Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-06-08

0
Medium
Published: Mon Jun 08 2026 (06/08/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed

Description

ThreatFox IOCs for 2026-06-08

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/09/2026, 00:19:17 UTC

Technical Analysis

The ThreatFox IOCs for 2026-06-08 describe a malware-related threat identified through open-source intelligence. It involves network activity and payload delivery but lacks detailed technical indicators or affected software versions. No known exploits or patches exist for this threat, and it is not associated with any cloud service. The threat level metrics indicate moderate distribution and low analysis depth.

Potential Impact

The impact is currently limited due to the absence of known exploits in the wild and lack of detailed technical indicators. Without specific affected versions or exploit data, the threat appears to be of moderate concern primarily for situational awareness and monitoring rather than immediate active exploitation.

Mitigation Recommendations

No patches or official fixes are available for this threat. Since it is an OSINT report of IOCs without confirmed exploitation, standard monitoring and threat intelligence integration are recommended. No urgent remediation actions are indicated based on the current data.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
7c4b78f5-f328-49a3-a3e2-fda2ad4eb2bd
Original Timestamp
1780963387

Indicators of Compromise

Domain

ValueDescriptionCopy
domainfrostapp.fr
BlankGrabber botnet C2 domain (confidence level: 100%)
domainkuralyok.com.tr
BlankGrabber botnet C2 domain (confidence level: 100%)
domainblank-rfhww.in
BlankGrabber botnet C2 domain (confidence level: 100%)
domainskoch-osjdw.in
BlankGrabber botnet C2 domain (confidence level: 100%)
domainskoch-wif67.in
BlankGrabber botnet C2 domain (confidence level: 100%)
domainblank-c1vj5.in
BlankGrabber botnet C2 domain (confidence level: 100%)
domaing98546cg.beget.tech
BlankGrabber botnet C2 domain (confidence level: 100%)
domainshaurma.fun
BlankGrabber botnet C2 domain (confidence level: 100%)
domainskoch-7bced.in
BlankGrabber botnet C2 domain (confidence level: 100%)
domaino5.gg
BlankGrabber botnet C2 domain (confidence level: 100%)
domainblank-jknks.in
BlankGrabber botnet C2 domain (confidence level: 100%)
domainskoch-eadr7.in
BlankGrabber botnet C2 domain (confidence level: 100%)
domainbrn-hacker.duckdns.org
BlankGrabber botnet C2 domain (confidence level: 100%)
domainblank-1spec.in
BlankGrabber botnet C2 domain (confidence level: 100%)
domaina0928733.xsph.ru
BlankGrabber botnet C2 domain (confidence level: 100%)
domainblank-actsa.in
BlankGrabber botnet C2 domain (confidence level: 100%)
domainblank-vm1ir.in
BlankGrabber botnet C2 domain (confidence level: 100%)
domainblank-iq5vj.in
BlankGrabber botnet C2 domain (confidence level: 100%)
domaindmitrievan.temp.swtest.ru
DCRat botnet C2 domain (confidence level: 100%)
domainsegurityopen12.mysynology.net
DCRat botnet C2 domain (confidence level: 100%)
domain583848.clmonth.nyashteam.top
DCRat botnet C2 domain (confidence level: 100%)
domain954591cm.nyashsens.top
DCRat botnet C2 domain (confidence level: 100%)
domainbl.furries.com.cn
DCRat botnet C2 domain (confidence level: 100%)
domainvelve12.duckdns.org
DCRat botnet C2 domain (confidence level: 100%)
domainlogisctismes.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainmarklogs.ddns.me
Remcos botnet C2 domain (confidence level: 100%)
domaincamtakeit.ddns.net
Remcos botnet C2 domain (confidence level: 100%)
domaincfo111.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domaincfo1111.ddns.net
Remcos botnet C2 domain (confidence level: 100%)
domaincfo1111.hopto.org
Remcos botnet C2 domain (confidence level: 100%)
domainxyzeeeee.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainalisteelhousee.ddns.net
NetWire RC botnet C2 domain (confidence level: 100%)
domainblackhills.ddns.net
NetWire RC botnet C2 domain (confidence level: 100%)
domainextensions14718.sytes.net
NetWire RC botnet C2 domain (confidence level: 100%)
domainnewmone.ddns.net
NetWire RC botnet C2 domain (confidence level: 100%)
domainwilliam1979.ddns.net
NetWire RC botnet C2 domain (confidence level: 100%)
domainadhaehaht-42050.portmap.host
donut_injector botnet C2 domain (confidence level: 100%)
domainvrstudio.life
donut_injector botnet C2 domain (confidence level: 100%)
domaingamestudio.life
donut_injector botnet C2 domain (confidence level: 100%)
domainteamszs.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domaindowncry.s3.ap-east-1.amazonaws.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domainteams-securecall.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domain404xh.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domain14cabp433878.vicp.fun
ValleyRAT botnet C2 domain (confidence level: 100%)
domainso-axiom.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domaingusikkwski.top
ValleyRAT botnet C2 domain (confidence level: 100%)
domainwwnbslklfdsrf.cn
ValleyRAT botnet C2 domain (confidence level: 100%)
domainmerengagoi.bond
DeerStealer botnet C2 domain (confidence level: 100%)
domaingooddogshop.click
DeerStealer botnet C2 domain (confidence level: 100%)
domaininfospi.pl
DeerStealer botnet C2 domain (confidence level: 100%)
domainkrempie.xyz
DeerStealer botnet C2 domain (confidence level: 100%)
domainproductionmaza.bond
DeerStealer botnet C2 domain (confidence level: 100%)
domainmymicroblog.lat
DeerStealer botnet C2 domain (confidence level: 100%)
domainbigboysclub.cyou
DeerStealer botnet C2 domain (confidence level: 100%)
domainantongandon.club
DeerStealer botnet C2 domain (confidence level: 100%)
domainproductionmaza.cfd
DeerStealer botnet C2 domain (confidence level: 100%)
domainmybiggestjoy.bond
DeerStealer botnet C2 domain (confidence level: 100%)
domaindenegnet.click
DeerStealer botnet C2 domain (confidence level: 100%)
domainproductionmaza.cyou
DeerStealer botnet C2 domain (confidence level: 100%)
domainblatnoitovar.xyz
DeerStealer botnet C2 domain (confidence level: 100%)
domaingoodgoodmoon.bond
DeerStealer botnet C2 domain (confidence level: 100%)
domainbestwebchlen.cyou
DeerStealer botnet C2 domain (confidence level: 100%)
domainbeacon-mysummitfcu.org
DeerStealer botnet C2 domain (confidence level: 100%)
domainallplanetssame.cfd
DeerStealer botnet C2 domain (confidence level: 100%)
domainmicroblob.bond
DeerStealer botnet C2 domain (confidence level: 100%)
domainmikelle.beer
ClearFake botnet C2 domain (confidence level: 100%)
domainremotesh.beer
ClearFake botnet C2 domain (confidence level: 100%)
domainremoteshcontrol.com
ClearFake botnet C2 domain (confidence level: 100%)
domaincreazionmedia.com
ClearFake payload delivery domain (confidence level: 100%)
domainflavorcreationsnola.com
ClearFake payload delivery domain (confidence level: 100%)
domainpsicohipnos.com
ClearFake payload delivery domain (confidence level: 100%)
domaingetalib.org
ClearFake botnet C2 domain (confidence level: 100%)
domainaplusrenovation.ca
ClearFake payload delivery domain (confidence level: 100%)
domainautotintas.com.br
ClearFake payload delivery domain (confidence level: 100%)
domainawaywithpauline.com
ClearFake payload delivery domain (confidence level: 100%)
domainbarqalsahra.com
ClearFake payload delivery domain (confidence level: 100%)
domaindanielrefaeli.com
ClearFake payload delivery domain (confidence level: 100%)
domaindesign360.asia
ClearFake payload delivery domain (confidence level: 100%)
domainebmaa.com
ClearFake payload delivery domain (confidence level: 100%)
domainecommerceautomators.com
ClearFake payload delivery domain (confidence level: 100%)
domainedu4arab.org
ClearFake payload delivery domain (confidence level: 100%)
domainemmauscollegeoftheology.com
ClearFake payload delivery domain (confidence level: 100%)
domainfebapak.org
ClearFake payload delivery domain (confidence level: 100%)
domaingcconsult.ca
ClearFake payload delivery domain (confidence level: 100%)
domaingergean.com.br
ClearFake payload delivery domain (confidence level: 100%)
domaingsc.design
ClearFake payload delivery domain (confidence level: 100%)
domainhutor68.ru
ClearFake payload delivery domain (confidence level: 100%)
domaininternationalshade.com
ClearFake payload delivery domain (confidence level: 100%)
domainjanadventures.com
ClearFake payload delivery domain (confidence level: 100%)
domainjust4dance.de
ClearFake payload delivery domain (confidence level: 100%)
domainkadatimes.com
ClearFake payload delivery domain (confidence level: 100%)
domainkijkinfo.com
ClearFake payload delivery domain (confidence level: 100%)
domainletsreadquran.com
ClearFake payload delivery domain (confidence level: 100%)
domainmarjeyounshoppingcenter.com
ClearFake payload delivery domain (confidence level: 100%)
domainmelixelectrical.com.au
ClearFake payload delivery domain (confidence level: 100%)
domainmeselectrics.com.au
ClearFake payload delivery domain (confidence level: 100%)
domainwashingtonvisiontherapy.com
ClearFake payload delivery domain (confidence level: 100%)
domainpdbrpnf.penaltibazi.com
ClearFake payload delivery domain (confidence level: 100%)
domainm5zv3oa7.parsgoal90.com
ClearFake payload delivery domain (confidence level: 100%)
domainegbofo.jamjahani.cash
ClearFake payload delivery domain (confidence level: 100%)
domainbl7gsqjt.parsgoal90.com
ClearFake payload delivery domain (confidence level: 100%)
domainatuxkke.penalti.website
ClearFake payload delivery domain (confidence level: 100%)
domainomxvqrt.penalty.casino
ClearFake payload delivery domain (confidence level: 100%)
domaineterjrb.one1x.bet
ClearFake payload delivery domain (confidence level: 100%)
domain1hrrc4q6.onexboro.com
ClearFake payload delivery domain (confidence level: 100%)
domainetpvftw.one1x.bet
ClearFake payload delivery domain (confidence level: 100%)
domaindihsov.jamjahani.cash
ClearFake payload delivery domain (confidence level: 100%)
domainhhb3xwzf.parspoker90.com
ClearFake payload delivery domain (confidence level: 100%)
domain1nmuyb5y.parspoker90.com
ClearFake payload delivery domain (confidence level: 100%)
domainuadcmxt.kbshavanese.com
ClearFake payload delivery domain (confidence level: 100%)
domainbdfzsbr.kvbel.com
ClearFake payload delivery domain (confidence level: 100%)
domain2844.xzz.cam
ValleyRAT botnet C2 domain (confidence level: 100%)
domainbackdoor.cyou
ValleyRAT botnet C2 domain (confidence level: 100%)
domaindphxsy.perfectgame.casino
ClearFake payload delivery domain (confidence level: 100%)
domainiidqou.jamjahani.app
ClearFake payload delivery domain (confidence level: 100%)
domainghbfozy.olabahiskayit.com
ClearFake payload delivery domain (confidence level: 100%)
domain33liwbcf.parspoker.casino
ClearFake payload delivery domain (confidence level: 100%)
domainpqxlboc.winsportiran.com
ClearFake payload delivery domain (confidence level: 100%)
domainwinstone.casino
ClearFake payload delivery domain (confidence level: 100%)
domaingysxrbg.winstone.casino
ClearFake payload delivery domain (confidence level: 100%)
domainbzwbfps.winxbet.co
ClearFake payload delivery domain (confidence level: 100%)
domainjfdewff.link
Ficker Stealer botnet C2 domain (confidence level: 100%)
domainmusonare.top
MetaStealer botnet C2 domain (confidence level: 100%)
domainproxybox.io
Socks5 Systemz botnet C2 domain (confidence level: 100%)
domainvsttorentz.net
Socks5 Systemz botnet C2 domain (confidence level: 100%)
domainproxy.am
Socks5 Systemz botnet C2 domain (confidence level: 100%)
domainejvphud.ua
Socks5 Systemz botnet C2 domain (confidence level: 100%)
domaingdpkvkr.com
Socks5 Systemz botnet C2 domain (confidence level: 100%)
domainbwiesit.com
Socks5 Systemz botnet C2 domain (confidence level: 100%)
domaingoeiwef.com
Socks5 Systemz botnet C2 domain (confidence level: 100%)
domainkruxjou.ua
Socks5 Systemz botnet C2 domain (confidence level: 100%)
domainshadownbr.ddns.net
NjRAT botnet C2 domain (confidence level: 100%)
domainricardotro.duckdns.org
NjRAT botnet C2 domain (confidence level: 100%)
domainrjnfjrtc.pwrp.cc
NjRAT botnet C2 domain (confidence level: 100%)
domainrdntotoso.ddns.net
NjRAT botnet C2 domain (confidence level: 100%)
domainphishing.two-i.com
NjRAT botnet C2 domain (confidence level: 100%)
domainphishing.researchinstitute.io
NjRAT botnet C2 domain (confidence level: 100%)
domainkad77.duckdns.org
NjRAT botnet C2 domain (confidence level: 100%)
domaingooglednsv1.gleeze.com
NjRAT botnet C2 domain (confidence level: 100%)
domainsame53-51830.portmap.host
NjRAT botnet C2 domain (confidence level: 100%)
domainphishing.classofcovid.org
NjRAT botnet C2 domain (confidence level: 100%)
domainstoneaged.ddns.net
NjRAT botnet C2 domain (confidence level: 100%)
domainphishing.clubmilanovolley.com
NjRAT botnet C2 domain (confidence level: 100%)
domainphishing.marthasvineyardfitness.com
NjRAT botnet C2 domain (confidence level: 100%)
domainfuck-life007.no-ip.biz
NjRAT botnet C2 domain (confidence level: 100%)
domainphishing.flyingdiscranchdates.com
NjRAT botnet C2 domain (confidence level: 100%)
domainhacker.two-i.com
NjRAT botnet C2 domain (confidence level: 100%)
domainphishing.www.cathedrale-images.com
NjRAT botnet C2 domain (confidence level: 100%)
domainphishing.xoilacane.live
NjRAT botnet C2 domain (confidence level: 100%)
domainmangy10.ddns.net
NjRAT botnet C2 domain (confidence level: 100%)
domainwolfenm.com
ClearFake payload delivery domain (confidence level: 100%)
domainylljjmv.wolfenm.com
ClearFake payload delivery domain (confidence level: 100%)
domainsesksz.venusbet90.com
ClearFake payload delivery domain (confidence level: 100%)
domainzqzlac.vezaratshart.com
ClearFake payload delivery domain (confidence level: 100%)
domainbikldg.volleyball.bet
ClearFake payload delivery domain (confidence level: 100%)
domain9t9m7lad.yektbet.bet
ClearFake payload delivery domain (confidence level: 100%)
domainzlyupbm.wrfc8.com
ClearFake payload delivery domain (confidence level: 100%)
domainqll4p9fw.one1xiran.bet
ClearFake payload delivery domain (confidence level: 100%)
domainpmhaqci.x50wheel.bet
ClearFake payload delivery domain (confidence level: 100%)
domaincqvdiki.xenicalby6.com
ClearFake payload delivery domain (confidence level: 100%)
domainallcountiesroofingltd.co.uk
IClickFix payload delivery domain (confidence level: 100%)
domainaltecva.com
IClickFix payload delivery domain (confidence level: 100%)
domainamici-di-pogrande.it
IClickFix payload delivery domain (confidence level: 100%)
domainandreawirsum.com
IClickFix payload delivery domain (confidence level: 100%)
domainargirisangelopoulos.gr
IClickFix payload delivery domain (confidence level: 100%)
domainbalkanrefugeenetwork.org
IClickFix payload delivery domain (confidence level: 100%)
domainbbchurch.net
IClickFix payload delivery domain (confidence level: 100%)
domainberlin21.info
IClickFix payload delivery domain (confidence level: 100%)
domainbuktijpmaluku.info
IClickFix payload delivery domain (confidence level: 100%)
domaincamtechpotiskum.edu.ng
IClickFix payload delivery domain (confidence level: 100%)
domaincasobrar.com.br
IClickFix payload delivery domain (confidence level: 100%)
domainciberci.com
IClickFix payload delivery domain (confidence level: 100%)
domaindanielediana.it
IClickFix payload delivery domain (confidence level: 100%)
domaindevelopmental-twins.com
IClickFix payload delivery domain (confidence level: 100%)
domaindjlandscapingltd.co.uk
IClickFix payload delivery domain (confidence level: 100%)
domaindropstars.ai
IClickFix payload delivery domain (confidence level: 100%)
domaindustyductsbegone.com
IClickFix payload delivery domain (confidence level: 100%)
domainerossiconsultoria.com.br
IClickFix payload delivery domain (confidence level: 100%)
domainevolutionairfilter.com
IClickFix payload delivery domain (confidence level: 100%)
domainfaculdadedamoda.com
IClickFix payload delivery domain (confidence level: 100%)
domaingenerativesolutionsus.com
IClickFix payload delivery domain (confidence level: 100%)
domaingomberg.net
IClickFix payload delivery domain (confidence level: 100%)
domainiconlng.com
IClickFix payload delivery domain (confidence level: 100%)
domaininfocus.tn
IClickFix payload delivery domain (confidence level: 100%)
domainireflect.net
IClickFix payload delivery domain (confidence level: 100%)
domainjkbuildersg.com
IClickFix payload delivery domain (confidence level: 100%)
domainjoannedeitsch.com
IClickFix payload delivery domain (confidence level: 100%)
domainkevinfreels.com
IClickFix payload delivery domain (confidence level: 100%)
domainkidsandtas.edu.do
IClickFix payload delivery domain (confidence level: 100%)
domainlegalmarketing.shop
IClickFix payload delivery domain (confidence level: 100%)
domainmediweightloss.com.au
IClickFix payload delivery domain (confidence level: 100%)
domainoficialwebsitepromotion.com
IClickFix payload delivery domain (confidence level: 100%)
domainruetraverse.com
IClickFix payload delivery domain (confidence level: 100%)
domainsouthasianher.com
IClickFix payload delivery domain (confidence level: 100%)
domainstampcollectshop.com
IClickFix payload delivery domain (confidence level: 100%)
domainstroycenter.net
IClickFix payload delivery domain (confidence level: 100%)
domainthepesthunter.com
IClickFix payload delivery domain (confidence level: 100%)
domaintknmetal.net
IClickFix payload delivery domain (confidence level: 100%)
domaintrustroofingltd.co.uk
IClickFix payload delivery domain (confidence level: 100%)
domainvernerestaurant.com
IClickFix payload delivery domain (confidence level: 100%)
domainviagmmy.com
IClickFix payload delivery domain (confidence level: 100%)
domainvictormeloadvogado.com
IClickFix payload delivery domain (confidence level: 100%)
domainvisualimpressao.com.br
IClickFix payload delivery domain (confidence level: 100%)
domainvitb.ac.in
IClickFix payload delivery domain (confidence level: 100%)
domainanpysts.yasbetapp.com
ClearFake payload delivery domain (confidence level: 100%)
domain5dwz6wj9.yekbetiran.com
ClearFake payload delivery domain (confidence level: 100%)
domainebwgtb.vezaratshart.com
ClearFake payload delivery domain (confidence level: 100%)
domainfrbvnnnfyr6xr622pbe0nq==
XWorm botnet C2 domain (confidence level: 75%)
domainyynpur.perfectgame.casino
ClearFake payload delivery domain (confidence level: 100%)
domainthrotboy.duckdns.org
Remcos botnet C2 domain (confidence level: 75%)
domainxzelng.jamjahani.cash
ClearFake payload delivery domain (confidence level: 100%)
domainmpozwop.winxbet.co
ClearFake payload delivery domain (confidence level: 100%)
domainwin.tennis
ClearFake payload delivery domain (confidence level: 100%)
domaintviyhdt.winstone.casino
ClearFake payload delivery domain (confidence level: 100%)
domainrykwhjt.winsportiran.com
ClearFake payload delivery domain (confidence level: 100%)
domainnanacccoz.hopto.org
Remcos botnet C2 domain (confidence level: 75%)
domainhavasssj291sld.com
Unknown malware payload delivery domain (confidence level: 100%)
domainphoto-27657.cfd
Unknown malware payload delivery domain (confidence level: 100%)
domainjsdakksd283ksl.com
Unknown malware payload delivery domain (confidence level: 100%)
domainhotelsphotosite.cloud
Unknown malware payload delivery domain (confidence level: 100%)
domainphoto-27757.cfd
Unknown malware payload delivery domain (confidence level: 100%)
domainphoto-26657.cfd
Unknown malware payload delivery domain (confidence level: 100%)
domaintracerecord.info
Unknown malware payload delivery domain (confidence level: 100%)
domainbook-photopage.info
Unknown malware payload delivery domain (confidence level: 100%)
domainhaddjskak827sja.com
Unknown malware payload delivery domain (confidence level: 100%)
domainhaskakwo291sa.com
Unknown malware payload delivery domain (confidence level: 100%)
domainphotohotelcheck.cloud
Unknown malware payload delivery domain (confidence level: 100%)
domainpic-imageh.info
Unknown malware payload delivery domain (confidence level: 100%)
domainphoto-pagebook.info
Unknown malware payload delivery domain (confidence level: 100%)
domainhotelphotoadm.info
Unknown malware payload delivery domain (confidence level: 100%)
domainsafehub-images.info
Unknown malware payload delivery domain (confidence level: 100%)
domainsafepic-img.info
Unknown malware payload delivery domain (confidence level: 100%)
domainsafegallery.info
Unknown malware payload delivery domain (confidence level: 100%)
domainhakdsiwqs281ks.com
Unknown malware payload delivery domain (confidence level: 100%)
domainteraview.info
Unknown malware payload delivery domain (confidence level: 100%)
domainphotforhotel.info
Unknown malware payload delivery domain (confidence level: 100%)
domainphoto-26656.cfd
Unknown malware payload delivery domain (confidence level: 100%)
domaindsjkaksfks324das.com
Unknown malware payload delivery domain (confidence level: 100%)
domainphoto-26653.cfd
Unknown malware payload delivery domain (confidence level: 100%)
domainphoto-26652.cfd
Unknown malware payload delivery domain (confidence level: 100%)
domainreg.turbo88op.top
Vidar botnet C2 domain (confidence level: 100%)
domainlla.firesupport.com
Vidar botnet C2 domain (confidence level: 100%)
domainfhe.firesupport.com
Vidar botnet C2 domain (confidence level: 100%)
domainpas.firesupport.com
Vidar botnet C2 domain (confidence level: 100%)
domainlla.fixsm188.top
Vidar botnet C2 domain (confidence level: 100%)
domainfhe.fixsm188.top
Vidar botnet C2 domain (confidence level: 100%)
domainpas.fixsm188.top
Vidar botnet C2 domain (confidence level: 100%)
domaininmjycz.olabahiskayit.com
ClearFake payload delivery domain (confidence level: 100%)
domaingwu729hw.parspoker.casino
ClearFake payload delivery domain (confidence level: 100%)
domainhjwaxur.kvbel.com
ClearFake payload delivery domain (confidence level: 100%)
domainhorizon.nvms9000updates.su
Mirai botnet C2 domain (confidence level: 100%)
domain000.nvms9000.su
Mirai botnet C2 domain (confidence level: 100%)
domain0000.nvms9000.su
Mirai botnet C2 domain (confidence level: 100%)
domain00000l.nvms9000.su
Mirai botnet C2 domain (confidence level: 100%)
domain000.hikvision-cctv.su
Mirai botnet C2 domain (confidence level: 100%)
domain0000.hikvision-cctv.su
Mirai botnet C2 domain (confidence level: 100%)
domain00000.hikvision-cctv.su
Mirai botnet C2 domain (confidence level: 100%)
domain0000g7bd7.hikvision-cctv.su
Mirai botnet C2 domain (confidence level: 100%)
domainbotdealers.st
Mirai botnet C2 domain (confidence level: 100%)
domainkys.botdealers.st
Mirai botnet C2 domain (confidence level: 100%)
domaincebsrg.jamjahani.football
ClearFake payload delivery domain (confidence level: 100%)
domainfhvteyb.kbshavanese.com
ClearFake payload delivery domain (confidence level: 100%)
domainzrqkapj.one1x.bet
ClearFake payload delivery domain (confidence level: 100%)
domainh0t75jy5.betgopro.com
ClearFake payload delivery domain (confidence level: 100%)
domainwowlowski.icu
KongTuke payload delivery domain (confidence level: 100%)
domainaura-checkpoint.top
KongTuke payload delivery domain (confidence level: 100%)
domaing1rxiw6o.parspoker90.com
ClearFake payload delivery domain (confidence level: 100%)
domainx3v1t7wb.parspoker90.com
ClearFake payload delivery domain (confidence level: 100%)
domainhknnbq.pablobet90.com
ClearFake payload delivery domain (confidence level: 100%)
domainte3znaut.parspoker90.com
ClearFake payload delivery domain (confidence level: 100%)
domainjjgnawd.penalti.website
ClearFake payload delivery domain (confidence level: 100%)
domainapp-front.anmaradigital.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainoczvda.oxidbet.bet
ClearFake payload delivery domain (confidence level: 100%)
domainhexbear.io
Nanocore RAT botnet C2 domain (confidence level: 75%)
domainjwfckz.onlineshart.com
ClearFake payload delivery domain (confidence level: 100%)
domain88aavn.one
Nanocore RAT botnet C2 domain (confidence level: 75%)
domainxhfecr.jamjahani2026.football
ClearFake payload delivery domain (confidence level: 100%)
domainvdchddh.penaltibazi.com
ClearFake payload delivery domain (confidence level: 100%)
domainfporlgd.penality.bet
ClearFake payload delivery domain (confidence level: 100%)
domainsouljaboynft.io
Nanocore RAT botnet C2 domain (confidence level: 75%)
domainemberhorizon.top
SmartApeSG payload delivery domain (confidence level: 100%)
domainenterprise1.pages.dev
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainendpoint.xsn10.com
Cobalt Strike payload delivery domain (confidence level: 85%)
domainapi.asn15.com
Cobalt Strike payload delivery domain (confidence level: 85%)
domain22wsnikmydlkyx4cwmiykxis7kjy4ugmlz453amazqhflwo3wjsz5tad.onion
Cobalt Strike botnet C2 domain (confidence level: 90%)
domainzjuflao.pasur21.com
ClearFake payload delivery domain (confidence level: 100%)
domainiebtnuo1.parsgoal90.com
ClearFake payload delivery domain (confidence level: 100%)
domaine20yl90d.parsgoal90.com
ClearFake payload delivery domain (confidence level: 100%)
domainvvpfsda.pasoor11.bet
ClearFake payload delivery domain (confidence level: 100%)
domainqcqsin.yasbet90.com
ClearFake payload delivery domain (confidence level: 100%)
domainsyheuby.mangobetfarsi.com
ClearFake payload delivery domain (confidence level: 100%)
domainperfectgameiran.com
ClearFake payload delivery domain (confidence level: 100%)
domainhfgzvf.perfectgameiran.com
ClearFake payload delivery domain (confidence level: 100%)
domainsad.fixsm188.top
Vidar botnet C2 domain (confidence level: 75%)
domainsad.firesupport.com
Vidar botnet C2 domain (confidence level: 75%)
domainidwpuur.ninjafruitcubes.bet
ClearFake payload delivery domain (confidence level: 100%)
domainpersianabet.casino
ClearFake payload delivery domain (confidence level: 100%)
domainflnntj.persianabet.casino
ClearFake payload delivery domain (confidence level: 100%)
domainlizablud.shop
Unknown Webinject payload delivery domain (confidence level: 100%)
domainchinabowl.club
Unknown Webinject payload delivery domain (confidence level: 100%)
domainzebswzz.one1xbet.net
ClearFake payload delivery domain (confidence level: 100%)
domaint748i6is.volleyball.vip
ClearFake payload delivery domain (confidence level: 100%)
domainv6o8c9xi.mrbet90.com
ClearFake payload delivery domain (confidence level: 100%)
domain0fqk0ho2.mrbet90.com
ClearFake payload delivery domain (confidence level: 100%)
domainpersian.sex
ClearFake payload delivery domain (confidence level: 100%)
domainikbnssq.persian.sex
ClearFake payload delivery domain (confidence level: 100%)
domainabrikos.xyz
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainanakondabob.club
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainap7.supportly.au
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainarigatodomen.sbs
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainbabybon.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainbearman.bond
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainbigbadwolf.click
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainbiggestchlen.lol
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainbiggestchlen.xyz
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainbiletors.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainblobtop.sbs
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainbobik.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainbulletpop.cyou
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainchinabowl.club
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainchubrik.sbs
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaincloudflare-check.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaincomicstar.lat
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaincorppop.shop
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaincosmostars.shop
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaindiddyparty.click
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainetomoe.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainetomoidomen.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainganiballektor.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaingdedengikarlos.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaingdelogi.lol
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaingovnol.lat
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaingppcdnns.beer
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainivangay.bond
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainlenders.digital
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainlizablud.shop
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmambet.lol
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmarinaradom.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmarmelad.lat
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmegamegalodon.click
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmerindashop.cyou
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmexicodreams.bond
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmicroblogver.bond
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmicrochlen.lat
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmicroloh.bond
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmilksos.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmnepohui.sbs
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmob.lanjut.in
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmyblobtop.site
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmygoodblog.bond
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmygoodblog.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmyverifhouse.sbs
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainmyverifyblog.sbs
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainnenadopapa.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainpeachbro.bond
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainpinokros.xyz
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainpohuimne.lol
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainponikas.cyou
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainpringlesbob.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainproductionmaza.sbs
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainprokladka.lol
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainrobodomain.sbs
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainsandman.bond
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainsandman.lat
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainsirata.asia
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainsitepromclop.click
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainsmackit.lat
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainsmesharik.bond
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainspartanec.lat
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainsuperpooper.click
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainwebanalytics-cdn.cfd
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainwhynotebanarot.xyz
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainyanepidor.mom
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainyoshicity.xyz
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainpersianshart.com
ClearFake payload delivery domain (confidence level: 100%)
domain!k!.persianshart.com
ClearFake payload delivery domain (confidence level: 100%)
domainzexrhdz.penaltibazi.com
ClearFake payload delivery domain (confidence level: 100%)
domainzoasav.onlineshart.com
ClearFake payload delivery domain (confidence level: 100%)
domainaencte.oxidbet.bet
ClearFake payload delivery domain (confidence level: 100%)
domaintwvjaye.penalti.website
ClearFake payload delivery domain (confidence level: 100%)
domainpbtgvx.pablobet90.com
ClearFake payload delivery domain (confidence level: 100%)
domainwebdot.ddns.net
PureLogs Stealer botnet C2 domain (confidence level: 100%)
domainhfpfhy7zytroclo.top
KongTuke botnet C2 domain (confidence level: 100%)
domaincrystalforgeway.top
SmartApeSG payload delivery domain (confidence level: 100%)
domainpbustxk.penalty.casino
ClearFake payload delivery domain (confidence level: 100%)
domainb8i7k0hi.parsbet90.com
ClearFake payload delivery domain (confidence level: 100%)
domainchzldmh3.parsbet90.com
ClearFake payload delivery domain (confidence level: 100%)
domaingts.fixsm188.top
Vidar botnet C2 domain (confidence level: 75%)
domaingts.firesupport.com
Vidar botnet C2 domain (confidence level: 75%)
domainojpqxkm.one1x.bet
ClearFake payload delivery domain (confidence level: 100%)
domainrbbhubp.kbshavanese.com
ClearFake payload delivery domain (confidence level: 100%)
domainzfomko.jamjahani.cash
ClearFake payload delivery domain (confidence level: 100%)
domainngieimu.kvbel.com
ClearFake payload delivery domain (confidence level: 100%)
domainxf4v3zjk.parspoker.casino
ClearFake payload delivery domain (confidence level: 100%)
domainxeledkz.olabahiskayit.com
ClearFake payload delivery domain (confidence level: 100%)
domainwinmastersbetiran.com
ClearFake payload delivery domain (confidence level: 100%)
domaine40nbbpq.winmastersbetiran.com
ClearFake payload delivery domain (confidence level: 100%)
domainlohgcyy.winsportiran.com
ClearFake payload delivery domain (confidence level: 100%)
domainsewgqnm.winxbet.co
ClearFake payload delivery domain (confidence level: 100%)
domainuru.fixsm188.top
Vidar botnet C2 domain (confidence level: 100%)
domainuru.firesupport.com
Vidar botnet C2 domain (confidence level: 100%)
domainpvvvvn.perfectgame.casino
ClearFake payload delivery domain (confidence level: 100%)
domaingsoxdy.vezaratshart.com
ClearFake payload delivery domain (confidence level: 100%)
domainoxyna912.yekbetiran.com
ClearFake payload delivery domain (confidence level: 100%)
domainfrowben.yasbetapp.com
ClearFake payload delivery domain (confidence level: 100%)
domainnlwgc0c9.yekbetiran.com
ClearFake payload delivery domain (confidence level: 100%)
domainakvljg.perspolisbet90.com
ClearFake payload delivery domain (confidence level: 100%)
domainperspolisbet.bet
ClearFake payload delivery domain (confidence level: 100%)
domaindeglis.perspolisbet.bet
ClearFake payload delivery domain (confidence level: 100%)
domainpik.bet
ClearFake payload delivery domain (confidence level: 100%)
domainnnwhxh.pik.bet
ClearFake payload delivery domain (confidence level: 100%)

File

ValueDescriptionCopy
file167.71.5.187
Kimwolf botnet C2 server (confidence level: 100%)
file134.209.87.103
Kimwolf botnet C2 server (confidence level: 100%)
file85.209.163.250
Unknown Stealer payload delivery server (confidence level: 100%)
file47.119.179.4
XMRIG payload delivery server (confidence level: 85%)
file115.231.76.176
XMRIG payload delivery server (confidence level: 85%)
file156.67.105.185
RedTail payload delivery server (confidence level: 85%)
file47.88.104.101
RedTail payload delivery server (confidence level: 85%)
file45.88.186.59
AsyncRAT botnet C2 server (confidence level: 50%)
file45.88.186.59
AsyncRAT botnet C2 server (confidence level: 50%)
file45.88.186.59
AsyncRAT botnet C2 server (confidence level: 50%)
file45.88.186.59
AsyncRAT botnet C2 server (confidence level: 50%)
file43.110.54.62
VShell botnet C2 server (confidence level: 100%)
file161.248.87.185
ValleyRAT botnet C2 server (confidence level: 75%)
file27.124.40.162
ValleyRAT botnet C2 server (confidence level: 75%)
file154.88.96.49
VShell botnet C2 server (confidence level: 100%)
file154.88.96.57
VShell botnet C2 server (confidence level: 100%)
file192.162.199.75
Quasar RAT botnet C2 server (confidence level: 100%)
file120.26.208.96
Cobalt Strike botnet C2 server (confidence level: 100%)
file120.26.208.96
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.64.111.20
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.163.135.135
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.64.111.19
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.64.111.21
Cobalt Strike botnet C2 server (confidence level: 100%)
file38.47.226.41
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.152.2.86
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.64.111.18
Cobalt Strike botnet C2 server (confidence level: 100%)
file112.213.113.171
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.130.121.65
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.121.65
Unknown malware botnet C2 server (confidence level: 100%)
file104.168.7.219
XWorm botnet C2 server (confidence level: 75%)
file107.173.63.252
Remcos botnet C2 server (confidence level: 75%)
file31.56.209.92
XWorm botnet C2 server (confidence level: 75%)
file62.102.148.174
Remcos botnet C2 server (confidence level: 75%)
file93.177.75.2
Remcos botnet C2 server (confidence level: 75%)
file107.172.13.245
XWorm botnet C2 server (confidence level: 75%)
file195.177.94.115
Remcos botnet C2 server (confidence level: 75%)
file104.168.7.208
Remcos botnet C2 server (confidence level: 75%)
file151.244.232.26
XWorm botnet C2 server (confidence level: 75%)
file216.250.250.247
XWorm botnet C2 server (confidence level: 75%)
file154.88.97.58
VShell botnet C2 server (confidence level: 100%)
file8.130.121.65
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.121.65
Unknown malware botnet C2 server (confidence level: 100%)
file154.23.189.157
Quasar RAT botnet C2 server (confidence level: 100%)
file31.56.209.126
XWorm botnet C2 server (confidence level: 75%)
file107.172.13.230
Remcos botnet C2 server (confidence level: 75%)
file192.3.45.8
Remcos botnet C2 server (confidence level: 75%)
file146.70.244.90
Remcos botnet C2 server (confidence level: 75%)
file107.175.148.82
Remcos botnet C2 server (confidence level: 75%)
file62.102.148.212
Remcos botnet C2 server (confidence level: 75%)
file87.120.107.29
XWorm botnet C2 server (confidence level: 75%)
file155.103.70.100
Remcos botnet C2 server (confidence level: 75%)
file182.23.2.163
Remcos botnet C2 server (confidence level: 75%)
file87.237.52.176
Unknown malware botnet C2 server (confidence level: 75%)
file89.125.255.5
Havoc botnet C2 server (confidence level: 75%)
file89.125.255.5
Havoc botnet C2 server (confidence level: 75%)
file94.183.232.247
Mirai botnet C2 server (confidence level: 75%)
file23.95.103.219
Remcos botnet C2 server (confidence level: 75%)
file107.175.179.48
Remcos botnet C2 server (confidence level: 75%)
file135.181.224.79
Vidar botnet C2 server (confidence level: 50%)
file65.21.96.131
Vidar botnet C2 server (confidence level: 50%)
file135.181.224.77
Vidar botnet C2 server (confidence level: 50%)
file135.181.224.75
Vidar botnet C2 server (confidence level: 50%)
file178.105.231.90
Vidar botnet C2 server (confidence level: 50%)
file135.181.224.73
Vidar botnet C2 server (confidence level: 50%)
file135.181.224.76
Vidar botnet C2 server (confidence level: 50%)
file135.181.224.74
Vidar botnet C2 server (confidence level: 50%)
file192.3.45.8
Remcos botnet C2 server (confidence level: 75%)
file84.38.129.122
XWorm botnet C2 server (confidence level: 75%)
file63.250.47.156
Havoc botnet C2 server (confidence level: 100%)
file118.107.1.135
DCRat botnet C2 server (confidence level: 100%)
file45.61.163.145
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.61.163.145
Cobalt Strike botnet C2 server (confidence level: 100%)
file168.222.97.59
Remcos botnet C2 server (confidence level: 75%)
file45.61.163.145
Cobalt Strike botnet C2 server (confidence level: 100%)
file117.72.115.168
Cobalt Strike botnet C2 server (confidence level: 100%)
file117.72.115.168
Cobalt Strike botnet C2 server (confidence level: 100%)
file117.72.115.168
Cobalt Strike botnet C2 server (confidence level: 100%)
file62.171.142.134
XMRIG payload delivery server (confidence level: 85%)
file47.253.94.140
RedTail payload delivery server (confidence level: 85%)
file45.238.101.91
RedTail payload delivery server (confidence level: 85%)
file189.51.43.54
RedTail payload delivery server (confidence level: 85%)
file167.126.6.183
RedTail payload delivery server (confidence level: 85%)
file106.14.116.17
Cobalt Strike botnet C2 server (confidence level: 75%)
file193.93.193.93
Unknown RAT botnet C2 server (confidence level: 100%)
file104.239.66.136
XWorm botnet C2 server (confidence level: 75%)
file130.12.180.36
AsyncRAT botnet C2 server (confidence level: 100%)
file154.23.189.122
Quasar RAT botnet C2 server (confidence level: 100%)
file107.175.148.82
Remcos botnet C2 server (confidence level: 75%)
file62.76.229.102
Cobalt Strike botnet C2 server (confidence level: 90%)
file20.81.43.36
PureLogs Stealer botnet C2 server (confidence level: 75%)
file20.81.43.36
PureLogs Stealer botnet C2 server (confidence level: 75%)
file64.95.13.15
KongTuke botnet C2 server (confidence level: 75%)
file15.235.189.218
Unknown malware botnet C2 server (confidence level: 75%)
file155.103.70.100
Remcos botnet C2 server (confidence level: 75%)
file182.23.2.163
Remcos botnet C2 server (confidence level: 75%)
file103.51.147.252
VShell botnet C2 server (confidence level: 100%)
file111.119.234.82
Unknown malware botnet C2 server (confidence level: 100%)
file74.48.202.123
Havoc botnet C2 server (confidence level: 100%)
file74.48.202.123
Havoc botnet C2 server (confidence level: 100%)
file182.255.82.121
Havoc botnet C2 server (confidence level: 100%)
file149.88.66.234
Cobalt Strike botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash25001
Kimwolf botnet C2 server (confidence level: 100%)
hash3000
Unknown Stealer payload delivery server (confidence level: 100%)
hash6379
XMRIG payload delivery server (confidence level: 85%)
hash60105
XMRIG payload delivery server (confidence level: 85%)
hash2375
RedTail payload delivery server (confidence level: 85%)
hash2375
RedTail payload delivery server (confidence level: 85%)
hash4444
AsyncRAT botnet C2 server (confidence level: 50%)
hash5000
AsyncRAT botnet C2 server (confidence level: 50%)
hash8808
AsyncRAT botnet C2 server (confidence level: 50%)
hash8888
AsyncRAT botnet C2 server (confidence level: 50%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash2844
ValleyRAT botnet C2 server (confidence level: 75%)
hash443
ValleyRAT botnet C2 server (confidence level: 75%)
hash8884
VShell botnet C2 server (confidence level: 100%)
hash8884
VShell botnet C2 server (confidence level: 100%)
hash2222
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash81
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash8823
XWorm botnet C2 server (confidence level: 75%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash443
XWorm botnet C2 server (confidence level: 75%)
hash37393
Remcos botnet C2 server (confidence level: 75%)
hash2467
Remcos botnet C2 server (confidence level: 75%)
hash7007
XWorm botnet C2 server (confidence level: 75%)
hash2037
Remcos botnet C2 server (confidence level: 75%)
hash4231
Remcos botnet C2 server (confidence level: 75%)
hash443
XWorm botnet C2 server (confidence level: 75%)
hash8086
XWorm botnet C2 server (confidence level: 75%)
hash8884
VShell botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash14782
Quasar RAT botnet C2 server (confidence level: 100%)
hash1996
XWorm botnet C2 server (confidence level: 75%)
hash3000
Remcos botnet C2 server (confidence level: 75%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash37393
Remcos botnet C2 server (confidence level: 75%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash37393
Remcos botnet C2 server (confidence level: 75%)
hash1194
XWorm botnet C2 server (confidence level: 75%)
hash13408
Remcos botnet C2 server (confidence level: 75%)
hash3252
Remcos botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash43026
Havoc botnet C2 server (confidence level: 75%)
hash9999
Havoc botnet C2 server (confidence level: 75%)
hash80
Mirai botnet C2 server (confidence level: 75%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash443
Vidar botnet C2 server (confidence level: 50%)
hash443
Vidar botnet C2 server (confidence level: 50%)
hash443
Vidar botnet C2 server (confidence level: 50%)
hash443
Vidar botnet C2 server (confidence level: 50%)
hash443
Vidar botnet C2 server (confidence level: 50%)
hash443
Vidar botnet C2 server (confidence level: 50%)
hash443
Vidar botnet C2 server (confidence level: 50%)
hash443
Vidar botnet C2 server (confidence level: 50%)
hash5000
Remcos botnet C2 server (confidence level: 75%)
hash443
XWorm botnet C2 server (confidence level: 75%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash8848
DCRat botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash6379
XMRIG payload delivery server (confidence level: 85%)
hash2375
RedTail payload delivery server (confidence level: 85%)
hash2375
RedTail payload delivery server (confidence level: 85%)
hash80
RedTail payload delivery server (confidence level: 85%)
hash80
RedTail payload delivery server (confidence level: 85%)
hash19443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8822
Unknown RAT botnet C2 server (confidence level: 100%)
hash007c16460b4b540cdbdb2488eb9be57baed53a31f2544bda86e3d21fb5e019ff
Unknown RAT payload (confidence level: 50%)
hashac2248d66cadf6597f428cde47f98c1adbb382da0473cceca632dec08ecf3e06
Unknown RAT payload (confidence level: 50%)
hash2017
XWorm botnet C2 server (confidence level: 75%)
hash22
AsyncRAT botnet C2 server (confidence level: 100%)
hash14782
Quasar RAT botnet C2 server (confidence level: 100%)
hash3001
Remcos botnet C2 server (confidence level: 75%)
hash56782
Cobalt Strike botnet C2 server (confidence level: 90%)
hashe3300ce9dce0d41690e711b8ee3bb5498ccf25c68d4bafe35416a77a2d88cbd2
Cobalt Strike payload (confidence level: 100%)
hash83a85d92277f0c762414e97f26538e4657f28a1cebe3e4f5d5d32e5ecf7b458a
Cobalt Strike payload (confidence level: 100%)
hash8030
PureLogs Stealer botnet C2 server (confidence level: 75%)
hash1011
PureLogs Stealer botnet C2 server (confidence level: 75%)
hash80
KongTuke botnet C2 server (confidence level: 75%)
hash56001
Unknown malware botnet C2 server (confidence level: 75%)
hash13407
Remcos botnet C2 server (confidence level: 75%)
hash12297
Remcos botnet C2 server (confidence level: 75%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash20050
Cobalt Strike botnet C2 server (confidence level: 75%)

Url

ValueDescriptionCopy
urlhttps://121.176.14.102/sh
RedTail payload delivery URL (confidence level: 85%)
urlhttps://hoteldugolfe.corsica/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.lorisdanesi.it/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://tracklifefit.com.br/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://sharepoint.tu-dresden.be/tqqud08zj6yh94pf
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://aboutbraces.org/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://flownavalarchitect.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://45.91.81.190:8443
Unknown malware botnet C2 (confidence level: 75%)
urlhttps://103.214.174.248:8443
Unknown malware botnet C2 (confidence level: 75%)
urlhttps://108.61.193.37:8443
Unknown malware botnet C2 (confidence level: 75%)
urlhttp://212.192.246.217/access.php
GCleaner botnet C2 (confidence level: 100%)
urlhttp://45.9.20.13/partner/loot.php
GCleaner botnet C2 (confidence level: 100%)
urlhttp://37.0.8.39/access.php
GCleaner botnet C2 (confidence level: 100%)
urlhttp://the-flash-man.com/installer_hwtcxtrp5s8kqr2v9ysbb7utrt/ultramediaburner.exe
GCleaner botnet C2 (confidence level: 100%)
urlhttp://hsiens.xyz/addinstall.php
GCleaner botnet C2 (confidence level: 100%)
urlhttp://194.145.227.161/partner.php
GCleaner botnet C2 (confidence level: 100%)
urlhttp://194.145.227.161/dlc/sharing.php
GCleaner botnet C2 (confidence level: 100%)
urlhttp://cleaner-partners.ltd/check.php
GCleaner botnet C2 (confidence level: 100%)
urlhttp://cleaner-partners.ltd/stats/save.php
GCleaner botnet C2 (confidence level: 100%)
urlhttp://mazama.xyz/addinstall.php
GCleaner botnet C2 (confidence level: 100%)
urlhttp://appwebstat.biz/stats/1.php
GCleaner botnet C2 (confidence level: 100%)
urlhttp://appwebstat.biz/connection
GCleaner botnet C2 (confidence level: 100%)
urlhttp://onlinehueplet.com/77_1.exe
GCleaner botnet C2 (confidence level: 100%)
urlhttp://gc-distribution.biz/pub.php
GCleaner botnet C2 (confidence level: 100%)
urlhttps://resultsxagency.com/
Vidar payload delivery URL (confidence level: 75%)
urlhttps://propertymiles.pk/
Vidar payload delivery URL (confidence level: 75%)
urlhttps://weekfoc.cyou
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://steamcommunity.com/profiles/76561198694566254
Vidar botnet C2 (confidence level: 100%)
urlhttps://telegram.me/d77xtr
Vidar botnet C2 (confidence level: 100%)
urlhttps://reg.turbo88op.top/
Vidar botnet C2 (confidence level: 100%)
urlhttps://lla.firesupport.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://fhe.firesupport.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://pas.firesupport.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://lla.fixsm188.top/
Vidar botnet C2 (confidence level: 100%)
urlhttps://fhe.fixsm188.top/
Vidar botnet C2 (confidence level: 100%)
urlhttps://pas.fixsm188.top/
Vidar botnet C2 (confidence level: 100%)
urlhttps://135.181.224.79/
Vidar botnet C2 (confidence level: 100%)
urlhttps://65.21.96.131/
Vidar botnet C2 (confidence level: 100%)
urlhttps://135.181.224.77/
Vidar botnet C2 (confidence level: 100%)
urlhttps://135.181.224.75/
Vidar botnet C2 (confidence level: 100%)
urlhttps://178.105.231.90/
Vidar botnet C2 (confidence level: 100%)
urlhttps://135.181.224.73/
Vidar botnet C2 (confidence level: 100%)
urlhttps://135.181.224.76/
Vidar botnet C2 (confidence level: 100%)
urlhttps://135.181.224.74/
Vidar botnet C2 (confidence level: 100%)
urlhttps://tknmetal.net/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://victormeloadvogado.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://oficialwebsitepromotion.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.jkbuildersg.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.kevinfreels.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://ireflect.net/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.iconlng.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.danielediana.it/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://developmental-twins.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.ciberci.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://buktijpmaluku.info/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.argirisangelopoulos.gr/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://andreawirsum.com/de/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.altecva.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://vrdccbank.com/doppee12.exe
Unknown RAT payload delivery URL (confidence level: 100%)
urlhttps://wowlowski.icu/file.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://wowlowski.icu/api/v1/session
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://wowlowski.icu/api/v1/verify
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://wowlowski.icu/api/v1/status
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://aura-checkpoint.top/o
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://jkylenewton.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://spaceco.com/ch
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://emberhorizon.top/role/role-view.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://emberhorizon.top/role/api-sessionstore
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://emberhorizon.top/role/refresh-layout.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://sad.fixsm188.top/
Vidar botnet C2 (confidence level: 75%)
urlhttps://sad.firesupport.com/
Vidar botnet C2 (confidence level: 75%)
urlhttps://kevinfreels.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://crystalforgeway.top/role/role-view.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://crystalforgeway.top/role/api-sessionstore
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://crystalforgeway.top/role/refresh-layout.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://gts.fixsm188.top/
Vidar botnet C2 (confidence level: 75%)
urlhttps://gts.firesupport.com/
Vidar botnet C2 (confidence level: 75%)
urlhttps://uru.fixsm188.top/
Vidar botnet C2 (confidence level: 100%)
urlhttps://uru.firesupport.com/
Vidar botnet C2 (confidence level: 100%)

Threat ID: 6a275bcde29bf47b50cdf4fe

Added to database: 6/9/2026, 12:18:21 AM

Last enriched: 6/9/2026, 12:19:17 AM

Last updated: 6/9/2026, 5:56:59 AM

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses