Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-06-15

0
Medium
Published: Mon Jun 15 2026 (06/15/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed

Description

ThreatFox IOCs for 2026-06-15

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/16/2026, 00:15:57 UTC

Technical Analysis

The report provides a set of ThreatFox IOCs collected on 2026-06-15 concerning malware-related network activity and payload delivery. There are no detailed technical indicators or affected software versions specified. No patches or vendor advisories are available, and no exploits are currently known to be active in the wild. The threat level is moderate, reflecting limited analysis and distribution data.

Potential Impact

The impact is currently unclear due to the absence of detailed indicators or affected software information. The threat involves malware-related network activity and payload delivery, which could potentially lead to compromise if exploited, but no active exploitation is reported.

Mitigation Recommendations

No patches or official remediations are available for this threat. Security teams should monitor for related IOCs from trusted sources like ThreatFox and apply standard network security controls relevant to malware detection and prevention. Since no vendor advisories or fixes exist, rely on threat intelligence updates for further guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
e3479bfd-6ad4-47e0-97f0-962e7eea20e3
Original Timestamp
1781568186

Indicators of Compromise

File

ValueDescriptionCopy
file173.44.139.144
SPICA botnet C2 server (confidence level: 75%)
file45.133.216.15
SPICA botnet C2 server (confidence level: 75%)
file95.164.17.94
SPICA botnet C2 server (confidence level: 75%)
file89.19.211.240
SPICA botnet C2 server (confidence level: 75%)
file185.188.155.179
Cobalt Strike botnet C2 server (confidence level: 93%)
file65.21.96.133
Vidar botnet C2 server (confidence level: 100%)
file46.224.136.4
Vidar botnet C2 server (confidence level: 100%)
file128.140.123.80
Vidar botnet C2 server (confidence level: 100%)
file5.161.119.247
Vidar botnet C2 server (confidence level: 100%)
file46.225.162.206
Vidar botnet C2 server (confidence level: 100%)
file204.168.163.225
Vidar botnet C2 server (confidence level: 100%)
file178.104.208.168
Vidar botnet C2 server (confidence level: 100%)
file62.238.44.180
Vidar botnet C2 server (confidence level: 100%)
file178.104.211.206
Vidar botnet C2 server (confidence level: 100%)
file46.62.255.252
Vidar botnet C2 server (confidence level: 100%)
file46.225.156.170
Vidar botnet C2 server (confidence level: 100%)
file95.216.152.191
Vidar botnet C2 server (confidence level: 100%)
file178.105.210.87
Vidar botnet C2 server (confidence level: 100%)
file43.228.79.138
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.228.79.138
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.228.79.138
Cobalt Strike botnet C2 server (confidence level: 100%)
file162.243.15.224
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.136.53.4
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.145.44.217
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.202.1.194
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.136.53.4
Cobalt Strike botnet C2 server (confidence level: 100%)
file151.239.24.141
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.228.79.138
Cobalt Strike botnet C2 server (confidence level: 100%)
file207.56.229.19
XMRIG payload delivery server (confidence level: 80%)
file77.223.99.43
XMRIG payload delivery server (confidence level: 80%)
file41.110.4.106
XMRIG payload delivery server (confidence level: 80%)
file202.61.224.163
XMRIG payload delivery server (confidence level: 80%)
file47.113.229.153
XMRIG payload delivery server (confidence level: 80%)
file138.197.39.208
RedTail payload delivery server (confidence level: 80%)
file180.93.43.226
RedTail payload delivery server (confidence level: 80%)
file181.104.43.225
RedTail payload delivery server (confidence level: 80%)
file192.3.16.60
RedTail payload delivery server (confidence level: 80%)
file195.54.179.244
RedTail payload delivery server (confidence level: 80%)
file212.127.90.201
RedTail payload delivery server (confidence level: 80%)
file107.172.133.182
AsyncRAT botnet C2 server (confidence level: 75%)
file131.143.251.246
AdaptixC2 botnet C2 server (confidence level: 75%)
file198.23.185.231
AsyncRAT botnet C2 server (confidence level: 75%)
file20.224.219.169
Havoc botnet C2 server (confidence level: 75%)
file209.99.187.37
Unknown malware botnet C2 server (confidence level: 75%)
file213.193.20.192
AdaptixC2 botnet C2 server (confidence level: 75%)
file31.6.11.162
AsyncRAT botnet C2 server (confidence level: 75%)
file31.76.87.112
Remcos botnet C2 server (confidence level: 75%)
file8.210.84.56
AdaptixC2 botnet C2 server (confidence level: 75%)
file83.229.85.74
AsyncRAT botnet C2 server (confidence level: 75%)
file87.182.39.55
AsyncRAT botnet C2 server (confidence level: 75%)
file89.42.134.220
AsyncRAT botnet C2 server (confidence level: 75%)
file8.136.53.4
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.136.53.4
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.136.53.4
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.202.1.194
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.202.1.194
Cobalt Strike botnet C2 server (confidence level: 100%)
file106.14.116.17
Unknown malware botnet C2 server (confidence level: 100%)
file106.14.116.17
Unknown malware botnet C2 server (confidence level: 100%)
file101.43.128.56
VShell botnet C2 server (confidence level: 100%)
file112.121.165.42
VShell botnet C2 server (confidence level: 100%)
file112.121.165.43
VShell botnet C2 server (confidence level: 100%)
file185.190.91.33
Sliver botnet C2 server (confidence level: 100%)
file185.89.182.91
Meterpreter botnet C2 server (confidence level: 94%)
file185.190.204.235
Meterpreter botnet C2 server (confidence level: 94%)
file185.188.156.119
Cobalt Strike botnet C2 server (confidence level: 94%)
file38.110.228.124
Unknown malware payload delivery server (confidence level: 75%)
file106.14.116.17
Unknown malware botnet C2 server (confidence level: 100%)
file156.244.13.30
Quasar RAT botnet C2 server (confidence level: 100%)
file172.245.106.54
XWorm botnet C2 server (confidence level: 75%)
file79.175.189.207
Cobalt Strike botnet C2 server (confidence level: 100%)
file79.175.189.207
Cobalt Strike botnet C2 server (confidence level: 100%)
file79.175.189.207
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.99.204.80
VShell botnet C2 server (confidence level: 100%)
file202.162.106.233
VShell botnet C2 server (confidence level: 100%)
file47.236.102.8
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.236.102.8
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.236.102.8
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.95.170.223
Cobalt Strike botnet C2 server (confidence level: 75%)
file77.83.39.246
Unknown RAT botnet C2 server (confidence level: 75%)
file77.83.39.195
Unknown RAT botnet C2 server (confidence level: 75%)
file209.99.185.82
Unknown RAT botnet C2 server (confidence level: 75%)
file209.99.184.204
Unknown RAT botnet C2 server (confidence level: 75%)
file209.99.184.6
Unknown RAT botnet C2 server (confidence level: 75%)
file209.99.184.206
Unknown RAT botnet C2 server (confidence level: 75%)
file209.99.185.52
Unknown RAT botnet C2 server (confidence level: 75%)
file209.99.190.86
Unknown RAT botnet C2 server (confidence level: 75%)
file209.99.188.199
Unknown RAT botnet C2 server (confidence level: 75%)
file85.137.52.21
Stealc botnet C2 server (confidence level: 80%)
file209.99.190.206
Unknown RAT botnet C2 server (confidence level: 75%)
file209.99.188.210
Unknown RAT botnet C2 server (confidence level: 75%)
file209.99.188.180
Unknown RAT botnet C2 server (confidence level: 75%)
file209.99.188.149
Unknown RAT botnet C2 server (confidence level: 75%)
file64.89.160.96
Unknown RAT botnet C2 server (confidence level: 75%)
file46.151.182.197
Unknown RAT botnet C2 server (confidence level: 75%)
file62.60.226.155
Unknown RAT botnet C2 server (confidence level: 75%)
file124.198.132.139
Unknown RAT botnet C2 server (confidence level: 75%)
file124.198.131.74
Unknown RAT botnet C2 server (confidence level: 75%)
file139.59.137.44
Remus botnet C2 server (confidence level: 75%)
file98.98.144.134
Nanocore RAT botnet C2 server (confidence level: 100%)
file98.98.144.133
Nanocore RAT botnet C2 server (confidence level: 100%)
file91.215.85.42
Unknown RAT botnet C2 server (confidence level: 75%)
file185.161.208.152
Remcos botnet C2 server (confidence level: 75%)
file185.161.208.152
Remcos botnet C2 server (confidence level: 75%)
file192.227.135.225
Remcos botnet C2 server (confidence level: 75%)
file124.198.131.252
Mirai payload delivery server (confidence level: 100%)
file192.159.99.110
Mirai payload delivery server (confidence level: 100%)
file92.42.100.131
Mirai payload delivery server (confidence level: 100%)
file45.153.34.146
Unknown malware botnet C2 server (confidence level: 75%)
file185.236.25.119
Unknown malware botnet C2 server (confidence level: 75%)
file85.90.197.26
Unknown malware botnet C2 server (confidence level: 75%)
file103.181.34.161
Cobalt Strike botnet C2 server (confidence level: 93%)
file102.220.160.222
AsyncRAT botnet C2 server (confidence level: 75%)
file102.46.221.148
AsyncRAT botnet C2 server (confidence level: 75%)
file144.31.236.223
Remcos botnet C2 server (confidence level: 75%)
file154.44.20.174
AdaptixC2 botnet C2 server (confidence level: 75%)
file156.247.54.10
DCRat botnet C2 server (confidence level: 75%)
file156.247.54.10
DCRat botnet C2 server (confidence level: 75%)
file156.247.54.12
DCRat botnet C2 server (confidence level: 75%)
file156.247.54.13
DCRat botnet C2 server (confidence level: 75%)
file156.247.54.14
DCRat botnet C2 server (confidence level: 75%)
file166.88.159.146
BianLian botnet C2 server (confidence level: 75%)
file172.245.195.233
Remcos botnet C2 server (confidence level: 75%)
file182.23.2.163
Remcos botnet C2 server (confidence level: 75%)
file182.23.2.163
Remcos botnet C2 server (confidence level: 75%)
file182.23.2.163
Remcos botnet C2 server (confidence level: 75%)
file185.190.142.121
Havoc botnet C2 server (confidence level: 75%)
file2.27.5.220
Remcos botnet C2 server (confidence level: 75%)
file212.193.5.199
Evilginx botnet C2 server (confidence level: 75%)
file72.52.132.8
Chaos botnet C2 server (confidence level: 75%)
file96.44.167.215
Remcos botnet C2 server (confidence level: 75%)
file155.103.71.244
XWorm botnet C2 server (confidence level: 75%)
file154.198.50.38
DCRat botnet C2 server (confidence level: 100%)
file47.120.20.86
Cobalt Strike botnet C2 server (confidence level: 100%)
file91.92.120.98
Remcos botnet C2 server (confidence level: 75%)
file107.173.47.132
Remcos botnet C2 server (confidence level: 75%)
file64.89.160.219
Remcos botnet C2 server (confidence level: 75%)
file129.204.14.131
Cobalt Strike botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash3000
SPICA botnet C2 server (confidence level: 75%)
hash3000
SPICA botnet C2 server (confidence level: 75%)
hash3000
SPICA botnet C2 server (confidence level: 75%)
hash3000
SPICA botnet C2 server (confidence level: 75%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 93%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash808
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9999
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9090
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2375
XMRIG payload delivery server (confidence level: 80%)
hash2375
XMRIG payload delivery server (confidence level: 80%)
hash2375
XMRIG payload delivery server (confidence level: 80%)
hash2375
XMRIG payload delivery server (confidence level: 80%)
hash6379
XMRIG payload delivery server (confidence level: 80%)
hash80
RedTail payload delivery server (confidence level: 80%)
hash80
RedTail payload delivery server (confidence level: 80%)
hash80
RedTail payload delivery server (confidence level: 80%)
hash80
RedTail payload delivery server (confidence level: 80%)
hash80
RedTail payload delivery server (confidence level: 80%)
hash80
RedTail payload delivery server (confidence level: 80%)
hash56002
AsyncRAT botnet C2 server (confidence level: 75%)
hash53921
AdaptixC2 botnet C2 server (confidence level: 75%)
hash70
AsyncRAT botnet C2 server (confidence level: 75%)
hash80
Havoc botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash9281
AdaptixC2 botnet C2 server (confidence level: 75%)
hash7070
AsyncRAT botnet C2 server (confidence level: 75%)
hash7716
Remcos botnet C2 server (confidence level: 75%)
hash8000
AdaptixC2 botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash51123
AsyncRAT botnet C2 server (confidence level: 75%)
hash1803
AsyncRAT botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
VShell botnet C2 server (confidence level: 100%)
hash80
VShell botnet C2 server (confidence level: 100%)
hash80
VShell botnet C2 server (confidence level: 100%)
hash9443
Sliver botnet C2 server (confidence level: 100%)
hash8443
Meterpreter botnet C2 server (confidence level: 94%)
hash443
Meterpreter botnet C2 server (confidence level: 94%)
hash443
Cobalt Strike botnet C2 server (confidence level: 94%)
hash79
Unknown malware payload delivery server (confidence level: 75%)
hash681c3b22d00252e557c458a84f4fdbf37e23ce34db9ba4bd419d17ba6c5ce937
Unknown malware payload (confidence level: 75%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash3333
XWorm botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8821
VShell botnet C2 server (confidence level: 100%)
hash18082
VShell botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash18443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash80
Stealc botnet C2 server (confidence level: 80%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash443
Unknown RAT botnet C2 server (confidence level: 75%)
hash5003
Remus botnet C2 server (confidence level: 75%)
hash443
Nanocore RAT botnet C2 server (confidence level: 100%)
hash443
Nanocore RAT botnet C2 server (confidence level: 100%)
hash3000
Unknown RAT botnet C2 server (confidence level: 75%)
hash51493
Remcos botnet C2 server (confidence level: 75%)
hash59657
Remcos botnet C2 server (confidence level: 75%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash2049
Mirai payload delivery server (confidence level: 100%)
hash2049
Mirai payload delivery server (confidence level: 100%)
hash4568
Mirai payload delivery server (confidence level: 100%)
hash3001
Unknown malware botnet C2 server (confidence level: 75%)
hash3001
Unknown malware botnet C2 server (confidence level: 75%)
hash7000
Unknown malware botnet C2 server (confidence level: 75%)
hashda8d89a25d0edc6186a9e70bca59e37a25b1f4ab84966ed1e4b9aa35d2c20601
Unknown malware payload (confidence level: 100%)
hasha92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0
Unknown malware payload (confidence level: 100%)
hashc0d896e94c4dd8b64f400d16ec3cb59f3c51fc940d06241a028d0204d0407a94
AsyncRAT payload (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 93%)
hash8808
AsyncRAT botnet C2 server (confidence level: 75%)
hash7707
AsyncRAT botnet C2 server (confidence level: 75%)
hash9405
Remcos botnet C2 server (confidence level: 75%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 75%)
hash12159
DCRat botnet C2 server (confidence level: 75%)
hash8848
DCRat botnet C2 server (confidence level: 75%)
hash12159
DCRat botnet C2 server (confidence level: 75%)
hash12159
DCRat botnet C2 server (confidence level: 75%)
hash12159
DCRat botnet C2 server (confidence level: 75%)
hash5353
BianLian botnet C2 server (confidence level: 75%)
hash14646
Remcos botnet C2 server (confidence level: 75%)
hash54257
Remcos botnet C2 server (confidence level: 75%)
hash625
Remcos botnet C2 server (confidence level: 75%)
hash7563
Remcos botnet C2 server (confidence level: 75%)
hash8443
Havoc botnet C2 server (confidence level: 75%)
hash2428
Remcos botnet C2 server (confidence level: 75%)
hash9000
Evilginx botnet C2 server (confidence level: 75%)
hash8081
Chaos botnet C2 server (confidence level: 75%)
hash14647
Remcos botnet C2 server (confidence level: 75%)
hash1234
XWorm botnet C2 server (confidence level: 75%)
hash8848
DCRat botnet C2 server (confidence level: 100%)
hash8989
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash8080
Remcos botnet C2 server (confidence level: 75%)
hash57000
Cobalt Strike botnet C2 server (confidence level: 75%)

Domain

ValueDescriptionCopy
domaintcp.tcptunnel.shop
Unknown RAT botnet C2 domain (confidence level: 100%)
domainl9oi6rwb.bordestan.com
ClearFake payload delivery domain (confidence level: 100%)
domaincwpjgrng.hugugtatbigi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaintwmpoxnh.hugugtejarat4.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainobuultev.casinokade.online
ClearFake payload delivery domain (confidence level: 100%)
domainq6ewl5b2.casinokade.online
ClearFake payload delivery domain (confidence level: 100%)
domainbgfwrtgo.jam-jahani.com
ClearFake payload delivery domain (confidence level: 100%)
domainqelljcx.megaparikade.com
ClearFake payload delivery domain (confidence level: 100%)
domainsdppicy4.shansline.com
ClearFake payload delivery domain (confidence level: 100%)
domainlhpahogn.karafarini.shop
ClearFake payload delivery domain (confidence level: 100%)
domainlvegwzzz.karbordriyaziyat.xyz
ClearFake payload delivery domain (confidence level: 100%)
domain384njud7.enfejarkade.online
ClearFake payload delivery domain (confidence level: 100%)
domainfkwiyfrv.leaguejazire.com
ClearFake payload delivery domain (confidence level: 100%)
domaintawej.bankefiile.com
ClearFake payload delivery domain (confidence level: 100%)
domain543533s9.nagshekeshi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaintblrdccw.mabanishimi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaineverztsi.maharatmodiran.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainpauheuld.questionsmotor.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainutnoqzc.melbetkade.com
ClearFake payload delivery domain (confidence level: 100%)
domainggt.glamisrents.com
Vidar botnet C2 domain (confidence level: 100%)
domainpod.turbo88jp.top
Vidar botnet C2 domain (confidence level: 100%)
domainewa1b63u.fununetadris.shop
ClearFake payload delivery domain (confidence level: 100%)
domain9zpx37x0.ganuneasasi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainqilapvvt.ganuneasasi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainvazqhwad.sadreislam.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainbcfrgjpx.sakhtemandade.shop
ClearFake payload delivery domain (confidence level: 100%)
domainsnd.goturbo88.top
Vidar botnet C2 domain (confidence level: 100%)
domainikg.goturbo88.top
Vidar botnet C2 domain (confidence level: 100%)
domainggt.goturbo88.top
Vidar botnet C2 domain (confidence level: 100%)
domainsnd.glamisrents.com
Vidar botnet C2 domain (confidence level: 100%)
domainikg.glamisrents.com
Vidar botnet C2 domain (confidence level: 100%)
domainfpsjq82d.shartbandifootballkade.online
ClearFake payload delivery domain (confidence level: 100%)
domainmaryaxdn.sanjeshravani.shop
ClearFake payload delivery domain (confidence level: 100%)
domainyqzbm.barnamenevisi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainfhprjdfj.sanjeshvaandazegiri.shop
ClearFake payload delivery domain (confidence level: 100%)
domainlmgz1tb4.garatequran.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainmukvsxft.sazebetonarme.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainonnzlkiy.shartbandi.games
ClearFake payload delivery domain (confidence level: 100%)
domainamrwjltv.tarikhcheravanshenasi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainpbh3hti8.gavaedfagahe.xyz
ClearFake payload delivery domain (confidence level: 100%)
domain0dt4r35j.gavaedfagahe.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainmjwougwp.tarikhravannovin.shop
ClearFake payload delivery domain (confidence level: 100%)
domainbigfrogs.info
Unknown Loader payload delivery domain (confidence level: 100%)
domainstrayweirds.info
Unknown Loader payload delivery domain (confidence level: 100%)
domainmarmoteilefinance.com
Unknown Loader payload delivery domain (confidence level: 100%)
domainfcxkiekt.tasisathosseini.shop
ClearFake payload delivery domain (confidence level: 100%)
domainqqpidjr.megaparikade.com
ClearFake payload delivery domain (confidence level: 100%)
domainvwochim.megaparikade.com
ClearFake payload delivery domain (confidence level: 100%)
domainoxfzzuaq.tasisathosseini.shop
ClearFake payload delivery domain (confidence level: 100%)
domaincucnczaq.testdrivepaye3.com
ClearFake payload delivery domain (confidence level: 100%)
domainbxzyp.daneshkhanevade.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaindkrxwehc.testpaye.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainttmwdcsm.testranandegi.com
ClearFake payload delivery domain (confidence level: 100%)
domainhfl413ch.geotechnictahuni.store
ClearFake payload delivery domain (confidence level: 100%)
domainfqcwxddh.tractor11.com
ClearFake payload delivery domain (confidence level: 100%)
domainncpzdseh.usoleamoozesh.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaineichmnnn.icu
KongTuke payload delivery domain (confidence level: 100%)
domaina.qqmusic1.com
ValleyRAT botnet C2 domain (confidence level: 75%)
domaingriontera.com
Unknown malware payload delivery domain (confidence level: 75%)
domainkcgxidkf.hugugmadani6.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainqeqnjdds.hugugmadani6.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainqbuhghd.melbetkade.com
ClearFake payload delivery domain (confidence level: 100%)
domainsvs-verificationdate.beer
Unknown malware payload delivery domain (confidence level: 100%)
domain0snofqmc.megaparikade.com
ClearFake payload delivery domain (confidence level: 100%)
domain4u3hglwc.moarefeslami.xyz
ClearFake payload delivery domain (confidence level: 100%)
domain0hz5u1mn.moarefeslami.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainone-verif.lol
KongTuke payload delivery domain (confidence level: 100%)
domainaenvmnaq.hugugmadanikatouzian.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainfroqlquf.hugugmadanikatouzian.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainopyo2s3o.akhlagvaahkam.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainzvxuc.darsnamejame.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaingnw.goturbo88.top
Vidar botnet C2 domain (confidence level: 75%)
domaingnw.glamisrents.com
Vidar botnet C2 domain (confidence level: 75%)
domainwgmqenjy.hugugtatbigi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainvdljitxt.hugugtatbigi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainfiles.smartpcai.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domaineminley.ydns.eu
XWorm botnet C2 domain (confidence level: 75%)
domainyuehqazj.hugugtejarat4.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainpaqyqptu.hugugtejarat4.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaincpulbnri.jam-jahani.com
ClearFake payload delivery domain (confidence level: 100%)
domainthhcalzn.jam-jahani.com
ClearFake payload delivery domain (confidence level: 100%)
domainft4borxw.questionstest.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainevoklbxr.karafarini.shop
ClearFake payload delivery domain (confidence level: 100%)
domaineofvjfbp.karafarini.shop
ClearFake payload delivery domain (confidence level: 100%)
domainstonewound.space
Unknown Loader botnet C2 domain (confidence level: 100%)
domainardaplumeit.top
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaincs.tpedu2metricstw.dpdns.org
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaindvbkmkq.rocketbet.pro
ClearFake payload delivery domain (confidence level: 100%)
domainlmlnqaju.karbordriyaziyat.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainprod-images.familyoffice-tech.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainyrzwlqcu.leaguejazire.com
ClearFake payload delivery domain (confidence level: 100%)
domainfinale-code.lol
KongTuke botnet C2 domain (confidence level: 100%)
domainuser.exathomessellmyhomeflorida.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainxipas.differentialkerayechiyan.store
ClearFake payload delivery domain (confidence level: 100%)
domainkulnpioc.mabanishimi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaindom.goturbo88.top
Vidar botnet C2 domain (confidence level: 100%)
domaindom.glamisrents.com
Vidar botnet C2 domain (confidence level: 100%)
domaindivaselinsajep.com
DeerStealer botnet C2 domain (confidence level: 100%)
domainl3fcolra.fubet24.net
ClearFake payload delivery domain (confidence level: 100%)
domaingeneral.activeworkshops.com
Remcos botnet C2 domain (confidence level: 75%)
domainmoonzonet.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainrdpztlxu.maharatmodiran.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaintonajukbhuakpo2.shop
Unknown Loader botnet C2 domain (confidence level: 100%)
domainmetsfgsd.duckdns.org
Unknown RAT botnet C2 domain (confidence level: 50%)
domainlandgforce.duckdns.org
Unknown RAT botnet C2 domain (confidence level: 50%)
domainbodvlnfv.masaelmohandesi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domaintwo-verif.lol
KongTuke payload delivery domain (confidence level: 100%)
domainrgojzoub.masaelmohandesi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainaiaufdwh.masirpayambari.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainckdydch.shansbartar.bet
ClearFake payload delivery domain (confidence level: 100%)
domainx8268vj9.hugugmadanikatouzian.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainljhxazhv.mechanickhodakarami.shop
ClearFake payload delivery domain (confidence level: 100%)
domainsmenapodik.bond
Unknown malware payload delivery domain (confidence level: 100%)
domainmdf.co.za
StrelaStealer payload delivery domain (confidence level: 100%)
domainxkpxrkko.mechanicsayalat.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainbtskl.downloadquran.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainjadepassagehub.top
SmartApeSG payload delivery domain (confidence level: 100%)
domainjehezikh.prozhecart.com
ClearFake payload delivery domain (confidence level: 100%)
domainscsjldll.prozhedownload.com
ClearFake payload delivery domain (confidence level: 100%)
domainvdigvuaz.prozhedownload.com
ClearFake payload delivery domain (confidence level: 100%)
domainlp4hvt2f.ravanshenakhti.shop
ClearFake payload delivery domain (confidence level: 100%)
domaingolkqcqa.psgnewsiran.com
ClearFake payload delivery domain (confidence level: 100%)
domaindbhmpap.shansline.com
ClearFake payload delivery domain (confidence level: 100%)
domainfbvxbuzt.questionsmotor.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainusa.glamisrents.com
Vidar botnet C2 domain (confidence level: 100%)
domainusa.goturbo88.top
Vidar botnet C2 domain (confidence level: 75%)
domainihypqyrn.sadreislam.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainabmkzgbs.sakhtemandade.shop
ClearFake payload delivery domain (confidence level: 100%)
domaincx2b8w38.anodaz.vip
ClearFake payload delivery domain (confidence level: 100%)
domaintuivp.ecologyardakani.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainmaxvicsh.sanjeshravani.shop
ClearFake payload delivery domain (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://infobhz.com.br/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://steamcommunity.com/profiles/76561198689449626
Vidar botnet C2 (confidence level: 100%)
urlhttps://telegram.me/turb00m
Vidar botnet C2 (confidence level: 100%)
urlhttps://snd.goturbo88.top/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ikg.goturbo88.top/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ggt.goturbo88.top/
Vidar botnet C2 (confidence level: 100%)
urlhttps://snd.glamisrents.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ikg.glamisrents.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ggt.glamisrents.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://65.21.96.133/
Vidar botnet C2 (confidence level: 100%)
urlhttps://46.224.136.4/
Vidar botnet C2 (confidence level: 100%)
urlhttps://128.140.123.80/
Vidar botnet C2 (confidence level: 100%)
urlhttps://5.161.119.247/
Vidar botnet C2 (confidence level: 100%)
urlhttps://46.225.162.206/
Vidar botnet C2 (confidence level: 100%)
urlhttps://204.168.163.225/
Vidar botnet C2 (confidence level: 100%)
urlhttps://178.104.208.168/
Vidar botnet C2 (confidence level: 100%)
urlhttps://62.238.44.180/
Vidar botnet C2 (confidence level: 100%)
urlhttps://178.104.211.206/
Vidar botnet C2 (confidence level: 100%)
urlhttps://46.62.255.252/
Vidar botnet C2 (confidence level: 100%)
urlhttps://46.225.156.170/
Vidar botnet C2 (confidence level: 100%)
urlhttps://95.216.152.191/
Vidar botnet C2 (confidence level: 100%)
urlhttps://178.105.210.87/
Vidar botnet C2 (confidence level: 100%)
urlhttp://cacywears.ga/index.php
SmokeLoader botnet C2 (confidence level: 100%)
urlhttps://eichmnnn.icu/file.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://eichmnnn.icu/api/v1/session
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://eichmnnn.icu/api/v1/verify
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://eichmnnn.icu/api/v1/status
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://one-verif.lol/o
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://gnw.goturbo88.top/
Vidar botnet C2 (confidence level: 75%)
urlhttps://gnw.glamisrents.com/
Vidar botnet C2 (confidence level: 75%)
urlhttp://littletonlawnpro.com:5789
Remus botnet C2 (confidence level: 75%)
urlhttp://apprxc.xyz:5003
Remus botnet C2 (confidence level: 75%)
urlhttps://dom.goturbo88.top/
Vidar botnet C2 (confidence level: 100%)
urlhttps://dom.glamisrents.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://lbs-lamb-withdrawal-thickness.trycloudflare.com/
Unknown Loader payload delivery URL (confidence level: 50%)
urlhttps://sharedtafel.com/grandfest.exe
Unknown RAT payload delivery URL (confidence level: 50%)
urlhttps://two-verif.lol/o
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://jadepassagehub.top/rate/metrics-json.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://jadepassagehub.top/rate/legacy-fetch
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://jadepassagehub.top/rate/reset-dom.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://seanofficials.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://usa.glamisrents.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://usa.goturbo88.top/
Vidar botnet C2 (confidence level: 75%)

Threat ID: 6a3095850b89be6888c52e3c

Added to database: 6/16/2026, 12:15:01 AM

Last enriched: 6/16/2026, 12:15:57 AM

Last updated: 6/16/2026, 4:56:30 AM

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses