Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-05-19

0
Medium
Published: Tue May 19 2026 (05/19/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-05-19

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/20/2026, 00:18:28 UTC

Technical Analysis

The data represents a collection of malware-related IOCs from ThreatFox dated 2026-05-19. It focuses on OSINT and network activity associated with payload delivery mechanisms. No specific software vulnerabilities or affected versions are listed, and no active exploits have been reported. The threat is not cloud-based and no remediation patches exist. The threat level is moderate, reflecting observed distribution but limited exploitation or impact details.

Potential Impact

The threat involves malware delivery and network activity that could potentially lead to compromise if the IOCs are relevant to an environment. However, no known active exploits or specific affected software versions are identified, limiting immediate impact. The absence of patches indicates this is not a vulnerability but rather intelligence on malicious activity patterns.

Mitigation Recommendations

Since this is an OSINT feed providing IOCs without associated vulnerabilities or patches, no direct remediation or patching is applicable. Security teams should incorporate these IOCs into detection and monitoring tools as appropriate. There is no official fix or vendor advisory related to this threat.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
6f8280e5-a6d3-4d8d-8651-a2bd6dd19058
Original Timestamp
1779235386

Indicators of Compromise

File

ValueDescriptionCopy
file178.16.54.156
Quasar RAT botnet C2 server (confidence level: 99%)
file27.124.19.53
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.144.19.220
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.144.19.220
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.144.19.220
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.142.51.69
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.142.51.69
Cobalt Strike botnet C2 server (confidence level: 100%)
file172.86.76.154
Cobalt Strike botnet C2 server (confidence level: 100%)
file172.86.76.154
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.219.228.206
VShell botnet C2 server (confidence level: 100%)
file8.138.187.231
VShell botnet C2 server (confidence level: 100%)
file47.236.130.154
VShell botnet C2 server (confidence level: 100%)
file104.248.92.176
Kimwolf botnet C2 server (confidence level: 100%)
file104.248.89.120
Kimwolf botnet C2 server (confidence level: 100%)
file47.93.9.48
VShell botnet C2 server (confidence level: 100%)
file45.221.115.160
VShell botnet C2 server (confidence level: 100%)
file121.41.222.75
VShell botnet C2 server (confidence level: 100%)
file39.106.211.60
VShell botnet C2 server (confidence level: 100%)
file146.190.107.127
VShell botnet C2 server (confidence level: 100%)
file138.201.86.48
Cobalt Strike botnet C2 server (confidence level: 95%)
file139.196.181.1
VShell botnet C2 server (confidence level: 100%)
file103.253.73.180
Quasar RAT botnet C2 server (confidence level: 100%)
file119.91.26.245
Cobalt Strike botnet C2 server (confidence level: 50%)
file47.116.67.169
Cobalt Strike botnet C2 server (confidence level: 50%)
file118.107.3.198
Quasar RAT botnet C2 server (confidence level: 50%)
file48.202.58.22
AsyncRAT botnet C2 server (confidence level: 50%)
file104.236.69.171
Cobalt Strike botnet C2 server (confidence level: 50%)
file160.22.28.230
Cobalt Strike botnet C2 server (confidence level: 50%)
file160.22.28.230
Cobalt Strike botnet C2 server (confidence level: 50%)
file172.174.90.104
Cobalt Strike botnet C2 server (confidence level: 50%)
file47.82.234.12
Cobalt Strike botnet C2 server (confidence level: 50%)
file43.143.145.187
Cobalt Strike botnet C2 server (confidence level: 50%)
file213.232.236.4
Quasar RAT botnet C2 server (confidence level: 50%)
file65.87.7.128
Unknown malware payload delivery server (confidence level: 80%)
file79.110.50.15
Unknown malware payload delivery server (confidence level: 80%)
file49.232.124.230
VShell botnet C2 server (confidence level: 100%)
file186.120.214.158
Havoc botnet C2 server (confidence level: 100%)
file62.181.55.38
Unknown malware botnet C2 server (confidence level: 100%)
file172.94.18.103
AsyncRAT botnet C2 server (confidence level: 100%)
file123.113.14.21
Quasar RAT botnet C2 server (confidence level: 100%)
file104.168.94.108
VShell botnet C2 server (confidence level: 100%)
file151.243.137.78
VShell botnet C2 server (confidence level: 100%)
file45.149.154.220
Unknown malware botnet C2 server (confidence level: 75%)
file95.85.236.201
Unknown malware botnet C2 server (confidence level: 75%)
file143.198.192.17
Remus botnet C2 server (confidence level: 75%)
file195.211.191.24
Remus botnet C2 server (confidence level: 75%)
file64.89.160.73
PureRAT botnet C2 server (confidence level: 75%)
file23.94.23.151
VShell botnet C2 server (confidence level: 100%)
file130.94.14.186
Cobalt Strike botnet C2 server (confidence level: 100%)
file130.94.14.186
Cobalt Strike botnet C2 server (confidence level: 100%)
file130.94.14.186
Cobalt Strike botnet C2 server (confidence level: 100%)
file111.230.36.144
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.105.76.33
Cobalt Strike botnet C2 server (confidence level: 100%)
file108.61.223.230
Cobalt Strike botnet C2 server (confidence level: 100%)
file175.24.201.23
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.152.65.240
Cobalt Strike botnet C2 server (confidence level: 100%)
file111.170.148.169
Cobalt Strike botnet C2 server (confidence level: 100%)
file173.230.134.215
Cobalt Strike botnet C2 server (confidence level: 100%)
file120.48.18.226
Cobalt Strike botnet C2 server (confidence level: 100%)
file64.225.64.37
Kimwolf botnet C2 server (confidence level: 100%)
file164.92.154.242
Kimwolf botnet C2 server (confidence level: 100%)
file154.12.86.154
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.12.86.154
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.12.86.154
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.12.86.154
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.144.11.180
Cobalt Strike botnet C2 server (confidence level: 100%)
file85.239.155.68
Unknown malware botnet C2 server (confidence level: 100%)
file101.33.251.229
VShell botnet C2 server (confidence level: 100%)
file139.196.181.1
VShell botnet C2 server (confidence level: 100%)
file185.136.15.2
PureRAT botnet C2 server (confidence level: 100%)
file185.136.15.2
PureRAT botnet C2 server (confidence level: 100%)
file185.136.15.2
PureRAT botnet C2 server (confidence level: 100%)
file43.144.11.180
Cobalt Strike botnet C2 server (confidence level: 100%)
file124.223.198.8
VShell botnet C2 server (confidence level: 100%)
file118.195.147.253
VShell botnet C2 server (confidence level: 100%)
file104.243.248.63
AsyncRAT botnet C2 server (confidence level: 75%)
file142.93.165.129
Evilginx botnet C2 server (confidence level: 75%)
file167.86.114.91
Unknown malware botnet C2 server (confidence level: 75%)
file176.120.22.127
PoshC2 botnet C2 server (confidence level: 75%)
file178.16.54.248
DCRat botnet C2 server (confidence level: 75%)
file43.144.11.180
Cobalt Strike botnet C2 server (confidence level: 100%)
file40.113.170.113
Quasar RAT botnet C2 server (confidence level: 100%)
file205.209.99.237
DCRat botnet C2 server (confidence level: 100%)
file47.116.115.84
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.116.115.84
Cobalt Strike botnet C2 server (confidence level: 100%)
file98.81.111.167
AdaptixC2 botnet C2 server (confidence level: 100%)
file47.116.115.84
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.116.115.84
Cobalt Strike botnet C2 server (confidence level: 100%)
file111.230.36.144
Cobalt Strike botnet C2 server (confidence level: 100%)
file111.230.36.144
Cobalt Strike botnet C2 server (confidence level: 100%)
file150.158.139.26
Unknown malware botnet C2 server (confidence level: 100%)
file150.158.139.26
Unknown malware botnet C2 server (confidence level: 100%)
file150.158.139.26
Unknown malware botnet C2 server (confidence level: 100%)
file150.158.139.26
Unknown malware botnet C2 server (confidence level: 100%)
file194.180.206.163
VShell botnet C2 server (confidence level: 100%)
file178.62.224.156
Kimwolf botnet C2 server (confidence level: 100%)
file188.166.104.40
Kimwolf botnet C2 server (confidence level: 100%)
file185.157.162.187
Unknown malware botnet C2 server (confidence level: 100%)
file39.105.197.2
VShell botnet C2 server (confidence level: 100%)
file165.154.201.9
Unknown malware botnet C2 server (confidence level: 100%)
file102.129.165.177
VShell botnet C2 server (confidence level: 100%)
file8.138.30.206
VShell botnet C2 server (confidence level: 100%)
file47.93.9.48
VShell botnet C2 server (confidence level: 100%)
file154.12.86.154
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.121.117.88
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.62.232.19
Kimwolf botnet C2 server (confidence level: 100%)
file91.215.85.121
Unknown Stealer botnet C2 server (confidence level: 75%)
file193.143.1.131
Unknown Stealer botnet C2 server (confidence level: 75%)
file193.143.1.24
Unknown Stealer botnet C2 server (confidence level: 75%)
file134.122.53.212
Kimwolf botnet C2 server (confidence level: 100%)
file100.110.56.1
Cobalt Strike botnet C2 server (confidence level: 75%)
file8.222.147.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.222.147.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.222.147.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file67.217.228.3
Unknown malware payload delivery server (confidence level: 75%)
file188.166.17.118
Kimwolf botnet C2 server (confidence level: 100%)
file167.99.35.28
Kimwolf botnet C2 server (confidence level: 100%)
file193.138.195.187
PureRAT botnet C2 server (confidence level: 75%)
file144.172.94.91
Remcos botnet C2 server (confidence level: 75%)
file144.172.94.91
Remcos botnet C2 server (confidence level: 75%)
file144.172.94.91
Remcos botnet C2 server (confidence level: 75%)
file172.111.233.80
AsyncRAT botnet C2 server (confidence level: 75%)
file192.159.99.50
Eye Pyramid botnet C2 server (confidence level: 75%)
file31.57.184.154
AsyncRAT botnet C2 server (confidence level: 75%)
file49.232.128.239
AdaptixC2 botnet C2 server (confidence level: 75%)
file5.101.81.163
Remcos botnet C2 server (confidence level: 75%)
file83.136.211.194
AsyncRAT botnet C2 server (confidence level: 75%)
file91.202.233.214
AdaptixC2 botnet C2 server (confidence level: 75%)
file43.142.137.169
Cobalt Strike botnet C2 server (confidence level: 75%)
file68.219.64.89
XWorm botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash61541
Quasar RAT botnet C2 server (confidence level: 99%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash33060
VShell botnet C2 server (confidence level: 100%)
hash8443
VShell botnet C2 server (confidence level: 100%)
hashe18e9309db33273762be1d78f5bdd78fa6ea41dadf5f6eef8ece4c841ea76110
ClearFake payload (confidence level: 80%)
hash8080
VShell botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash60001
VShell botnet C2 server (confidence level: 100%)
hash1433
VShell botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash8088
VShell botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 95%)
hash20001
VShell botnet C2 server (confidence level: 100%)
hash9999
Quasar RAT botnet C2 server (confidence level: 100%)
hash6666
Cobalt Strike botnet C2 server (confidence level: 50%)
hash2087
Cobalt Strike botnet C2 server (confidence level: 50%)
hash4782
Quasar RAT botnet C2 server (confidence level: 50%)
hash2055
AsyncRAT botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash49680
Quasar RAT botnet C2 server (confidence level: 50%)
hash443
Unknown malware payload delivery server (confidence level: 80%)
hash443
Unknown malware payload delivery server (confidence level: 80%)
hash78be219b8793d648213172a6bc2c1738f4e14f7b65a01d2d875e40c858e1b484
Unknown malware payload (confidence level: 75%)
hash6c974418247ab414c674fb699ee001d1703f8a6c54810b1773cdc1647cc69e52
Unknown malware payload (confidence level: 75%)
hashd0c2fe58efadb86c93f9930cb8668cd40b60399f3a8db54b1c9974ee4eab4b39
Unknown malware payload (confidence level: 75%)
hashb2af4e6e723b7a8074ed41a90da69c6cd1b1db4fc4cc8a2e2930daa58704443c
Unknown malware payload (confidence level: 75%)
hash52461a7264164f0e8d1723ef0b76e99f394936b5290df25a5f26c8552a01369a
Unknown malware payload (confidence level: 75%)
hash9a6b750766ff30309502a31bf3bacae5c60211f2257c446c114f28148d2f4fd8
Unknown malware payload (confidence level: 85%)
hash8000
VShell botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash8000
Unknown malware botnet C2 server (confidence level: 100%)
hash76
AsyncRAT botnet C2 server (confidence level: 100%)
hash4285
Quasar RAT botnet C2 server (confidence level: 100%)
hash8082
VShell botnet C2 server (confidence level: 100%)
hash80
VShell botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 75%)
hash3652
Unknown malware botnet C2 server (confidence level: 75%)
hash4538
Remus botnet C2 server (confidence level: 75%)
hash7673
Remus botnet C2 server (confidence level: 75%)
hash443
PureRAT botnet C2 server (confidence level: 75%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8090
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8081
Cobalt Strike botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash8001
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash3001
Unknown malware botnet C2 server (confidence level: 100%)
hash9999
VShell botnet C2 server (confidence level: 100%)
hash20026
VShell botnet C2 server (confidence level: 100%)
hash56001
PureRAT botnet C2 server (confidence level: 100%)
hash56002
PureRAT botnet C2 server (confidence level: 100%)
hash56003
PureRAT botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash50002
VShell botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash1805
AsyncRAT botnet C2 server (confidence level: 75%)
hash3334
Evilginx botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash443
PoshC2 botnet C2 server (confidence level: 75%)
hash55380
DCRat botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Quasar RAT botnet C2 server (confidence level: 100%)
hash8848
DCRat botnet C2 server (confidence level: 100%)
hash8001
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
AdaptixC2 botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash19181
VShell botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash3176
Unknown malware botnet C2 server (confidence level: 100%)
hash13421
VShell botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8083
VShell botnet C2 server (confidence level: 100%)
hash8011
VShell botnet C2 server (confidence level: 100%)
hash60006
VShell botnet C2 server (confidence level: 100%)
hash8000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash766b70cb0477fbfcd6b012573f1dbc3831c6da44f372e34500e8314fd1084943
Unknown malware payload (confidence level: 75%)
hash4591e91432b52478c20b04fe138b6da5003710b7c74701600bbb4a39148f4783
Unknown malware payload (confidence level: 75%)
hash5051
Unknown Stealer botnet C2 server (confidence level: 75%)
hash5051
Unknown Stealer botnet C2 server (confidence level: 75%)
hash5051
Unknown Stealer botnet C2 server (confidence level: 75%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Unknown malware payload delivery server (confidence level: 75%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash5555
PureRAT botnet C2 server (confidence level: 75%)
hash1122
Remcos botnet C2 server (confidence level: 75%)
hash2255
Remcos botnet C2 server (confidence level: 75%)
hash3333
Remcos botnet C2 server (confidence level: 75%)
hash6666
AsyncRAT botnet C2 server (confidence level: 75%)
hash7443
Eye Pyramid botnet C2 server (confidence level: 75%)
hash2502
AsyncRAT botnet C2 server (confidence level: 75%)
hash6099
AdaptixC2 botnet C2 server (confidence level: 75%)
hash47524
Remcos botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash44123
AdaptixC2 botnet C2 server (confidence level: 75%)
hash18443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash4444
XWorm botnet C2 server (confidence level: 75%)

Url

ValueDescriptionCopy
urlhttps://435123332155.com/api.php
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://abernaehy.lol/file.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://abernaehy.lol/api/v1/session
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://abernaehy.lol/api/v1/verify
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://abernaehy.lol/api/v1/status
KongTuke payload delivery URL (confidence level: 100%)
urlhttp://79.110.50.15:8089/borlndmm.dll
Unknown malware payload delivery URL (confidence level: 80%)
urlhttp://85.239.155.68:3001/upload
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://85.239.155.68:3001/internal/log
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://85.239.155.68:3001/ws
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://91.92.241.242/success
GCleaner botnet C2 (confidence level: 100%)
urlhttp://91.92.241.242/service
GCleaner botnet C2 (confidence level: 100%)
urlhttp://91.92.241.242/update
GCleaner botnet C2 (confidence level: 100%)
urlhttp://91.92.241.242/info
GCleaner botnet C2 (confidence level: 100%)
urlhttp://91.92.241.242/dll
GCleaner botnet C2 (confidence level: 100%)
urlhttps://tri.tristans-tea.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://tri.fazvende.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://aspf.com.br/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://185.157.162.187:3176/pages/login.php
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://reynoldy.lol/file.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://reynoldy.lol/api/v1/session
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://reynoldy.lol/api/v1/verify
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://reynoldy.lol/api/v1/status
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://human-confirmation.top/m
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://human-confirmation.top/o
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://u3hqns4msrc4hei.top/1.php?s=580e250d-effb-401a-b981-fb7fd80635a2
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://rpi.tristans-tea.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://rpi.fazvende.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://wed.tristans-tea.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://wed.fazvende.com.br/
Vidar botnet C2 (confidence level: 100%)
urlhttps://brownhc.cyou
Lumma Stealer botnet C2 (confidence level: 75%)

Domain

ValueDescriptionCopy
domainabernaehy.lol
KongTuke payload delivery domain (confidence level: 100%)
domain435123332155.com
Unknown RAT botnet C2 domain (confidence level: 75%)
domainttsadnfgsdf.cn
Winos payload delivery domain (confidence level: 80%)
domainrubysen.com
EtherRAT botnet C2 domain (confidence level: 100%)
domainager-stp.org
EtherRAT botnet C2 domain (confidence level: 100%)
domainbrand-physics-aerial-companion.trycloudflare.com
EtherRAT botnet C2 domain (confidence level: 100%)
domaindistributedbloomnetwork.garden
ClearFake payload delivery domain (confidence level: 100%)
domainbotanicalresourcecontroller.garden
ClearFake payload delivery domain (confidence level: 100%)
domainirrigationanalyticssystem.garden
ClearFake payload delivery domain (confidence level: 100%)
domainrjcuszqj.siciliandefensetheory.digital
ClearFake payload delivery domain (confidence level: 100%)
domain8duc5067.siciliandefensetheory.digital
ClearFake payload delivery domain (confidence level: 100%)
domainfederatedgardenplatform.garden
ClearFake payload delivery domain (confidence level: 100%)
domainmeadowworkflowframework.garden
ClearFake payload delivery domain (confidence level: 100%)
domaincapcutdev.com
Unknown malware payload delivery domain (confidence level: 80%)
domainlog32-normal.capcutdev.com
Unknown malware payload delivery domain (confidence level: 80%)
domaincloud.integritybusinessolutions.com
Unknown malware payload delivery domain (confidence level: 80%)
domainfloraobservabilitycenter.garden
ClearFake payload delivery domain (confidence level: 100%)
domainstbe26oz.meadowworkflowframework.garden
ClearFake payload delivery domain (confidence level: 100%)
domaintake.takemetotheriver.top
Unknown malware botnet C2 domain (confidence level: 100%)
domainhey.wtfomginc.top
Unknown malware botnet C2 domain (confidence level: 100%)
domainds.emailmeanything.sbs
Unknown malware botnet C2 domain (confidence level: 100%)
domaintop.realslimshady.xyz
Unknown malware botnet C2 domain (confidence level: 100%)
domain92.dmrdjmejuah.icu
Unknown malware botnet C2 domain (confidence level: 100%)
domainreal.kabgagk234d.info
Unknown malware botnet C2 domain (confidence level: 100%)
domainset.setmeasdomain.cyou
Unknown malware botnet C2 domain (confidence level: 100%)
domainomg.itsjasonborn.today
Unknown malware botnet C2 domain (confidence level: 100%)
domainoh.whatisyourname.buzz
Unknown malware botnet C2 domain (confidence level: 100%)
domainapi.itsjusttesting.top
Unknown malware botnet C2 domain (confidence level: 100%)
domaincontainerizedplantengine.garden
ClearFake payload delivery domain (confidence level: 100%)
domainholistic-detective-agency.garden
ClearFake payload delivery domain (confidence level: 100%)
domainnw3tvo7k.audioattenuatorschematic.digital
ClearFake payload delivery domain (confidence level: 100%)
domainx8drf7ed.audioattenuatorschematic.digital
ClearFake payload delivery domain (confidence level: 100%)
domainxenomorph-hive-intelligence.garden
ClearFake payload delivery domain (confidence level: 100%)
domainphase-shift-bridge-driver.garden
ClearFake payload delivery domain (confidence level: 100%)
domainamber-fossil-mosquito.garden
ClearFake payload delivery domain (confidence level: 100%)
domainquantum-entanglement-crypt.garden
ClearFake payload delivery domain (confidence level: 100%)
domainthe-sopranos-family-tree.garden
ClearFake payload delivery domain (confidence level: 100%)
domainbadabingsopranoslounge.digital
ClearFake payload delivery domain (confidence level: 100%)
domain0g6xawfs.badabingsopranoslounge.digital
ClearFake payload delivery domain (confidence level: 100%)
domainq956x3rl.badabingsopranoslounge.digital
ClearFake payload delivery domain (confidence level: 100%)
domainapigrokcloud.icu
ACR Stealer botnet C2 domain (confidence level: 100%)
domainhs.imitationfinancialfootwork.icu
ACR Stealer botnet C2 domain (confidence level: 100%)
domaingetauthdash.icu
ACR Stealer botnet C2 domain (confidence level: 100%)
domaincybersec-chile.online
Unknown malware botnet C2 domain (confidence level: 100%)
domainmaterial-deals.com
Remus botnet C2 domain (confidence level: 100%)
domainsubterranean-bunker-outpost.garden
ClearFake payload delivery domain (confidence level: 100%)
domainryoubornagain.com
Remus botnet C2 domain (confidence level: 100%)
domainrootsandextracts.com
Remus botnet C2 domain (confidence level: 100%)
domainciuzdaw.shop
Remus botnet C2 domain (confidence level: 100%)
domaintectonic-fault-seismograph.garden
ClearFake payload delivery domain (confidence level: 100%)
domainmodular-analog-synthesizer.garden
ClearFake payload delivery domain (confidence level: 100%)
domain6rto54ve.orbitaldockingmodule.digital
ClearFake payload delivery domain (confidence level: 100%)
domainrgx5w3o2.orbitaldockingmodule.digital
ClearFake payload delivery domain (confidence level: 100%)
domainstratographic-core-drill.garden
ClearFake payload delivery domain (confidence level: 100%)
domainstealth-bomber-radar-cross.garden
ClearFake payload delivery domain (confidence level: 100%)
domainancient-colosseum-engineering.garden
ClearFake payload delivery domain (confidence level: 100%)
domaininterstellar-dust-nebula.garden
ClearFake payload delivery domain (confidence level: 100%)
domaintri.tristans-tea.com
Vidar botnet C2 domain (confidence level: 100%)
domaintri.fazvende.com
Vidar botnet C2 domain (confidence level: 100%)
domainbioluminescent-fungi-spore.garden
ClearFake payload delivery domain (confidence level: 100%)
domainqvf16jfy.crispychickencutlets.digital
ClearFake payload delivery domain (confidence level: 100%)
domain46fmfamd.crispychickencutlets.digital
ClearFake payload delivery domain (confidence level: 100%)
domaincarbon-fiber-monocoque.garden
ClearFake payload delivery domain (confidence level: 100%)
domaingreenhouseworkflowcenter.garden
ClearFake payload delivery domain (confidence level: 100%)
domainpetalresourceengine.garden
ClearFake payload delivery domain (confidence level: 100%)
domainwildfloramanagementplatform.garden
ClearFake payload delivery domain (confidence level: 100%)
domaindistributedgardenanalytics.garden
ClearFake payload delivery domain (confidence level: 100%)
domainsubfossiloakchronology.digital
ClearFake payload delivery domain (confidence level: 100%)
domain1ml4kzh4.subfossiloakchronology.digital
ClearFake payload delivery domain (confidence level: 100%)
domain3zqfx034.subfossiloakchronology.digital
ClearFake payload delivery domain (confidence level: 100%)
domainsp13.gstats-api-cont.co
Unknown malware botnet C2 domain (confidence level: 100%)
domaingatuso.duckdns.org
XWorm botnet C2 domain (confidence level: 100%)
domainbotanicalautomationframework.garden
ClearFake payload delivery domain (confidence level: 100%)
domainapi.operilezabre.com
FAKEUPDATES payload delivery domain (confidence level: 100%)
domainirrigationtelemetrysystem.garden
ClearFake payload delivery domain (confidence level: 100%)
domainsmetana-js.beer
Unknown malware payload delivery domain (confidence level: 100%)
domainfederatedgrowthnetwork.garden
ClearFake payload delivery domain (confidence level: 100%)
domainmeadowoperationshub.garden
ClearFake payload delivery domain (confidence level: 100%)
domainlv5evztg.cyberneticprostheticlab.digital
ClearFake payload delivery domain (confidence level: 100%)
domainfloraresourcecontroller.garden
ClearFake payload delivery domain (confidence level: 100%)
domaingr33bzph.cyberneticprostheticlab.digital
ClearFake payload delivery domain (confidence level: 100%)
domainreynoldy.lol
KongTuke payload delivery domain (confidence level: 100%)
domaincontainerizedgardenengine.garden
ClearFake payload delivery domain (confidence level: 100%)
domaingreen-macrohim-work-center.garden
ClearFake payload delivery domain (confidence level: 100%)
domaindengrep-resource-opencut-engine.garden
ClearFake payload delivery domain (confidence level: 100%)
domaindev-portal.ptbaconsulting.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainsocialrockstar.it
StrelaStealer payload delivery domain (confidence level: 100%)
domainbagansi-wild-flowr-manage-form.garden
ClearFake payload delivery domain (confidence level: 100%)
domainhuman-confirmation.top
Unknown malware payload delivery domain (confidence level: 75%)
domainw5r4tev8.magneticlevitationtrain.digital
ClearFake payload delivery domain (confidence level: 100%)
domainuh83re33.magneticlevitationtrain.digital
ClearFake payload delivery domain (confidence level: 100%)
domainscaletax-bute-analytics-toeheap.garden
ClearFake payload delivery domain (confidence level: 100%)
domainmodelcut-auto-frame-nodipfs.garden
ClearFake payload delivery domain (confidence level: 100%)
domainu3hqns4msrc4hei.top
Unknown malware payload delivery domain (confidence level: 75%)
domainmodesix-iontel-scalapie-system.garden
ClearFake payload delivery domain (confidence level: 100%)
domainslngftr.beer
Unknown malware payload delivery domain (confidence level: 100%)
domainagilebee-federate-growth-net.garden
ClearFake payload delivery domain (confidence level: 100%)
domainmendocs-opera-shub-cowddos.garden
ClearFake payload delivery domain (confidence level: 100%)
domain0wv09g11.gothiccathedralblueprint.digital
ClearFake payload delivery domain (confidence level: 100%)
domain8xtx6dv2.gothiccathedralblueprint.digital
ClearFake payload delivery domain (confidence level: 100%)
domaindampcaps-flor-sou-rail.garden
ClearFake payload delivery domain (confidence level: 100%)
domaincodepit-rized-denengine.garden
ClearFake payload delivery domain (confidence level: 100%)
domaingreenhouse-resource-center.garden
ClearFake payload delivery domain (confidence level: 100%)
domainc533d8a0-2c69-47ed-b173-0234c17c3989.codepit-rized-denengine.garden
ClearFake payload delivery domain (confidence level: 100%)
domainzef6cv5o.byte-lattice.digital
ClearFake payload delivery domain (confidence level: 100%)
domainwildfloraworkflowhub.garden
ClearFake payload delivery domain (confidence level: 100%)
domainrpi.tristans-tea.com
Vidar botnet C2 domain (confidence level: 100%)
domainrpi.fazvende.com
Vidar botnet C2 domain (confidence level: 100%)
domainpetal-processing-platform.garden
ClearFake payload delivery domain (confidence level: 100%)
domaindistributedgardenmesh.garden
ClearFake payload delivery domain (confidence level: 100%)
domainbotanical-control-framework.garden
ClearFake payload delivery domain (confidence level: 100%)
domainmeadowanalyticsengine.garden
ClearFake payload delivery domain (confidence level: 100%)
domaint8oasjc8.cyber-harbor.digital
ClearFake payload delivery domain (confidence level: 100%)
domainflora-resource-network.garden
ClearFake payload delivery domain (confidence level: 100%)
domaincontainerized-growth-system.garden
ClearFake payload delivery domain (confidence level: 100%)
domainwed.tristans-tea.com
Vidar botnet C2 domain (confidence level: 100%)
domainwed.fazvende.com.br
Vidar botnet C2 domain (confidence level: 100%)
domaindagatructiep.fashion
AsyncRAT botnet C2 domain (confidence level: 75%)
domainecosystemprocessingcore.garden
ClearFake payload delivery domain (confidence level: 100%)
domainmicroflora-observability-platform.garden
ClearFake payload delivery domain (confidence level: 100%)
domainjq7mk5ac.logic-pulse.digital
ClearFake payload delivery domain (confidence level: 100%)
domaincoriolis-effect-trajectory.garden
ClearFake payload delivery domain (confidence level: 100%)
domainabyssal-plain-topography.garden
ClearFake payload delivery domain (confidence level: 100%)
domainperfect-bolognese-simmer.garden
ClearFake payload delivery domain (confidence level: 100%)
domainvacuum-tube-amplifier.garden
ClearFake payload delivery domain (confidence level: 100%)

Threat ID: 6a0cfdceba1db47362fd4a03

Added to database: 5/20/2026, 12:18:22 AM

Last enriched: 5/20/2026, 12:18:28 AM

Last updated: 5/20/2026, 5:44:53 AM

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses