ThreatFox IOC Database

You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.


690

IOCs shared (past 24 hours)

ClearFake

Most seen malware family (past 24 hours)

1'675'491

IOCs in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • ioc:ms-debug-services.com ( run)
  • malware:CobaltStrike ( run)
  • tag:TA505 ( run)
  • threat_type:cc_skimming ( run)
  • uuid:87f310f3-540b-11eb-922c-42010aa4000a ( run)

Date (UTC)IOCMalwareTagsReporter
2026-04-17 06:14167.235.234.45:443 Interlock RAT aqedg
2026-04-17 06:1469.169.109.132:443 Interlock RAT aqedg
2026-04-17 06:1423.227.203.52:443 Interlock RAT aqedg
2026-02-18 07:10422755116ab311b473dd38ec88f129d9 Interlockinterlock Ransomware TheRavenFile
2026-02-18 07:10b2b03dfcdc2e59d81e99d20c15919a13 Interlockinterlock Ransomware TheRavenFile
2026-02-18 07:109451420233168c7b0c595257d43c7b85 Interlockinterlock Ransomware TheRavenFile
2026-02-18 07:10784bc5b431fe71aaf85f7d39c014f099 Interlockinterlock Ransomware TheRavenFile
2025-10-01 02:337e5ec68fd647e1a8fef30a2fbe250f9cf6bf6ea0ec1aa6bd37534517dd537a68 Interlock Grim
2025-10-01 02:332c3d53c36f9d92978ab86b7ac0f4f5193c054914 Interlock Grim
2025-10-01 02:337d90538f56b96333034287fdc5934a7c Interlock Grim
2025-10-01 02:339ba7bd0357cfd7907a4ee637dff005ec Interlock Grim
2025-10-01 02:33960bfbed44a5b8abf1ae2fcb7eecb46ac526840030d5cdef1fad6a6bb379996c Interlock Grim
2025-10-01 02:33f4bd4ea391c5bb63d817f0857703235145614b5c Interlock Grim
2025-10-01 02:339e35477130cd2731755a35e8b4c0429b Interlock Grim
2025-10-01 02:33a501583bca532c4ea11b56780a13a865b609d6a0fcd92b9c9b522f1edcc49c29 Interlock Grim
2025-10-01 02:3328811b212449cd4b23042770b437b98acb3f9c47 Interlock Grim
2025-06-25 09:51event-time-microsoft.org InterlockCloudflare netresec
2025-06-25 09:51event-datamicrosoft.live InterlockCloudflare netresec
2025-06-25 09:51windows-msgas.com InterlockCloudflare netresec
2025-06-25 09:51eventdata-microsoft.live InterlockCloudflare netresec
2025-06-25 09:51varying-rentals-calgary-predict.trycloudflare.com InterlockCloudflare netresec
2025-06-13 06:03assets-msnmicosot-ds.live Interlockc2 interlock validin juroots
2025-06-13 06:03payment.mysoroush.com Interlockc2 interlock validin juroots
2025-06-13 06:03windows-msn-cn.org Interlockc2 interlock validin juroots
2025-06-13 06:03assets-msn-ds.live Interlockc2 interlock validin juroots
2025-06-13 06:03teams-msg.com Interlockc2 interlock validin juroots
2025-06-13 06:03silverithm-dispatch.store Interlockc2 interlock validin juroots
2025-06-13 06:03settings-datamicrosoft.live Interlockc2 interlock validin juroots
2025-06-13 06:03events-datamicrosoft.live Interlockc2 interlock validin juroots
2025-06-13 06:03orion.mysoroush.com Interlockc2 interlock validin juroots
2025-06-13 06:03configedge-assets.org Interlockc2 interlock validin juroots
2025-06-13 06:03events-data-microsoft.live Interlockc2 interlock validin juroots
2025-06-13 06:03grupomax-api.marcalgyn.com.br Interlockc2 interlock validin juroots
2025-06-13 06:03eventsdata-microsoft-live.com Interlockc2 interlock validin juroots
2025-06-13 06:03dnsg-windows-ds-data.live Interlockc2 interlock validin juroots
2025-06-13 06:03events-data-microsoft.com Interlockc2 interlock validin juroots
2025-06-13 06:03canismajor.mysoroush.com Interlockc2 interlock validin juroots
2025-06-13 06:03swiftlymeds.com Interlockc2 interlock validin juroots
2025-06-13 06:03configedge-assets.live Interlockc2 interlock validin juroots
2025-06-13 06:03dnsg-windows-ds-data.com Interlockc2 interlock validin juroots
2025-06-13 06:03teams-msg-ns.com Interlockc2 interlock validin juroots
2025-06-13 06:03iarm.co.kr Interlockc2 interlock validin juroots
2025-06-13 06:03assets-msn-ds.org Interlockc2 interlock validin juroots
2025-06-13 06:03windowsds-time.live Interlockc2 interlock validin juroots
2025-06-13 06:03windows-ds-time.live Interlockc2 interlock validin juroots
2025-06-13 06:03teams-msg.live Interlockc2 interlock validin juroots
2025-06-13 06:03dns-microsofts.com Interlockc2 interlock validin juroots
2025-06-13 06:03assets-msn.live Interlockc2 interlock validin juroots
2025-06-13 06:03events-dat-amicrosoft.live Interlockc2 interlock validin juroots
2025-06-13 06:03settings-win-data-microsoft.org Interlockc2 interlock validin juroots
2025-06-13 06:03windows-msg-as.live Interlockc2 interlock validin juroots
2025-06-13 06:03dng-microsof-event.org Interlockc2 interlock validin juroots
2025-06-13 06:03msgmicrosoft.com Interlockc2 interlock validin juroots
2025-06-13 06:03assetsmsn-micosot.org Interlockc2 interlock validin juroots
2025-06-13 06:03dns-gowindows-ds.org Interlockc2 interlock validin juroots
2025-06-13 06:03teamsmsg-ns.live Interlockc2 interlock validin juroots
2025-06-13 06:03windows-msgas.org Interlockc2 interlock validin juroots
2025-06-13 06:03eventsdat-amicrosoft.live Interlockc2 interlock validin juroots
2025-06-13 06:03windows-msg-as.com Interlockc2 interlock validin juroots
2025-06-13 06:03teams-msg-microsoft.live Interlockc2 interlock validin juroots
2025-06-13 06:03dnsgowindows-ds.live Interlockc2 interlock validin juroots
2025-06-13 06:03windows-msg-as.org Interlockc2 interlock validin juroots
2025-06-12 11:03never-powered-agency-hear.trycloudflare.com Interlockc2 interlock juroots
2025-06-12 11:03reached-loose-cashiers-logic.trycloudflare.com Interlockc2 interlock juroots
2025-06-12 11:03ears-circus-cam-lake.trycloudflare.com Interlockc2 interlock juroots
2025-06-12 11:03scary-halo-designing-time.trycloudflare.com Interlockc2 interlock juroots
2025-06-12 11:03showing-bl-order-skiing.trycloudflare.com Interlockc2 interlock juroots
2025-06-12 11:03config-edge-assets.live Interlockc2 interlock juroots
2025-06-04 05:38efea43500a35eb76433e596eeeb92f3e6bae37ca07611cd03cc3b56b18721627 Interlock RATInterlockRAT Overkill1984zzz
2025-06-04 05:3845.61.136.109:443 Interlock RATInterlockRAT Overkill1984zzz
2025-06-04 05:3849.12.69.80:443 Interlock RATInterlockRAT Overkill1984zzz
2025-06-04 05:381e6d4f3eacfef45e2fdfe4d5218aa33079a9b5ca2bba1b0eb3c71f9a5d663ea9 Interlock RATInterlockRAT Overkill1984zzz
2025-06-04 05:38177.136.225.135:443 Interlock RATInterlockRAT Overkill1984zzz
2025-06-04 05:38e40e82b77019edca06c7760b6133c6cc481d9a22585dd80bce393f0bfbe47a99 Interlock RATInterlockRAT Overkill1984zzz
2025-06-04 05:38128.140.120.188:443 Interlock RATInterlockRAT Overkill1984zzz
2025-05-20 06:12sublime-tragedy-counties-sculpture.trycloudflare.com Interlockc2 interlock juroots
2025-05-20 06:12hours-affected-personals-grey.trycloudflare.com Interlockc2 interlock juroots
2025-05-05 10:35faf9a658f4f9b424be3dab262a8af81c Interlockinterlock Ransomware TheRavenFile
2025-05-05 10:3533d8eabbf428fef8c5cd50b440ee3d07 Interlockinterlock Ransomware TheRavenFile
2025-05-05 10:35f73005682c1d90f4b3269483b687e891 Interlockinterlock Ransomware TheRavenFile
2025-05-05 10:353104efb23ea174ac5eda9f5fd0e8c077 Interlockinterlock Ransomware TheRavenFile