Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-05-25

0
Medium
Published: Mon May 25 2026 (05/25/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-05-25

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/26/2026, 00:09:51 UTC

Technical Analysis

The provided data represents a set of malware-related IOCs published on 2026-05-25 by the ThreatFox MISP Feed. It is classified as OSINT with a focus on payload delivery and network activity. No specific software versions are affected, and no known exploits are currently active in the wild. The threat level is moderate, with no available patches or fixes. The data is intended for situational awareness and threat detection rather than indicating a direct vulnerability or exploit.

Potential Impact

The threat is categorized as medium severity malware activity involving payload delivery and network behavior. There are no known active exploits or affected software versions, so the immediate impact appears limited to detection and monitoring. No direct patch or remediation is applicable as this is an intelligence feed rather than a vulnerability report.

Mitigation Recommendations

Since this is an OSINT feed providing IOCs without a specific vulnerability or patch, no direct remediation or patch is available. Security teams should incorporate these IOCs into their detection and monitoring tools to enhance situational awareness. No urgent action is required beyond standard threat intelligence integration.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
122768a7-62ab-46a2-a47e-b0c5bd171858
Original Timestamp
1779753789

Indicators of Compromise

File

ValueDescriptionCopy
file89.23.108.134
Unknown malware payload delivery server (confidence level: 80%)
file42.51.37.74
VShell botnet C2 server (confidence level: 100%)
file178.154.253.119
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.202.18
Sliver botnet C2 server (confidence level: 100%)
file178.154.224.141
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.138.192.16
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.138.192.16
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.148.72.173
VShell botnet C2 server (confidence level: 100%)
file1.92.95.105
Cobalt Strike botnet C2 server (confidence level: 50%)
file197.147.49.135
AsyncRAT botnet C2 server (confidence level: 50%)
file178.154.252.244
Cobalt Strike botnet C2 server (confidence level: 100%)
file111.228.0.252
VShell botnet C2 server (confidence level: 100%)
file139.84.242.161
VShell botnet C2 server (confidence level: 100%)
file217.194.133.112
VShell botnet C2 server (confidence level: 100%)
file88.119.167.142
AdaptixC2 botnet C2 server (confidence level: 100%)
file88.119.167.142
AdaptixC2 botnet C2 server (confidence level: 100%)
file178.154.192.211
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.218.92
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.197.33
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.197.84
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.217.149
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.195.3
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.241.10
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.204.219
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.246.238
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.225.21
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.221.167
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.231.45
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.214.82
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.254.6
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.240.132
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.252.97
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.221.93
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.197.224
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.154.206.19
Cobalt Strike botnet C2 server (confidence level: 100%)
file88.119.167.142
AdaptixC2 botnet C2 server (confidence level: 100%)
file192.3.176.241
AsyncRAT botnet C2 server (confidence level: 100%)
file157.20.182.18
AsyncRAT botnet C2 server (confidence level: 100%)
file157.20.182.17
AsyncRAT botnet C2 server (confidence level: 100%)
file157.20.182.17
AsyncRAT botnet C2 server (confidence level: 100%)
file27.124.45.118
ValleyRAT botnet C2 server (confidence level: 75%)
file27.124.45.97
ValleyRAT botnet C2 server (confidence level: 75%)
file178.154.222.195
Cobalt Strike botnet C2 server (confidence level: 85%)
file178.154.208.54
Cobalt Strike botnet C2 server (confidence level: 85%)
file178.154.203.218
Cobalt Strike botnet C2 server (confidence level: 85%)
file178.154.202.31
Cobalt Strike botnet C2 server (confidence level: 85%)
file178.154.253.223
Cobalt Strike botnet C2 server (confidence level: 85%)
file178.154.225.78
Cobalt Strike botnet C2 server (confidence level: 85%)
file178.154.209.249
Cobalt Strike botnet C2 server (confidence level: 85%)
file178.154.233.48
Cobalt Strike botnet C2 server (confidence level: 85%)
file178.154.223.251
Cobalt Strike botnet C2 server (confidence level: 85%)
file119.91.254.26
Cobalt Strike botnet C2 server (confidence level: 100%)
file134.175.78.181
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.136.217.32
Cobalt Strike botnet C2 server (confidence level: 100%)
file157.20.182.17
AsyncRAT botnet C2 server (confidence level: 100%)
file47.239.20.75
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.239.20.75
Cobalt Strike botnet C2 server (confidence level: 100%)
file37.120.163.114
Cobalt Strike botnet C2 server (confidence level: 70%)
file37.120.139.245
Cobalt Strike botnet C2 server (confidence level: 70%)
file47.239.20.75
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.210.103.84
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.210.103.84
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.210.103.84
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.135.18.143
VShell botnet C2 server (confidence level: 100%)
file185.188.119.7
Cobalt Strike botnet C2 server (confidence level: 70%)
file185.188.72.28
Cobalt Strike botnet C2 server (confidence level: 70%)
file45.67.216.142
Cobalt Strike botnet C2 server (confidence level: 70%)
file64.118.131.36
VShell botnet C2 server (confidence level: 100%)
file198.46.159.243
VShell botnet C2 server (confidence level: 100%)
file192.227.212.57
VShell botnet C2 server (confidence level: 100%)
file184.82.98.158
Havoc botnet C2 server (confidence level: 100%)
file109.110.188.156
Chaos botnet C2 server (confidence level: 75%)
file157.20.182.17
AsyncRAT botnet C2 server (confidence level: 75%)
file157.20.182.18
AsyncRAT botnet C2 server (confidence level: 75%)
file195.114.193.56
Unknown malware botnet C2 server (confidence level: 75%)
file83.142.209.64
DCRat botnet C2 server (confidence level: 75%)
file158.51.96.38
Unknown malware payload delivery server (confidence level: 80%)
file151.59.141.196
SectopRAT botnet C2 server (confidence level: 75%)
file217.60.98.113
SectopRAT botnet C2 server (confidence level: 75%)
file146.103.115.182
SectopRAT botnet C2 server (confidence level: 75%)
file154.41.194.132
Xtreme RAT botnet C2 server (confidence level: 75%)
file38.124.86.253
Xtreme RAT botnet C2 server (confidence level: 75%)
file121.37.200.35
Cobalt Strike botnet C2 server (confidence level: 50%)
file193.29.58.188
Cobalt Strike botnet C2 server (confidence level: 50%)
file45.67.230.81
Cobalt Strike botnet C2 server (confidence level: 70%)
file194.58.76.12
Cobalt Strike botnet C2 server (confidence level: 70%)
file194.58.126.182
Cobalt Strike botnet C2 server (confidence level: 70%)
file45.153.127.224
Chaos botnet C2 server (confidence level: 50%)
file47.238.154.144
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.238.154.144
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.238.154.144
Cobalt Strike botnet C2 server (confidence level: 100%)
file207.180.250.181
AsyncRAT botnet C2 server (confidence level: 100%)
file157.20.182.17
AsyncRAT botnet C2 server (confidence level: 100%)
file178.16.54.226
Unknown malware payload delivery server (confidence level: 80%)
file194.58.93.75
Cobalt Strike botnet C2 server (confidence level: 70%)
file192.210.150.44
Unknown malware payload delivery server (confidence level: 80%)
file194.32.248.126
Unknown malware payload delivery server (confidence level: 90%)
file138.9.41.208
Remcos botnet C2 server (confidence level: 75%)
file155.103.71.232
Remcos botnet C2 server (confidence level: 75%)
file157.20.182.17
AsyncRAT botnet C2 server (confidence level: 75%)
file157.20.182.18
AsyncRAT botnet C2 server (confidence level: 75%)
file178.16.54.208
Remcos botnet C2 server (confidence level: 75%)
file185.122.166.184
AsyncRAT botnet C2 server (confidence level: 75%)
file188.137.239.44
AsyncRAT botnet C2 server (confidence level: 75%)
file202.95.8.92
AdaptixC2 botnet C2 server (confidence level: 75%)
file27.102.137.139
Remcos botnet C2 server (confidence level: 75%)
file37.77.150.174
Eye Pyramid botnet C2 server (confidence level: 75%)
file37.77.150.174
Eye Pyramid botnet C2 server (confidence level: 75%)
file45.154.98.254
Remcos botnet C2 server (confidence level: 75%)
file45.56.162.61
RansomHub botnet C2 server (confidence level: 75%)
file45.56.162.61
RansomHub botnet C2 server (confidence level: 75%)
file5.101.82.98
Remcos botnet C2 server (confidence level: 75%)
file5.101.83.143
Remcos botnet C2 server (confidence level: 75%)
file54.196.247.235
DanaBot botnet C2 server (confidence level: 75%)
file91.92.242.64
AsyncRAT botnet C2 server (confidence level: 75%)
file138.124.79.146
FAKEUPDATES payload delivery server (confidence level: 100%)
file43.156.42.49
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.108.25.113
Cobalt Strike botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash80
Unknown malware payload delivery server (confidence level: 80%)
hash81deb32cde378e3886a7bfb6e0b9dff6dc34a5d0
Unknown Stealer payload (confidence level: 100%)
hashf250b75677d5e944e5ab5fbba5e04b08f3ba9354
Unknown Stealer payload (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8090
VShell botnet C2 server (confidence level: 100%)
hash8889
Cobalt Strike botnet C2 server (confidence level: 50%)
hash5000
AsyncRAT botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash888
VShell botnet C2 server (confidence level: 100%)
hash11000
VShell botnet C2 server (confidence level: 100%)
hash443
AdaptixC2 botnet C2 server (confidence level: 100%)
hash80
AdaptixC2 botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
AdaptixC2 botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash4444
AsyncRAT botnet C2 server (confidence level: 100%)
hash1337
AsyncRAT botnet C2 server (confidence level: 100%)
hash1338
AsyncRAT botnet C2 server (confidence level: 100%)
hash3391
ValleyRAT botnet C2 server (confidence level: 75%)
hash3390
ValleyRAT botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 85%)
hash443
Cobalt Strike botnet C2 server (confidence level: 85%)
hash443
Cobalt Strike botnet C2 server (confidence level: 85%)
hash443
Cobalt Strike botnet C2 server (confidence level: 85%)
hash443
Cobalt Strike botnet C2 server (confidence level: 85%)
hash443
Cobalt Strike botnet C2 server (confidence level: 85%)
hash443
Cobalt Strike botnet C2 server (confidence level: 85%)
hash443
Cobalt Strike botnet C2 server (confidence level: 85%)
hash443
Cobalt Strike botnet C2 server (confidence level: 85%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9999
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4444
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 70%)
hash443
Cobalt Strike botnet C2 server (confidence level: 70%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 70%)
hash443
Cobalt Strike botnet C2 server (confidence level: 70%)
hash443
Cobalt Strike botnet C2 server (confidence level: 70%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash2086
VShell botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
Chaos botnet C2 server (confidence level: 75%)
hash6666
AsyncRAT botnet C2 server (confidence level: 75%)
hash6666
AsyncRAT botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash35630
DCRat botnet C2 server (confidence level: 75%)
hash80
Unknown malware payload delivery server (confidence level: 80%)
hash8080
SectopRAT botnet C2 server (confidence level: 75%)
hash9000
SectopRAT botnet C2 server (confidence level: 75%)
hash9000
SectopRAT botnet C2 server (confidence level: 75%)
hash139
Xtreme RAT botnet C2 server (confidence level: 75%)
hash445
Xtreme RAT botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 70%)
hash443
Cobalt Strike botnet C2 server (confidence level: 70%)
hash443
Cobalt Strike botnet C2 server (confidence level: 70%)
hash8080
Chaos botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash30700
AsyncRAT botnet C2 server (confidence level: 100%)
hash4443
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Unknown malware payload delivery server (confidence level: 80%)
hash443
Cobalt Strike botnet C2 server (confidence level: 70%)
hash80
Unknown malware payload delivery server (confidence level: 80%)
hash3333
Unknown malware payload delivery server (confidence level: 90%)
hash4dc1958010564d8482320890ef4bdc35e1055e2023ce6cd7588a9044a221553f
Unknown malware payload (confidence level: 90%)
hashee01795618295e975dca07d025f20bbcaec559ecbcefc15dd813a3437c5bd989
Unknown malware payload (confidence level: 90%)
hashbc6e0a5693e0b6bf2997a7c93c31d2ef2c351a35fdf81a02df33ff1df7bdf784
Unknown malware payload (confidence level: 90%)
hashe96d103b7982cf988bffe33ce6eb066d25a830fb53e58da536a847ce2139d45b
Unknown malware payload (confidence level: 90%)
hash46c1a2426b2213b770cadb674591c8998b965273cadf1bc84ccfb5901d96e337
Unknown malware payload (confidence level: 90%)
hash316e131a04cc717d2912d371c80e016eb89cf2bb9b02eb42c2a53167422465e2
Unknown malware payload (confidence level: 90%)
hash9bb90d779fc12b6a10036b5477613d72a9da0612a677ae88843f79944d37801b
Unknown malware payload (confidence level: 90%)
hashc6d9ba54fffc9c7638e04df63e0bdd7f99daecd6b7bdb347d05a30fe16d68c7d
Unknown malware payload (confidence level: 90%)
hash88f4b2193b87a76bbf56fdb7c282438f2d07a320784b2fa663ac45776ccd8bec
Unknown malware payload (confidence level: 90%)
hash8015
Remcos botnet C2 server (confidence level: 75%)
hash15406
Remcos botnet C2 server (confidence level: 75%)
hash1998
AsyncRAT botnet C2 server (confidence level: 75%)
hash1992
AsyncRAT botnet C2 server (confidence level: 75%)
hash61099
Remcos botnet C2 server (confidence level: 75%)
hash7707
AsyncRAT botnet C2 server (confidence level: 75%)
hash54298
AsyncRAT botnet C2 server (confidence level: 75%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 75%)
hash1243
Remcos botnet C2 server (confidence level: 75%)
hash4332
Eye Pyramid botnet C2 server (confidence level: 75%)
hash4333
Eye Pyramid botnet C2 server (confidence level: 75%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash443
RansomHub botnet C2 server (confidence level: 75%)
hash6031
RansomHub botnet C2 server (confidence level: 75%)
hash42859
Remcos botnet C2 server (confidence level: 75%)
hash7312
Remcos botnet C2 server (confidence level: 75%)
hash8082
DanaBot botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash443
FAKEUPDATES payload delivery server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)

Domain

ValueDescriptionCopy
domainreceipt-view.com
Unknown malware payload delivery domain (confidence level: 75%)
domaincoinbase.receipt-view.com
Unknown malware payload delivery domain (confidence level: 75%)
domainbysjry.fusionize.org
ClearFake payload delivery domain (confidence level: 100%)
domainwy809hmu.container-bridge.digital
ClearFake payload delivery domain (confidence level: 100%)
domainm8fpbfz3.container-bridge.digital
ClearFake payload delivery domain (confidence level: 100%)
domainohowxc.gamesystem.hu
ClearFake payload delivery domain (confidence level: 100%)
domainrapiny.gamesystem.hu
ClearFake payload delivery domain (confidence level: 100%)
domaindoigau.geokalk.hu
ClearFake payload delivery domain (confidence level: 100%)
domainqcjqcd.geokalk.hu
ClearFake payload delivery domain (confidence level: 100%)
domainztwwcx.gerecseglamping.com
ClearFake payload delivery domain (confidence level: 100%)
domainsneodo.gerecseglamping.com
ClearFake payload delivery domain (confidence level: 100%)
domaineyqlyo.gerecseglamping.hu
ClearFake payload delivery domain (confidence level: 100%)
domaintugovc.gesol.hu
ClearFake payload delivery domain (confidence level: 100%)
domainuekdrl.gesol.hu
ClearFake payload delivery domain (confidence level: 100%)
domainh8w5a5u0.proxy-orbit.digital
ClearFake payload delivery domain (confidence level: 100%)
domainbzngye4l.proxy-orbit.digital
ClearFake payload delivery domain (confidence level: 100%)
domainglfree.hu
ClearFake payload delivery domain (confidence level: 100%)
domaingcrexj.glfree.hu
ClearFake payload delivery domain (confidence level: 100%)
domainnwjlgv.glfree.hu
ClearFake payload delivery domain (confidence level: 100%)
domainuzrekc.globalcontact.hu
ClearFake payload delivery domain (confidence level: 100%)
domainhatvtf.globalcontact.hu
ClearFake payload delivery domain (confidence level: 100%)
domaingreenwaysolar.hu
ClearFake payload delivery domain (confidence level: 100%)
domainzbzldh.greenwaysolar.hu
ClearFake payload delivery domain (confidence level: 100%)
domainfayzcm.greenwaysolar.hu
ClearFake payload delivery domain (confidence level: 100%)
domainnvxgxz.gulyaskriszti.hu
ClearFake payload delivery domain (confidence level: 100%)
domainvgkjld.gulyaskriszti.hu
ClearFake payload delivery domain (confidence level: 100%)
domainserver.us.org
AsyncRAT botnet C2 domain (confidence level: 75%)
domainsoaprise.me
AsyncRAT botnet C2 domain (confidence level: 75%)
domainxn88.se.net
AsyncRAT botnet C2 domain (confidence level: 75%)
domainkncqqq.gyorsanhaz.hu
ClearFake payload delivery domain (confidence level: 100%)
domainusoiuv.gyorsanhaz.hu
ClearFake payload delivery domain (confidence level: 100%)
domainstack-frontier.digital
ClearFake payload delivery domain (confidence level: 100%)
domain5bvcnkto.stack-frontier.digital
ClearFake payload delivery domain (confidence level: 100%)
domainrlaa5uje.stack-frontier.digital
ClearFake payload delivery domain (confidence level: 100%)
domainmjurmy.gyorsotthont.hu
ClearFake payload delivery domain (confidence level: 100%)
domainykdeqf.gyorsotthont.hu
ClearFake payload delivery domain (confidence level: 100%)
domainuwyaac.gyulaicsevego.hu
ClearFake payload delivery domain (confidence level: 100%)
domainrqwanh.gyulaicsevego.hu
ClearFake payload delivery domain (confidence level: 100%)
domainjuuaxu.h13lakopark.hu
ClearFake payload delivery domain (confidence level: 100%)
domainfoqovv.h13lakopark.hu
ClearFake payload delivery domain (confidence level: 100%)
domainsimplegiftsfarmcsa.com
Nanocore RAT botnet C2 domain (confidence level: 75%)
domainsekaikan.org
StrelaStealer payload delivery domain (confidence level: 100%)
domainpremierrentalpurchase.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainbrezxcchec.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainc56qm35r.proxy-orbit.digital
ClearFake payload delivery domain (confidence level: 100%)
domainn9bv1oq5.proxy-orbit.digital
ClearFake payload delivery domain (confidence level: 100%)
domainkdksfm.gyorsanhaz.hu
ClearFake payload delivery domain (confidence level: 100%)
domainfiwmth.gyorsanhaz.hu
ClearFake payload delivery domain (confidence level: 100%)
domainxrwunf.highlife-global.com
ClearFake payload delivery domain (confidence level: 100%)
domaintorrrj.highlife-global.com
ClearFake payload delivery domain (confidence level: 100%)
domaingnuvtk.holisztikuscsontkovacs.hu
ClearFake payload delivery domain (confidence level: 100%)
domainxredgj.holisztikuscsontkovacs.hu
ClearFake payload delivery domain (confidence level: 100%)
domainrgaxgg.hyflowtp.com
ClearFake payload delivery domain (confidence level: 100%)
domainkzaftq.hyflowtp.com
ClearFake payload delivery domain (confidence level: 100%)
domainindebud.hu
ClearFake payload delivery domain (confidence level: 100%)
domainblaold.indebud.hu
ClearFake payload delivery domain (confidence level: 100%)
domaindacfsh.indebud.hu
ClearFake payload delivery domain (confidence level: 100%)
domain7f2utlvn.telemetry-sphere.digital
ClearFake payload delivery domain (confidence level: 100%)
domainvzjahpug.telemetry-sphere.digital
ClearFake payload delivery domain (confidence level: 100%)
domainmprgta.inoxsystem.hu
ClearFake payload delivery domain (confidence level: 100%)
domainrosrcf.inoxsystem.hu
ClearFake payload delivery domain (confidence level: 100%)
domaineellner.lol
KongTuke payload delivery domain (confidence level: 100%)
domaincymctm.interimpro.hu
ClearFake payload delivery domain (confidence level: 100%)
domaingqsgdt.interimpro.hu
ClearFake payload delivery domain (confidence level: 100%)
domainfull-brown.com
Unknown malware botnet C2 domain (confidence level: 100%)
domain1364170351-fntufi0mu7.ap-guangzhou.tencentscf.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainoeclat.iparivillanyszerelo.hu
ClearFake payload delivery domain (confidence level: 100%)
domainfgyfhb.iparivillanyszerelo.hu
ClearFake payload delivery domain (confidence level: 100%)
domainschluter.lol
KongTuke payload delivery domain (confidence level: 100%)
domaindogqal.ispilates.hu
ClearFake payload delivery domain (confidence level: 100%)
domainvdbkti.ispilates.hu
ClearFake payload delivery domain (confidence level: 100%)
domain42ef9q7x.system-forge.digital
ClearFake payload delivery domain (confidence level: 100%)
domain3k3qw9fd.system-forge.digital
ClearFake payload delivery domain (confidence level: 100%)
domainitsmarthungary.hu
ClearFake payload delivery domain (confidence level: 100%)
domainqxyamp.itsmarthungary.hu
ClearFake payload delivery domain (confidence level: 100%)
domainkferlw.itsmarthungary.hu
ClearFake payload delivery domain (confidence level: 100%)
domaincqwaew.jatekotmindenkinek.hu
ClearFake payload delivery domain (confidence level: 100%)
domainhtfnjw.jatekotmindenkinek.hu
ClearFake payload delivery domain (confidence level: 100%)
domainspbbay.knminerals.hu
ClearFake payload delivery domain (confidence level: 100%)
domainglsvuu.knminerals.hu
ClearFake payload delivery domain (confidence level: 100%)
domainnqdscr.kokeny.com
ClearFake payload delivery domain (confidence level: 100%)
domainycmztd.kokeny.com
ClearFake payload delivery domain (confidence level: 100%)
domaincpanel.houston-familyoffice.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainkovacsago.com
ClearFake payload delivery domain (confidence level: 100%)
domainoynxty.kovacsago.com
ClearFake payload delivery domain (confidence level: 100%)
domainznbsrq.kovacsago.com
ClearFake payload delivery domain (confidence level: 100%)
domainn8t62ep9.stack-orbit.digital
ClearFake payload delivery domain (confidence level: 100%)
domain5ib6hoc4.stack-orbit.digital
ClearFake payload delivery domain (confidence level: 100%)
domainkovacsago.hu
ClearFake payload delivery domain (confidence level: 100%)
domaingdqsdd.kovacsago.hu
ClearFake payload delivery domain (confidence level: 100%)
domainecjimr.kovacsago.hu
ClearFake payload delivery domain (confidence level: 100%)
domainkrolikrojer.lat
Unknown malware botnet C2 domain (confidence level: 100%)
domainovoqxk.kpmarketing.hu
ClearFake payload delivery domain (confidence level: 100%)
domainfdgxxt.kpmarketing.hu
ClearFake payload delivery domain (confidence level: 100%)
domainxyzsm188.top
Vidar botnet C2 domain (confidence level: 75%)
domainasbaph.krisztinavarga.hu
ClearFake payload delivery domain (confidence level: 100%)
domainbxjmrg.krisztinavarga.hu
ClearFake payload delivery domain (confidence level: 100%)
domainnjunlh.krokodilpince.hu
ClearFake payload delivery domain (confidence level: 100%)
domainnspbcu.krokodilpince.hu
ClearFake payload delivery domain (confidence level: 100%)
domainksfogaszat.hu
ClearFake payload delivery domain (confidence level: 100%)
domainenuvdz.ksfogaszat.hu
ClearFake payload delivery domain (confidence level: 100%)
domainafun.it.com
Remcos botnet C2 domain (confidence level: 75%)
domaingoldenscissoreindhoven.nl
Remcos botnet C2 domain (confidence level: 75%)
domaintg77.it.com
Remcos botnet C2 domain (confidence level: 75%)
domainyellowred.in
Remcos botnet C2 domain (confidence level: 75%)
domainrxpvcd.ksfogaszat.hu
ClearFake payload delivery domain (confidence level: 100%)
domainqgatk150.script-nexus.digital
ClearFake payload delivery domain (confidence level: 100%)
domainmp696mc8.script-nexus.digital
ClearFake payload delivery domain (confidence level: 100%)
domainojbprh.krokodilpince.hu
ClearFake payload delivery domain (confidence level: 100%)
domainsagdxf.krokodilpince.hu
ClearFake payload delivery domain (confidence level: 100%)
domainlucidgardenhub.top
SmartApeSG payload delivery domain (confidence level: 100%)
domainbrightvoyagerstudio.com
SmartApeSG payload delivery domain (confidence level: 100%)
domaintcymfy.krokodilpince.hu
ClearFake payload delivery domain (confidence level: 100%)
domainkjvbjr.krokodilpince.hu
ClearFake payload delivery domain (confidence level: 100%)
domainremiumholdings.com
Latrodectus payload delivery domain (confidence level: 100%)
domainlestyanesfiai.hu
ClearFake payload delivery domain (confidence level: 100%)
domainrtixcz.lestyanesfiai.hu
ClearFake payload delivery domain (confidence level: 100%)
domainkxqxhh.lestyanesfiai.hu
ClearFake payload delivery domain (confidence level: 100%)
domainlevelupadventure.hu
ClearFake payload delivery domain (confidence level: 100%)
domainjexvgc.levelupadventure.hu
ClearFake payload delivery domain (confidence level: 100%)
domainoleavv.levelupadventure.hu
ClearFake payload delivery domain (confidence level: 100%)
domaingxxaob.levivilaga.hu
ClearFake payload delivery domain (confidence level: 100%)
domainudiqhj.levivilaga.hu
ClearFake payload delivery domain (confidence level: 100%)
domain8tdv3jg9.proxy-harbor.digital
ClearFake payload delivery domain (confidence level: 100%)
domainci7uxmq7.proxy-harbor.digital
ClearFake payload delivery domain (confidence level: 100%)
domainfendqt.lifealigned.hu
ClearFake payload delivery domain (confidence level: 100%)
domainqlhsnt.lifealigned.hu
ClearFake payload delivery domain (confidence level: 100%)
domainpaaglx.lifemax.hu
ClearFake payload delivery domain (confidence level: 100%)
domaincftxqt.lifemax.hu
ClearFake payload delivery domain (confidence level: 100%)
domaingcwuus.liftoff.hu
ClearFake payload delivery domain (confidence level: 100%)
domainqczybp.liftoff.hu
ClearFake payload delivery domain (confidence level: 100%)
domainmqhafu.lilbaukft.hu
ClearFake payload delivery domain (confidence level: 100%)
domainrpyrxh.lilbaukft.hu
ClearFake payload delivery domain (confidence level: 100%)
domaintvrywt.lillafunfit.com
ClearFake payload delivery domain (confidence level: 100%)
domaind3yac2xw.network-vector.digital
ClearFake payload delivery domain (confidence level: 100%)
domainuubbkkxd.network-vector.digital
ClearFake payload delivery domain (confidence level: 100%)
domainonwqrw.lillafunfit.com
ClearFake payload delivery domain (confidence level: 100%)
domainnwefud.lillafunfit.hu
ClearFake payload delivery domain (confidence level: 100%)
domainzjehuv.liltkereskedohaz.hu
ClearFake payload delivery domain (confidence level: 100%)
domainwdplqn.liltkereskedohaz.hu
ClearFake payload delivery domain (confidence level: 100%)
domainzawifk.liltkereskedohaz.hu
ClearFake payload delivery domain (confidence level: 100%)
domainiejzed.liltkereskedohaz.hu
ClearFake payload delivery domain (confidence level: 100%)
domaincwlzmg.lillafunfit.hu
ClearFake payload delivery domain (confidence level: 100%)
domainwzkdxp.nr1office.hu
ClearFake payload delivery domain (confidence level: 100%)
domainequinixad.monster
Unknown malware payload delivery domain (confidence level: 100%)
domainlegalreads.monster
Unknown malware payload delivery domain (confidence level: 100%)
domainmicroservice-compass.digital
ClearFake payload delivery domain (confidence level: 100%)
domain2hpvs1tu.microservice-compass.digital
ClearFake payload delivery domain (confidence level: 100%)
domain7louefau.microservice-compass.digital
ClearFake payload delivery domain (confidence level: 100%)
domainfmslna.nr1office.hu
ClearFake payload delivery domain (confidence level: 100%)
domainpjsxdd.nyitottkeramia.hu
ClearFake payload delivery domain (confidence level: 100%)
domainclainasns.beer
Unknown malware payload delivery domain (confidence level: 100%)
domainsbnsdns.beer
Unknown malware payload delivery domain (confidence level: 100%)
domainlvavdb.nyitottkeramia.hu
ClearFake payload delivery domain (confidence level: 100%)
domainxbyq.olcsongepet.hu
ClearFake payload delivery domain (confidence level: 100%)
domainoazd.olcsongepet.hu
ClearFake payload delivery domain (confidence level: 100%)
domaingzme.oltigergely.hu
ClearFake payload delivery domain (confidence level: 100%)
domainyvcg.oltigergely.hu
ClearFake payload delivery domain (confidence level: 100%)
domainaorx.olcsongepet.hu
ClearFake payload delivery domain (confidence level: 100%)
domainayov.olcsongepet.hu
ClearFake payload delivery domain (confidence level: 100%)
domainjtcy.oltigergely.hu
ClearFake payload delivery domain (confidence level: 100%)
domainodna.oltigergely.hu
ClearFake payload delivery domain (confidence level: 100%)
domaintpcu.oltigergo.hu
ClearFake payload delivery domain (confidence level: 100%)
domainwzfm.oltigergo.hu
ClearFake payload delivery domain (confidence level: 100%)
domainprmr.olyusvirag.hu
ClearFake payload delivery domain (confidence level: 100%)
domainaxnb.olyusvirag.hu
ClearFake payload delivery domain (confidence level: 100%)
domaingzxz.onlyfansagency.hu
ClearFake payload delivery domain (confidence level: 100%)
domainrnfg.onlyfansagency.hu
ClearFake payload delivery domain (confidence level: 100%)
domainquuos.optikusom.hu
ClearFake payload delivery domain (confidence level: 100%)
domainphmro.optikusom.hu
ClearFake payload delivery domain (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttp://209.99.186.230/69e263ad31aa46a5bc37.php
Stealc botnet C2 (confidence level: 100%)
urlhttps://eletrosoldaitumbiara.com.br/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://imperialguard.icu:1672
Antidot botnet C2 (confidence level: 100%)
urlhttps://catfoodeuro.shop:12655
Antidot botnet C2 (confidence level: 100%)
urlhttps://fastconsulting.info:19586
Antidot botnet C2 (confidence level: 100%)
urlhttps://fastdeliveryaservice.world:2468
Antidot botnet C2 (confidence level: 100%)
urlhttps://sites.google.com/view/deutchbremac
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://brezxcchec.com/
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://premierrentalpurchase.com/curl/5b7250991558c1089d217b180d9418df77886996c22f8f319d7f640895e03381
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://sites.google.com/view/clau-ver-un-24
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttps://fairpoint29.com/
Unknown Stealer payload delivery URL (confidence level: 100%)
urlhttp://85.239.151.41/shr
Unknown malware payload delivery URL (confidence level: 75%)
urlhttp://203.145.34.131/wipi
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://eellner.lol/file.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://eellner.lol/api/v1/session
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://eellner.lol/api/v1/verify
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://sites.google.com/view/clau-ver-un-v25
Unknown Stealer payload delivery URL (confidence level: 75%)
urlhttps://schluter.lol/file.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://schluter.lol/api/v1/session
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://schluter.lol/api/v1/verify
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://lucidgardenhub.top/role/acl-request
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://lucidgardenhub.top/role/reset-theme.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://5.78.219.202
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://5.78.214.140
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://brightvoyagerstudio.com/studio
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://krolikrojer.lat/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.weissratings-billing.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://194.32.248.126/updates/svchost.exe
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://194.32.248.126/updates/microsoft%20windows%20health%20service%20diagnostics.exe
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://194.32.248.126/updates/svchost_laptop.exe
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://194.32.248.126/updates/system%20protection%20background%20task.exe
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://194.32.248.126/updates/windows%20update%20diagnostic%20task%20handler.exe
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://194.32.248.126/updates/microsoft%20windows%20pnp%20device%20driver%20loader.exe
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://194.32.248.126/updates/onedrive%20sync%20shell%20extension%20processor.exe
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://194.32.248.126/updates/windows%20update%20elevated%20service.exe
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://diplokb.cyou
Lumma Stealer botnet C2 (confidence level: 75%)

Threat ID: 6a14e4caa5ae1af1aafa8da2

Added to database: 5/26/2026, 12:09:46 AM

Last enriched: 5/26/2026, 12:09:51 AM

Last updated: 5/26/2026, 2:20:55 AM

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses