Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-06-20

0
Medium
Published: 06/20/2026 (06/20/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed

Description

ThreatFox IOCs for 2026-06-20

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/21/2026, 00:07:41 UTC

Technical Analysis

The ThreatFox MISP Feed published a set of malware-related IOCs on 2026-06-20. These IOCs are intended to support threat intelligence and detection efforts but do not specify affected software versions or detailed vulnerability information. The threat is classified with a medium severity level and involves payload delivery and network activity. No patches or remediation measures are indicated, and no active exploitation has been reported.

Potential Impact

The impact is limited to the presence of malware-related indicators that may be used for detection and analysis. There is no evidence of active exploitation or direct compromise detailed in the provided data. No specific software or systems are identified as vulnerable.

Mitigation Recommendations

No patches or official remediation measures are available or applicable. Security teams should incorporate the provided IOCs into their detection and monitoring tools as part of their threat intelligence processes. Since no active exploitation is reported, no urgent remediation actions are required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
de220f60-5142-452a-8b16-704ebf8b0125
Original Timestamp
1782000187

Indicators of Compromise

File

ValueDescriptionCopy
file212.127.90.201
RedTail payload delivery server (confidence level: 80%)
file147.139.136.75
RedTail payload delivery server (confidence level: 80%)
file31.132.90.3
RedTail payload delivery server (confidence level: 80%)
file115.248.8.65
RedTail payload delivery server (confidence level: 80%)
file167.233.68.137
RedTail payload delivery server (confidence level: 80%)
file5.40.229.236
XMRIG payload delivery server (confidence level: 80%)
file39.34.134.209
XMRIG payload delivery server (confidence level: 80%)
file103.217.176.73
XMRIG payload delivery server (confidence level: 80%)
file213.209.159.66
XMRIG payload delivery server (confidence level: 80%)
file64.89.163.82
XMRIG payload delivery server (confidence level: 80%)
file80.96.113.59
XMRIG botnet C2 server (confidence level: 100%)
file64.89.163.212
XMRIG botnet C2 server (confidence level: 100%)
file64.89.163.212
XMRIG botnet C2 server (confidence level: 100%)
file64.89.163.212
XMRIG botnet C2 server (confidence level: 100%)
file172.93.185.254
NetSupportManager RAT payload delivery server (confidence level: 100%)
file217.60.195.144
Mirai botnet C2 server (confidence level: 100%)
file116.204.36.177
Cobalt Strike botnet C2 server (confidence level: 100%)
file116.204.36.177
Cobalt Strike botnet C2 server (confidence level: 100%)
file81.69.253.132
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.116.45.227
VShell botnet C2 server (confidence level: 100%)
file81.69.253.132
Cobalt Strike botnet C2 server (confidence level: 100%)
file102.209.117.153
VShell botnet C2 server (confidence level: 100%)
file101.42.5.27
VShell botnet C2 server (confidence level: 100%)
file64.81.30.35
ValleyRAT botnet C2 server (confidence level: 100%)
file47.86.32.238
ValleyRAT botnet C2 server (confidence level: 100%)
file47.243.155.184
ValleyRAT botnet C2 server (confidence level: 100%)
file158.160.75.185
RatonRAT botnet C2 server (confidence level: 100%)
file47.243.155.184
ValleyRAT botnet C2 server (confidence level: 75%)
file198.23.185.136
AsyncRAT botnet C2 server (confidence level: 100%)
file13.62.76.12
AsyncRAT botnet C2 server (confidence level: 100%)
file13.62.76.12
AsyncRAT botnet C2 server (confidence level: 100%)
file185.89.249.66
Cobalt Strike botnet C2 server (confidence level: 93%)
file193.23.160.213
Cobalt Strike botnet C2 server (confidence level: 100%)
file193.23.160.213
Cobalt Strike botnet C2 server (confidence level: 100%)
file152.236.7.10
Mirai botnet C2 server (confidence level: 100%)
file193.23.160.213
Cobalt Strike botnet C2 server (confidence level: 100%)
file193.23.160.213
Cobalt Strike botnet C2 server (confidence level: 100%)
file171.80.9.253
VShell botnet C2 server (confidence level: 100%)
file51.91.103.206
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.152.2.86
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.140.213.6
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.37.215.213
Cobalt Strike botnet C2 server (confidence level: 100%)
file111.231.173.74
Cobalt Strike botnet C2 server (confidence level: 100%)
file176.121.49.225
Cobalt Strike botnet C2 server (confidence level: 100%)
file89.169.183.76
Cobalt Strike botnet C2 server (confidence level: 100%)
file107.172.232.71
Unknown malware botnet C2 server (confidence level: 75%)
file15.235.159.82
Unknown malware botnet C2 server (confidence level: 75%)
file147.93.191.75
AsyncRAT botnet C2 server (confidence level: 75%)
file188.253.104.174
AsyncRAT botnet C2 server (confidence level: 75%)
file198.23.185.136
AsyncRAT botnet C2 server (confidence level: 75%)
file217.60.195.176
Remcos botnet C2 server (confidence level: 75%)
file36.50.85.69
AdaptixC2 botnet C2 server (confidence level: 75%)
file45.32.64.12
AdaptixC2 botnet C2 server (confidence level: 75%)
file47.83.254.175
AdaptixC2 botnet C2 server (confidence level: 75%)
file5.188.61.49
Eye Pyramid botnet C2 server (confidence level: 75%)
file107.173.122.193
Cobalt Strike botnet C2 server (confidence level: 100%)
file107.173.122.193
Cobalt Strike botnet C2 server (confidence level: 100%)
file139.196.89.43
Cobalt Strike botnet C2 server (confidence level: 75%)
file43.143.244.134
Cobalt Strike botnet C2 server (confidence level: 75%)
file195.20.115.197
AsyncRAT botnet C2 server (confidence level: 100%)
file43.138.165.203
Cobalt Strike botnet C2 server (confidence level: 100%)
file49.233.136.227
VShell botnet C2 server (confidence level: 100%)
file102.220.160.217
AsyncRAT botnet C2 server (confidence level: 75%)
file104.194.151.163
AdaptixC2 botnet C2 server (confidence level: 75%)
file13.140.160.249
AsyncRAT botnet C2 server (confidence level: 75%)
file13.140.160.249
AsyncRAT botnet C2 server (confidence level: 75%)
file162.216.241.206
DCRat botnet C2 server (confidence level: 75%)
file188.23.170.123
Eye Pyramid botnet C2 server (confidence level: 75%)
file195.20.115.197
AsyncRAT botnet C2 server (confidence level: 75%)
file195.20.115.197
AsyncRAT botnet C2 server (confidence level: 75%)
file195.20.115.197
AsyncRAT botnet C2 server (confidence level: 75%)
file198.23.185.136
AsyncRAT botnet C2 server (confidence level: 75%)
file45.77.254.232
Unknown malware botnet C2 server (confidence level: 75%)
file45.81.243.44
AsyncRAT botnet C2 server (confidence level: 75%)
file47.243.211.244
Unknown malware botnet C2 server (confidence level: 75%)
file5.101.85.65
AdaptixC2 botnet C2 server (confidence level: 75%)
file5.200.176.105
DCRat botnet C2 server (confidence level: 75%)
file8.217.141.231
Remcos botnet C2 server (confidence level: 75%)
file80.211.129.141
Unknown malware botnet C2 server (confidence level: 75%)
file89.124.107.161
Unknown malware botnet C2 server (confidence level: 75%)
file100.110.56.1
Cobalt Strike botnet C2 server (confidence level: 75%)
file116.213.42.110
Cobalt Strike botnet C2 server (confidence level: 75%)
file185.56.46.230
AsyncRAT botnet C2 server (confidence level: 75%)
file185.56.46.230
AsyncRAT botnet C2 server (confidence level: 75%)
file185.56.46.230
AsyncRAT botnet C2 server (confidence level: 75%)
file185.56.46.230
AsyncRAT botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash2375
RedTail payload delivery server (confidence level: 80%)
hash2375
RedTail payload delivery server (confidence level: 80%)
hash80
RedTail payload delivery server (confidence level: 80%)
hash80
RedTail payload delivery server (confidence level: 80%)
hash80
RedTail payload delivery server (confidence level: 80%)
hash6379
XMRIG payload delivery server (confidence level: 80%)
hash6379
XMRIG payload delivery server (confidence level: 80%)
hash6379
XMRIG payload delivery server (confidence level: 80%)
hash5432
XMRIG payload delivery server (confidence level: 80%)
hash5432
XMRIG payload delivery server (confidence level: 80%)
hashc343f53916747c5b8a60aed844b1882863f432af65867297edf1913f167c4f68
Unknown malware payload (confidence level: 75%)
hashe8ee3e3e25e9deef039131b7e66855a2e614d36f395b582f9b7e6365ffd61484
Unknown malware payload (confidence level: 75%)
hash8060
XMRIG botnet C2 server (confidence level: 100%)
hash8060
XMRIG botnet C2 server (confidence level: 100%)
hash8058
XMRIG botnet C2 server (confidence level: 100%)
hash8057
XMRIG botnet C2 server (confidence level: 100%)
hash80
NetSupportManager RAT payload delivery server (confidence level: 100%)
hash13420d64ce091f6dc0505d5a2ca5858f6080f3d91580459c2284bd68fdcb1979
Unknown malware payload (confidence level: 75%)
hash1999
Mirai botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
VShell botnet C2 server (confidence level: 100%)
hashaa40a70d1dbf91af1d2bfc5209417fadb3b4ad2192a4ea4cbf802e2b10d5b0ce
WannaCryptor payload (confidence level: 95%)
hash791618590c32a2164037f241b401f4698e37c239
WannaCryptor payload (confidence level: 95%)
hash6640820a921a5235ffa3448c7640039c
WannaCryptor payload (confidence level: 95%)
hash8d347ecef1e388d150a55d84f0397dc39be24d22c456681eb57ca23580f4083f
WannaCryptor payload (confidence level: 95%)
hashd7784fdaca930daf2e664a388ce2c9fed3ca7ca4
WannaCryptor payload (confidence level: 95%)
hash9d9e293be0bc3323060ff6271cc00d4f
WannaCryptor payload (confidence level: 95%)
hash798138899fae930a2eb5d70aafd8ba622fd1674fec571e282e9c9589b39cffef
Nanocore RAT payload (confidence level: 95%)
hash9c9b962deead54c4364d378324e1f4ec603ab81c
Nanocore RAT payload (confidence level: 95%)
hashd3e37de6dd2dc8ce1bb72536259529cc
Nanocore RAT payload (confidence level: 95%)
hashb8431716195045f269fabd7d4e58fc37d24281a7bc0e4af3ce5424276add5792
Nanocore RAT payload (confidence level: 95%)
hashc7bb21bf48c0c879b9f382143b94c9e16bd6c81e
Nanocore RAT payload (confidence level: 95%)
hash63ab7828b518397c0b01596c92a0a0b0
Nanocore RAT payload (confidence level: 95%)
hash8408c932e1f5f49509bdb4a3d27b358de7309a660a4fa01841dbf0f2d1b4bf40
WannaCryptor payload (confidence level: 95%)
hashd9c52e67f65c25c3933ca39fee55d0797b3c2c9d
WannaCryptor payload (confidence level: 95%)
hashe80c4a3ceb6417d7194183326d498ea5
WannaCryptor payload (confidence level: 95%)
hashce990051cbbec61b7e5fda012e29bc9776d0f298cc586c20ed13f949f34db37b
Nanocore RAT payload (confidence level: 95%)
hash409af51ffa0d10f41374a2b1f3517b98b950ed00
Nanocore RAT payload (confidence level: 95%)
hash1702f6476993eb605fe93eebbbc5fc42
Nanocore RAT payload (confidence level: 95%)
hash2e16f46c063ff79af0b312364375706e98674b5869a4c9bb9f96a14b77277c5b
Nanocore RAT payload (confidence level: 95%)
hash5801812345faf457a9be2ede940097ad1e88a626
Nanocore RAT payload (confidence level: 95%)
hash2470c9c99f13ded1f5b86a2fabde0780
Nanocore RAT payload (confidence level: 95%)
hashc2c8ed567f9c65686c4f6599e9259bd31d2ad984c24cf17ad9ebd9d594dcb0ba
Nanocore RAT payload (confidence level: 95%)
hash4ccba704170269b7c7ca1ecafe2ed57fd11dcba8
Nanocore RAT payload (confidence level: 95%)
hash10cf94eef24c8932d28698e02faf43e5
Nanocore RAT payload (confidence level: 95%)
hashef0e9301403d58a4729aaa9cd81abf942b1c8a301a651b1512bc2b5d9e599303
Nanocore RAT payload (confidence level: 95%)
hash0b8b5c278750f6e4a14fde3495cd403eddb9f2bc
Nanocore RAT payload (confidence level: 95%)
hash93e61d5a877bbb937e885d3ca385ac8a
Nanocore RAT payload (confidence level: 95%)
hashd34be339fd8c47756de5b4e6c402612a333c50b9e1fa4bffdd32cb3f9d5c1d74
Venus Stealer payload (confidence level: 95%)
hashe2b60f4ee39925843ad191a57064d35055d0cf02
Venus Stealer payload (confidence level: 95%)
hash63ffc60f431eb604910d605d8d72754b
Venus Stealer payload (confidence level: 95%)
hash55f65c7a077407e09b5bf46c0d1885e88759583bb56ee3c5495804d0da127dab
WannaCryptor payload (confidence level: 95%)
hash6bfb4ccd96be883142ec5bb5f35846feaca79b81
WannaCryptor payload (confidence level: 95%)
hash3e90a82f5360cae528a12c76d22fe6a2
WannaCryptor payload (confidence level: 95%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8000
VShell botnet C2 server (confidence level: 100%)
hash8880
VShell botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash10087
ValleyRAT botnet C2 server (confidence level: 100%)
hash770
ValleyRAT botnet C2 server (confidence level: 100%)
hash42757
RatonRAT botnet C2 server (confidence level: 100%)
hash771
ValleyRAT botnet C2 server (confidence level: 75%)
hash6006
AsyncRAT botnet C2 server (confidence level: 100%)
hash9000
AsyncRAT botnet C2 server (confidence level: 100%)
hash8000
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 93%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash27177
Mirai botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9998
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash88
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8086
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8086
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash5002
Unknown malware botnet C2 server (confidence level: 75%)
hash56005
Unknown malware botnet C2 server (confidence level: 75%)
hash30400
AsyncRAT botnet C2 server (confidence level: 75%)
hash2026
AsyncRAT botnet C2 server (confidence level: 75%)
hash20600
AsyncRAT botnet C2 server (confidence level: 75%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash1235
AdaptixC2 botnet C2 server (confidence level: 75%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 75%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 75%)
hash44443
Eye Pyramid botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash10443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash4443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash9002
Cobalt Strike botnet C2 server (confidence level: 100%)
hash18083
VShell botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash65381
AdaptixC2 botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash7707
AsyncRAT botnet C2 server (confidence level: 75%)
hash7997
DCRat botnet C2 server (confidence level: 75%)
hash8000
Eye Pyramid botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash7707
AsyncRAT botnet C2 server (confidence level: 75%)
hash7829
AsyncRAT botnet C2 server (confidence level: 75%)
hash10900
AsyncRAT botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 75%)
hash55476
DCRat botnet C2 server (confidence level: 75%)
hash636
Remcos botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash8000
Cobalt Strike botnet C2 server (confidence level: 75%)
hash5005
Cobalt Strike botnet C2 server (confidence level: 75%)
hash1605
AsyncRAT botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash7707
AsyncRAT botnet C2 server (confidence level: 75%)
hash8808
AsyncRAT botnet C2 server (confidence level: 75%)
hash0ecd4eed4e6933a51dbedfb4927b330135e0df7957e4e1eb6c6cee939a5bdec4
ValleyRAT payload (confidence level: 95%)
hashcb1d22c31403322adabd6b6f72ab53347661450b
ValleyRAT payload (confidence level: 95%)
hashe76c8f8521a3c532b93466301076cccb
ValleyRAT payload (confidence level: 95%)
hashef3b3ab549f0abd21112eaa6b2d92cc43268960cc784241dc0512b38db090923
RemoteX payload (confidence level: 95%)
hashcf1a1e8a99cb6db904e6c1712d045f4437b3ae82
RemoteX payload (confidence level: 95%)
hashbe10a9ac2bfe28e74a4ed2029a077d28
RemoteX payload (confidence level: 95%)
hash6696a32df2f9598926cda34e6a239e24c66e417fe40617ad5853b2cb339481a4
SalatStealer payload (confidence level: 95%)
hashb0e87085fc953ca47d20dd900eaf1765d00ff74f
SalatStealer payload (confidence level: 95%)
hashe716660c19bd9ca857be57cc3926d60a
SalatStealer payload (confidence level: 95%)
hash7348ea4bd90ba897c35d9cdcc1da7470d8ad00db072538e21686db797e3b1a69
SalatStealer payload (confidence level: 95%)
hash0a3fa4f8d598e6a92e0814924a93fc8782e2752d
SalatStealer payload (confidence level: 95%)
hash1d562cac7c67ff7ebbe87a6a9dcfcd35
SalatStealer payload (confidence level: 95%)
hash16f121c04202eb4a7cc68ecafdc85e66a114801e2edbcf5f2561437993bbd278
stealler payload (confidence level: 95%)
hash5b92ef29344c1dbce51dfd4632605107cd21f1e9
stealler payload (confidence level: 95%)
hasha01b56eb305f46b4c8c4a72256124510
stealler payload (confidence level: 95%)
hash3368d54f30631c9e305f6df3464e08b6b4f24eebdb605240c44b144deed717fa
Luca Stealer payload (confidence level: 95%)
hash50cdc90b8ac39e4167409fedb3d25e4de8229578
Luca Stealer payload (confidence level: 95%)
hashc83776891f0407e6401a7d7004691f86
Luca Stealer payload (confidence level: 95%)
hashe7a53970dbc5a570d4d98e963902f37641fc6e526ef9af1e7117806436b7a394
SalatStealer payload (confidence level: 95%)
hash3df8d4836f520c7acf17b3e82f21d04f4dc0e676
SalatStealer payload (confidence level: 95%)
hashd36c0c4fe0ddc64e42a4674da64d7838
SalatStealer payload (confidence level: 95%)
hash13dd71dc712256f0bf365439e1b814f17347f5fa797577801afd5bc334349532
NjRAT payload (confidence level: 95%)
hash9cc3d2d139d493012fe15e7bbb3ce4cb1563d4bc
NjRAT payload (confidence level: 95%)
hash8c84bbc4ae0513b991821a21fac9f8d6
NjRAT payload (confidence level: 95%)
hash88a2c9db752d0474d3acae63d3a5c7059051460c588142ee8d0769d9765ddc18
NjRAT payload (confidence level: 95%)
hashdf5cc073aaec64c7998cca5e7561d1a423112f7b
NjRAT payload (confidence level: 95%)
hashf72f667fac878f750e4b8d4d59643f26
NjRAT payload (confidence level: 95%)
hashaff0e85a8e066750e4380b756c2a12b9c9b4bdf7460eff4dba462422e572fe81
Sliver payload (confidence level: 95%)
hash063cd1d546e0ebc972a8be86415848262795375a
Sliver payload (confidence level: 95%)
hashb0e1d25b47d005257990f1626739383e
Sliver payload (confidence level: 95%)
hashe8c84a21131672927104f8a91d1062a71351e97e3052dd1d3ca04b7b73b6e37e
NjRAT payload (confidence level: 95%)
hash43b5bdb67072735ae2791a0bdce47548aa0b56e2
NjRAT payload (confidence level: 95%)
hash67540f6e31a6430c90c370a4572e7cf1
NjRAT payload (confidence level: 95%)
hash5d08aed3131bd6ea086a72aca7084f54ad16cc23f05ed8eded1006cece746270
NetWire RC payload (confidence level: 95%)
hash064df4beb9b4ca437a317b6744dc89f985aa37ed
NetWire RC payload (confidence level: 95%)
hash69952dfc4e13803c1ded01e97e859178
NetWire RC payload (confidence level: 95%)
hash1de74088c8dc5abbb6f5c8d708d0fa4c396f5474e27eb56a8c5e961464b89c3e
NetWire RC payload (confidence level: 95%)
hashb9b32ae4989254713d181e658f1fadf6725611f6
NetWire RC payload (confidence level: 95%)
hash31a28a1e13d0f9cb638cd445f2acb559
NetWire RC payload (confidence level: 95%)
hashaefc4db306e46c7b1baf4542dcd7ab3e0324f92fc5e5734be180b90c0546205b
SalatStealer payload (confidence level: 95%)
hash70b9a9a1b50c2b48bd1cbc0fd0465618e97b3faa
SalatStealer payload (confidence level: 95%)
hash5e6a3929d6e3020f75115a47addbf987
SalatStealer payload (confidence level: 95%)
hashc9a93549b2b5999337eb51e916a489456466b0fbaf6d3aa27bb45cb28ca614a6
Coinminer payload (confidence level: 95%)
hash341b470efe14cdd2601ecdd8ea7e723aeca8c9bd
Coinminer payload (confidence level: 95%)
hashcbb52530c3719b037e97c552abffc626
Coinminer payload (confidence level: 95%)
hashd3189d197237dcaafd3e04413bda0ad055dfe236679f4a004732af2954416f93
SalatStealer payload (confidence level: 95%)
hash5e9058e3d99c0c99a36d3bed8284042ca5390c0e
SalatStealer payload (confidence level: 95%)
hash8edc3fc30ff421f6383006a6820b6137
SalatStealer payload (confidence level: 95%)
hash59c31b45f7e3a04bfc35651d087d063e95f7e31d1246018eed1150a177410125
Coinminer payload (confidence level: 95%)
hashd98b8274ad5c0dd6cf544bcda38774a93d50027b
Coinminer payload (confidence level: 95%)
hash3b118bb05c12ba6f65e001a95d723bac
Coinminer payload (confidence level: 95%)
hash47167ee6a2eedbb6a361b502516be53365b4399ca8c05a51c21b0dea8980e33f
Coinminer payload (confidence level: 95%)
hash47c68148c07d104bacdf77757e977f40d2fdf54f
Coinminer payload (confidence level: 95%)
hash8234ba4a21540a58a60ca07853c4279e
Coinminer payload (confidence level: 95%)
hash77ef08194ab04f99824d79503fe719c893f3bf180faf94ba5b1afbcc418d872b
SalatStealer payload (confidence level: 95%)
hash700a24f5aecb59c23e7142094cb425c0a732624b
SalatStealer payload (confidence level: 95%)
hash0e7c42de35a8effa21d8aedd55170f6c
SalatStealer payload (confidence level: 95%)
hash0932c80cd89391d69281f4938676d354d5982379f52381794a31f8e20fc74f17
SalatStealer payload (confidence level: 95%)
hash5fc628830a5096201995d90855c65e0728bdcb20
SalatStealer payload (confidence level: 95%)
hash5017c337b5a477b716148f78735344cf
SalatStealer payload (confidence level: 95%)
hashb9f2ba742e2e227a55912746acf22992d2dfc416d3877665b83abf0bc3e3f093
SalatStealer payload (confidence level: 95%)
hashded7a484d242d344a7c5f06638f87e9cfa19a870
SalatStealer payload (confidence level: 95%)
hashedc2b0119fa8b56272bc613dca7c6a92
SalatStealer payload (confidence level: 95%)
hash93de66680b277c94cf8925ea36b9e396e6a57096f018f493edf64df898034dd0
SalatStealer payload (confidence level: 95%)
hash4ff4720313ae142d1979ed78678728827eb508b8
SalatStealer payload (confidence level: 95%)
hash8ad98d809e87c146555686b252feacfa
SalatStealer payload (confidence level: 95%)
hashed32368823c139fa2e2f0771e6716f93c7db856aa24bbc81c0eea653ac3618f8
SalatStealer payload (confidence level: 95%)
hashd864ee78933a3c2758eb4446cbf601ed0826b8e2
SalatStealer payload (confidence level: 95%)
hash93f74ef611a21edab4602bacc1925b7c
SalatStealer payload (confidence level: 95%)
hash7ffea08c03e9c49def06aab41881b65596e26bba26ca30f2cc26640e892d38ee
SalatStealer payload (confidence level: 95%)
hash7d553a1a6d7cdc7a177665644b11ccfa34cd4b30
SalatStealer payload (confidence level: 95%)
hashccdc1f893f3e7bd91ac4dd77a1ddc377
SalatStealer payload (confidence level: 95%)
hash89a9dfb74bf31b40951bac672cd108db9c7c4cbdcf282d1f29e8049d3b4b47d7
SalatStealer payload (confidence level: 95%)
hashc8e94b71624a15d3ac6661856c943e2c9f989da2
SalatStealer payload (confidence level: 95%)
hashcead56d13a90d65bc036283e71985c10
SalatStealer payload (confidence level: 95%)
hashafa807cee34e8b931688ccf2be76b7ea5337af3d64714a348bead839c756643a
Luca Stealer payload (confidence level: 95%)
hashc23880aace575129c384723e82fa92e8e25d54c8
Luca Stealer payload (confidence level: 95%)
hash2f9ec23d6ca74629b928f5f149d9feb4
Luca Stealer payload (confidence level: 95%)
hash0dcbe5afb17831300599e9cdc3c8a655c1380c86a1562db04fec664677a50e20
Vidar payload (confidence level: 95%)
hashbf382fab74d8255350a0058f5dbec9a0742f81a5
Vidar payload (confidence level: 95%)
hash8820cc652b0c3ed6dfff7c4032f646b1
Vidar payload (confidence level: 95%)
hashe176972714a4fd0fe9b299ae8598487c92d9da508de42d042d1ddccb8548a3b5
NetWire RC payload (confidence level: 95%)
hashd8c611e7d43a0d746530580f3d87d71aebbc446a
NetWire RC payload (confidence level: 95%)
hashb274c8c20aa752171b716382707b85f3
NetWire RC payload (confidence level: 95%)
hash2ee10a4e204a3adbf2102913c95c3cad56199bd75e1c6e194f239a7cf4837e36
NetWire RC payload (confidence level: 95%)
hash864b9623279497e028ba193b2f52233b1cb6be53
NetWire RC payload (confidence level: 95%)
hashb4e61dcfcf46bbd01ee140b355d738c8
NetWire RC payload (confidence level: 95%)
hash6bc5bbef79cd96c26cee4702a22eec2b7d49adc7c67b0a76efcc852df2252214
NetWire RC payload (confidence level: 95%)
hash81c89ddcb7ff90acd948aceaab9aa358fa9674ca
NetWire RC payload (confidence level: 95%)
hashed32f554a6e15f3d3112e9b07f21e8fa
NetWire RC payload (confidence level: 95%)
hashe681fb538d6b064f2bb81ffc552784b264d3888eb18df2ae50fd133b35feb95a
NetWire RC payload (confidence level: 95%)
hashdbf792049783f13098d6fc6cf14eeb80a1be0caf
NetWire RC payload (confidence level: 95%)
hash016b642c77e8ee87b4faf0b0e507e15d
NetWire RC payload (confidence level: 95%)
hash29352f59456553b5f5484561ad72727866119f00dfa50626b152ec47d68369a9
Amadey payload (confidence level: 95%)
hashf5afd7c8ebd868bde7287829ad63d07e0681cfe2
Amadey payload (confidence level: 95%)
hash9be1777c6150a1a50e4961902a487ef5
Amadey payload (confidence level: 95%)
hashee50115e22710719e3fc70e61fa09ce101e409d0acb6d9b9a1b4f32c96917c06
BlackShades payload (confidence level: 95%)
hash6cf6221711c69d1b908e24ed08ab5c5766d0a882
BlackShades payload (confidence level: 95%)
hash49cb19282d2e43eadf128dd03ff98394
BlackShades payload (confidence level: 95%)
hash2f8b6ff170d5c231fc25d0ecc9b907448a5cdea6513bef52a10856fd1b814479
BlackShades payload (confidence level: 95%)
hash399921c6d715c4166b7641cf64fdc41ad06dde65
BlackShades payload (confidence level: 95%)
hash72e11e578b0195306835b11387846662
BlackShades payload (confidence level: 95%)
hash691c74f56d546998e51af78a4a55a0b13744b3d4a882b0247da05b59e1e1d6c6
NetWire RC payload (confidence level: 95%)
hash9604fdffe5573bca0dc7e224867e90ffdc0c491e
NetWire RC payload (confidence level: 95%)
hashdb5f9352503f9cd7f1c572d03a64f32d
NetWire RC payload (confidence level: 95%)
hash9c48fc643b569e7b37d851c8e3c3a19d1469427a99d405b7f9fdefaa0b40f9b4
NetWire RC payload (confidence level: 95%)
hash9e7c5644cb14f71db5a5ec9820594ee55e4eb949
NetWire RC payload (confidence level: 95%)
hashf97369c65ce71afac2ebab1ae5c96e16
NetWire RC payload (confidence level: 95%)
hash1e6d5898bea2ebf6b249707ea4235e17e009eda510f2476ce885b97fcd8c26a2
Meterpreter payload (confidence level: 95%)
hashcad40d347c87fc9bc1a2f1038e4e8761a6cc080c
Meterpreter payload (confidence level: 95%)
hashc2005d83afa2f81ddeb3c4513734d3b7
Meterpreter payload (confidence level: 95%)
hash2fe27cfc680a6fb118a023caa55bfa39a55d4aecf9e540f65b531874066fec16
NetWire RC payload (confidence level: 95%)
hashdcb74d6c2fe8a0cf6906bab57e48b2cd18b2cecc
NetWire RC payload (confidence level: 95%)
hash30a9ecc59bc94186d32978e4a9f5bb0d
NetWire RC payload (confidence level: 95%)
hash2f14862545773c034e41f1ece62bc0618cb1396eacfd2bbe2aec9c958689e002
NetWire RC payload (confidence level: 95%)
hashd48ec01d6c8143a571fae4bbcabb9969fbfa1c84
NetWire RC payload (confidence level: 95%)
hash2ce7e3f516c80084cda7b9a35809e90b
NetWire RC payload (confidence level: 95%)
hashe35d943f539f6d61e0d9e5d39f5cc78180accb01a7a42fe7287b2000dadfaf4a
NetWire RC payload (confidence level: 95%)
hasha0bc24435ea17b686873950175f23cdc31c81df5
NetWire RC payload (confidence level: 95%)
hash8f45724779f470a3697b39fa6a6be4db
NetWire RC payload (confidence level: 95%)
hashda6dec4baeadb44b654d21d14c27530851ed1c57e71d50c39c16ff3fb730af86
NetWire RC payload (confidence level: 95%)
hash05b88c149fbce94d91166c7eb92c861f0d269915
NetWire RC payload (confidence level: 95%)
hash4f19d659d8a775b1a1f77d5263113f23
NetWire RC payload (confidence level: 95%)
hash3c4e06fe06b26cb70c0dabc743b728db50c87151606c421cb809e19b29876fbe
NetWire RC payload (confidence level: 95%)
hashfcea5aa80c9154c30a2ecf73de6d93c1d3a2436c
NetWire RC payload (confidence level: 95%)
hashdc993e02dd8b72b4c1d2d31e13811746
NetWire RC payload (confidence level: 95%)
hashaadc96fe85cb6f7089b51457c2bd30ff443262ccd53fbb3ca4529289c70a595f
NetWire RC payload (confidence level: 95%)
hasha77cb0942631742512c5a015c580ad0c6a6e2afc
NetWire RC payload (confidence level: 95%)
hashf69859707432442f70c49c2f0678f675
NetWire RC payload (confidence level: 95%)
hash0c620497c06028c783050d81daf378edc7c0cfba3977f0137ebc3ffdd8765a56
Xloader payload (confidence level: 95%)
hashafca972d30b80f02e2a2abc4d653cb1579cb509b
Xloader payload (confidence level: 95%)
hash349e9cfa230a379f16ba28418a73d3bf
Xloader payload (confidence level: 95%)
hash2af09010211b22731abbc733c648be84f75ac947f919ac895374dd28719c32f6
Vidar payload (confidence level: 95%)
hash85af6e8ac64a65f9f163199e6cc85ee5409dd74f
Vidar payload (confidence level: 95%)
hash4a9c90e7662bc3876f4ef627816c6eff
Vidar payload (confidence level: 95%)
hash0aa7360574fed7f19d3c1b9c12e0e3e90f0b415eab4d0901559fbe7703dfe939
Xloader payload (confidence level: 95%)
hashf545a0384505117c03a33842384f9ea397ffc835
Xloader payload (confidence level: 95%)
hashf2a520db47f163760eef8629fc4a92e2
Xloader payload (confidence level: 95%)
hashd0da8e7c8c47561a8b9f78b38e31e02964dcf4ae1d10cc01a99e409d20ad73ef
Vidar payload (confidence level: 95%)
hash1f8e8faddb98e2e6cd723c4c1854000281ef3913
Vidar payload (confidence level: 95%)
hash64e9b14f81a21120b831e19ef94f902e
Vidar payload (confidence level: 95%)

Url

ValueDescriptionCopy
urlhttps://coralregistry.top/middleware/role-render.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://coralregistry.top/middleware/version-schema
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://coralregistry.top/middleware/endpoint-asset.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://google2oauth.com/google.txt
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://imgur.media/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://elijahwgummer.baby/monkey-e669fb0-a99aeeab-5e65331880-0b06979
Unknown malware botnet C2 (confidence level: 75%)
urlhttp://www.kongographics.com/200
Unknown malware payload delivery URL (confidence level: 75%)
urlhttp://cdn.librarygrades.com/200.txt
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://vigipart.fr/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://ivorycourtyard.top/middleware/role-render.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://153.117.15.187:54011/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttp://223.123.124.121:60095/mozi.7
Mozi payload delivery URL (confidence level: 75%)
urlhttp://45.230.66.112:11404/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttps://prguru.pk/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://bullpcn.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://154.91.75.105/getinstall64
ValleyRAT botnet C2 (confidence level: 100%)
urlhttp://103.186.77.95:49560/mozi.a
Mozi payload delivery URL (confidence level: 75%)
urlhttp://72.255.3.39:41763/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttp://153.117.13.227:34153/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttp://mathlah.com:9432
Remus botnet C2 (confidence level: 75%)
urlhttps://cdn.jsdelivr.net/gh/savina-41/mcv4f-jp5/launching
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://193.148.57.10/88004f4d3e32489389ea.php
Stealc botnet C2 (confidence level: 75%)
urlhttps://almontm.xyz/file.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://cdn.jsdelivr.net/gh/savina-41/8a-96dfe89a4aa3/hum-id46
ClearFake payload delivery URL (confidence level: 100%)

Domain

ValueDescriptionCopy
domaincoralregistry.top
SmartApeSG payload delivery domain (confidence level: 100%)
domaindgdf.nimographic.com
Unknown malware payload delivery domain (confidence level: 75%)
domainapi-ext.bixbitemarketing.com
FAKEUPDATES payload delivery domain (confidence level: 100%)
domaincoldtechreview.vip
XMRIG botnet C2 domain (confidence level: 100%)
domainnode54group.com
NetSupportManager RAT botnet C2 domain (confidence level: 100%)
domainnode66group.pro
NetSupportManager RAT botnet C2 domain (confidence level: 100%)
domaingoogle2oauth.com
NetSupportManager RAT payload delivery domain (confidence level: 100%)
domainelijahwgummer.baby
Unknown malware botnet C2 domain (confidence level: 75%)
domaine57ra5jx.plinkobet.casino
ClearFake payload delivery domain (confidence level: 100%)
domain0odlgi4q.motuntakhasosi.store
ClearFake payload delivery domain (confidence level: 100%)
domaing6gib60b.raftarsazmani.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainlc5lya7l.romabetkade.com
ClearFake payload delivery domain (confidence level: 100%)
domainbook-imageport.info
Unknown Loader payload delivery domain (confidence level: 100%)
domainshart303.com
ClearFake payload delivery domain (confidence level: 100%)
domain13i466gp.shart303.com
ClearFake payload delivery domain (confidence level: 100%)
domainv8xihekm.ramzfile.com
ClearFake payload delivery domain (confidence level: 100%)
domain7cj04th6.shartland.com
ClearFake payload delivery domain (confidence level: 100%)
domainyek1.bet
ClearFake payload delivery domain (confidence level: 100%)
domain87khq5gx.ravabetensani.site
ClearFake payload delivery domain (confidence level: 100%)
domainrurhmgw2.readthisintro.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainzxe9u0st.sigaribetkade.com
ClearFake payload delivery domain (confidence level: 100%)
domain58shz66o.tahlilsazeha.xyz
ClearFake payload delivery domain (confidence level: 100%)
domain4q74zsh8.raftarsazmani.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainzuldqm04.riyaziyattajrobi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainalmontm.xyz
KongTuke payload delivery domain (confidence level: 100%)
domainliwxdd48.romabetkade.com
ClearFake payload delivery domain (confidence level: 100%)
domainhost.serveminecraft.net
AsyncRAT botnet C2 domain (confidence level: 75%)
domainiplzbag0.shartbandi.casino
ClearFake payload delivery domain (confidence level: 100%)
domainl3q1ng7a.azmoondadrasi.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainwc7skdzu.yakhbet.com
ClearFake payload delivery domain (confidence level: 100%)
domainzabantehrani.shop
ClearFake payload delivery domain (confidence level: 100%)

Threat ID: 6a372b499c760d8addf7a69a

Added to database: 06/21/2026, 00:07:37 UTC

Last enriched: 06/21/2026, 00:07:41 UTC

Last updated: 06/21/2026, 04:07:37 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses