Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-05-23

0
Medium
Published: Sat May 23 2026 (05/23/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-05-23

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/24/2026, 00:16:33 UTC

Technical Analysis

The report details malware-related IOCs collected on 2026-05-23 from the ThreatFox MISP feed, focusing on OSINT and network activity associated with payload delivery. It does not specify affected products or versions, nor does it include concrete exploit or vulnerability information. No patch or remediation is applicable since this is an intelligence feed entry rather than a software vulnerability. The threat level is medium with moderate distribution but limited analysis and threat level scores.

Potential Impact

The impact is limited to the presence of malware-related indicators that may assist in detection and response efforts. There is no direct vulnerability or exploit described, and no known active exploitation is reported. This information supports threat intelligence and situational awareness but does not indicate an immediate exploitable security flaw.

Mitigation Recommendations

No patch or remediation is applicable as this is an OSINT report of malware IOCs rather than a vulnerability. Security teams should incorporate these IOCs into their detection and monitoring tools as appropriate. No urgent action is required based on this report alone.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
cec67dd2-6a07-40fa-9702-3f541e743d2c
Original Timestamp
1779580987

Indicators of Compromise

File

ValueDescriptionCopy
file120.48.122.238
VShell botnet C2 server (confidence level: 100%)
file134.122.1.247
Unknown malware payload delivery server (confidence level: 85%)
file45.55.35.80
Unknown malware botnet C2 server (confidence level: 75%)
file206.189.148.105
Unknown malware botnet C2 server (confidence level: 50%)
file178.128.18.57
Unknown malware botnet C2 server (confidence level: 50%)
file159.203.95.70
Unknown Stealer botnet C2 server (confidence level: 50%)
file179.43.139.82
XMRIG payload delivery server (confidence level: 70%)
file179.43.139.80
XMRIG payload delivery server (confidence level: 60%)
file179.43.139.81
XMRIG payload delivery server (confidence level: 60%)
file5.109.182.231
Cobalt Strike botnet C2 server (confidence level: 100%)
file60.204.239.241
Cobalt Strike botnet C2 server (confidence level: 100%)
file60.204.239.241
Cobalt Strike botnet C2 server (confidence level: 100%)
file60.204.239.241
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.144.245.73
Unknown malware botnet C2 server (confidence level: 100%)
file47.243.194.204
VShell botnet C2 server (confidence level: 100%)
file47.99.206.62
VShell botnet C2 server (confidence level: 100%)
file37.32.15.8
Cobalt Strike botnet C2 server (confidence level: 100%)
file1.117.77.166
Cobalt Strike botnet C2 server (confidence level: 50%)
file93.45.38.163
Quasar RAT botnet C2 server (confidence level: 50%)
file50.114.179.143
AsyncRAT botnet C2 server (confidence level: 50%)
file64.95.12.40
VShell botnet C2 server (confidence level: 100%)
file23.106.135.33
Cobalt Strike botnet C2 server (confidence level: 100%)
file39.100.91.115
VShell botnet C2 server (confidence level: 100%)
file146.103.106.59
AdaptixC2 botnet C2 server (confidence level: 100%)
file146.103.106.59
AdaptixC2 botnet C2 server (confidence level: 100%)
file146.103.106.59
AdaptixC2 botnet C2 server (confidence level: 100%)
file103.236.92.3
VShell botnet C2 server (confidence level: 100%)
file23.20.229.225
AdaptixC2 botnet C2 server (confidence level: 100%)
file23.20.229.225
AdaptixC2 botnet C2 server (confidence level: 100%)
file38.54.56.91
VShell botnet C2 server (confidence level: 100%)
file47.103.78.72
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.103.78.72
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.103.78.72
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.103.78.72
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.152.65.240
Cobalt Strike botnet C2 server (confidence level: 100%)
file94.26.90.55
DCRat botnet C2 server (confidence level: 100%)
file93.177.103.55
DCRat botnet C2 server (confidence level: 100%)
file85.217.248.243
Quasar RAT botnet C2 server (confidence level: 100%)
file43.164.191.203
Unknown malware botnet C2 server (confidence level: 100%)
file43.164.191.203
Unknown malware botnet C2 server (confidence level: 100%)
file43.164.191.203
Unknown malware botnet C2 server (confidence level: 100%)
file43.164.191.203
Unknown malware botnet C2 server (confidence level: 100%)
file68.64.180.15
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.148.10.210
Mirai payload delivery server (confidence level: 85%)
file45.198.224.5
Unknown malware botnet C2 server (confidence level: 80%)
file87.121.79.193
Dofloo payload delivery server (confidence level: 80%)
file87.121.79.73
Dofloo payload delivery server (confidence level: 80%)
file107.189.3.150
RedTail payload delivery server (confidence level: 85%)
file140.99.32.48
RedTail payload delivery server (confidence level: 85%)
file34.9.216.246
Unknown malware payload delivery server (confidence level: 85%)
file115.178.75.242
Unknown malware botnet C2 server (confidence level: 90%)
file103.13.210.49
Havoc botnet C2 server (confidence level: 75%)
file190.255.82.151
Remcos botnet C2 server (confidence level: 75%)
file2.26.75.240
Remcos botnet C2 server (confidence level: 75%)
file23.81.118.124
Remcos botnet C2 server (confidence level: 75%)
file50.114.179.143
AsyncRAT botnet C2 server (confidence level: 75%)
file91.232.103.163
AsyncRAT botnet C2 server (confidence level: 75%)
file213.136.74.96
Chaos botnet C2 server (confidence level: 100%)
file213.136.74.96
Chaos botnet C2 server (confidence level: 50%)
file68.64.180.15
Cobalt Strike botnet C2 server (confidence level: 100%)
file68.64.180.15
Cobalt Strike botnet C2 server (confidence level: 100%)
file66.63.187.106
VShell botnet C2 server (confidence level: 100%)
file115.190.80.27
VShell botnet C2 server (confidence level: 100%)
file203.83.10.114
Cobalt Strike botnet C2 server (confidence level: 100%)
file203.83.10.114
Cobalt Strike botnet C2 server (confidence level: 100%)
file203.83.10.114
Cobalt Strike botnet C2 server (confidence level: 100%)
file203.83.10.114
Cobalt Strike botnet C2 server (confidence level: 100%)
file3.16.166.49
Quasar RAT botnet C2 server (confidence level: 100%)
file161.97.166.38
AsyncRAT botnet C2 server (confidence level: 100%)
file107.175.189.195
VShell botnet C2 server (confidence level: 100%)
file119.45.134.74
VShell botnet C2 server (confidence level: 100%)
file119.29.117.194
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.104.199.189
Cobalt Strike botnet C2 server (confidence level: 100%)
file102.204.223.106
Cobalt Strike botnet C2 server (confidence level: 100%)
file35.220.177.232
Cobalt Strike botnet C2 server (confidence level: 100%)
file68.64.178.130
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.137.170.3
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.173.105.177
Cobalt Strike botnet C2 server (confidence level: 100%)
file101.126.10.34
Cobalt Strike botnet C2 server (confidence level: 100%)
file64.176.51.87
VShell botnet C2 server (confidence level: 100%)
file176.65.139.199
Mirai botnet C2 server (confidence level: 80%)
file151.236.20.3
AdaptixC2 botnet C2 server (confidence level: 75%)
file157.254.223.135
AsyncRAT botnet C2 server (confidence level: 75%)
file168.222.97.106
AsyncRAT botnet C2 server (confidence level: 75%)
file18.118.196.244
AsyncRAT botnet C2 server (confidence level: 75%)
file191.101.131.244
Sliver botnet C2 server (confidence level: 75%)
file191.101.131.244
Sliver botnet C2 server (confidence level: 75%)
file44.255.242.255
Brute Ratel C4 botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash8084
VShell botnet C2 server (confidence level: 100%)
hash79
Unknown malware payload delivery server (confidence level: 85%)
hash80
Unknown malware botnet C2 server (confidence level: 75%)
hash8080
Unknown malware botnet C2 server (confidence level: 50%)
hash8443
Unknown malware botnet C2 server (confidence level: 50%)
hash5000
Unknown Stealer botnet C2 server (confidence level: 50%)
hashef355778546bc6e044330691404b63eddf83d7fc6073047394a25dd0e98c7d7d
XMRIG payload (confidence level: 90%)
hash80
XMRIG payload delivery server (confidence level: 70%)
hash80
XMRIG payload delivery server (confidence level: 60%)
hash80
XMRIG payload delivery server (confidence level: 60%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash60611
VShell botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash3310
Cobalt Strike botnet C2 server (confidence level: 50%)
hash4567
Quasar RAT botnet C2 server (confidence level: 50%)
hash8088
AsyncRAT botnet C2 server (confidence level: 50%)
hash8080
VShell botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash80
AdaptixC2 botnet C2 server (confidence level: 100%)
hash8080
AdaptixC2 botnet C2 server (confidence level: 100%)
hash443
AdaptixC2 botnet C2 server (confidence level: 100%)
hash10000
VShell botnet C2 server (confidence level: 100%)
hash80
AdaptixC2 botnet C2 server (confidence level: 100%)
hash8080
AdaptixC2 botnet C2 server (confidence level: 100%)
hash8080
VShell botnet C2 server (confidence level: 100%)
hash7777
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
DCRat botnet C2 server (confidence level: 100%)
hash9999
DCRat botnet C2 server (confidence level: 100%)
hash443
Quasar RAT botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Mirai payload delivery server (confidence level: 85%)
hash80
Unknown malware botnet C2 server (confidence level: 80%)
hash80
Dofloo payload delivery server (confidence level: 80%)
hash80
Dofloo payload delivery server (confidence level: 80%)
hash80
RedTail payload delivery server (confidence level: 85%)
hash80
RedTail payload delivery server (confidence level: 85%)
hash80
Unknown malware payload delivery server (confidence level: 85%)
hash22
Unknown malware botnet C2 server (confidence level: 90%)
hash443
Havoc botnet C2 server (confidence level: 75%)
hash5500
Remcos botnet C2 server (confidence level: 75%)
hash1377
Remcos botnet C2 server (confidence level: 75%)
hash8080
Remcos botnet C2 server (confidence level: 75%)
hash6066
AsyncRAT botnet C2 server (confidence level: 75%)
hash1604
AsyncRAT botnet C2 server (confidence level: 75%)
hash8090
Chaos botnet C2 server (confidence level: 100%)
hash8090
Chaos botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash18084
VShell botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Quasar RAT botnet C2 server (confidence level: 100%)
hash10900
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
VShell botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash5555
VShell botnet C2 server (confidence level: 100%)
hash1999
Mirai botnet C2 server (confidence level: 80%)
hash8080
AdaptixC2 botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash6666
AsyncRAT botnet C2 server (confidence level: 75%)
hash31337
Sliver botnet C2 server (confidence level: 75%)
hash40056
Sliver botnet C2 server (confidence level: 75%)
hash80
Brute Ratel C4 botnet C2 server (confidence level: 75%)

Domain

ValueDescriptionCopy
domainsam-sa.net
Unknown malware payload delivery domain (confidence level: 85%)
domainclaudemo.net
Unknown malware payload delivery domain (confidence level: 85%)
domainfinger.claudemo.net
Unknown malware payload delivery domain (confidence level: 85%)
domain1morepizza.com
Vidar payload delivery domain (confidence level: 100%)
domainratting.top
Unknown malware botnet C2 domain (confidence level: 100%)
domainkalpa-logistics.com
Vidar payload delivery domain (confidence level: 100%)
domainlogisteg.com.br
Vidar payload delivery domain (confidence level: 100%)
domainmeastt.gov.tt
Vidar payload delivery domain (confidence level: 100%)
domainnamathejaljawdah.com
Vidar payload delivery domain (confidence level: 100%)
domainnarquitetos.com
Vidar payload delivery domain (confidence level: 100%)
domainpinnaclebrit.co.uk
Vidar payload delivery domain (confidence level: 100%)
domainpizzadoughrollers.ca
Vidar payload delivery domain (confidence level: 100%)
domainrodrigooliveiracontabil.com.br
Vidar payload delivery domain (confidence level: 100%)
domainsalzhomecare.com
Vidar payload delivery domain (confidence level: 100%)
domainseingetronic.com
Vidar payload delivery domain (confidence level: 100%)
domainshimanto-kango.ac.jp
Vidar payload delivery domain (confidence level: 100%)
domainsouthcoastflagging.com
Vidar payload delivery domain (confidence level: 100%)
domainsunscapehills.com
Vidar payload delivery domain (confidence level: 100%)
domaintechnocraft.fr
Vidar payload delivery domain (confidence level: 100%)
domaincookingrt.com
Vidar payload delivery domain (confidence level: 100%)
domaindonmontero.pl
Vidar payload delivery domain (confidence level: 100%)
domainfabiopischedda.it
Vidar payload delivery domain (confidence level: 100%)
domainthunderplanethub.top
SmartApeSG payload delivery domain (confidence level: 100%)
domainnorthernbridgeworks.com
SmartApeSG payload delivery domain (confidence level: 100%)
domainetokrol.lol
Vidar payload delivery domain (confidence level: 100%)
domaingovnol.lat
Vidar payload delivery domain (confidence level: 100%)
domainmyblobtop.site
Vidar payload delivery domain (confidence level: 100%)
domainacxmquqg.winter-pulse.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainrpc-cloud.beer
Vidar botnet C2 domain (confidence level: 100%)
domainrpc-framework-check.cfd
Vidar botnet C2 domain (confidence level: 100%)
domainrpc-framework-check.click
Vidar botnet C2 domain (confidence level: 100%)
domainrpc-polygon.beer
Vidar botnet C2 domain (confidence level: 100%)
domainsdn-cloudflare-js-css.cfd
Vidar botnet C2 domain (confidence level: 100%)
domainsdn-cloudflare-js-css.click
Vidar botnet C2 domain (confidence level: 100%)
domainsiteamnsserv.beer
Vidar botnet C2 domain (confidence level: 100%)
domainsmnsdns.beer
Vidar botnet C2 domain (confidence level: 100%)
domainstore-image.sbs
Vidar botnet C2 domain (confidence level: 100%)
domainstore-image.shop
Vidar botnet C2 domain (confidence level: 100%)
domainstyles-get-img.cfd
Vidar botnet C2 domain (confidence level: 100%)
domaintesterlau.lat
Vidar botnet C2 domain (confidence level: 100%)
domaintesthostrouter.onthewifi.com
Vidar botnet C2 domain (confidence level: 100%)
domaintestsoryy.hopto.org
Vidar botnet C2 domain (confidence level: 100%)
domainvaer-cdn-3.sbs
Vidar botnet C2 domain (confidence level: 100%)
domainvblbs.beer
Vidar botnet C2 domain (confidence level: 100%)
domainvdsinatest.beer
Vidar botnet C2 domain (confidence level: 100%)
domainvisual-ns-portal.beer
Vidar botnet C2 domain (confidence level: 100%)
domainwinupdate.cfd
Vidar botnet C2 domain (confidence level: 100%)
domainwinupdateconf.cfd
Vidar botnet C2 domain (confidence level: 100%)
domainworkcdnmass.beer
Vidar botnet C2 domain (confidence level: 100%)
domainftjilgqw.winter-pulse.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainlsnsdns.beer
Vidar botnet C2 domain (confidence level: 100%)
domainlstyle-sdn.sbs
Vidar botnet C2 domain (confidence level: 100%)
domainlvlensourgat.sbs
Vidar botnet C2 domain (confidence level: 100%)
domainminecraft65server.3utilities.com
Vidar botnet C2 domain (confidence level: 100%)
domainminecraftserverapigame.xyz
Vidar botnet C2 domain (confidence level: 100%)
domainnascdn-js.click
Vidar botnet C2 domain (confidence level: 100%)
domainnascdn-js.life
Vidar botnet C2 domain (confidence level: 100%)
domainnetworksolutionson.sbs
Vidar botnet C2 domain (confidence level: 100%)
domainnstv-css-styles-19.sbs
Vidar botnet C2 domain (confidence level: 100%)
domainntsnsdns.beer
Vidar botnet C2 domain (confidence level: 100%)
domainpoygon-notifications.cfd
Vidar botnet C2 domain (confidence level: 100%)
domainpoygon-notifications.click
Vidar botnet C2 domain (confidence level: 100%)
domainistile-c-cloud.beer
Vidar botnet C2 domain (confidence level: 100%)
domainjs-server.beer
Vidar botnet C2 domain (confidence level: 100%)
domainl3cdnns.beer
Vidar botnet C2 domain (confidence level: 100%)
domainlasthauszver.beer
Vidar botnet C2 domain (confidence level: 100%)
domainimage-hoster11.sbs
Vidar botnet C2 domain (confidence level: 100%)
domainimg-cdn-cloud.cfd
Vidar botnet C2 domain (confidence level: 100%)
domainimg-cdn-cloud.click
Vidar botnet C2 domain (confidence level: 100%)
domainferlik.shop
Vidar botnet C2 domain (confidence level: 100%)
domainfontawesome-cdn.cfd
Vidar botnet C2 domain (confidence level: 100%)
domainfontawesome-js-ico.beer
Vidar botnet C2 domain (confidence level: 100%)
domainfonts-fontawesome.cfd
Vidar botnet C2 domain (confidence level: 100%)
domainfonts25-save.sbs
Vidar botnet C2 domain (confidence level: 100%)
domainghdnsserverns.beer
Vidar botnet C2 domain (confidence level: 100%)
domaincdn-clodflare-fotns.cfd
Vidar botnet C2 domain (confidence level: 100%)
domaincdn-js-conhost.click
Vidar botnet C2 domain (confidence level: 100%)
domaincdn-js-conhost.icu
Vidar botnet C2 domain (confidence level: 100%)
domaincdn-server-styles.cfd
Vidar botnet C2 domain (confidence level: 100%)
domaincdn-server-styles.click
Vidar botnet C2 domain (confidence level: 100%)
domaincdn-server.beer
Vidar botnet C2 domain (confidence level: 100%)
domaincdn-server.click
Vidar botnet C2 domain (confidence level: 100%)
domaincdnjsdelivr.beer
Vidar botnet C2 domain (confidence level: 100%)
domainchekbrow.beer
Vidar botnet C2 domain (confidence level: 100%)
domaincloud-safe.cfd
Vidar botnet C2 domain (confidence level: 100%)
domaincloud-safe.click
Vidar botnet C2 domain (confidence level: 100%)
domainclpcentr.world
Vidar botnet C2 domain (confidence level: 100%)
domainclpuanmeserver.shop
Vidar botnet C2 domain (confidence level: 100%)
domainclpuserabcserver.xyz
Vidar botnet C2 domain (confidence level: 100%)
domainclpusserver.xyz
Vidar botnet C2 domain (confidence level: 100%)
domaindev-js-cdn.cfd
Vidar botnet C2 domain (confidence level: 100%)
domaindev.clpcentr.world
Vidar botnet C2 domain (confidence level: 100%)
domaindreff-nsdns.beer
Vidar botnet C2 domain (confidence level: 100%)
domainbacloudserver.beer
Vidar botnet C2 domain (confidence level: 100%)
domainbbdsnssserver.beer
Vidar botnet C2 domain (confidence level: 100%)
domainbcncdncl-ns.beer
Vidar botnet C2 domain (confidence level: 100%)
domainbedcdnset.beer
Vidar botnet C2 domain (confidence level: 100%)
domainbest-claudns-js.beer
Vidar botnet C2 domain (confidence level: 100%)
domainbigsmart.beer
Vidar botnet C2 domain (confidence level: 100%)
domainbootstrap-css-framework.cfd
Vidar botnet C2 domain (confidence level: 100%)
domainbssapi.click
Vidar botnet C2 domain (confidence level: 100%)
domaincaptcha-cds.cfd
Vidar botnet C2 domain (confidence level: 100%)
domaincaptcha-cds.click
Vidar botnet C2 domain (confidence level: 100%)
domain2fa-cp.cfd
Vidar botnet C2 domain (confidence level: 100%)
domain2fa-cp.click
Vidar botnet C2 domain (confidence level: 100%)
domainnet883.com
Nanocore RAT botnet C2 domain (confidence level: 75%)
domainmvltyody.frost-engine.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainauhlsdki.frost-engine.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainholiday-matrix.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainymeivxaj.holiday-matrix.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainhoycbijv.holiday-matrix.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainbetnoise-unionour.cyou
ClearFake payload delivery domain (confidence level: 100%)
domainmfbrkbuv.betnoise-unionour.cyou
ClearFake payload delivery domain (confidence level: 100%)
domainflopstin-gymcargo.cyou
ClearFake payload delivery domain (confidence level: 100%)
domainmkszunli.flopstin-gymcargo.cyou
ClearFake payload delivery domain (confidence level: 100%)
domainipv4has-lampnew.cyou
ClearFake payload delivery domain (confidence level: 100%)
domainilhvyrij.ipv4has-lampnew.cyou
ClearFake payload delivery domain (confidence level: 100%)
domaindebugshy-fansync.cyou
ClearFake payload delivery domain (confidence level: 100%)
domainmckglhnz.holiday-matrix.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainihtfqktk.holiday-matrix.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainbrhwmjkk.frost-engine.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainhzlqlpfw.frost-engine.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainpaqcfwvt.winter-pulse.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainthdnyyif.winter-pulse.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainxusyyrhk.gift-lattice.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainmokmgdal.gift-lattice.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainynkcoqkg.snow-harbor.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainukkqtbst.snow-harbor.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainhayedi.sa.com
Nanocore RAT botnet C2 domain (confidence level: 75%)
domainxiidysrc.xenomorphhiveintel.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainlzascdxk.xenomorphhiveintel.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainacfcjsbi.gift-lattice.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainbadxqjge.gift-lattice.christmas
ClearFake payload delivery domain (confidence level: 100%)
domaincomputationalgrid.com
ClearFake payload delivery domain (confidence level: 100%)
domainpvnhnpre.computationalgrid.com
ClearFake payload delivery domain (confidence level: 100%)
domaineuftrhnx.computationalgrid.com
ClearFake payload delivery domain (confidence level: 100%)
domainqmxvwfew.winter-pulse.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainetc-cte.org
Nanocore RAT botnet C2 domain (confidence level: 75%)
domainbj88play.games
Remcos botnet C2 domain (confidence level: 75%)
domainga888vn.ru.com
Remcos botnet C2 domain (confidence level: 75%)
domaingb-westerveld.nl
Remcos botnet C2 domain (confidence level: 75%)
domaingrell.nl
Remcos botnet C2 domain (confidence level: 75%)
domainledele.de
Remcos botnet C2 domain (confidence level: 75%)
domainselectkoi.nl
Remcos botnet C2 domain (confidence level: 75%)
domainvuurwerkwinkeldordrecht.nl
Remcos botnet C2 domain (confidence level: 75%)
domainvksprfuc.winter-pulse.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainsmuufy.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainfjqantqo.winter-pulse.christmas
ClearFake payload delivery domain (confidence level: 100%)
domaindsthypsv.winter-pulse.christmas
ClearFake payload delivery domain (confidence level: 100%)
domaintmmlokbk.winter-pulse.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainqrxnqauz.winter-pulse.christmas
ClearFake payload delivery domain (confidence level: 100%)
domaincyy.fbvendas.com
Vidar botnet C2 domain (confidence level: 100%)
domainc2.slagerijbloem.nl
AsyncRAT botnet C2 domain (confidence level: 75%)
domainmalware.seegersbelettering.nl
AsyncRAT botnet C2 domain (confidence level: 75%)
domainheap-lawcert.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainzhqqgpts.heap-lawcert.christmas
ClearFake payload delivery domain (confidence level: 100%)
domaindzhjdyty.raw-cert-bigzlib.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainzsrfochj.junitdog-ipv6-try.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainzythdolm.cn
ValleyRAT botnet C2 domain (confidence level: 100%)
domaingxfsxs.cn
ValleyRAT botnet C2 domain (confidence level: 100%)
domainpegasjam-wikieye.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainyazervan.pegasjam-wikieye.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainbhisdvrm.probe-got-vmnetmob.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainzvkzxqai.snow-packet-hub.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainapi.cloudservicecon.com
Unknown Webinject credit card skimming domain (confidence level: 100%)
domaintqccotdd.gift-runtime-engine.christmas
ClearFake payload delivery domain (confidence level: 100%)
domaintkrlojuc.wintersync.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainnuynpeej.frost-network-platform.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainkmhgspmw.holiday-control-node.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainadpptgxb.bell-processing-core.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainlkxwuddc.northworkflow.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainhxxxrrqo.northworkflow.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainsanta-resource-engine.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainqwcwsiiz.santa-resource-engine.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainuudbsfju.evergreen-routing-system.christmas
ClearFake payload delivery domain (confidence level: 100%)
domaingsngaxof.reindeer-cluster-hub.christmas
ClearFake payload delivery domain (confidence level: 100%)
domaineitxotup.icicle-processing-engine.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainemcqesvk.garland-network-hub.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainhvfojddm.mistletoe-control-platform.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainytiobnml.candlerouting.christmas
ClearFake payload delivery domain (confidence level: 100%)
domaingaijyzda.ornament-distribution-node.christmas
ClearFake payload delivery domain (confidence level: 100%)
domain123b-mb.com
AsyncRAT botnet C2 domain (confidence level: 75%)
domainsxawufyj.sled-resource-framework.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainiltpbkuv.snowflakecluster.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainproxy-frontier.digital
ClearFake payload delivery domain (confidence level: 100%)
domainzvh595js.proxy-frontier.digital
ClearFake payload delivery domain (confidence level: 100%)
domain9v42ch67.proxy-frontier.digital
ClearFake payload delivery domain (confidence level: 100%)
domainilvspowf.chimney-sync-engine.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainkbmlndkx.holly-processing-system.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainazfnlhbk.starlight-workflow-hub.christmas
ClearFake payload delivery domain (confidence level: 100%)
domainnlwbkskj.lhoperations.com
ClearFake payload delivery domain (confidence level: 100%)
domainpolikov.hu
ClearFake payload delivery domain (confidence level: 100%)
domaindmong.io
AsyncRAT botnet C2 domain (confidence level: 75%)
domainbalanceyourlife.hu
ClearFake payload delivery domain (confidence level: 100%)
domainonlinebettingsite.us.com
AsyncRAT botnet C2 domain (confidence level: 75%)
domain28.hu
ClearFake payload delivery domain (confidence level: 100%)
domain2emelet.hu
ClearFake payload delivery domain (confidence level: 100%)
domainvsactivens.sbs
Unknown malware payload delivery domain (confidence level: 100%)
domainnextpgh3.com
Unknown malware payload delivery domain (confidence level: 100%)
domaintotalads.monster
Unknown malware payload delivery domain (confidence level: 100%)
domainpicturequitting.monster
Unknown malware payload delivery domain (confidence level: 100%)
domainadvex.monster
Unknown malware payload delivery domain (confidence level: 100%)
domainmhaskins.top
Unknown malware payload delivery domain (confidence level: 100%)
domainsmtnscerver.beer
Unknown malware payload delivery domain (confidence level: 100%)
domainfredcreate.beer
Unknown malware payload delivery domain (confidence level: 100%)
domainbootstrup-framework-js.beer
Unknown malware payload delivery domain (confidence level: 100%)
domainunacerveza.beer
Unknown malware payload delivery domain (confidence level: 100%)
domaingraciasdenada.beer
Unknown malware payload delivery domain (confidence level: 100%)
domainmdzgddyj.7naposokosotthonkihivas.hu
ClearFake payload delivery domain (confidence level: 100%)
domainkpghbfvn.8route.hu
ClearFake payload delivery domain (confidence level: 100%)
domaingmokdazc.aapartman.hu
ClearFake payload delivery domain (confidence level: 100%)
domaincyy.turbo88ml.top
Vidar botnet C2 domain (confidence level: 100%)
domainavhepv.aapartman.hu
ClearFake payload delivery domain (confidence level: 100%)
domainaenysk.aborszerintem.hu
ClearFake payload delivery domain (confidence level: 100%)
domainykpwsn.accredit.hu
ClearFake payload delivery domain (confidence level: 100%)
domainbkbtgg.accredit.hu
ClearFake payload delivery domain (confidence level: 100%)
domainqxoopq.bmiroda.hu
ClearFake payload delivery domain (confidence level: 100%)
domainsx932d8l.network-foundry.digital
ClearFake payload delivery domain (confidence level: 100%)
domainy4gf3n18.network-foundry.digital
ClearFake payload delivery domain (confidence level: 100%)
domainbmz.hu
ClearFake payload delivery domain (confidence level: 100%)
domaindoishd.bmz.hu
ClearFake payload delivery domain (confidence level: 100%)
domainbni-ai.com
ClearFake payload delivery domain (confidence level: 100%)
domainyyaohk.bni-ai.com
ClearFake payload delivery domain (confidence level: 100%)
domaindkqaxl.bninolimit.com
ClearFake payload delivery domain (confidence level: 100%)
domaineisnuo.bognarautomoso.hu
ClearFake payload delivery domain (confidence level: 100%)
domainmtlhms.bognartransport.hu
ClearFake payload delivery domain (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://claudemo.net/infos.php?fronts=1
Unknown malware payload delivery URL (confidence level: 85%)
urlhttp://mascard.biz:8768
Remus payload delivery URL (confidence level: 50%)
urlhttps://thunderplanethub.top/role/rate-hook
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://thunderplanethub.top/role/principal-validator.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://178.156.199.54
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://5.161.235.47
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://northernbridgeworks.com/more
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://103.144.245.73:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://faisst-vorburger.ch/
Vidar payload delivery URL (confidence level: 75%)
urlhttp://45.148.10.210/hostmane
Mirai payload delivery URL (confidence level: 85%)
urlhttp://45.148.10.210/blackbih
Mirai payload delivery URL (confidence level: 85%)
urlhttp://45.148.10.210/blackboi
Mirai payload delivery URL (confidence level: 85%)
urlhttp://45.148.10.210/listener
Mirai payload delivery URL (confidence level: 85%)
urlhttp://151.242.125.187/dck
Dofloo payload delivery URL (confidence level: 85%)
urlhttp://87.121.79.193/dck
Dofloo payload delivery URL (confidence level: 80%)
urlhttp://87.121.79.73/dck
Dofloo payload delivery URL (confidence level: 80%)
urlhttp://107.189.3.150/b2f628/cronb.sh
RedTail payload delivery URL (confidence level: 90%)
urlhttp://140.99.32.48/b2f628/cronb.sh
RedTail payload delivery URL (confidence level: 85%)
urlhttp://205.185.118.246/b2f628/cronb.sh
RedTail payload delivery URL (confidence level: 90%)
urlhttp://209.141.58.166/b2f628/cronb.sh
RedTail payload delivery URL (confidence level: 90%)
urlhttp://b.9-9-8.com/brysj/cronb.sh
RedTail payload delivery URL (confidence level: 85%)
urlhttp://176.65.139.43/lessram.pl
Unknown malware payload delivery URL (confidence level: 85%)
urlhttps://sites.google.com/view/hiddenhub
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://cyy.fbvendas.com/
Vidar botnet C2 (confidence level: 100%)
urlhttp://170.130.55.223/8a5722931e174543a98d.php
Stealc botnet C2 (confidence level: 100%)
urlhttps://cyy.turbo88ml.top/
Vidar botnet C2 (confidence level: 100%)

Threat ID: 6a12435b09f6977edb7cea97

Added to database: 5/24/2026, 12:16:27 AM

Last enriched: 5/24/2026, 12:16:33 AM

Last updated: 5/24/2026, 5:32:27 AM

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses