################################################################ # ThreatFox IOCs: recent domains - CSV format # # Last updated: 2024-09-14 04:01:26 UTC # # # # Terms Of Use: https://threatfox.abuse.ch/faq/#tos # # For questions please contact threatfox [at] abuse.ch # ################################################################ # # "first_seen_utc","ioc_id","ioc_value","ioc_type","threat_type","fk_malware","malware_alias","malware_printable","last_seen_utc","confidence_level","reference","tags","anonymous","reporter" "2024-09-14 04:01:26", "1324518", "www.visual.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.visual.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-14 00:01:19", "1324332", "hdobussl.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+hdobussl.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-14 00:01:18", "1324330", "wwwwwwwp.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwwwwwp.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-14 00:01:18", "1324331", "layerzero-crystaldash.co", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+layerzero-crystaldash.co", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-14 00:01:17", "1324327", "wwwhdobussl.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwhdobussl.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-14 00:01:17", "1324328", "www.wwwsuperset.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwsuperset.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-14 00:01:17", "1324329", "wwwdev.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwdev.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-14 00:01:16", "1324325", "mail.back-dev.hook.app.br", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/51.38.65.96+mail.back-dev.hook.app.br", "AS16276,C2,censys,Hookbot,OVH", "0", "DonPasci" "2024-09-14 00:01:16", "1324326", "wwwkfrlllogin.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwkfrlllogin.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-14 00:01:15", "1324323", "wwwchart.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwchart.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-14 00:01:15", "1324324", "metis-launchpad.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+metis-launchpad.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-14 00:01:14", "1324321", "launchpads-metis.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+launchpads-metis.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-14 00:01:14", "1324322", "www.kfrlllogin.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.kfrlllogin.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 21:37:09", "1324300", "sixvd16pt.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 21:37:09", "1324301", "tventyvd20ht.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 21:37:09", "1324302", "eihtv18pn.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 21:37:09", "1324303", "tventyvd20sr.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 21:37:08", "1324296", "sevtvd17pt.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 21:37:08", "1324297", "forcj4pt.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 21:37:08", "1324298", "eihtvd18ht.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 21:37:08", "1324299", "eihtvd18sr.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 20:00:48", "1324290", "govpet.mysynology.net", "domain", "botnet_cc", "win.asyncrat", "None", "AsyncRAT", "", "100", "https://search.censys.io/hosts/45.89.247.87+govpet.mysynology.net", "AS394711,C2,censys,LIMENET,RAT", "0", "DonPasci" "2024-09-13 13:23:24", "1324256", "fiftv15pn.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:24", "1324257", "forv14pn.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:24", "1324258", "sixv16sb.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:23", "1324245", "fiftvd15ht.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:23", "1324246", "elevenvd11sr.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:23", "1324247", "fiftvd15sr.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:23", "1324248", "sevtv17pn.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:23", "1324249", "sevtvd17sr.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:23", "1324250", "sixv16pn.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:23", "1324251", "sixvd16sr.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:23", "1324252", "tenvd10sr.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:23", "1324253", "thirtv13pn.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:23", "1324254", "thirtvd13sr.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:23", "1324255", "twelvevd12sr.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:22", "1324241", "forvd14sr.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:22", "1324242", "sevtvd17ht.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:22", "1324243", "sixvd16ht.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 13:23:22", "1324244", "fiftvd15pt.top", "domain", "botnet_cc", "win.cryptbot", "None", "CryptBot", "", "100", "", "c2,domain", "0", "DonPasci" "2024-09-13 12:01:04", "1324238", "www.wwwwwwvdi.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwwwwvdi.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:01:04", "1324239", "www.wwwwwwbackend.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwwwwbackend.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:01:03", "1324236", "apps.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+apps.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:01:03", "1324237", "www.wwwvpnssl.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwvpnssl.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:01:02", "1324234", "reports.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+reports.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:01:02", "1324235", "login.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+login.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:01:01", "1324233", "www.virtualstudent.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.virtualstudent.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:01:00", "1324231", "chart.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+chart.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:01:00", "1324232", "www.intel.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.intel.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:00:59", "1324228", "wwwwwwvirtualapps.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwwwwvirtualapps.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:00:59", "1324229", "www.wwwintra.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwintra.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:00:59", "1324230", "webmail.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+webmail.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:00:58", "1324226", "dev.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+dev.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:00:58", "1324227", "wwwsitemap.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwsitemap.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:00:57", "1324224", "guild-zksync.io", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+guild-zksync.io", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:00:57", "1324225", "www.wwwgatewayrdweb.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwgatewayrdweb.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:00:56", "1324222", "www.wwwclientesvpn.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwclientesvpn.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:00:56", "1324223", "wwwssl.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwssl.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:00:55", "1324220", "wwwwwwvirtualstudent.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwwwwvirtualstudent.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 12:00:55", "1324221", "wwwwwwapps.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwwwwapps.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:02:16", "1324185", "danzimmer.space", "domain", "botnet_cc", "unknown", "None", "Unknown malware", "", "100", "https://search.censys.io/hosts/185.236.203.114+danzimmer.space", "AS9009,C2,censys,M247,panel,Unam", "0", "DonPasci" "2024-09-13 08:01:19", "1324179", "www.connect.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.connect.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:19", "1324180", "www.wwwwwwwww1.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwwwwwww1.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:18", "1324177", "visual.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+visual.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:18", "1324178", "www.clientesvpn.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.clientesvpn.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:17", "1324175", "studentsvpn.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+studentsvpn.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:17", "1324176", "www.wwwaccess.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwaccess.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:16", "1324173", "www.cnlenwwwofficevpn.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.cnlenwwwofficevpn.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:16", "1324174", "wwwsitemap.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwsitemap.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:15", "1324170", "wwwsecure.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwsecure.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:15", "1324171", "gatewaycitrix.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+gatewaycitrix.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:15", "1324172", "register-blendprotocol.io", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+register-blendprotocol.io", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:14", "1324168", "wwwxmofxwwwpublicsecure.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwxmofxwwwpublicsecure.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 08:01:14", "1324169", "www.mail.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.mail.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 05:22:40", "1324155", "kxmmcdmnb.online", "domain", "botnet_cc", "win.plugx", "Destroy RAT,Kaba,Korplug,Sogu,TIGERPLUG,RedDelta", "PlugX", "", "75", "", "darkpeony,operationcontrolplug", "0", "Rony" "2024-09-13 04:01:09", "1324150", "druginthepunto.shop", "domain", "botnet_cc", "unknown", "None", "Unknown malware", "", "100", "https://search.censys.io/hosts/185.196.11.251+druginthepunto.shop", "AS42624,C2,censys,panel,SWISSNETWORK02,Unam", "0", "DonPasci" "2024-09-13 04:00:49", "1324144", "www.skcvycevgwwwwsowgoowa.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.skcvycevgwwwwsowgoowa.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 04:00:49", "1324145", "sbqobsowgoowa.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+sbqobsowgoowa.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 04:00:48", "1324142", "www.2024.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.2024.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 04:00:48", "1324143", "wwwapp.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwapp.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 00:36:02", "1324135", "dddotx.shop", "domain", "botnet_cc", "win.lokipws", "Burkina,Loki,LokiBot,LokiPWS", "Loki Password Stealer (PWS)", "2024-09-14 04:36:02", "50", "https://tracker.viriback.com/index.php?q=dddotx.shop", "Lokibot,ViriBack", "0", "abuse_ch" "2024-09-13 00:00:56", "1323918", "research.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+research.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 00:00:56", "1323919", "wwwwwwwebmail.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwwwwwebmail.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 00:00:56", "1323920", "www.gryhazardowe.cloud", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.gryhazardowe.cloud", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 00:00:55", "1323916", "www.lohhnwwwssl.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.lohhnwwwssl.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 00:00:55", "1323917", "wwwsecure.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwsecure.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 00:00:54", "1323913", "www.analyze.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.analyze.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 00:00:54", "1323914", "www.login.ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.login.ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 00:00:54", "1323915", "gryhazardowe.vip", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+gryhazardowe.vip", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-13 00:00:53", "1323912", "ethergases.app", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+ethergases.app", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 18:49:54", "1323632", "touxzw.ir", "domain", "botnet_cc", "win.lokipws", "Burkina,Loki,LokiBot,LokiPWS", "Loki Password Stealer (PWS)", "2024-09-14 04:36:02", "75", "None", "infostealer,lokibot,stealer", "0", "SarlackLab" "2024-09-12 18:49:47", "1323654", "whhhelewmni.shop", "domain", "botnet_cc", "win.lumma", "LummaC2 Stealer", "Lumma Stealer", "", "50", "", "lumma", "0", "genesys" "2024-09-12 18:49:46", "1323655", "stryyridomwn.shop", "domain", "botnet_cc", "win.lumma", "LummaC2 Stealer", "Lumma Stealer", "", "50", "", "lumma", "0", "genesys" "2024-09-12 18:49:46", "1323656", "addicitedoqowm.shop", "domain", "botnet_cc", "win.lumma", "LummaC2 Stealer", "Lumma Stealer", "", "50", "", "lumma", "0", "genesys" "2024-09-12 18:49:44", "1323657", "polishuwqiwom.shop", "domain", "botnet_cc", "win.lumma", "LummaC2 Stealer", "Lumma Stealer", "", "50", "", "lumma", "0", "genesys" "2024-09-12 18:49:43", "1323658", "harassuwqom.shop", "domain", "botnet_cc", "win.lumma", "LummaC2 Stealer", "Lumma Stealer", "", "50", "", "lumma", "0", "genesys" "2024-09-12 18:49:42", "1323659", "damagedowqm.shop", "domain", "botnet_cc", "win.lumma", "LummaC2 Stealer", "Lumma Stealer", "", "50", "", "lumma", "0", "genesys" "2024-09-12 18:48:52", "1323811", "tatemosher.com", "domain", "payload_delivery", "js.fakeupdates", "FakeUpdate,SocGholish", "FAKEUPDATES", "", "100", "https://infosec.exchange/@monitorsg/113124629200754269", "SmartApeSG", "0", "monitorsg" "2024-09-12 08:01:35", "1323779", "pacmanspiele-online.de", "domain", "botnet_cc", "unknown", "None", "Unknown malware", "", "100", "https://search.censys.io/hosts/168.119.120.21+pacmanspiele-online.de", "AS24940,C2,censys,HETZNER-AS,panel,Unam", "0", "DonPasci" "2024-09-12 08:01:34", "1323778", "www.mmclub.info", "domain", "botnet_cc", "unknown", "None", "Unknown malware", "", "100", "https://search.censys.io/hosts/168.119.120.21+www.mmclub.info", "AS24940,C2,censys,HETZNER-AS,panel,Unam", "0", "DonPasci" "2024-09-12 08:01:22", "1323776", "ng1.portableonline.online", "domain", "botnet_cc", "win.meduza", "None", "Meduza Stealer", "", "100", "https://search.censys.io/hosts/104.21.89.101+ng1.portableonline.online", "AS13335,C2,censys,CLOUDFLARENET,Stealer", "0", "DonPasci" "2024-09-12 08:01:06", "1323769", "www.wp.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wp.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:06", "1323770", "wwwwwwsslvpn.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwwwwsslvpn.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:06", "1323771", "www.wwwwwwconnect.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwwwwconnect.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:05", "1323766", "analytic.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+analytic.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:05", "1323767", "www.wwwwwwwwwwebmail.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwwwwwwwwebmail.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:05", "1323768", "www.khwnlwwwowa.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.khwnlwwwowa.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:04", "1323763", "intel.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+intel.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:04", "1323764", "wwwwwwadmin.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwwwwadmin.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:04", "1323765", "www.wwwsitemap.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwsitemap.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:03", "1323761", "intelligence.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+intelligence.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:03", "1323762", "www.wwwmail.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwmail.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:02", "1323760", "mail.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+mail.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:01", "1323758", "wwwwwwrds.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwwwwrds.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:01", "1323759", "www.wwwwww2024.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwwww2024.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:00", "1323755", "www.forecast.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.forecast.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:00", "1323756", "www.reporting.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.reporting.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:01:00", "1323757", "stats.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+stats.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:59", "1323753", "hocdvsitemaps.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+hocdvsitemaps.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:59", "1323754", "www.wwwsslvpn.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwsslvpn.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:58", "1323751", "www.vpn.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.vpn.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:58", "1323752", "wwwcnlenwwwofficevpn.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwcnlenwwwofficevpn.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:57", "1323748", "www.wwwvdi.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwvdi.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:57", "1323749", "www.www1.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.www1.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:57", "1323750", "login.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+login.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:56", "1323745", "www.wwwwwwbackend.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwwwwbackend.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:56", "1323746", "metric.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+metric.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:56", "1323747", "www.analytic.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.analytic.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:55", "1323743", "connect.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+connect.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:54", "1323740", "publicsecure.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+publicsecure.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:54", "1323741", "www.wwwwwwwwwvirtualapps.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwwwwwwwvirtualapps.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:54", "1323742", "www.wwwtthvlgatewaycitrix.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwtthvlgatewaycitrix.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:53", "1323738", "www.cloud.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.cloud.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:53", "1323739", "www.stats.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.stats.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:52", "1323735", "www.analyze.ethergases.org", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.analyze.ethergases.org", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:52", "1323736", "ssl.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+ssl.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:52", "1323737", "wwwwwwonline.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+wwwwwwonline.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:51", "1323733", "www.anyconnect.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.anyconnect.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:51", "1323734", "www.wwwwwwvpnssl.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwwwwvpnssl.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:50", "1323731", "app.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+app.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" "2024-09-12 08:00:50", "1323732", "www.wwwwwwvirtualapps.pythr.net", "domain", "botnet_cc", "apk.hook", "None", "Hook", "", "100", "https://search.censys.io/hosts/185.149.120.187+www.wwwwwwvirtualapps.pythr.net", "AS57724,C2,censys,DDOS-GUARD,Hookbot", "0", "DonPasci" # Number of entries: 141