188.166.17.50
Kimwolf botnet C2 server (confidence level: 100%)
file159.223.215.79
Kimwolf botnet C2 server (confidence level: 100%)
file164.90.203.145
Kimwolf botnet C2 server (confidence level: 100%)
file103.143.207.71
AsyncRAT botnet C2 server (confidence level: 75%)
file104.243.248.63
AsyncRAT botnet C2 server (confidence level: 75%)
file146.185.233.71
Remcos botnet C2 server (confidence level: 75%)
file155.103.71.115
Remcos botnet C2 server (confidence level: 75%)
file2.26.96.209
Havoc botnet C2 server (confidence level: 75%)
file207.148.2.115
Sliver botnet C2 server (confidence level: 75%)
file207.148.2.115
Sliver botnet C2 server (confidence level: 75%)
file31.57.184.48
AsyncRAT botnet C2 server (confidence level: 75%)
file31.57.201.105
Havoc botnet C2 server (confidence level: 75%)
file45.142.107.41
Sliver botnet C2 server (confidence level: 75%)
file45.142.107.41
Sliver botnet C2 server (confidence level: 75%)
file62.171.190.148
Havoc botnet C2 server (confidence level: 75%)
file62.84.114.70
AdaptixC2 botnet C2 server (confidence level: 75%)
file67.180.188.88
Remcos botnet C2 server (confidence level: 75%)
file85.158.57.247
AdaptixC2 botnet C2 server (confidence level: 75%)
file91.215.85.121
DCRat botnet C2 server (confidence level: 75%)
file91.92.243.38
DCRat botnet C2 server (confidence level: 75%)
file101.132.156.12
Cobalt Strike botnet C2 server (confidence level: 75%)
file101.35.102.87
Cobalt Strike botnet C2 server (confidence level: 75%)
file117.72.168.103
Cobalt Strike botnet C2 server (confidence level: 75%)
file118.31.62.238
Cobalt Strike botnet C2 server (confidence level: 75%)
file103.45.65.107
ValleyRAT botnet C2 server (confidence level: 100%)
file103.45.65.107
ValleyRAT botnet C2 server (confidence level: 75%)
file77.110.127.178
Unknown malware botnet C2 server (confidence level: 50%)
file172.233.51.64
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.61.72
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.41.120
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.166.9
Kimwolf botnet C2 server (confidence level: 100%)
file172.235.174.113
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.47.162
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.39.7
Kimwolf botnet C2 server (confidence level: 100%)
file172.233.57.164
Kimwolf botnet C2 server (confidence level: 100%)
file134.122.163.220
ValleyRAT botnet C2 server (confidence level: 100%)
file134.122.163.220
ValleyRAT botnet C2 server (confidence level: 100%)
file5.78.196.67
SmartApeSG payload delivery server (confidence level: 75%)
file5.78.222.200
SmartApeSG payload delivery server (confidence level: 75%)
file115.42.60.72
Cobalt Strike botnet C2 server (confidence level: 100%)
file121.41.78.82
Cobalt Strike botnet C2 server (confidence level: 100%)
file198.44.179.38
Cobalt Strike botnet C2 server (confidence level: 100%)
file175.178.36.137
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.108.62.225
Cobalt Strike botnet C2 server (confidence level: 100%)
file139.155.112.211
Cobalt Strike botnet C2 server (confidence level: 100%)
file101.245.103.200
Cobalt Strike botnet C2 server (confidence level: 100%)
file194.87.198.120
Cobalt Strike botnet C2 server (confidence level: 100%)
file122.51.144.88
Cobalt Strike botnet C2 server (confidence level: 100%)
file95.85.246.53
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file89.213.118.219
AsyncRAT botnet C2 server (confidence level: 100%)
file2.27.17.179
Remcos botnet C2 server (confidence level: 75%)
file37.72.172.58
AsyncRAT botnet C2 server (confidence level: 75%)
file94.198.51.234
Havoc botnet C2 server (confidence level: 75%)
file34.75.35.194
AsyncRAT botnet C2 server (confidence level: 100%)
file103.83.87.8
Remcos botnet C2 server (confidence level: 75%)
file20.93.112.67
Loda botnet C2 server (confidence level: 100%)
file45.197.237.53
ValleyRAT botnet C2 server (confidence level: 100%)
file27.124.44.80
ValleyRAT botnet C2 server (confidence level: 100%)
file161.248.87.10
Cobalt Strike botnet C2 server (confidence level: 75%)
file168.222.97.93
Cobalt Strike botnet C2 server (confidence level: 75%)
file168.222.97.93
Cobalt Strike botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 50%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash3941d2e13d9ed19d7f867bd266338e9ec0c8eb986ff656743c83c6d1a03555cc
AsyncRAT payload (confidence level: 90%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash4848
Cobalt Strike botnet C2 server (confidence level: 50%)
hash6007
Cobalt Strike botnet C2 server (confidence level: 50%)
hash1961
Meterpreter botnet C2 server (confidence level: 50%)
hash48063
Meterpreter botnet C2 server (confidence level: 50%)
hash1911
Meterpreter botnet C2 server (confidence level: 50%)
hash443
Unknown malware botnet C2 server (confidence level: 75%)
hash443
Unknown malware botnet C2 server (confidence level: 75%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash971f76da2e6af3dd892550411d2bb53208f21f114f8835c0582f8bd1f4becbcc
KongTuke payload (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash9003
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash2083
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8902
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8902
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8902
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8902
Cobalt Strike botnet C2 server (confidence level: 50%)
hash1105
Sliver botnet C2 server (confidence level: 50%)
hash1111
Sliver botnet C2 server (confidence level: 50%)
hash1201
Sliver botnet C2 server (confidence level: 50%)
hash1601
Sliver botnet C2 server (confidence level: 50%)
hash1701
Sliver botnet C2 server (confidence level: 50%)
hash1801
Sliver botnet C2 server (confidence level: 50%)
hash1901
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash21
Sliver botnet C2 server (confidence level: 50%)
hash10000
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash9273
Sliver botnet C2 server (confidence level: 50%)
hash3000
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash3790
Meterpreter botnet C2 server (confidence level: 50%)
hash443
Quasar RAT botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash9130
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash8443
Sliver botnet C2 server (confidence level: 50%)
hash5000
AsyncRAT botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash6000
AsyncRAT botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash80
Brute Ratel C4 botnet C2 server (confidence level: 50%)
hash3790
Meterpreter botnet C2 server (confidence level: 50%)
hash2288
Quasar RAT botnet C2 server (confidence level: 50%)
hash8888
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash8808
AsyncRAT botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Quasar RAT botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash8808
AsyncRAT botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash8080
Quasar RAT botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash3307
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash3307
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash35333
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
Sliver botnet C2 server (confidence level: 50%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash443
AsyncRAT botnet C2 server (confidence level: 75%)
hash1803
AsyncRAT botnet C2 server (confidence level: 75%)
hash41254
Remcos botnet C2 server (confidence level: 75%)
hash14549
Remcos botnet C2 server (confidence level: 75%)
hash8080
Havoc botnet C2 server (confidence level: 75%)
hash60060
Sliver botnet C2 server (confidence level: 75%)
hash60061
Sliver botnet C2 server (confidence level: 75%)
hash7456
AsyncRAT botnet C2 server (confidence level: 75%)
hash443
Havoc botnet C2 server (confidence level: 75%)
hash1030
Sliver botnet C2 server (confidence level: 75%)
hash31337
Sliver botnet C2 server (confidence level: 75%)
hash443
Havoc botnet C2 server (confidence level: 75%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 75%)
hash443
Remcos botnet C2 server (confidence level: 75%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 75%)
hash6466
DCRat botnet C2 server (confidence level: 75%)
hash35630
DCRat botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash18443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash50011
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash10101
ValleyRAT botnet C2 server (confidence level: 100%)
hash10102
ValleyRAT botnet C2 server (confidence level: 75%)
hash6969
Unknown malware botnet C2 server (confidence level: 50%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash7881
ValleyRAT botnet C2 server (confidence level: 100%)
hash7880
ValleyRAT botnet C2 server (confidence level: 100%)
hash443
SmartApeSG payload delivery server (confidence level: 75%)
hash443
SmartApeSG payload delivery server (confidence level: 75%)
hash045479ee61a4b0035941606b5efb1d9fdd7dc8c82b8982bd6ea2228a1f2fbf27
SmartApeSG payload (confidence level: 75%)
hash4bc79922cb13d5ea727818222b14f28c69ae6fd161212ed4e136ff7456c4d652
SmartApeSG payload (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash3000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8081
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash801
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash2000
AsyncRAT botnet C2 server (confidence level: 100%)
hash6644
Remcos botnet C2 server (confidence level: 75%)
hash7077
AsyncRAT botnet C2 server (confidence level: 75%)
hash443
Havoc botnet C2 server (confidence level: 75%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash1515
Remcos botnet C2 server (confidence level: 75%)
hash4782
Loda botnet C2 server (confidence level: 100%)
hash9000
ValleyRAT botnet C2 server (confidence level: 100%)
hash443
ValleyRAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)

Url

ValueDescriptionCopy
urlhttps://www.proplayuk.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://zofianatra.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.yogaonthewallkill.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.shivshankarexp.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.scalp-coiffure.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://kidspepe.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://jm-reformas.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://htfautoparts.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://jobloom.info/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://tramproject.com/private-page-do-not-access/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://winesportbet.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.mkscoffee.co.uk/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.njfamilyphotography.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://miariym.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://mamaspusties.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.lombardoautomotive.it/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://ktgafurov.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://kawamawidows.org/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.jessicaassociates.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://infodehrifcam.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.hudaaldosari.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.ianvance.co.uk/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.centralathleticfoundation.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.drisdellehomes.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.diversidadecatolica.com.br/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://compraway.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.berylsegerschronicles.com.au/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://b2b.castorsunglasses.es/opciones/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://columbusisles.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://speedpc.info/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://stgeo.org/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://realxlbd.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.gustavogorriaran.com.uy/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://hyper-evm.pages.dev/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://192.253.234.96:4040/login
Unknown Stealer botnet C2 (confidence level: 50%)
urlhttp://45.141.119.91/b74ec2afc8f3449ba8f9.php
Stealc botnet C2 (confidence level: 100%)
urlhttps://greyandbold.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://parkspringshotel.com/m/lu6aeloo.php
Unknown malware botnet C2 (confidence level: 49%)
urlhttps://auraguest.lk/m/douv2quu.php
Unknown malware botnet C2 (confidence level: 49%)
urlhttp://31.130.132.86:80
Unknown malware botnet C2 (confidence level: 49%)
urlhttp://85.11.161.32:80
Unknown malware botnet C2 (confidence level: 49%)
urlhttps://bradtte.lol/file.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://bradtte.lol/t
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://bradtte.lol/g
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://bradtte.lol/c
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://mlzabnwk6xx.com/d
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://milksos.cfd/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://pleasurewarlock.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://mlzabnwk6xx.com/d
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://dba.chriskendall.media/
Vidar botnet C2 (confidence level: 100%)
urlhttps://wnm.chriskendall.media/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ehj.chriskendall.media/
Vidar botnet C2 (confidence level: 100%)
urlhttps://mpd.chriskendall.media/
Vidar botnet C2 (confidence level: 100%)
urlhttps://j2rconsulting.fr/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://ewtbv.be/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://filev2.getsession.org/file/
Unknown malware botnet C2 (confidence level: 49%)
urlhttps://git-tanstack.com/transformers.pyz
Unknown malware botnet C2 (confidence level: 49%)
urlhttps://filev2.getsession.org/file/
Shai-Hulud botnet C2 (confidence level: 49%)
urlhttps://ponikas.cyou/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://ndg.chriskendall.media/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ndg.loniluekegerman.com/
Vidar botnet C2 (confidence level: 100%)
urlhttp://ch375962.tw1.ru/l1nc0in.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://wwnbslklfdsrf.cn:8880/getinstall64
ValleyRAT botnet C2 (confidence level: 100%)
urlhttp://cdntestconnect.com
Stealc botnet C2 (confidence level: 75%)
urlhttp://www.apartuk.info/hpum/index.php?account=w4naf290
XLoader botnet C2 (confidence level: 100%)
urlhttp://www.axilo.top/00ab/index.php?account=scb0vgw
XLoader botnet C2 (confidence level: 100%)
urlhttp://cdntestconnect.com/ed54b97a570943999715.php
Stealc botnet C2 (confidence level: 100%)
urlhttps://precisionorbitlabs.com/python
SmartApeSG payload delivery URL (confidence level: 75%)
urlhttp://5.78.196.67/
SmartApeSG payload delivery URL (confidence level: 75%)
urlhttp://5.78.222.200/
SmartApeSG payload delivery URL (confidence level: 75%)
urlhttp://duclongetc.com/vvvv/need/work/panel/five/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttps://duclongetc.com/vvvv/need/work/panel/five/fre.php?
Loki Password Stealer (PWS) botnet C2 (confidence level: 75%)
urlhttps://prt.chriskendall.media/
Vidar botnet C2 (confidence level: 100%)
urlhttps://prt.loniluekegerman.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://bos.chriskendall.media/
Vidar botnet C2 (confidence level: 100%)
urlhttps://bos.loniluekegerman.com/
Vidar botnet C2 (confidence level: 100%)
urlhttp://cx802615.tw1.ru/l1nc0in.php
DCRat botnet C2 (confidence level: 100%)

Domain

ValueDescriptionCopy
domainleafypage.com
Vidar payload delivery domain (confidence level: 100%)
domainlekeitioikt.eus
Vidar payload delivery domain (confidence level: 100%)
domainlengochuan.com
Vidar payload delivery domain (confidence level: 100%)
domainlindabrasil.store
Vidar payload delivery domain (confidence level: 100%)
domainlinqr.info
Vidar payload delivery domain (confidence level: 100%)
domainlionsclubs-ghana.org
Vidar payload delivery domain (confidence level: 100%)
domainlisanslandiniz.com
Vidar payload delivery domain (confidence level: 100%)
domainlittleshutterhomes.com
Vidar payload delivery domain (confidence level: 100%)
domainlivewelltoday.site
Vidar payload delivery domain (confidence level: 100%)
domainlmrentacar.com
Vidar payload delivery domain (confidence level: 100%)
domainlnded.net
Vidar payload delivery domain (confidence level: 100%)
domainlumyq.com
Vidar payload delivery domain (confidence level: 100%)
domainluxehavenretrat.com
Vidar payload delivery domain (confidence level: 100%)
domainmaddog-supply.com
Vidar payload delivery domain (confidence level: 100%)
domainmaidog.fr
Vidar payload delivery domain (confidence level: 100%)
domainmajestichomecare.nl
Vidar payload delivery domain (confidence level: 100%)
domainmanuelaguerra.com
Vidar payload delivery domain (confidence level: 100%)
domainmarmodelkaiser.com
Vidar payload delivery domain (confidence level: 100%)
domainmasakaschools.sc.tz
Vidar payload delivery domain (confidence level: 100%)
domainmassagebienetre-badia.fr
Vidar payload delivery domain (confidence level: 100%)
domainmatthewsbuildingadvisors.co.uk
Vidar payload delivery domain (confidence level: 100%)
domainmdthomasconstructions.com
Vidar payload delivery domain (confidence level: 100%)
domainmeccabot.id
Vidar payload delivery domain (confidence level: 100%)
domainmechanicalseals.co.za
Vidar payload delivery domain (confidence level: 100%)
domainmedinova.ng
Vidar payload delivery domain (confidence level: 100%)
domainmedoratechlabs.com
Vidar payload delivery domain (confidence level: 100%)
domainmedraa.com
Vidar payload delivery domain (confidence level: 100%)
domainmesonandaluz.es
Vidar payload delivery domain (confidence level: 100%)
domainmgo.vn
Vidar payload delivery domain (confidence level: 100%)
domainmichellebarton.love
Vidar payload delivery domain (confidence level: 100%)
domainmiohome.com.tw
Vidar payload delivery domain (confidence level: 100%)
domainmiraducksolutions.com
Vidar payload delivery domain (confidence level: 100%)
domainmissflocage.fr
Vidar payload delivery domain (confidence level: 100%)
domainmlbodesign.com
Vidar payload delivery domain (confidence level: 100%)
domainmnasalonsuites.com
Vidar payload delivery domain (confidence level: 100%)
domainmosw.gov.sl
Vidar payload delivery domain (confidence level: 100%)
domainmotomorini.mg
Vidar payload delivery domain (confidence level: 100%)
domainmsg3d.com.br
Vidar payload delivery domain (confidence level: 100%)
domainmuqtasid.com
Vidar payload delivery domain (confidence level: 100%)
domainmwcmetals.com
Vidar payload delivery domain (confidence level: 100%)
domainmyachtconsulting.com
Vidar payload delivery domain (confidence level: 100%)
domainmyhouseinspain.com
Vidar payload delivery domain (confidence level: 100%)
domainmykonos-explorer.com
Vidar payload delivery domain (confidence level: 100%)
domainmymedicarebasics.com
Vidar payload delivery domain (confidence level: 100%)
domainmysaraoutfit.com
Vidar payload delivery domain (confidence level: 100%)
domainnateberger.com
Vidar payload delivery domain (confidence level: 100%)
domainnelsonmrodriguez.com
Vidar payload delivery domain (confidence level: 100%)
domainnetcooilfield.com
Vidar payload delivery domain (confidence level: 100%)
domainnetworthadjusters.com
Vidar payload delivery domain (confidence level: 100%)
domainneuronoetics.org
Vidar payload delivery domain (confidence level: 100%)
domainnewhomerebatesdfw.com
Vidar payload delivery domain (confidence level: 100%)
domainnewspaperhelp.com
Vidar payload delivery domain (confidence level: 100%)
domainnextcell.com.my
Vidar payload delivery domain (confidence level: 100%)
domainnhatnamco.com
Vidar payload delivery domain (confidence level: 100%)
domainnidhidigital.com
Vidar payload delivery domain (confidence level: 100%)
domainnigerianconsulatesa.org
Vidar payload delivery domain (confidence level: 100%)
domainnoblegeneralconstruction.com
Vidar payload delivery domain (confidence level: 100%)
domainnomoretype2.site
Vidar payload delivery domain (confidence level: 100%)
domainnovacasasv.com
Vidar payload delivery domain (confidence level: 100%)
domainnovaluxoptica.com
Vidar payload delivery domain (confidence level: 100%)
domainnsantosmaintenanceltd.co.uk
Vidar payload delivery domain (confidence level: 100%)
domainntdepannage.fr
Vidar payload delivery domain (confidence level: 100%)
domainoffersnbrands.site
Vidar payload delivery domain (confidence level: 100%)
domainofficialguidebarcelona.com
Vidar payload delivery domain (confidence level: 100%)
domainomicsynergy.net
Vidar payload delivery domain (confidence level: 100%)
domainonlinebutor.com
Vidar payload delivery domain (confidence level: 100%)
domainonoffsound.com
Vidar payload delivery domain (confidence level: 100%)
domainonyon.org
Vidar payload delivery domain (confidence level: 100%)
domainosnfabtech.com
Vidar payload delivery domain (confidence level: 100%)
domainoxar.dz
Vidar payload delivery domain (confidence level: 100%)
domainozchph-sabinov.sk
Vidar payload delivery domain (confidence level: 100%)
domainp33.info
Vidar payload delivery domain (confidence level: 100%)
domainpachagadgets.com
Vidar payload delivery domain (confidence level: 100%)
domainpanaceafarmakeio.com
Vidar payload delivery domain (confidence level: 100%)
domainpantipendowokudus.com
Vidar payload delivery domain (confidence level: 100%)
domainparenthesegourmande.fr
Vidar payload delivery domain (confidence level: 100%)
domainparolaajans.com
Vidar payload delivery domain (confidence level: 100%)
domainpasbannews.net
Vidar payload delivery domain (confidence level: 100%)
domainpcccthanhhuy.com
Vidar payload delivery domain (confidence level: 100%)
domainpeoplesphone.co.uk
Vidar payload delivery domain (confidence level: 100%)
domainpeptidguide.com
Vidar payload delivery domain (confidence level: 100%)
domainpermacyclists.com
Vidar payload delivery domain (confidence level: 100%)
domainpicorad.com
Vidar payload delivery domain (confidence level: 100%)
domainpicsofficial.com
Vidar payload delivery domain (confidence level: 100%)
domainpietepublice.ro
Vidar payload delivery domain (confidence level: 100%)
domainpillar-ms.com
Vidar payload delivery domain (confidence level: 100%)
domainpilotandcar.ae
Vidar payload delivery domain (confidence level: 100%)
domainpishealth.com
Vidar payload delivery domain (confidence level: 100%)
domainpixelgraphy.in
Vidar payload delivery domain (confidence level: 100%)
domainplansbid.com
Vidar payload delivery domain (confidence level: 100%)
domainplatinumedical.com
Vidar payload delivery domain (confidence level: 100%)
domainplusgeek.net
Vidar payload delivery domain (confidence level: 100%)
domainpods.emkay.id
Vidar payload delivery domain (confidence level: 100%)
domainpoledreamstudio.com
Vidar payload delivery domain (confidence level: 100%)
domainpollyplayford.com
Vidar payload delivery domain (confidence level: 100%)
domainpremasa.com
Vidar payload delivery domain (confidence level: 100%)
domainprimecareheart.co.ke
Vidar payload delivery domain (confidence level: 100%)
domainprimeenvironmentalgroup.com
Vidar payload delivery domain (confidence level: 100%)
domainprintingshell.co.uk
Vidar payload delivery domain (confidence level: 100%)
domainproperio.co.il
Vidar payload delivery domain (confidence level: 100%)
domainproteinplus.com.br
Vidar payload delivery domain (confidence level: 100%)
domainpsychotherapie-praxis-tenner-paustian.de
Vidar payload delivery domain (confidence level: 100%)
domainpulp-design.com
Vidar payload delivery domain (confidence level: 100%)
domainradioamistadaucayacu.com
Vidar payload delivery domain (confidence level: 100%)
domainradiodeputter.nl
Vidar payload delivery domain (confidence level: 100%)
domainrashedi.studio
Vidar payload delivery domain (confidence level: 100%)
domainrealtechengineeringltd.com
Vidar payload delivery domain (confidence level: 100%)
domainrealxlbd.com
Vidar payload delivery domain (confidence level: 100%)
domainreferences.c3pluriel.fr
Vidar payload delivery domain (confidence level: 100%)
domainretiredmafia.com
Vidar payload delivery domain (confidence level: 100%)
domainriah.dev
Vidar payload delivery domain (confidence level: 100%)
domainrnceducation.com
Vidar payload delivery domain (confidence level: 100%)
domainrobertkandell.com
Vidar payload delivery domain (confidence level: 100%)
domainrosecutdiamonds.ca
Vidar payload delivery domain (confidence level: 100%)
domainrutherfordinvestments.com
Vidar payload delivery domain (confidence level: 100%)
domainsafarwithsasha.com
Vidar payload delivery domain (confidence level: 100%)
domainsafeschoolsandhealthylearning.com
Vidar payload delivery domain (confidence level: 100%)
domainsangromeccanica.it
Vidar payload delivery domain (confidence level: 100%)
domainsantamarialanghe.com
Vidar payload delivery domain (confidence level: 100%)
domainsanycur.com.ar
Vidar payload delivery domain (confidence level: 100%)
domainschool60.kiev.ua
Vidar payload delivery domain (confidence level: 100%)
domainsciencenewstoday.online
Vidar payload delivery domain (confidence level: 100%)
domainseniorenbund.oevp-burgenland.at
Vidar payload delivery domain (confidence level: 100%)
domainsethsawariyabizmart.com
Vidar payload delivery domain (confidence level: 100%)
domainsgka.co.uk
Vidar payload delivery domain (confidence level: 100%)
domainshakirhajjservices.com
Vidar payload delivery domain (confidence level: 100%)
domainsharkltd.com
Vidar payload delivery domain (confidence level: 100%)
domainshbnet.id
Vidar payload delivery domain (confidence level: 100%)
domainshinevervecosmetics.com
Vidar payload delivery domain (confidence level: 100%)
domainshirazicafe.com
Vidar payload delivery domain (confidence level: 100%)
domainshivshaktidancecostumes.com
Vidar payload delivery domain (confidence level: 100%)
domainshootingcreekbrewery.com
Vidar payload delivery domain (confidence level: 100%)
domainshowerdoorsrepair.com
Vidar payload delivery domain (confidence level: 100%)
domainsidneymanzo.com
Vidar payload delivery domain (confidence level: 100%)
domainsigma-medicare.com
Vidar payload delivery domain (confidence level: 100%)
domainsimpledaytips.com
Vidar payload delivery domain (confidence level: 100%)
domainsina-global.com
Vidar payload delivery domain (confidence level: 100%)
domainsitepacket.com
Vidar payload delivery domain (confidence level: 100%)
domainskchs.org
Vidar payload delivery domain (confidence level: 100%)
domainskpnijmegen.nl
Vidar payload delivery domain (confidence level: 100%)
domainsleetindustries.com
Vidar payload delivery domain (confidence level: 100%)
domainsmartenviro.ro
Vidar payload delivery domain (confidence level: 100%)
domainsmkbuildingmaroc.com
Vidar payload delivery domain (confidence level: 100%)
domainsnabinegoce.com
Vidar payload delivery domain (confidence level: 100%)
domainsoarebc.com
Vidar payload delivery domain (confidence level: 100%)
domainsolar-parks.ch
Vidar payload delivery domain (confidence level: 100%)
domainsolarpowercentre.com.ng
Vidar payload delivery domain (confidence level: 100%)
domainsonjacapeller.at
Vidar payload delivery domain (confidence level: 100%)
domainsoroptimist.sk
Vidar payload delivery domain (confidence level: 100%)
domainsotothailand.com
Vidar payload delivery domain (confidence level: 100%)
domainsoufaempowermentfoundation.com
Vidar payload delivery domain (confidence level: 100%)
domainsouthernriversdental.com
Vidar payload delivery domain (confidence level: 100%)
domainsparklestepclean.com
Vidar payload delivery domain (confidence level: 100%)
domainspeakup-pharos.grantthornton.gr
Vidar payload delivery domain (confidence level: 100%)
domainspringglobalmedia.com
Vidar payload delivery domain (confidence level: 100%)
domainspymyheart.com
Vidar payload delivery domain (confidence level: 100%)
domainstartmarketing.com.vn
Vidar payload delivery domain (confidence level: 100%)
domainstgeo.org
Vidar payload delivery domain (confidence level: 100%)
domainsthapottobid.com
Vidar payload delivery domain (confidence level: 100%)
domainstradacapital.com
Vidar payload delivery domain (confidence level: 100%)
domainstrongholdone.com
Vidar payload delivery domain (confidence level: 100%)
domainstruk-tur.com
Vidar payload delivery domain (confidence level: 100%)
domainstudiolegaleterrazzano.it
Vidar payload delivery domain (confidence level: 100%)
domainsufiyakashif.com
Vidar payload delivery domain (confidence level: 100%)
domainsuitsgaming.com
Vidar payload delivery domain (confidence level: 100%)
domainsulfomax-dz.com
Vidar payload delivery domain (confidence level: 100%)
domainsuperinventario.com
Vidar payload delivery domain (confidence level: 100%)
domainsuperslot-gmae.net
Vidar payload delivery domain (confidence level: 100%)
domainsupremeriverside.xyz
Vidar payload delivery domain (confidence level: 100%)
domainsv-1890-nordshausen.de
Vidar payload delivery domain (confidence level: 100%)
domainswiped.com
Vidar payload delivery domain (confidence level: 100%)
domainswiss-tradingacademy.com
Vidar payload delivery domain (confidence level: 100%)
domaintabelafipe.site
Vidar payload delivery domain (confidence level: 100%)
domaintakeawaytwenty2.com.au
Vidar payload delivery domain (confidence level: 100%)
domaintbgcleaningsystems.com
Vidar payload delivery domain (confidence level: 100%)
domainteambuildingstrand.nl
Vidar payload delivery domain (confidence level: 100%)
domainteamtacticals.com
Vidar payload delivery domain (confidence level: 100%)
domaintechmillsolutions.com
Vidar payload delivery domain (confidence level: 100%)
domaintechno-sem.com
Vidar payload delivery domain (confidence level: 100%)
domaintechnopliancee.com
Vidar payload delivery domain (confidence level: 100%)
domainteckdg.com
Vidar payload delivery domain (confidence level: 100%)
domaintelemania.hu
Vidar payload delivery domain (confidence level: 100%)
domaintesvoraustralia.au
Vidar payload delivery domain (confidence level: 100%)
domainthaithainoodle.com
Vidar payload delivery domain (confidence level: 100%)
domainthayamkeryroyalinn.in
Vidar payload delivery domain (confidence level: 100%)
domainthegioisocorp.com
Vidar payload delivery domain (confidence level: 100%)
domaintheglobalhub.net
Vidar payload delivery domain (confidence level: 100%)
domainthehumanxpress.com
Vidar payload delivery domain (confidence level: 100%)
domaintmcelitehomes.com
Vidar payload delivery domain (confidence level: 100%)
domaintomcat.vn
Vidar payload delivery domain (confidence level: 100%)
domaintoussaintlouverture.org
Vidar payload delivery domain (confidence level: 100%)
domaintraiteurvincent.be
Vidar payload delivery domain (confidence level: 100%)
domaintranquilhavenresort.com
Vidar payload delivery domain (confidence level: 100%)
domaintransportestmm.com.mx
Vidar payload delivery domain (confidence level: 100%)
domaintridestined.com
Vidar payload delivery domain (confidence level: 100%)
domaintriumphcapitalltd.com
Vidar payload delivery domain (confidence level: 100%)
domaintruckstotal.com
Vidar payload delivery domain (confidence level: 100%)
domaintrulandscape.com
Vidar payload delivery domain (confidence level: 100%)
domaintuganetcloud.com
Vidar payload delivery domain (confidence level: 100%)
domaintuivaikhongdetaz.vn
Vidar payload delivery domain (confidence level: 100%)
domaintuttodrink.it
Vidar payload delivery domain (confidence level: 100%)
domaintvmarinternet.com
Vidar payload delivery domain (confidence level: 100%)
domaintweewees.nl
Vidar payload delivery domain (confidence level: 100%)
domainuilfplnapolicampania.it
Vidar payload delivery domain (confidence level: 100%)
domainuitjesscheveningen.nl
Vidar payload delivery domain (confidence level: 100%)
domainurf-careers.com
Vidar payload delivery domain (confidence level: 100%)
domainursula-strauss.at
Vidar payload delivery domain (confidence level: 100%)
domainusmanelectronics.com
Vidar payload delivery domain (confidence level: 100%)
domainvariedades-monica.com
Vidar payload delivery domain (confidence level: 100%)
domainvdumas.com
Vidar payload delivery domain (confidence level: 100%)
domainvedro.fr
Vidar payload delivery domain (confidence level: 100%)
domainvergaderenstrand.nl
Vidar payload delivery domain (confidence level: 100%)
domainvermoegen-mit-plan.de
Vidar payload delivery domain (confidence level: 100%)
domainvicunaadventuresperu.com
Vidar payload delivery domain (confidence level: 100%)
domainviennoithat.vn
Vidar payload delivery domain (confidence level: 100%)
domainwallybaleja.com
Vidar payload delivery domain (confidence level: 100%)
domainwari.com.pe
Vidar payload delivery domain (confidence level: 100%)
domainweddingcarsofmaleny.com.au
Vidar payload delivery domain (confidence level: 100%)
domainwereldfestival.be
Vidar payload delivery domain (confidence level: 100%)
domainwine-more.com
Vidar payload delivery domain (confidence level: 100%)
domainwinworkorders.com
Vidar payload delivery domain (confidence level: 100%)
domainwistineservices.co.ke
Vidar payload delivery domain (confidence level: 100%)
domainwnwfm.com
Vidar payload delivery domain (confidence level: 100%)
domainwolfcabinetsandgranites.com
Vidar payload delivery domain (confidence level: 100%)
domainwordpresstraininglondon.co.uk
Vidar payload delivery domain (confidence level: 100%)
domainxlmeubels.nl
Vidar payload delivery domain (confidence level: 100%)
domainxn--sanmartindecaaveras-73b.es
Vidar payload delivery domain (confidence level: 100%)
domainyaronamotorspares.com
Vidar payload delivery domain (confidence level: 100%)
domainyousufdigitalcenter.com
Vidar payload delivery domain (confidence level: 100%)
domainzaciszewbobrzy.pl
Vidar payload delivery domain (confidence level: 100%)
domainzadaljnna.org
Vidar payload delivery domain (confidence level: 100%)
domainzerosyntax.in
Vidar payload delivery domain (confidence level: 100%)
domainziaurrahmanbd.com
Vidar payload delivery domain (confidence level: 100%)
domainzoomcreatives.jp
Vidar payload delivery domain (confidence level: 100%)
domainbriskinternet.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainghdfhfjhfg.webhop.me
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainiloveyoulucid.space
Unknown Stealer botnet C2 domain (confidence level: 100%)
domain0kt.one
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainlucidstealer.one
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainstoredonutsmp.net
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaincustomroofingcontractors.com
Unknown malware botnet C2 domain (confidence level: 49%)
domaincloudservbr.com
Unknown malware botnet C2 domain (confidence level: 49%)
domaininfra-telemetry.com
Unknown malware botnet C2 domain (confidence level: 49%)
domainwrned.com
Unknown malware botnet C2 domain (confidence level: 49%)
domainbasandor.top
Unknown malware botnet C2 domain (confidence level: 49%)
domainnasdam.xyz
Unknown malware botnet C2 domain (confidence level: 49%)
domainwehatasm.xyz
Unknown malware botnet C2 domain (confidence level: 49%)
domaindavanatas.top
Unknown malware botnet C2 domain (confidence level: 49%)
domainapi-v2.needlestich.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainbradtte.lol
KongTuke payload delivery domain (confidence level: 100%)
domainmlzabnwk6xx.com
KongTuke payload delivery domain (confidence level: 100%)
domainrecargapopular.com
Unknown malware botnet C2 domain (confidence level: 49%)
domainwelovechinatown.info
Unknown malware botnet C2 domain (confidence level: 49%)
domainupdate-treix.com
Unknown malware botnet C2 domain (confidence level: 49%)
domainn8toji7qc96.com
KongTuke botnet C2 domain (confidence level: 100%)
domaininfra-net-logic-unit.co
ClearFake payload delivery domain (confidence level: 100%)
domaindata-flow-ops-mgr.co
ClearFake payload delivery domain (confidence level: 100%)
domaincpanel.importersexportersltd.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domaindba.chriskendall.media
Vidar botnet C2 domain (confidence level: 100%)
domainsys-core-node-stack.co
ClearFake payload delivery domain (confidence level: 100%)
domainglobal-cloud-infra-logic-manual.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainsystem-stack-node-data-reference.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainsc88885.com
AsyncRAT botnet C2 domain (confidence level: 75%)
domainx88.run
AsyncRAT botnet C2 domain (confidence level: 75%)
domainopen-api-protocol-storage-guide.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainnetwork-security-ops-flow-base.wiki
ClearFake payload delivery domain (confidence level: 100%)
domaindata-core-logic-resource-center.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainweb-logic-stack-dev-notebook.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainwnm.chriskendall.media
Vidar botnet C2 domain (confidence level: 100%)
domainehj.chriskendall.media
Vidar botnet C2 domain (confidence level: 100%)
domainmpd.chriskendall.media
Vidar botnet C2 domain (confidence level: 100%)
domainbcncdncl-ns.beer
Unknown malware payload delivery domain (confidence level: 100%)
domaininfra-point-bits-service-atlas.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainbildad.us.org
Quasar RAT botnet C2 domain (confidence level: 75%)
domainbrandy.it.com
XWorm botnet C2 domain (confidence level: 75%)
domaindigital-node-cloud-ops-manual.wiki
ClearFake payload delivery domain (confidence level: 100%)
domaintiktikmod.ru.com
XWorm botnet C2 domain (confidence level: 75%)
domainponikas.cyou
Unknown malware payload delivery domain (confidence level: 100%)
domainwemovetoanewrelablesourcewhichverymanans.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainyywyvtur.hor1inka-lonely.digital
ClearFake payload delivery domain (confidence level: 100%)
domainbz6o5g3c.hor1inka-lonely.digital
ClearFake payload delivery domain (confidence level: 100%)
domainpvn.xybcaap.my.id
Vidar botnet C2 domain (confidence level: 100%)
domaintech-script-logic-unit-reference.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainadminxoilac1.site
Quasar RAT botnet C2 domain (confidence level: 75%)
domainapi.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainapi17.colatv88xd.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainapiv1.alilicloud.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainbackup.adminxoilac1.site
Quasar RAT botnet C2 domain (confidence level: 75%)
domainbackup.chatboxvs.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainbackup.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainbackup.unpkg.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainbackup.xoilackvb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domaincdn.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domaincdn.haircutmenfrederickmd.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domaincel-robox.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domaind3j9d91vxmbmsx.cloudfront.net
Quasar RAT botnet C2 domain (confidence level: 75%)
domaindata.adminxoilac1.site
Quasar RAT botnet C2 domain (confidence level: 75%)
domaindata.chatboxvs.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domaindata.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domaindata.unpkg.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domaindata.xoilackvb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainddos.adminxoilac1.site
Quasar RAT botnet C2 domain (confidence level: 75%)
domainddos.chatboxvs.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainddos.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainddos.unpkg.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainddos.xoilackvb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domaindonghua.jmsec.app
Quasar RAT botnet C2 domain (confidence level: 75%)
domaingatex.adminxoilac1.site
Quasar RAT botnet C2 domain (confidence level: 75%)
domaingatex.chatboxvs.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domaingatex.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domaingatex.unpkg.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domaingatex.xoilackvb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainimg.colatv88xd.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainimg.thesports.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainlive.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainlive5.msrktz.app
Quasar RAT botnet C2 domain (confidence level: 75%)
domainmalware.adminxoilac1.site
Quasar RAT botnet C2 domain (confidence level: 75%)
domainmalware.chatboxvs.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainmalware.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainmalware.unpkg.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainmalware.xoilackvb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainphishing.adminxoilac1.site
Quasar RAT botnet C2 domain (confidence level: 75%)
domainphishing.chatboxvs.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainphishing.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainphishing.unpkg.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainphishing.xoilackvb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainquantri.adminxoilac1.site
Quasar RAT botnet C2 domain (confidence level: 75%)
domainquantri.chatboxvs.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainquantri.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainquantri.unpkg.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainquantri.xoilackvb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domaintracker.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainv2.adminxoilac1.site
Quasar RAT botnet C2 domain (confidence level: 75%)
domainv2.chatboxvs.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainv2.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainv2.unpkg.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainv2.xoilackvb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainv3.adminxoilac1.site
Quasar RAT botnet C2 domain (confidence level: 75%)
domainv3.chatboxvs.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainv3.colatv88xb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainv3.unpkg.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainv3.xoilackvb.cc
Quasar RAT botnet C2 domain (confidence level: 75%)
domainwarframe-builder.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domaingit-tanstack.com
Shai-Hulud botnet C2 domain (confidence level: 49%)
domainfilev2.getsession.org
Unknown malware botnet C2 domain (confidence level: 49%)
domainseed1.getsession.org
Unknown malware botnet C2 domain (confidence level: 49%)
domainapi.masscan.cloud
Unknown malware botnet C2 domain (confidence level: 49%)
domainmaster-system-data-core-wiki.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainthijsbroekhuizen.nl
Quasar RAT botnet C2 domain (confidence level: 75%)
domaindashcorpcloud.co
ClearFake payload delivery domain (confidence level: 100%)
domaindatapulse.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainnetvector.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainndg.chriskendall.media
Vidar botnet C2 domain (confidence level: 100%)
domainndg.loniluekegerman.com
Vidar botnet C2 domain (confidence level: 100%)
domainspreader.grabber.cy
Unknown malware payload delivery domain (confidence level: 100%)
domainvexxproject.org
Unknown malware botnet C2 domain (confidence level: 100%)
domainapi.vexxproject.org
Unknown malware botnet C2 domain (confidence level: 100%)
domainkmot.co.kr
Unknown malware botnet C2 domain (confidence level: 49%)
domainchoisy.fr
Unknown malware botnet C2 domain (confidence level: 49%)
domainabledom.net
Unknown malware botnet C2 domain (confidence level: 49%)
domain5hx0aygl.unp2idvalk.digital
ClearFake payload delivery domain (confidence level: 100%)
domainp9015zuh.unp2idvalk.digital
ClearFake payload delivery domain (confidence level: 100%)
domainox18mx54.hor1inka-lonely.digital
ClearFake payload delivery domain (confidence level: 100%)
domainb5fdl2mw.hor1inka-lonely.digital
ClearFake payload delivery domain (confidence level: 100%)
domainprecisionorbitlabs.com
SmartApeSG payload delivery domain (confidence level: 75%)
domainfirstclassiptv.info
StrelaStealer payload delivery domain (confidence level: 100%)
domaincompany21d.com
StrelaStealer payload delivery domain (confidence level: 75%)
domaincaribb.ru
Unknown malware botnet C2 domain (confidence level: 49%)
domainmekhovaya-shuba.ru
Unknown malware botnet C2 domain (confidence level: 49%)
domainbeboss34.ru
Unknown malware botnet C2 domain (confidence level: 49%)
domainelbowfrisk.digital
ClearFake payload delivery domain (confidence level: 100%)
domain7lqe804i.greyhounds1uidor.digital
ClearFake payload delivery domain (confidence level: 100%)
domainwww.axilo.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.apartuk.info
Formbook botnet C2 domain (confidence level: 50%)
domainprt.chriskendall.media
Vidar botnet C2 domain (confidence level: 100%)
domainprt.loniluekegerman.com
Vidar botnet C2 domain (confidence level: 100%)
domainstackforge.wiki
ClearFake payload delivery domain (confidence level: 100%)
domaincodeframe.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainscriptmesh.surf
ClearFake payload delivery domain (confidence level: 100%)
domainbyteforge.surf
ClearFake payload delivery domain (confidence level: 100%)
domaincryptogrid.wiki
ClearFake payload delivery domain (confidence level: 100%)
domain9nogvuq1.chronicle5-diachiha.digital
ClearFake payload delivery domain (confidence level: 100%)
domainqaff1aeg.chronicle5-diachiha.digital
ClearFake payload delivery domain (confidence level: 100%)
domaindevmatrix.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainscreencard.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainsupplyflash.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainsoftwarefile.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainunitmemory.wiki
ClearFake payload delivery domain (confidence level: 100%)
domain1ss.giize.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainlaptoplink.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainpasswordweb.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainbos.chriskendall.media
Vidar botnet C2 domain (confidence level: 100%)
domainbos.loniluekegerman.com
Vidar botnet C2 domain (confidence level: 100%)
domainordersub-versive.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainpassoverphysiqclass.wiki
ClearFake payload delivery domain (confidence level: 100%)
domaingirlytrans-fusion.wiki
ClearFake payload delivery domain (confidence level: 100%)
domaindnmjbsbqsb.com
ValleyRAT botnet C2 domain (confidence level: 75%)
domainangelpatter.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainglarsitttrain.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainlong-pescar.wiki
ClearFake payload delivery domain (confidence level: 100%)
domainmiststarvationsify.wiki
ClearFake payload delivery domain (confidence level: 100%)

Threat ID: 6a03c077cbff5d861028c25d

Added to database: 5/13/2026, 12:06:15 AM

Last enriched: 5/13/2026, 12:21:19 AM

Last updated: 5/13/2026, 1:19:29 AM

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses