ThreatFox IOC Database

You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.


88

IOCs shared (past 24 hours)

Cobalt Strike

Most seen malware family (past 24 hours)

1'299'983

IOCs in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • ioc:ms-debug-services.com ( run)
  • malware:CobaltStrike ( run)
  • tag:TA505 ( run)
  • threat_type:cc_skimming ( run)
  • uuid:87f310f3-540b-11eb-922c-42010aa4000a ( run)

Date (UTC)IOCMalwareTagsReporter
2024-11-21 06:0745.77.64.151:80 Cobalt StrikeCobaltStrike cs-watermark-391144938 abuse_ch
2024-11-21 06:07110.40.36.87:1234 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-21 06:07123.57.69.200:1234 Cobalt StrikeCobaltStrike cs-watermark-666666666 abuse_ch
2024-11-21 06:07212.115.54.214:8080 Cobalt StrikeCobaltStrike cs-watermark-100000 abuse_ch
2024-11-21 06:078.210.234.49:80 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-21 06:07129.204.86.107:80 Cobalt StrikeCobaltStrike cs-watermark-305419896 abuse_ch
2024-11-21 06:0747.108.137.47:80 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-21 06:07117.18.3.53:4444 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-21 06:0647.95.17.42:443 Cobalt StrikeCobaltStrike cs-watermark-666666 abuse_ch
2024-11-21 06:06198.98.49.132:443 Cobalt StrikeCobaltStrike cs-watermark-666666666 abuse_ch
2024-11-21 06:05154.211.13.143:80 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-21 06:05116.204.21.94:80 Cobalt StrikeCobaltStrike cs-watermark-666666666 abuse_ch
2024-11-21 06:0547.108.60.233:80 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-21 06:0547.108.60.233:8090 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-21 06:0543.131.246.114:8000 Cobalt StrikeCobaltStrike abuse_ch
2024-11-21 06:0543.139.248.193:8443 Cobalt StrikeCobaltStrike cs-watermark-666666666 abuse_ch
2024-11-21 06:05150.158.10.232:80 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-21 06:0543.142.166.217:80 Cobalt StrikeCobaltStrike cs-watermark-666666666 abuse_ch
2024-11-21 06:05117.72.14.90:89 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-21 06:04116.204.21.94:443 Cobalt StrikeCobaltStrike cs-watermark-666666666 abuse_ch
2024-11-21 06:04https://89c9bebf541c17a229d921556d14a4ffd4.com/MWZjODg0YjhhMWVi/ Coper agesipolis1
2024-11-21 06:0418.246.231.120:80 Loki Password Stealer (PWS)infostealer LokiBot stealer SarlackLab
2024-11-21 06:04remcosnov24.duckdns.org Remcosc2 duckdns remcos DaveLikesMalwre
2024-11-21 06:04https://bsfchile.com/work/das.php FAKEUPDATESSmartApeSG HuntYethHounds
2024-11-21 06:04https://bsfchile.com/work/original.js FAKEUPDATESSmartApeSG HuntYethHounds
2024-11-21 06:04https://bsfchile.com/work/fix.php FAKEUPDATESSmartApeSG HuntYethHounds
2024-11-21 06:04http://38.180.147.18:80/palofd Spectre RatPA palo alto Spectre stopransom
2024-11-21 06:04http://67.207.85.215:8888/supershell/login/ Unknown malwareAS14061 DigitalOcean LLC Supershell antiphishorg
2024-11-21 06:0467.207.85.215:8888 Unknown malwareAS14061 DigitalOcean LLC Supershell antiphishorg
2024-11-20 20:47103.54.153.76:56001 AsyncRATasyncrat NDA0E
2024-11-20 20:21www.aviationchartersolutions.com AsyncRATasyncrat Donut DonutInjector DonutLoader NDA0E
2024-11-20 20:21aviationchartersolutions.com AsyncRATasyncrat Donut DonutInjector DonutLoader NDA0E
2024-11-20 15:41https://nyciot.com/js.php FAKEUPDATESKongtuke monitorsg
2024-11-20 15:41nyciot.com FAKEUPDATESKongtuke monitorsg
2024-11-20 15:41https://nyciot.com/je5vl.js FAKEUPDATESKongtuke monitorsg
2024-11-20 15:41segurofinalizar.shop FAKEUPDATESSmartApeSG monitorsg
2024-11-20 15:41https://segurofinalizar.shop/work/fix2.php FAKEUPDATESSmartApeSG monitorsg
2024-11-20 15:41https://segurofinalizar.shop/work/xxx.zip FAKEUPDATESSmartApeSG monitorsg
2024-11-20 15:41https://segurofinalizar.shop/work/index.php FAKEUPDATESSmartApeSG monitorsg
2024-11-20 15:41https://segurofinalizar.shop/work/original.js FAKEUPDATESSmartApeSG monitorsg
2024-11-20 15:41https://jaipurraj.com/work/original.js FAKEUPDATESSmartApeSG HuntYethHounds
2024-11-20 15:41https://jaipurraj.com/work/das.php FAKEUPDATESSmartApeSG HuntYethHounds
2024-11-20 15:41https://jaipurraj.com/work/fix.php FAKEUPDATESSmartApeSG HuntYethHounds
2024-11-20 15:41http://94.156.177.41/simple/five/PvqDq929BSx_A_D_M1n_a.php LokiBotAS214943 LokiBot Railnet LLC antiphishorg
2024-11-20 15:40192.129.178.61:9001 DCRatc2 dcrat juroots
2024-11-20 15:4045.158.14.11:8089 Hookc2 HookBot juroots
2024-11-20 15:40185.251.91.157:443 FAKEUPDATESSocGholish threatcat_ch
2024-11-20 15:40http://31.177.109.184/8331a12a495c21b2.php StealcStealc abuse_ch
2024-11-20 15:31106.75.33.253:8081 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:31139.180.190.205:8088 Cobalt StrikeCobaltStrike cs-watermark-666666666 abuse_ch
2024-11-20 15:31113.45.142.235:8888 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:3116.162.220.217:443 Cobalt StrikeCobaltStrike cs-watermark-666666666 abuse_ch
2024-11-20 15:31129.204.11.57:443 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:3147.108.72.55:83 Cobalt StrikeCobaltStrike cs-watermark-391144938 abuse_ch
2024-11-20 15:318.152.216.26:443 Cobalt StrikeCobaltStrike cs-watermark-426352781 abuse_ch
2024-11-20 15:3145.140.168.166:8080 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:30202.95.12.137:443 Cobalt StrikeCobaltStrike cs-watermark-391144938 abuse_ch
2024-11-20 15:30110.40.138.5:4545 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:298.156.64.248:1234 Cobalt StrikeCobaltStrike cs-watermark-391144938 abuse_ch
2024-11-20 15:29152.32.206.5:9999 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:2981.70.19.128:443 Cobalt StrikeCobaltStrike cs-watermark-666666666 abuse_ch
2024-11-20 15:29118.195.137.190:80 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:29120.27.215.186:8443 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:2960.204.138.63:801 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:29162.14.73.44:8090 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:29108.61.181.191:8090 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:29118.195.137.190:443 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:29106.55.134.168:443 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:29124.222.164.43:80 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 15:29124.222.164.43:5555 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2024-11-20 12:5387.121.86.8:5055 STRRATSTRRAT NDA0E
2024-11-20 12:53badmiles.ddns.net STRRATSTRRAT NDA0E
2024-11-20 12:40http://101.133.156.69:7001/fwlink Cobalt StrikeCobaltStrike abuse_ch
2024-11-20 10:34http://179.60.149.194:8080/vxhxrqnb DarkGateAS395839 c2 DarkGate drk2 HOSTKEY-USA payload DonPasci
2024-11-20 10:34http://91.243.50.68:8080/rdullfph DarkGateAS34665 c2 DarkGate jma755 payload PINDC-AS DonPasci
2024-11-20 10:34http://91.243.50.68:8080/eqvukhda DarkGateAS34665 c2 DarkGate jma755 payload PINDC-AS DonPasci
2024-11-20 10:1791.243.50.68:80 DarkGateAS34665 c2 DarkGate jma755 PINDC-AS DonPasci
2024-11-20 10:10164.132.5.124:1111 DarkGateAS16276 c2 DarkGate Derry OVH DonPasci
2024-11-20 10:08reateberam.com Latrodectus Cryptolaemus1
2024-11-20 10:02179.60.149.194:8080 DarkGateAS395839 c2 DarkGate drk2 HOSTKEY-USA payload DonPasci
2024-11-20 10:02179.60.149.194:80 DarkGateAS395839 c2 DarkGate drk2 HOSTKEY-USA DonPasci
2024-11-20 09:52https://bestmarsgood.com/test/ Latrodectus Cryptolaemus1
2024-11-20 09:52https://cerwintifed.com/test/ Latrodectus Cryptolaemus1
2024-11-20 06:55http://94.156.177.41/simple/five/fre.php Loki Password Stealer (PWS)LokiBot abuse_ch