Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-06-13

0
Medium
Published: Sat Jun 13 2026 (06/13/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed

Description

ThreatFox IOCs for 2026-06-13

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/14/2026, 00:09:17 UTC

Technical Analysis

The ThreatFox IOCs for 2026-06-13 represent a collection of threat intelligence indicators related to malware activity. The data is sourced from an OSINT feed and focuses on network activity and payload delivery mechanisms. No specific vulnerabilities or affected software versions are identified, and no active exploits have been reported. The threat level is assessed as moderate based on available metadata, but detailed technical analysis or exploitation methods are not provided.

Potential Impact

No direct impact details or affected software are specified. The threat relates to malware indicators that could assist in detection and response but does not describe an exploitable vulnerability or confirmed active attack. There is no evidence of exploitation in the wild.

Mitigation Recommendations

No patch or official remediation is available or required as this is an intelligence report of IOCs rather than a vulnerability. Security teams should use the provided indicators to enhance detection capabilities but no urgent remediation actions are indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
0016806c-a25b-4142-a0a4-a7cd2269a44f
Original Timestamp
1781395387

Indicators of Compromise

File

ValueDescriptionCopy
file178.16.54.109
Phorpiex botnet C2 server (confidence level: 75%)
file188.164.250.223
Cobalt Strike botnet C2 server (confidence level: 100%)
file107.189.22.35
Cobalt Strike botnet C2 server (confidence level: 100%)
file185.89.254.46
Meterpreter botnet C2 server (confidence level: 100%)
file195.211.191.95
Remus botnet C2 server (confidence level: 75%)
file103.39.235.194
Meterpreter botnet C2 server (confidence level: 100%)
file43.156.218.130
Cobalt Strike botnet C2 server (confidence level: 50%)
file157.230.248.213
Cobalt Strike botnet C2 server (confidence level: 50%)
file103.245.27.100
Mirai payload delivery server (confidence level: 100%)
file152.236.6.8
Mirai botnet C2 server (confidence level: 100%)
file45.156.87.226
AsyncRAT botnet C2 server (confidence level: 100%)
file178.154.229.148
Cobalt Strike botnet C2 server (confidence level: 93%)
file92.53.97.113
Cobalt Strike botnet C2 server (confidence level: 96%)
file192.3.252.164
VShell botnet C2 server (confidence level: 100%)
file120.24.144.243
VShell botnet C2 server (confidence level: 100%)
file101.33.202.134
AdaptixC2 botnet C2 server (confidence level: 75%)
file102.46.221.148
AsyncRAT botnet C2 server (confidence level: 75%)
file107.173.9.88
AsyncRAT botnet C2 server (confidence level: 75%)
file108.181.115.254
RansomHub botnet C2 server (confidence level: 75%)
file108.181.115.254
RansomHub botnet C2 server (confidence level: 75%)
file130.185.82.117
AdaptixC2 botnet C2 server (confidence level: 75%)
file172.245.195.233
Remcos botnet C2 server (confidence level: 75%)
file182.23.2.163
Remcos botnet C2 server (confidence level: 75%)
file185.212.129.185
Evilginx botnet C2 server (confidence level: 75%)
file188.121.162.153
AsyncRAT botnet C2 server (confidence level: 75%)
file23.235.185.44
DCRat botnet C2 server (confidence level: 75%)
file31.76.32.201
Remcos botnet C2 server (confidence level: 75%)
file31.76.32.230
Remcos botnet C2 server (confidence level: 75%)
file34.123.214.16
BianLian botnet C2 server (confidence level: 75%)
file69.164.245.165
Remcos botnet C2 server (confidence level: 75%)
file89.42.134.220
AsyncRAT botnet C2 server (confidence level: 75%)
file98.191.176.231
DeimosC2 botnet C2 server (confidence level: 75%)
file185.207.154.11
AdaptixC2 botnet C2 server (confidence level: 100%)
file185.207.154.11
AdaptixC2 botnet C2 server (confidence level: 100%)
file185.207.154.11
AdaptixC2 botnet C2 server (confidence level: 100%)
file43.130.246.23
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.130.246.23
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.130.246.23
Cobalt Strike botnet C2 server (confidence level: 100%)
file95.182.114.29
Cobalt Strike botnet C2 server (confidence level: 100%)
file95.182.114.29
Cobalt Strike botnet C2 server (confidence level: 100%)
file118.24.128.201
Cobalt Strike botnet C2 server (confidence level: 75%)
file124.220.41.22
Cobalt Strike botnet C2 server (confidence level: 100%)
file124.220.41.22
Cobalt Strike botnet C2 server (confidence level: 100%)
file188.121.162.153
AsyncRAT botnet C2 server (confidence level: 100%)
file180.93.109.34
AsyncRAT botnet C2 server (confidence level: 100%)
file139.5.108.17
Cobalt Strike botnet C2 server (confidence level: 100%)
file139.5.108.17
Cobalt Strike botnet C2 server (confidence level: 100%)
file115.190.138.41
Cobalt Strike botnet C2 server (confidence level: 100%)
file115.190.138.41
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.152.67.129
VShell botnet C2 server (confidence level: 100%)
file23.27.0.84
VShell botnet C2 server (confidence level: 100%)
file18.232.64.100
Cobalt Strike botnet C2 server (confidence level: 100%)
file18.232.64.100
Cobalt Strike botnet C2 server (confidence level: 100%)
file18.232.64.100
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.107.106.178
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.141.121.30
Cobalt Strike botnet C2 server (confidence level: 100%)
file111.90.143.196
Cobalt Strike botnet C2 server (confidence level: 100%)
file107.172.133.182
AsyncRAT botnet C2 server (confidence level: 75%)
file144.91.78.57
DCRat botnet C2 server (confidence level: 75%)
file155.103.71.115
Remcos botnet C2 server (confidence level: 75%)
file157.22.185.5
AdaptixC2 botnet C2 server (confidence level: 75%)
file172.245.195.233
Remcos botnet C2 server (confidence level: 75%)
file182.23.2.163
Remcos botnet C2 server (confidence level: 75%)
file182.23.2.163
Remcos botnet C2 server (confidence level: 75%)
file191.107.87.183
AsyncRAT botnet C2 server (confidence level: 75%)
file191.107.87.183
Remcos botnet C2 server (confidence level: 75%)
file193.187.91.216
Remcos botnet C2 server (confidence level: 75%)
file2.26.75.218
Remcos botnet C2 server (confidence level: 75%)
file2.27.5.179
Remcos botnet C2 server (confidence level: 75%)
file209.99.185.96
AsyncRAT botnet C2 server (confidence level: 75%)
file209.99.189.198
Remcos botnet C2 server (confidence level: 75%)
file209.99.189.198
Remcos botnet C2 server (confidence level: 75%)
file31.76.32.181
Remcos botnet C2 server (confidence level: 75%)
file31.76.87.218
Remcos botnet C2 server (confidence level: 75%)
file45.153.127.224
Chaos botnet C2 server (confidence level: 75%)
file46.246.4.9
DCRat botnet C2 server (confidence level: 75%)
file72.51.57.131
DCRat botnet C2 server (confidence level: 75%)
file72.51.57.131
DCRat botnet C2 server (confidence level: 75%)
file85.121.176.239
Unknown malware botnet C2 server (confidence level: 75%)
file9.141.105.20
Unknown malware botnet C2 server (confidence level: 75%)
file94.103.1.223
Remcos botnet C2 server (confidence level: 75%)
file96.44.167.215
Remcos botnet C2 server (confidence level: 75%)
file96.44.167.215
Remcos botnet C2 server (confidence level: 75%)
file96.44.167.215
Remcos botnet C2 server (confidence level: 75%)
file128.90.63.86
AsyncRAT botnet C2 server (confidence level: 100%)
file209.99.185.96
AsyncRAT botnet C2 server (confidence level: 100%)
file120.27.245.127
Cobalt Strike botnet C2 server (confidence level: 100%)
file120.27.245.127
Cobalt Strike botnet C2 server (confidence level: 100%)
file120.27.245.127
Cobalt Strike botnet C2 server (confidence level: 100%)
file38.190.198.37
VShell botnet C2 server (confidence level: 100%)
file103.47.83.115
VShell botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash6000
Phorpiex botnet C2 server (confidence level: 75%)
hash3388
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Meterpreter botnet C2 server (confidence level: 100%)
hash4190
Remus botnet C2 server (confidence level: 75%)
hash443
Meterpreter botnet C2 server (confidence level: 100%)
hash8000
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Mirai payload delivery server (confidence level: 100%)
hashf2cbfb04c06d7a29349769b1c9b2c5c6b9b34f1d9f827d89b444016069f36656
Loki Password Stealer (PWS) payload (confidence level: 95%)
hash6eaf280a71db28b3557ebed4073412a6357f08c8
Loki Password Stealer (PWS) payload (confidence level: 95%)
hasha1e49c1cf7db97c042a5e5403fed0c79
Loki Password Stealer (PWS) payload (confidence level: 95%)
hash24efe51c32a2017f5ad0aab43a2eb099eaf4379846f1b4e8a62093338ddae517
Nanocore RAT payload (confidence level: 95%)
hash1f81e5529c284ea4561fd49997d5beb395ee2aa4
Nanocore RAT payload (confidence level: 95%)
hashe5cd97b309afed34383aff420333d831
Nanocore RAT payload (confidence level: 95%)
hashe913c5f78dbe49989518ee50ee56cdb581a16a16b5ebb2ff567d526b238a0fc2
Nanocore RAT payload (confidence level: 95%)
hash7c1dc6b792df9cf72d40102b9daa1969ce88e5f5
Nanocore RAT payload (confidence level: 95%)
hash94d2ca3c409914ad4d42ea57ce4b36b1
Nanocore RAT payload (confidence level: 95%)
hash13a1587305880da5fbd956cf9a1353a336996a66735f887004e38ed65b2f7ff1
Taurus Stealer payload (confidence level: 95%)
hash7105e52803914e37050b6f2a4c0d8a8339a2a381
Taurus Stealer payload (confidence level: 95%)
hash8368894761e8f296575356fe49978880
Taurus Stealer payload (confidence level: 95%)
hashaf71d8886f256bf2393b1bf6d44b2fcb50d7d546e49bb7b6fbe151a3cf2032f5
Ghost RAT payload (confidence level: 95%)
hashf16c4398c613a78c391f2e721f95d879e9bd356c
Ghost RAT payload (confidence level: 95%)
hashfceaf8af1a6e83e0a1ae35a4a2fa35a7
Ghost RAT payload (confidence level: 95%)
hash49999f257686cfba6fe9504ff99a7776f998e3ba4887d28d2957f040ac346306
Amadey payload (confidence level: 95%)
hash1d3a5e780488095d6174bcdc49ee16c0ea802a6a
Amadey payload (confidence level: 95%)
hash347187dc7824a887b8f6a3272b3baf12
Amadey payload (confidence level: 95%)
hash28291
Mirai botnet C2 server (confidence level: 100%)
hash8545
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 93%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 96%)
hash80
VShell botnet C2 server (confidence level: 100%)
hash16001
VShell botnet C2 server (confidence level: 100%)
hash9989
AdaptixC2 botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash8000
AsyncRAT botnet C2 server (confidence level: 75%)
hash443
RansomHub botnet C2 server (confidence level: 75%)
hash7045
RansomHub botnet C2 server (confidence level: 75%)
hash5641
AdaptixC2 botnet C2 server (confidence level: 75%)
hash14641
Remcos botnet C2 server (confidence level: 75%)
hash59678
Remcos botnet C2 server (confidence level: 75%)
hash9000
Evilginx botnet C2 server (confidence level: 75%)
hash5000
AsyncRAT botnet C2 server (confidence level: 75%)
hash12159
DCRat botnet C2 server (confidence level: 75%)
hash1377
Remcos botnet C2 server (confidence level: 75%)
hash1499
Remcos botnet C2 server (confidence level: 75%)
hash8443
BianLian botnet C2 server (confidence level: 75%)
hash8930
Remcos botnet C2 server (confidence level: 75%)
hash1991
AsyncRAT botnet C2 server (confidence level: 75%)
hash8080
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
AdaptixC2 botnet C2 server (confidence level: 100%)
hash80
AdaptixC2 botnet C2 server (confidence level: 100%)
hash8080
AdaptixC2 botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash64727
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8000
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8086
VShell botnet C2 server (confidence level: 100%)
hash50001
VShell botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8081
Cobalt Strike botnet C2 server (confidence level: 100%)
hash56003
AsyncRAT botnet C2 server (confidence level: 75%)
hash207
DCRat botnet C2 server (confidence level: 75%)
hash14409
Remcos botnet C2 server (confidence level: 75%)
hash443
AdaptixC2 botnet C2 server (confidence level: 75%)
hash14644
Remcos botnet C2 server (confidence level: 75%)
hash49415
Remcos botnet C2 server (confidence level: 75%)
hash5814
Remcos botnet C2 server (confidence level: 75%)
hash5011
AsyncRAT botnet C2 server (confidence level: 75%)
hash5469
Remcos botnet C2 server (confidence level: 75%)
hash51842
Remcos botnet C2 server (confidence level: 75%)
hash6913
Remcos botnet C2 server (confidence level: 75%)
hash4509
Remcos botnet C2 server (confidence level: 75%)
hash2025
AsyncRAT botnet C2 server (confidence level: 75%)
hash7005
Remcos botnet C2 server (confidence level: 75%)
hash7006
Remcos botnet C2 server (confidence level: 75%)
hash8455
Remcos botnet C2 server (confidence level: 75%)
hash9405
Remcos botnet C2 server (confidence level: 75%)
hash443
Chaos botnet C2 server (confidence level: 75%)
hash8848
DCRat botnet C2 server (confidence level: 75%)
hash5202
DCRat botnet C2 server (confidence level: 75%)
hash7997
DCRat botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash3421
Remcos botnet C2 server (confidence level: 75%)
hash14644
Remcos botnet C2 server (confidence level: 75%)
hash14646
Remcos botnet C2 server (confidence level: 75%)
hash14648
Remcos botnet C2 server (confidence level: 75%)
hash4444
AsyncRAT botnet C2 server (confidence level: 100%)
hash3000
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash10001
VShell botnet C2 server (confidence level: 100%)

Domain

ValueDescriptionCopy
domainfrreliny.com
Unidentified 001 botnet C2 domain (confidence level: 75%)
domainavexor.top
SmartApeSG botnet C2 domain (confidence level: 75%)
domaindivinenarratives.org
SmartApeSG payload delivery domain (confidence level: 100%)
domaincowhdabq.shartbandi.games
ClearFake payload delivery domain (confidence level: 100%)
domainedtmogyp.red90.casino
ClearFake payload delivery domain (confidence level: 100%)
domaintkzvl.nagshekeshi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainfmhkmjyi.hugugtejarat4.xyz
ClearFake payload delivery domain (confidence level: 100%)
domain9xt13o7k.moarefeslami.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainwutgubeq.hugugtatbigi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaincdvmgdw.melbetkade.com
ClearFake payload delivery domain (confidence level: 100%)
domainqjgjbwpw.hugugnasiri.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainxmxmplzc.hugugmadanikatouzian.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainp4pav6zh.garatequran.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainwgtpfakz.akhlagvaahkam.xyz
ClearFake payload delivery domain (confidence level: 100%)
domain9fmgmj87.garatequran.xyz
ClearFake payload delivery domain (confidence level: 100%)
domain2igj4kg6.shartbandifootballkade.online
ClearFake payload delivery domain (confidence level: 100%)
domainvbotnt1.duckdns.org
Mirai botnet C2 domain (confidence level: 100%)
domainezrzb.downloadquran.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainnwklhlmm.hugugmadani6.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainmhhalmi.pokerkade.online
ClearFake payload delivery domain (confidence level: 100%)
domaindngzhceb.hugugmadani3.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainpsmecdlr.hugugedari.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainkg0kdihy.gavaedfagahe.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainjyvartai.hugugdaryayi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainaoeoelfz.hugugbime.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainkrigo.ecologyardakani.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaingsdzofat.winxbet.co
ClearFake payload delivery domain (confidence level: 100%)
domainv47e4385.fununetadris.shop
ClearFake payload delivery domain (confidence level: 100%)
domainggcjxgov.fununetadris.shop
ClearFake payload delivery domain (confidence level: 100%)
domainobmhxqg.rocketbet.pro
ClearFake payload delivery domain (confidence level: 100%)
domainalrwomdp.restaurantguideaarhus.com
ClearFake payload delivery domain (confidence level: 100%)
domainsh6rkpx6.shartmag.bet
ClearFake payload delivery domain (confidence level: 100%)
domain29jpudxc.geotechnictahuni.store
ClearFake payload delivery domain (confidence level: 100%)
domainggifzobt.hugugmadani3.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainowbzzpof.1xbetmag.com
ClearFake payload delivery domain (confidence level: 100%)
domainfaogw.bankefile.com
ClearFake payload delivery domain (confidence level: 100%)
domainzthedtkr.1xbitkade.com
ClearFake payload delivery domain (confidence level: 100%)
domain5dg7o57f.questionstest.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainundb4pt3.questionstest.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaintoolcvu.livebetkade.com
ClearFake payload delivery domain (confidence level: 100%)
domainymwntmdt.1xborokade.com
ClearFake payload delivery domain (confidence level: 100%)
domainxrekqgkh.1xyek.net
ClearFake payload delivery domain (confidence level: 100%)
domainhhghzngh.22betkade.online
ClearFake payload delivery domain (confidence level: 100%)
domainmkspkafs.4030bet.app
ClearFake payload delivery domain (confidence level: 100%)
domainqnuaqbez.anodaz.vip
ClearFake payload delivery domain (confidence level: 100%)
domain8dtstox1.bordestan.com
ClearFake payload delivery domain (confidence level: 100%)
domainframework-css-styles-js.beer
Vidar botnet C2 domain (confidence level: 100%)
domainethercdnns.beer
Vidar botnet C2 domain (confidence level: 100%)
domainmisterslivker.asia
Vidar botnet C2 domain (confidence level: 100%)
domainmylovedomen.asia
Vidar botnet C2 domain (confidence level: 100%)
domainslivkishow.asia
Vidar botnet C2 domain (confidence level: 100%)
domainthisismine.asia
Vidar botnet C2 domain (confidence level: 100%)
domainverification-js-cdn.boats
Vidar botnet C2 domain (confidence level: 100%)
domainkdqtqtbo.ace9bet.net
ClearFake payload delivery domain (confidence level: 100%)
domainwabel.azmoonzare.online
ClearFake payload delivery domain (confidence level: 100%)
domainboqetwvb.bcgamekade.online
ClearFake payload delivery domain (confidence level: 100%)
domainqzxjphs.megaparikade.com
ClearFake payload delivery domain (confidence level: 100%)
domainqoutbfpg.bet120x.net
ClearFake payload delivery domain (confidence level: 100%)
domaink969mylb.casinokade.online
ClearFake payload delivery domain (confidence level: 100%)
domainphw2uk1e.casinokade.online
ClearFake payload delivery domain (confidence level: 100%)
domainbqxhfhog.bet313.org
ClearFake payload delivery domain (confidence level: 100%)
domaindyqanvdt.betfidokade.com
ClearFake payload delivery domain (confidence level: 100%)
domainurelelgc.betforwardkade.com
ClearFake payload delivery domain (confidence level: 100%)
domaincugeuvle.betwanna.com
ClearFake payload delivery domain (confidence level: 100%)
domainxetxx.bankefile.com
ClearFake payload delivery domain (confidence level: 100%)
domainvkmz8u3b.enfejarkade.online
ClearFake payload delivery domain (confidence level: 100%)
domainhaoriskdk839ska.com
Unknown Loader payload delivery domain (confidence level: 100%)
domainhatksaks281ksa.com
Unknown Loader payload delivery domain (confidence level: 100%)
domainphoto-27857.cfd
Unknown Loader payload delivery domain (confidence level: 100%)
domainphoto-37857.cfd
Unknown Loader payload delivery domain (confidence level: 100%)
domainphoto-47857.cfd
Unknown Loader payload delivery domain (confidence level: 100%)
domain1mp15ubu.shansline.com
ClearFake payload delivery domain (confidence level: 100%)
domainfswqsjdd.betxane.com
ClearFake payload delivery domain (confidence level: 100%)
domaingbbzykw.melbetkade.com
ClearFake payload delivery domain (confidence level: 100%)
domainhoneymoonshop.asia
Unknown malware payload delivery domain (confidence level: 100%)
domainmampodik.asia
Unknown malware payload delivery domain (confidence level: 100%)
domainnqsaymjr.betyek.net
ClearFake payload delivery domain (confidence level: 100%)
domainjrmcsezq.hugugbime.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainvhsqohyd.hugugdaryayi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainlmjkrmqt.fubet24.net
ClearFake payload delivery domain (confidence level: 100%)
domainosggwts6.fubet24.net
ClearFake payload delivery domain (confidence level: 100%)
domainwdbcypih.hugugedari.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainkzkzbbha.hugugmadani6.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainhfolz.bookdrive.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainkl23rl6f.nahjolbalage.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainigrbuyo.pokerkade.online
ClearFake payload delivery domain (confidence level: 100%)
domainuhnuyfcr.hugugmadanikatouzian.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainlungilehealth.com
StrelaStealer payload delivery domain (confidence level: 100%)
domainyym1l9om.qurandownload.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainxeviozwk.hugugnasiri.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainahkyokta.hugugtatbigi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainpirqlheh.hugugtejarat4.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainzkclsegh.jam-jahani.com
ClearFake payload delivery domain (confidence level: 100%)
domainyba7z7vt.ravansalamat.shop
ClearFake payload delivery domain (confidence level: 100%)
domain8r61gwvq.ravansalamat.shop
ClearFake payload delivery domain (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://bge-visa.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://divinenarratives.org/d.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://mottla.shop:4190
Remus botnet C2 (confidence level: 75%)
urlhttp://abscete.info/ret/two/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttp://verification-js-cdn.boats/5c89e36548466c44
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://verification-js-cdn.boats/5c89e36548466c44?_=1
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://verification-js-cdn.boats/5c89e36548466c44?ack=1
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://verification-js-cdn.boats/67422f998296584824aa06c4066c9074457e4dd28a5a84cb209900f0c82a47f0
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://devltd.us/flomos1.zip
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://supertransfer.ch/
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://galaxygraphicsprints.com/
Vidar payload delivery URL (confidence level: 75%)
urlhttp://alchsp.xyz:7673
Remus botnet C2 (confidence level: 75%)

Threat ID: 6a2df128e617e2d8345dee1c

Added to database: 6/14/2026, 12:09:12 AM

Last enriched: 6/14/2026, 12:09:17 AM

Last updated: 6/14/2026, 2:36:15 AM

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses