ThreatFox IOC Database

You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.


300

IOCs shared (past 24 hours)

ClearFake

Most seen malware family (past 24 hours)

1'626'305

IOCs in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • ioc:ms-debug-services.com ( run)
  • malware:CobaltStrike ( run)
  • tag:TA505 ( run)
  • threat_type:cc_skimming ( run)
  • uuid:87f310f3-540b-11eb-922c-42010aa4000a ( run)

Date (UTC)IOCMalwareTagsReporter
2026-02-20 09:45saltwave.oceanprim.in.net ClearFakeClearFake threatcat_ch
2026-02-20 09:32bluecurrent.oceanprim.in.net ClearFakeClearFake threatcat_ch
2026-02-20 09:24ironclove.bakhkondach.in.net ClearFakeClearFake threatcat_ch
2026-02-20 09:17blackroot.bakhkondach.in.net ClearFakeClearFake threatcat_ch
2026-02-20 09:0047.76.249.152:447 ValleyRATRAT ValleyRAT abuse_ch
2026-02-20 08:56darkspice.bakhkondach.in.net ClearFakeClearFake Anonymous
2026-02-20 08:5195.216.212.8:8888 Sliverdrb-ra sliver abuse_ch
2026-02-20 08:50xworm2026.ddns.net XWormXWorm abuse_ch
2026-02-20 08:47185.180.198.3:2025 RansomHubdrb-ra RansomHub abuse_ch
2026-02-20 08:47185.180.198.3:443 RansomHubdrb-ra RansomHub abuse_ch
2026-02-20 08:46167.172.199.123:443 Sliverdrb-ra sliver abuse_ch
2026-02-20 08:46167.172.199.123:8888 Sliverdrb-ra sliver abuse_ch
2026-02-20 08:46163.181.208.79:4506 DeimosC2Deimos drb-ra abuse_ch
2026-02-20 08:4413.248.136.191:443 DeimosC2Deimos drb-ra abuse_ch
2026-02-20 08:44firecharge.highexplos.in.net ClearFakeClearFake threatcat_ch
2026-02-20 08:37shockflare.highexplos.in.net ClearFakeClearFake threatcat_ch
2026-02-20 08:30blastzone.highexplos.in.net ClearFakeClearFake threatcat_ch
2026-02-20 08:10rockpanel.flatdon.in.net ClearFakeClearFake threatcat_ch
2026-02-20 08:03plainforge.flatdon.in.net ClearFakeClearFake threatcat_ch
2026-02-20 08:02168.245.203.186:3790 MeterpreterAS58580 c2 censys FASTRACK hacktool MetaSploit Meterpreter DonPasci
2026-02-20 08:02103.177.47.207:3790 MeterpreterAS58580 c2 censys FASTRACK hacktool MetaSploit Meterpreter DonPasci
2026-02-20 08:02103.177.47.174:3790 MeterpreterAS58580 c2 censys FASTRACK hacktool MetaSploit Meterpreter DonPasci
2026-02-20 08:023.107.169.157:2 MeterpreterAMAZON-02 AS16509 c2 censys hacktool MetaSploit Meterpreter DonPasci
2026-02-20 08:01104.223.84.7:14646 RemcosAS-COLOCROSSING AS36352 c2 censys RAT remcos DonPasci
2026-02-20 08:0191.92.41.4:5555 RemcosAS211443 c2 censys RAT remcos SINOWORLDWIDE DonPasci
2026-02-20 07:51dustcrate.flatdon.in.net ClearFakeClearFake threatcat_ch
2026-02-20 07:5038.46.11.202:1107 ValleyRATRAT ValleyRAT abuse_ch
2026-02-20 07:50192.163.162.194:447 ValleyRATRAT ValleyRAT abuse_ch
2026-02-20 07:46193.26.115.60:6000 Remcos2026 AUTO-REG FEBRERO persistence RAT remcos Neiki
2026-02-20 07:4638.49.215.118:8443 PureRATcollection discovery execution NETREACTOR PureHVNC spyware stealer Neiki
2026-02-20 07:4623.94.252.101:7000 XWormARCH-EXEC AUTO-STARTUP discovery NETREACTOR RAT trojan XWorm Neiki
2026-02-20 07:4583.142.209.92:11200 PureRATdiscovery NETREACTOR PureHVNC Neiki
2026-02-20 07:45https://ainttby.com/6f54.js KongTukeKongtuke monitorsg
2026-02-20 07:45ainttby.com KongTukeKongtuke monitorsg
2026-02-20 07:45https://ainttby.com/js.php KongTukeKongtuke monitorsg
2026-02-20 07:45http://212.85.166.12:22448/.i Unknown malwarehoneypot greedybear
2026-02-20 07:45203.192.206.72:1988 AsyncRATasyncrat Default discovery NETREACTOR PROTECTOR RAT Neiki
2026-02-20 07:45193.124.250.110:8080 XWormdefense_evasion RAT trojan XWorm Neiki
2026-02-20 07:45172.94.111.65:8098 Remcosdiscovery RAT remcos REMOTEHOST Neiki
2026-02-20 07:455.101.86.26:49274 Remcosdiscovery EXCESSMONEY RAT remcos Neiki
2026-02-20 07:45excessmon001.duckdns.org Remcosdiscovery EXCESSMONEY RAT remcos Neiki
2026-02-20 07:45x1edaroughgan8hajous20.duckdns.org RemcosLAST RAT remcos Neiki
2026-02-20 07:45x1edaroughgan8hajous30.duckdns.org RemcosLAST RAT remcos Neiki
2026-02-20 07:45x1edaroughgan8hajous40.duckdns.org RemcosLAST RAT remcos Neiki
2026-02-20 07:45https://89.58.25.125/ Unknown malwareClickFix CarsonWilliams
2026-02-20 07:45cygnusn.cyou Lumma Stealerdomain Lumma Lumma Stealer stealer RacWatchin8872
2026-02-20 07:45khantym.cyou Lumma Stealerdomain Lumma Lumma Stealer stealer RacWatchin8872
2026-02-20 07:45salivae.cyou Lumma Stealerdomain Lumma Lumma Stealer stealer RacWatchin8872
2026-02-20 07:45swederq.cyou Lumma Stealerdomain Lumma Lumma Stealer stealer RacWatchin8872
2026-02-20 07:45transpd.cyou Lumma Stealerdomain Lumma Lumma Stealer stealer RacWatchin8872
2026-02-20 07:45tributj.cyou Lumma Stealerdomain Lumma Lumma Stealer stealer RacWatchin8872
2026-02-20 07:44intranet.milnetstresser.ru Miraibotnet defense_evasion discovery linux Mirai owari Neiki
2026-02-20 07:4487.121.84.58:8080 MiraiMirai elfdigest
2026-02-20 07:4387.121.84.58:2901 MiraiMirai seckle
2026-02-20 07:43146.70.51.74:2712 DCRatAMSI-BYPASS asyncrat dcrat discovery NEWR2712 RAT Neiki
2026-02-20 07:433.127.59.75:11637 NjRAT?????? AUTO-STARTUP defense_evasion discovery njrat persistence RAT Neiki
2026-02-20 07:43193.161.193.99:64601 XWormRAT trojan XWorm Neiki
2026-02-20 07:43http://198.46.147.169:8888/supershell/login/ Unknown malwareAS36352 HostPapa Supershell antiphishorg
2026-02-20 07:42heattrail.agrahurry.in.net ClearFakeClearFake threatcat_ch
2026-02-20 07:27rushgrain.agrahurry.in.net ClearFakeClearFake threatcat_ch
2026-02-20 07:17speedcargo.agrahurry.in.net ClearFakeClearFake threatcat_ch
2026-02-20 07:0981.68.89.216:8088 Cobalt StrikeCobaltStrike cs-watermark-987654321 abuse_ch
2026-02-20 07:00221.229.53.161:10001 Xtreme RATAS146966 c2 censys RAT dyingbreeds_
2026-02-20 06:52wildhorn.goatbreed.in.net ClearFakeClearFake threatcat_ch
2026-02-20 06:36stonegraze.goatbreed.in.net ClearFakeClearFake threatcat_ch
2026-02-20 06:34share2e2git.autos Unknown Stealerc2 domain MacSync stealer VirusTotal DonPasci
2026-02-20 06:30stormfield.goatbreed.in.net ClearFakeClearFake threatcat_ch
2026-02-20 06:28horsten.fun Unknown Stealerc2 domain MacSync stealer VirusTotal DonPasci
2026-02-20 06:23rocketmoll.com Unknown Stealerc2 domain MacSync stealer VirusTotal DonPasci
2026-02-20 06:22argoflyleens.city Unknown Stealerc2 domain MacSync stealer VirusTotal DonPasci
2026-02-20 06:19elfrodbloom.city Unknown Stealerc2 domain MacSync stealer VirusTotal DonPasci
2026-02-20 06:07159.26.100.159:59476 Nanocore RATAS208172 c2 NanoCore RAT triage DonPasci
2026-02-20 06:05bluepoint.northlake.in.net ClearFakeClearFake threatcat_ch
2026-02-20 06:02shroudcloud.ru.com AsyncRATasyncrat c2 domain RAT triage DonPasci
2026-02-20 06:02kishlay.in.net AsyncRATasyncrat c2 domain RAT triage DonPasci
2026-02-20 06:02hpandroid2025.jp.net AsyncRATasyncrat c2 domain RAT triage DonPasci
2026-02-20 05:50icefront.northlake.in.net ClearFakeClearFake Anonymous
2026-02-20 05:39coldwater.northlake.in.net ClearFakeClearFake threatcat_ch
2026-02-20 05:24northshore.northlake.in.net ClearFakeClearFake threatcat_ch
2026-02-20 05:20165.227.177.122:1177 NjRATnjrat abuse_ch
2026-02-20 04:46westwave.westlake.in.net ClearFakeClearFake threatcat_ch
2026-02-20 04:02168.245.203.199:3790 MeterpreterAS58580 c2 censys FASTRACK hacktool MetaSploit Meterpreter DonPasci
2026-02-20 04:02168.245.203.224:3790 MeterpreterAS58580 c2 censys FASTRACK hacktool MetaSploit Meterpreter DonPasci
2026-02-20 04:02168.245.203.51:3790 MeterpreterAS58580 c2 censys FASTRACK hacktool MetaSploit Meterpreter DonPasci
2026-02-20 04:02168.245.203.231:3790 MeterpreterAS58580 c2 censys FASTRACK hacktool MetaSploit Meterpreter DonPasci
2026-02-20 04:0194.242.52.160:445 HavocAS43317 c2 censys Havoc VEESP-AS DonPasci
2026-02-20 03:36coolsurf.westlake.in.net ClearFakeClearFake threatcat_ch
2026-02-20 03:32deepblue.westlake.in.net ClearFakeClearFake threatcat_ch
2026-02-20 02:32waterfront.westlake.in.net ClearFakeClearFake threatcat_ch
2026-02-20 02:20greenpath.deepwood.in.net ClearFakeClearFake threatcat_ch
2026-02-20 02:13wildleaf.deepwood.in.net ClearFakeClearFake threatcat_ch
2026-02-20 02:03darktimber.deepwood.in.net ClearFakeClearFake threatcat_ch
2026-02-20 01:35deeproot.deepwood.in.net ClearFakeClearFake threatcat_ch
2026-02-20 01:27redcore.redwood.in.net ClearFakeClearFake threatcat_ch
2026-02-20 01:20tallbranch.redwood.in.net ClearFakeClearFake threatcat_ch
2026-02-20 01:06oldroot.redwood.in.net ClearFakeClearFake threatcat_ch
2026-02-20 00:57strongleaf.redwood.in.net ClearFakeClearFake threatcat_ch
2026-02-20 00:49silentnode.darkmoon.in.net ClearFakeClearFake threatcat_ch
2026-02-20 00:41hiddenside.darkmoon.in.net ClearFakeClearFake threatcat_ch
2026-02-20 00:34blackorbit.darkmoon.in.net ClearFakeClearFake threatcat_ch
2026-02-20 00:29shadowphase.darkmoon.in.net ClearFakeClearFake threatcat_ch
2026-02-20 00:23goldtrace.goldwind.in.net ClearFakeClearFake threatcat_ch
2026-02-20 00:17fastglow.goldwind.in.net ClearFakeClearFake threatcat_ch
2026-02-20 00:11shineflow.goldwind.in.net ClearFakeClearFake Anonymous
2026-02-20 00:07warmbreeze.goldwind.in.net ClearFakeClearFake threatcat_ch
2026-02-20 00:02heavynode.ironwave.in.net ClearFakeClearFake threatcat_ch
2026-02-20 00:02138.197.196.147:80 Empire DownloaderAS14061 c2 censys DIGITALOCEAN-ASN PowershellEmpire DonPasci
2026-02-20 00:0215.216.95.47:2701 MeterpreterAMAZON-02 AS16509 c2 censys hacktool MetaSploit Meterpreter DonPasci
2026-02-20 00:0191.92.243.47:4449 Venom RATAS202412 c2 censys OMEGATECH-AS RAT Venom DonPasci
2026-02-20 00:01bkn-connects.com HavocAS13335 c2 censys CLOUDFLARENET Havoc DonPasci
2026-02-20 00:0189.40.206.98:2050 RemcosAS9009 c2 censys M247 RAT remcos DonPasci
2026-02-19 23:50powerlink.ironwave.in.net ClearFakeClearFake threatcat_ch
2026-02-19 23:34hardflow.ironwave.in.net ClearFakeClearFake threatcat_ch
2026-02-19 23:29steelsync.ironwave.in.net ClearFakeClearFake threatcat_ch
2026-02-19 23:04coldbeam.coolstar.in.net ClearFakeClearFake threatcat_ch
2026-02-19 23:00209.74.82.76:3333 Unknown malwareAS22612 censys EvilGoPhish phishing dyingbreeds_
2026-02-19 23:003.85.107.177:8443 HavocAS14618 c2 censys dyingbreeds_
2026-02-19 23:003.148.25.195:80 HavocAS16509 c2 censys dyingbreeds_
2026-02-19 23:0075.119.151.20:80 HavocAS51167 c2 censys CONTABO dyingbreeds_
2026-02-19 23:00bkn-partr.com HavocAS13335 c2 censys dyingbreeds_
2026-02-19 23:00juandaza2025pu.camdvr.org Remcosremcos dyingbreeds_
2026-02-19 23:0016.58.121.239:443 Unknown malwareAS16509 c2 censys Mythic dyingbreeds_
2026-02-19 23:00manager.3utilities.com Remcosremcos dyingbreeds_
2026-02-19 23:00165.232.45.1:8088 AsyncRATAS14061 c2 censys RAT dyingbreeds_
2026-02-19 23:00155.138.162.127:443 SliverAS20473 c2 censys dyingbreeds_
2026-02-19 23:00154.219.97.206:5758 Ghost RATAS401701 c2 censys RAT dyingbreeds_
2026-02-19 23:00154.219.97.142:5758 Ghost RATAS401701 c2 censys RAT dyingbreeds_
2026-02-19 23:00154.219.97.70:5758 Ghost RATAS401701 c2 censys RAT dyingbreeds_
2026-02-19 22:46spaceview.coolstar.in.net ClearFakeClearFake threatcat_ch
2026-02-19 22:40y5d9oidj.blue128cinder.digital ClearFakeClearFake Anonymous
2026-02-19 22:39423vlwlb.blue128cinder.digital ClearFakeClearFake threatcat_ch
2026-02-19 22:39brightpoint.coolstar.in.net ClearFakeClearFake threatcat_ch
2026-02-19 22:25lightcore.coolstar.in.net ClearFakeClearFake threatcat_ch
2026-02-19 22:16leadpulse.bluewolf.in.net ClearFakeClearFake threatcat_ch
2026-02-19 22:09nightrun.bluewolf.in.net ClearFakeClearFake threatcat_ch
2026-02-19 21:56bluehunt.bluewolf.in.net ClearFakeClearFake threatcat_ch
2026-02-19 21:45forestnode.graywolf.in.net ClearFakeClearFake threatcat_ch
2026-02-19 21:39greytrack.graywolf.in.net ClearFakeClearFake Anonymous
2026-02-19 21:34wildstep.graywolf.in.net ClearFakeClearFake threatcat_ch
2026-02-19 21:24huntpack.graywolf.in.net ClearFakeClearFake threatcat_ch
2026-02-19 21:14176.108.250.50:443 Cobalt StrikeEarth Baxia Rony
2026-02-19 20:41spacecore.brightstar.in.net ClearFakeClearFake threatcat_ch
2026-02-19 20:33lightbeam.brightstar.in.net ClearFakeClearFake threatcat_ch
2026-02-19 20:18northgale.coldwind.in.net ClearFakeClearFake threatcat_ch
2026-02-19 20:07snowtrack.coldwind.in.net ClearFakeClearFake threatcat_ch
2026-02-19 20:05156.225.19.99:2324 ValleyRATvalleyrat_s2 abuse_ch
2026-02-19 20:03winterblast.coldwind.in.net ClearFakeClearFake threatcat_ch
2026-02-19 20:0289.58.25.125:443 Unknown malwareAS197540 c2 censys ClickFix first-stage NETCUP-AS DonPasci
2026-02-19 20:0254.91.209.10:16930 MeterpreterAMAZON-AES AS14618 c2 censys hacktool MetaSploit Meterpreter DonPasci
2026-02-19 20:0251.92.40.130:1234 MeterpreterAMAZON-02 AS16509 c2 censys hacktool MetaSploit Meterpreter DonPasci
2026-02-19 20:0251.84.9.169:9999 MeterpreterAMAZON-02 AS16509 c2 censys hacktool MetaSploit Meterpreter DonPasci
2026-02-19 20:0118.236.192.145:80 HavocAMAZON-02 AS16509 c2 censys Havoc DonPasci
2026-02-19 20:013.140.254.73:443 HavocAMAZON-02 AS16509 c2 censys Havoc DonPasci
2026-02-19 20:01178.236.252.109:3000 Unknown malwareAS215826 c2 censys Mythic PARTNER-HOSTING-LTD DonPasci
2026-02-19 20:0120.39.130.27:443 Unknown malwareAS8075 c2 censys MICROSOFT-CORP-MSN-AS-BLOCK Mythic DonPasci
2026-02-19 20:01155.117.40.221:443 Unknown malwareAS32097 c2 censys Mythic WII DonPasci
2026-02-19 20:013.148.25.195:7443 Unknown malwareAMAZON-02 AS16509 c2 censys Mythic DonPasci
2026-02-19 20:01159.203.79.29:443 SliverAS14061 c2 censys DIGITALOCEAN-ASN sliver DonPasci
2026-02-19 20:0118.221.223.195:443 SliverAMAZON-02 AS16509 c2 censys sliver DonPasci
2026-02-19 20:0187.106.187.97:443 SliverAS8560 c2 censys IONOS-AS sliver DonPasci
2026-02-19 20:01181.235.2.89:2404 RemcosAS3816 c2 censys COLOMBIA RAT remcos DonPasci
2026-02-19 20:01192.227.219.80:2404 RemcosAS-COLOCROSSING AS36352 c2 censys RAT remcos DonPasci
2026-02-19 19:53freezepoint.coldwind.in.net ClearFakeClearFake threatcat_ch
2026-02-19 19:44coalbase.firepath.in.net ClearFakeClearFake threatcat_ch
2026-02-19 19:29glowtrace.firepath.in.net ClearFakeClearFake threatcat_ch
2026-02-19 19:2595.85.239.201:443 NetSupportManager RATNetSupport abuse_ch
2026-02-19 19:22ashcloud.firepath.in.net ClearFakeClearFake threatcat_ch
2026-02-19 19:09hotstone.firepath.in.net ClearFakeClearFake threatcat_ch
2026-02-19 19:05saltreef.deepwave.in.net ClearFakeClearFake threatcat_ch
2026-02-19 19:00107.189.27.83:8443 HavocAS14956 c2 censys dyingbreeds_
2026-02-19 19:0044.198.60.243:443 HavocAS14618 c2 censys dyingbreeds_
2026-02-19 18:58178.236.252.109:7443 Unknown malwaredrb-ra Mythic abuse_ch
2026-02-19 18:51149.28.151.106:8888 Sliverdrb-ra sliver abuse_ch
2026-02-19 18:50seacurrent.deepwave.in.net ClearFakeClearFake threatcat_ch
2026-02-19 18:46117.187.252.19:10250 DeimosC2Deimos drb-ra abuse_ch
2026-02-19 18:14darkwater.deepwave.in.net ClearFakeClearFake threatcat_ch
2026-02-19 18:0595.156.205.13:55575 SpyNoteAndroid AS57169 c2 Spynote triage DonPasci
2026-02-19 18:04178.116.38.74:1912 RedLine StealerAS6848 c2 RedLine RedLineStealer stealer triage DonPasci
2026-02-19 18:0292lottery.coach AsyncRATasyncrat c2 domain RAT triage DonPasci
2026-02-19 18:01172.86.68.38:28886 VShellAS14956 c2 ROUTERHOSTING VirusTotal Vshell DonPasci
2026-02-19 18:01blueocean.deepwave.in.net ClearFakeClearFake threatcat_ch
2026-02-19 18:01103.83.86.162:1985 XWormAS44382 c2 triage XWorm DonPasci
2026-02-19 18:00119.45.214.169:8443 VShellAS45090 c2 TENCENT-NET-AP VirusTotal Vshell DonPasci
2026-02-19 17:5839.101.174.60:8084 VShellALIBABA-CN-NET AS37963 c2 VirusTotal Vshell DonPasci
2026-02-19 17:49softmist.skyrain.in.net ClearFakeClearFake threatcat_ch
2026-02-19 17:38clearair.skyrain.in.net ClearFakeClearFake threatcat_ch
2026-02-19 17:28highwind.skyrain.in.net ClearFakeClearFake Anonymous
2026-02-19 17:12bluecloud.skyrain.in.net ClearFakeClearFake threatcat_ch
2026-02-19 17:05195.177.94.71:4000 LodaLoda abuse_ch
2026-02-19 17:05136.0.157.17:9304 Quasar RATQuasarRAT RAT abuse_ch
2026-02-19 16:54globalfruit.kiwi9ship3.coupons ClearFakeClearFake threatcat_ch
2026-02-19 16:38portside.kiwi9ship3.coupons ClearFakeClearFake threatcat_ch
2026-02-19 16:32oceanbird.kiwi9ship3.coupons ClearFakeClearFake threatcat_ch
2026-02-19 16:07kiwitransit.kiwi9ship3.coupons ClearFakeClearFake threatcat_ch
2026-02-19 16:04stockhub.box671plum.coupons ClearFakeClearFake threatcat_ch
2026-02-19 16:0215.229.32.243:1234 AdaptixC2AdaptixC2 AMAZON-02 AS16509 c2 censys DonPasci
2026-02-19 16:0169.5.189.249:7701 RemcosAS42624 c2 censys RAT remcos SWISSNETWORK02 DonPasci
2026-02-19 15:34blueplum.box671plum.coupons ClearFakeClearFake threatcat_ch
2026-02-19 15:27heavybox.box671plum.coupons ClearFakeClearFake Anonymous
2026-02-19 15:03193.161.193.99:63603 XWormXWorm dyingbreeds_
2026-02-19 15:0337.4.250.173:63603 XWormXWorm dyingbreeds_
2026-02-19 15:02plumfield.box671plum.coupons ClearFakeClearFake threatcat_ch
2026-02-19 15:01103.109.234.117:4782 Quasar RATquasar dyingbreeds_
2026-02-19 15:01vnwns-188-163-102-33.a.free.pinggy.link Quasar RATquasar dyingbreeds_
2026-02-19 15:01www.lighter500.com Remcosremcos dyingbreeds_
2026-02-19 15:0089.125.50.65:7443 Unknown malwareAS212477 c2 censys Mythic ROYALE-AS dyingbreeds_
2026-02-19 15:00149.28.151.106:443 SliverAS20473 c2 censys dyingbreeds_
2026-02-19 15:00abnewszamanpaper72.sa.com AsyncRATasyncrat dyingbreeds_
2026-02-19 15:00p-93kketo.ru.com AsyncRATasyncrat dyingbreeds_
2026-02-19 14:57boxflow.fig08box.coupons ClearFakeClearFake threatcat_ch
2026-02-19 14:45megafilehub2.baby Unknown Stealerc2 domain MacSync stealer DonPasci
2026-02-19 14:45megafilehub3.baby Unknown Stealerc2 domain MacSync stealer DonPasci
2026-02-19 14:45megafilehub4.baby Unknown Stealerc2 domain MacSync stealer DonPasci
2026-02-19 14:41freshfig.fig08box.coupons ClearFakeClearFake threatcat_ch
2026-02-19 14:395.230.159.62:7000 XWormAS12586 ASGHOSTNET c2 XWorm DonPasci
2026-02-19 14:3920.234.151.26:6000 XWormAS8075 c2 MICROSOFT-CORP-MSN-AS-BLOCK XWorm DonPasci
2026-02-19 14:3945.61.149.192:6000 XWormAS14956 c2 ROUTERHOSTING XWorm DonPasci
2026-02-19 14:3945.137.98.189:6666 XWormAS49581 c2 FERDINANDZINK XWorm DonPasci
2026-02-19 14:3945.141.26.201:6000 XWormAS142299 c2 CLOUDFORESTCOLTD-AS-AP XWorm DonPasci
2026-02-19 14:3982.26.104.128:6000 XWormAS63989 c2 DE-CORP XWorm DonPasci
2026-02-19 14:3991.208.197.30:1605 XWormALEXHOST AS200019 c2 XWorm DonPasci
2026-02-19 14:36kys.li Unknown Stealerc2 domain phexia stealer DonPasci
2026-02-19 14:35virtualspeechtherapists.com Unknown Stealerc2 domain MacSync stealer DonPasci
2026-02-19 14:35megafilehub1.baby Unknown Stealerc2 domain MacSync stealer DonPasci
2026-02-19 14:31103.163.219.252:7000 XWormAS140787 c2 LAMA-AS-VN XWorm DonPasci
2026-02-19 14:31141.11.213.91:8282 XWormAS212477 c2 ROYALE-AS XWorm DonPasci
2026-02-19 14:31147.45.45.110:7777 XWormAS215826 c2 PARTNER-HOSTING-LTD XWorm DonPasci
2026-02-19 14:31193.233.113.137:7000 XWormAS215826 c2 PARTNER-HOSTING-LTD XWorm DonPasci
2026-02-19 14:30134.122.152.135:7000 XWormAS152194 c2 CTGSERVERLIMITED-AS-AP XWorm DonPasci
2026-02-19 14:30134.122.154.171:7000 XWormAS152194 c2 CTGSERVERLIMITED-AS-AP XWorm DonPasci
2026-02-19 14:30202.95.17.184:7000 XWormAS152194 c2 CTGSERVERLIMITED-AS-AP XWorm DonPasci
2026-02-19 14:30202.95.18.16:7000 XWormAS152194 c2 CTGSERVERLIMITED-AS-AP XWorm DonPasci
2026-02-19 14:30134.122.140.89:7000 XWormAS152194 c2 CTGSERVERLIMITED-AS-AP XWorm DonPasci
2026-02-19 14:20smallbox.fig08box.coupons ClearFakeClearFake threatcat_ch
2026-02-19 14:16figbranch.fig08box.coupons ClearFakeClearFake threatcat_ch
2026-02-19 14:08coalpoint.darkfire.coupons ClearFakeClearFake threatcat_ch
2026-02-19 13:57smoketrace.darkfire.coupons ClearFakeClearFake threatcat_ch
2026-02-19 13:54hotelement.darkfire.coupons ClearFakeClearFake threatcat_ch
2026-02-19 13:19sys-kernel-update.to XOR DDoSxorddos abuse_ch
2026-02-19 13:19telemetry-pipe.sh XOR DDoSxorddos abuse_ch
2026-02-19 13:18blackfire.darkfire.coupons ClearFakeClearFake threatcat_ch
2026-02-19 13:17velvet-parrot.com SantaStealerc2 SantaStealer burger
2026-02-19 13:17api-metadata-v6.is XOR DDoSANTIVM botnet discovery Downloader execution linux persistence xorddos Neiki
2026-02-19 13:16213.152.161.162:5103 XWormAMSI-BYPASS AUTO-REG persistence RAT trojan XWorm Neiki
2026-02-19 13:16https://trofeyincs.top/login/middleware-json.php SmartApeSGSmartApeSG monitorsg
2026-02-19 13:16trofeyincs.top SmartApeSGSmartApeSG monitorsg
2026-02-19 13:16https://trofeyincs.top/login/auth-response.js SmartApeSGSmartApeSG monitorsg
2026-02-19 13:16https://trombolistic.com/111-file-r SmartApeSGSmartApeSG monitorsg
2026-02-19 13:16https://79.141.163.163/320-zip SmartApeSGSmartApeSG monitorsg
2026-02-19 13:10farmfresh.pear7pack.coupons ClearFakeClearFake threatcat_ch
2026-02-19 13:05goldpack.pear7pack.coupons ClearFakeClearFake threatcat_ch
2026-02-19 12:50pizzashop.kozow.com AsyncRATasyncrat abuse_ch
2026-02-19 12:50brotherspizza.kozow.com AsyncRATasyncrat abuse_ch
2026-02-19 12:47sweetfruit.pear7pack.coupons ClearFakeClearFake threatcat_ch
2026-02-19 12:23pearline.pear7pack.coupons ClearFakeClearFake threatcat_ch
2026-02-19 12:11stormtrack.westwind.coupons ClearFakeClearFake threatcat_ch
2026-02-19 12:02168.245.203.52:3790 MeterpreterAS58580 c2 censys FASTRACK hacktool MetaSploit Meterpreter DonPasci
2026-02-19 12:02168.245.203.54:3790 MeterpreterAS58580 c2 censys FASTRACK hacktool MetaSploit Meterpreter DonPasci
2026-02-19 12:0265.87.7.237:8888 AdaptixC2AdaptixC2 AS215659 c2 censys MOEMOEKYUN DonPasci
2026-02-19 12:0280.71.235.24:8888 AdaptixC2AdaptixC2 AS211673 c2 censys MYNYMBOX DonPasci
2026-02-19 12:0294.237.58.158:8000 MimiKatzAS202053 c2 censys hacktool Mimikatz open-dir UPCLOUD DonPasci
2026-02-19 12:01178.16.53.96:888 RemcosAS202412 c2 censys OMEGATECH-AS RAT remcos DonPasci
2026-02-19 11:54172.94.100.227:29811 Remcosdiscovery LAST RAT remcos Neiki
2026-02-19 11:54apiv4.frostapi.com Unknown Stealerc2 FrostStealer burger
2026-02-19 11:39openfield.westwind.coupons ClearFakeClearFake threatcat_ch
2026-02-19 11:16strongblow.westwind.coupons ClearFakeClearFake threatcat_ch
2026-02-19 11:07westcoast.westwind.coupons ClearFakeClearFake threatcat_ch
2026-02-19 11:03bra.gadgetwalabd.com VidarVidar crep1x
2026-02-19 11:03bra.alpinematters.com VidarVidar crep1x
2026-02-19 11:03https://bra.alpinematters.com/ VidarVidar crep1x
2026-02-19 11:03https://bra.gadgetwalabd.com/ VidarVidar crep1x
2026-02-19 11:02dawdawf-45472.portmap.host XWormXWorm dyingbreeds_
2026-02-19 11:00223.109.90.98:10001 Xtreme RATAS56046 c2 censys RAT dyingbreeds_
2026-02-19 11:00183.2.143.61:43350 Xtreme RATAS4134 c2 censys RAT dyingbreeds_
2026-02-19 11:00183.2.143.61:10001 Xtreme RATAS4134 c2 censys RAT dyingbreeds_
2026-02-19 11:0062.102.148.154:3066 Remcosremcos dyingbreeds_
2026-02-19 11:00daroughgan1.com Remcosremcos dyingbreeds_
2026-02-19 11:00daroughgan8hajous30.duckdns.org Remcosremcos dyingbreeds_
2026-02-19 11:00daroughgan8hajous40.duckdns.org Remcosremcos dyingbreeds_
2026-02-19 11:00daroughgan8hajous50.duckdns.org Remcosremcos dyingbreeds_
2026-02-19 11:0083.228.224.244:7443 Unknown malwareAS29222 c2 censys INFOMANIAK-AS Mythic dyingbreeds_
2026-02-19 11:00158.94.210.95:6606 AsyncRATAS202412 c2 censys OMEGATECH-AS RAT dyingbreeds_
2026-02-19 11:00789f.br.com AsyncRATasyncrat dyingbreeds_
2026-02-19 11:00bertran.ru.com AsyncRATasyncrat dyingbreeds_
2026-02-19 11:00frunglewump.gb.net AsyncRATasyncrat dyingbreeds_
2026-02-19 11:00hcolaba.ru.com AsyncRATasyncrat dyingbreeds_
2026-02-19 11:00wwn.uk.com AsyncRATasyncrat dyingbreeds_
2026-02-19 11:00hg0088.co.com AsyncRATasyncrat dyingbreeds_
2026-02-19 11:00wsc.in.net AsyncRATasyncrat dyingbreeds_
2026-02-19 11:00colaba.ru.com AsyncRATasyncrat dyingbreeds_
2026-02-19 10:56skyline.ship46kiwi.coupons ClearFakeClearFake threatcat_ch
2026-02-19 10:45fastkiwi.ship46kiwi.coupons ClearFakeClearFake threatcat_ch
2026-02-19 10:22greenbird.ship46kiwi.coupons ClearFakeClearFake threatcat_ch
2026-02-19 10:15kiwitalk.ship46kiwi.coupons ClearFakeClearFake threatcat_ch
2026-02-19 10:09138.199.59.6:60736 Remcos2026 collection defense_evasion discovery execution RAT remcos SUSP-POWERSHELL Neiki
2026-02-19 10:09fastpack.ship48mint.coupons ClearFake19February2026 ClearFake Commandline Windows Gi7w0rm