Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-06-28

0
Medium
Published: 06/28/2026 (06/28/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed

Description

ThreatFox IOCs for 2026-06-28

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/29/2026, 00:16:50 UTC

Technical Analysis

The ThreatFox IOCs for 2026-06-28 represent a collection of open-source intelligence related to malware, focusing on payload delivery and network activity. The data does not specify affected software versions, detailed attack vectors, or exploitation methods. No patch or remediation is available, and no active exploitation has been reported. The threat level is moderate, with limited analysis and distribution indicators provided.

Potential Impact

The impact is currently limited due to the absence of known exploits in the wild and no specific affected software versions. The threat represents potential malware activity that could lead to payload delivery and network-based compromise if leveraged. Without further details, the precise impact cannot be fully assessed.

Mitigation Recommendations

No patches or official remediation are available for this threat. Security teams should monitor for related indicators of compromise as provided by ThreatFox and apply standard malware detection and prevention measures. Since no active exploitation is known, no urgent remediation actions are required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
4772e1d8-78ea-4777-a268-f692df967f5c
Original Timestamp
1782691387

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://thespeedyhomeoffer.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://hollytree-transport.co.uk/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://emdgroupe.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://cgain.net/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://purplebandage.org.za/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.rssssociety.org.in/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://188.169.20.12:35057/mozi.a
Mozi payload delivery URL (confidence level: 75%)
urlhttp://172.168.137.58:37141/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttp://5.166.134.69:43702/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttp://223.123.43.71:35524/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttps://encalabrino.life/.ssa-auth-connect/scn/reff/screenconnect.clientsetup.exe
Unknown RAT payload delivery URL (confidence level: 75%)
urlhttp://119.157.76.175:39761/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttp://47.236.116.9/y8jdgc5js/index.php
Amadey botnet C2 (confidence level: 100%)
urlhttp://101.53.225.41:45308/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttp://112.246.97.119:37502/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttp://153.117.15.75:41179/mozi.a
Mozi payload delivery URL (confidence level: 75%)
urlhttps://bibliorock.lol/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://memshowblob.forum/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://mistertwister.sale/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://engr-salahuddin.com/
Vidar payload delivery URL (confidence level: 75%)
urlhttps://geurtuin.com/
Vidar payload delivery URL (confidence level: 75%)
urlhttp://153.117.41.29:45738/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttp://175.107.208.203:48676/mozi.m
Mozi payload delivery URL (confidence level: 75%)
urlhttp://lawofi.xyz:7538
Remus botnet C2 (confidence level: 75%)
urlhttps://geurtuin.com/?doing_wp_cron=1782651363.9469881057739257812500
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://citrusocarpetscleaning.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://103.146.231.107:80/dfne
Cobalt Strike botnet C2 (confidence level: 75%)
urlhttps://vihangamyoga.org/
Vidar payload delivery URL (confidence level: 75%)

File

ValueDescriptionCopy
file147.182.140.2
Aisuru botnet C2 server (confidence level: 100%)
file91.92.42.125
Mirai botnet C2 server (confidence level: 100%)
file46.8.236.234
Mirai botnet C2 server (confidence level: 100%)
file46.8.236.234
Mirai botnet C2 server (confidence level: 100%)
file46.8.236.234
Mirai botnet C2 server (confidence level: 100%)
file144.31.61.126
NjRAT botnet C2 server (confidence level: 100%)
file194.59.31.123
Quasar RAT botnet C2 server (confidence level: 50%)
file49.232.169.67
VShell botnet C2 server (confidence level: 100%)
file196.75.14.206
Meterpreter botnet C2 server (confidence level: 50%)
file91.92.40.63
Mirai botnet C2 server (confidence level: 100%)
file141.11.88.109
Mirai botnet C2 server (confidence level: 100%)
file47.236.116.9
Amadey botnet C2 server (confidence level: 50%)
file46.8.238.161
Mirai botnet C2 server (confidence level: 100%)
file46.8.238.161
Mirai botnet C2 server (confidence level: 100%)
file46.8.238.161
Mirai botnet C2 server (confidence level: 100%)
file116.62.100.25
AsyncRAT botnet C2 server (confidence level: 100%)
file149.50.96.57
AsyncRAT botnet C2 server (confidence level: 100%)
file27.124.43.182
DCRat botnet C2 server (confidence level: 100%)
file103.253.212.175
Mirai botnet C2 server (confidence level: 75%)
file176.125.243.228
Cobalt Strike botnet C2 server (confidence level: 100%)
file101.43.94.240
VShell botnet C2 server (confidence level: 100%)
file160.202.238.114
VShell botnet C2 server (confidence level: 100%)
file45.88.186.141
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file103.11.41.20
Remcos botnet C2 server (confidence level: 75%)
file103.83.87.87
Remcos botnet C2 server (confidence level: 75%)
file141.98.10.150
Remcos botnet C2 server (confidence level: 75%)
file159.195.193.179
Unknown malware botnet C2 server (confidence level: 75%)
file167.94.81.175
AsyncRAT botnet C2 server (confidence level: 75%)
file177.22.119.145
DanaBot botnet C2 server (confidence level: 75%)
file185.212.128.231
Evilginx botnet C2 server (confidence level: 75%)
file192.162.199.149
AsyncRAT botnet C2 server (confidence level: 75%)
file45.74.7.173
Remcos botnet C2 server (confidence level: 75%)
file134.122.155.142
ValleyRAT botnet C2 server (confidence level: 75%)
file82.157.78.201
Cobalt Strike botnet C2 server (confidence level: 100%)
file27.124.43.241
DCRat botnet C2 server (confidence level: 100%)
file185.126.115.48
Quasar RAT botnet C2 server (confidence level: 100%)
file82.157.78.201
Cobalt Strike botnet C2 server (confidence level: 100%)
file104.248.201.191
Cobalt Strike botnet C2 server (confidence level: 100%)
file106.52.59.233
VShell botnet C2 server (confidence level: 100%)
file103.11.41.10
Remcos botnet C2 server (confidence level: 75%)
file103.11.41.19
Remcos botnet C2 server (confidence level: 75%)
file103.11.41.20
Remcos botnet C2 server (confidence level: 75%)
file109.227.35.147
DanaBot botnet C2 server (confidence level: 75%)
file185.115.164.59
Remcos botnet C2 server (confidence level: 75%)
file199.247.14.228
Chaos botnet C2 server (confidence level: 75%)
file45.150.38.95
AdaptixC2 botnet C2 server (confidence level: 75%)
file45.94.23.42
Unknown malware botnet C2 server (confidence level: 75%)
file5.8.19.157
Remcos botnet C2 server (confidence level: 75%)
file5.8.19.157
Remcos botnet C2 server (confidence level: 75%)
file54.180.147.42
AsyncRAT botnet C2 server (confidence level: 75%)
file54.180.147.42
AsyncRAT botnet C2 server (confidence level: 75%)
file82.157.191.79
Cobalt Strike botnet C2 server (confidence level: 100%)
file104.248.201.191
Cobalt Strike botnet C2 server (confidence level: 100%)
file82.157.191.79
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.73.161.60
Cobalt Strike botnet C2 server (confidence level: 75%)
file117.72.159.96
Cobalt Strike botnet C2 server (confidence level: 75%)
file38.54.117.107
Cobalt Strike botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash12345
Aisuru botnet C2 server (confidence level: 100%)
hash9111
Mirai botnet C2 server (confidence level: 100%)
hash80
Mirai botnet C2 server (confidence level: 100%)
hash123
Mirai botnet C2 server (confidence level: 100%)
hash25565
Mirai botnet C2 server (confidence level: 100%)
hash21418
NjRAT botnet C2 server (confidence level: 100%)
hash4444
Quasar RAT botnet C2 server (confidence level: 50%)
hash80
VShell botnet C2 server (confidence level: 100%)
hash2222
Meterpreter botnet C2 server (confidence level: 50%)
hash9111
Mirai botnet C2 server (confidence level: 100%)
hash6767
Mirai botnet C2 server (confidence level: 100%)
hash80
Amadey botnet C2 server (confidence level: 50%)
hash80
Mirai botnet C2 server (confidence level: 100%)
hash123
Mirai botnet C2 server (confidence level: 100%)
hash25565
Mirai botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8000
AsyncRAT botnet C2 server (confidence level: 100%)
hash12159
DCRat botnet C2 server (confidence level: 100%)
hash6868
Mirai botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8084
VShell botnet C2 server (confidence level: 100%)
hash8002
VShell botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash201
Remcos botnet C2 server (confidence level: 75%)
hash25900
Remcos botnet C2 server (confidence level: 75%)
hash14648
Remcos botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash62722
AsyncRAT botnet C2 server (confidence level: 75%)
hash9001
DanaBot botnet C2 server (confidence level: 75%)
hash9000
Evilginx botnet C2 server (confidence level: 75%)
hash7707
AsyncRAT botnet C2 server (confidence level: 75%)
hash9521
Remcos botnet C2 server (confidence level: 75%)
hash6276
ValleyRAT botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash12159
DCRat botnet C2 server (confidence level: 100%)
hash4443
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash39001
VShell botnet C2 server (confidence level: 100%)
hash8237
Remcos botnet C2 server (confidence level: 75%)
hash16666
Remcos botnet C2 server (confidence level: 75%)
hash1000
Remcos botnet C2 server (confidence level: 75%)
hash4433
DanaBot botnet C2 server (confidence level: 75%)
hash2892
Remcos botnet C2 server (confidence level: 75%)
hash8080
Chaos botnet C2 server (confidence level: 75%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash14645
Remcos botnet C2 server (confidence level: 75%)
hash14646
Remcos botnet C2 server (confidence level: 75%)
hash7707
AsyncRAT botnet C2 server (confidence level: 75%)
hash8808
AsyncRAT botnet C2 server (confidence level: 75%)
hash8001
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9005
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8777
Cobalt Strike botnet C2 server (confidence level: 75%)
hash6666
Cobalt Strike botnet C2 server (confidence level: 75%)

Domain

ValueDescriptionCopy
domainbonavol.pro
Unknown malware payload delivery domain (confidence level: 100%)
domainjaffacakes118-is-a-stupid-nigger.online
Mirai botnet C2 domain (confidence level: 100%)
domainlumennix.top
Unknown malware payload delivery domain (confidence level: 100%)
domainfunrat.co
Unknown malware botnet C2 domain (confidence level: 100%)
domainbestcheats.online
Unknown malware payload delivery domain (confidence level: 100%)
domainfigural.pro
Unknown malware payload delivery domain (confidence level: 100%)
domainadvanceslibrary.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainremiumholdings.com
Unknown Stealer botnet C2 domain (confidence level: 75%)
domainmistertwister.sale
IClickFix payload delivery domain (confidence level: 100%)
domainbibliorock.lol
Vidar botnet C2 domain (confidence level: 75%)
domainmistertwister.sale
Vidar botnet C2 domain (confidence level: 100%)
domainmemshowblob.forum
Vidar botnet C2 domain (confidence level: 100%)
domaincd5p7l7t.xbetone.com
ClearFake payload delivery domain (confidence level: 100%)
domain2ffuyto6.taktikbet.bio
ClearFake payload delivery domain (confidence level: 100%)
domainc0yc77zn.blackjackonlineplay83.com
ClearFake payload delivery domain (confidence level: 100%)
domainhigher.makeup
Mirai botnet C2 domain (confidence level: 100%)
domainnzr.narxzz.biz.id
Mirai botnet C2 domain (confidence level: 100%)
domainlawofi.xyz
Remus botnet C2 domain (confidence level: 100%)
domainrjjgfvu6.vip1xbet.org
ClearFake payload delivery domain (confidence level: 100%)
domainbcxmyrgq.betbuf.live
ClearFake payload delivery domain (confidence level: 100%)
domain1v6qcobc.betbuf.live
ClearFake payload delivery domain (confidence level: 100%)
domain1bmaiu5y.1xbetpartnersiran.com
ClearFake payload delivery domain (confidence level: 100%)
domainfagaheestedlali.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainiranfitness.top
ClearFake payload delivery domain (confidence level: 100%)
domainnqxr9m1i.iranfitness.top
ClearFake payload delivery domain (confidence level: 100%)
domainvacante-ieftine.ro
IClickFix payload delivery domain (confidence level: 100%)
domaingenova.com.vn
IClickFix payload delivery domain (confidence level: 100%)
domaingeurtuin.com
IClickFix payload delivery domain (confidence level: 100%)
domainengr-salahuddin.com
IClickFix payload delivery domain (confidence level: 100%)
domainjarayemaleyhamval.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainmokatebatedari.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainhuz6wkqi.mokatebatedari.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainfjy9zygx.1xsignupbet.com
ClearFake payload delivery domain (confidence level: 100%)
domainhtfll3q5.1x303.casino
ClearFake payload delivery domain (confidence level: 100%)
domaindows.sabad724.bio
ClearFake payload delivery domain (confidence level: 100%)
domain8zdusrwn.xbetone.com
ClearFake payload delivery domain (confidence level: 100%)

Threat ID: 6a41b96d27e9c79719d775e8

Added to database: 06/29/2026, 00:16:45 UTC

Last enriched: 06/29/2026, 00:16:50 UTC

Last updated: 06/29/2026, 04:51:11 UTC

Views: 16

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses