################################################################ # ThreatFox IOCs: recent domains - CSV format # # Last updated: 2025-06-21 11:57:15 UTC # # # # Terms Of Use: https://threatfox.abuse.ch/faq/#tos # # For questions please contact threatfox [at] abuse.ch # ################################################################ # # "first_seen_utc","ioc_id","ioc_value","ioc_type","threat_type","fk_malware","malware_alias","malware_printable","last_seen_utc","confidence_level","reference","tags","anonymous","reporter" "2025-06-21 11:57:15", "1548240", "hamster-exchange.top", "domain", "botnet_cc", "win.asyncrat", "None", "AsyncRAT", "", "100", "https://tria.ge/250621-dzv5tswnx9", "AsyncRAT,c2,domain", "0", "DonPasci" "2025-06-21 11:53:35", "1548239", "return-aug.gl.at.ply.gg", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "100", "https://tria.ge/250621-eahc4sfk5w", "c2,domain,xworm", "0", "DonPasci" "2025-06-21 11:18:35", "1548227", "anyukov-43802.portmap.io", "domain", "botnet_cc", "win.quasar_rat", "CinaRAT,QuasarRAT,Yggdrasil", "Quasar RAT", "", "100", "https://tria.ge/250621-m59pvayqw2", "c2,domain,Quasar,RAT", "0", "DonPasci" "2025-06-21 08:55:38", "1548221", "webapi.360se.dpdns.org", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:56:16", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-21 04:01:19", "1548189", "ec2-54-250-175-201.ap-northeast-1.compute.amazonaws.com", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "", "100", "https://search.censys.io/hosts/54.250.175.201+ec2-54-250-175-201.ap-northeast-1.compute.amazonaws.com", "AMAZON-02,AS16509,C2,censys,CobaltStrike,open-dir", "0", "DonPasci" "2025-06-21 02:53:55", "1548153", "dd.tstcs888.com", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:46", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 22:54:37", "1548134", "office.soft-storelive.com", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:56:10", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 22:54:37", "1548133", "ns4.jk001.cc", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:56:10", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 22:54:36", "1548132", "ns3.jk001.cc", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:56:09", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 22:54:30", "1548131", "ns1.asianinvasion.net", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:56:00", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 22:54:30", "1548130", "ns1.asdxxcg.top", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:56:00", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 22:54:26", "1548129", "log.nongfushan.org", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:53", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 22:54:26", "1548128", "jk002.cc", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:52", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 22:54:16", "1548127", "apps.soft-storelive.com", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:39", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 20:52:12", "1548115", "www.ddddddddguashjdka.top", "domain", "botnet_cc", "win.valley_rat", "Winos", "ValleyRAT", "", "100", "https://tria.ge/250620-zfqlwsgr6t", "c2,domain,RAT,ValleyRAT", "0", "DonPasci" "2025-06-20 19:22:57", "1548081", "2tuff-33336.portmap.io", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "100", "https://tria.ge/250620-xczdhstvex", "c2,domain,xworm", "0", "DonPasci" "2025-06-20 16:14:13", "1548064", "junie15.duckdns.org", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "100", "https://www.virustotal.com/gui/ip-address/172.111.168.228", "c2,domain,virustotal,xworm", "0", "DonPasci" "2025-06-20 16:12:20", "1548063", "lespencer.duckdns.org", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "100", "https://tria.ge/250620-svfxnsdk4z", "c2,domain,xworm", "0", "DonPasci" "2025-06-20 16:08:38", "1548061", "district-graphical.gl.at.ply.gg", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "100", "https://tria.ge/250620-te6c3aek4s", "c2,domain,xworm", "0", "DonPasci" "2025-06-20 14:12:47", "1548044", "0.0.mastermaths.com.sg", "domain", "botnet_cc", "win.vidar", "None", "Vidar", "", "100", "", "Vidar", "0", "crep1x" "2025-06-20 13:23:20", "1548035", "app.symphoniabags.com", "domain", "botnet_cc", "js.fakeupdates", "FakeUpdate,SocGholish", "FAKEUPDATES", "2025-06-20 13:15:58", "100", "https://infosec.exchange/@monitorsg/114715857650303913", "SocGholish", "0", "monitorsg" "2025-06-20 13:09:10", "1548033", "down.gitlab.sbs", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "", "100", "https://x.com/500mk500/status/1936048194292687212", "CobaltStrike,cs-watermark-100000000", "0", "abuse_ch" "2025-06-20 13:09:10", "1548032", "api.r-cdn.icu", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "", "100", "https://x.com/500mk500/status/1936048194292687212", "CobaltStrike,cs-watermark-100000000", "0", "abuse_ch" "2025-06-20 13:09:10", "1548031", "api.googleapi.top", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "", "100", "https://x.com/500mk500/status/1936048194292687212", "CobaltStrike,cs-watermark-100000000", "0", "abuse_ch" "2025-06-20 13:09:10", "1548030", "r-cdn.icu", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "", "100", "https://x.com/500mk500/status/1936048194292687212", "CobaltStrike,cs-watermark-100000000", "0", "abuse_ch" "2025-06-20 13:09:10", "1548029", "gitlab.sbs", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "", "100", "https://x.com/500mk500/status/1936048194292687212", "CobaltStrike,cs-watermark-100000000", "0", "abuse_ch" "2025-06-20 12:56:29", "1548028", "d.tstcs888.com", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:46", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 12:25:32", "1548024", "api.micosoftr.icu", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-20 13:09:10", "100", "https://bazaar.abuse.ch/sample/91e851f8cd9a32f9077f9fbbf1a64278e6be460ed5908778e4b45e62e495167e/", "CobaltStrike,cs-watermark-100000000", "0", "abuse_ch" "2025-06-20 12:25:32", "1548023", "www.googleapi.top", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-20 13:09:10", "100", "https://bazaar.abuse.ch/sample/91e851f8cd9a32f9077f9fbbf1a64278e6be460ed5908778e4b45e62e495167e/", "CobaltStrike,cs-watermark-100000000", "0", "abuse_ch" "2025-06-20 08:55:30", "1547987", "cf.testcs888.com", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:43", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 08:55:29", "1547986", "cf.1v5sd1c2ds.com", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:43", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 08:55:18", "1547985", "8vz75cfcfmey5.cfc-execute.bj.baidubce.com", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:37", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 07:20:57", "1547950", "reason-tribal.gl.at.ply.gg", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "50", "", "c2,xworm", "0", "juroots" "2025-06-20 07:20:57", "1547951", "we-referring.gl.at.ply.gg", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "50", "", "c2,xworm", "0", "juroots" "2025-06-20 07:20:10", "1547948", "yn.eoow.cn", "domain", "botnet_cc", "elf.mirai", "Katana", "Mirai", "", "50", "", "c2,mirai", "0", "juroots" "2025-06-20 07:19:16", "1547946", "us.worldisendmail.ml", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "", "50", "", "c2,cobaltstrike", "0", "juroots" "2025-06-20 07:18:18", "1547943", "tax-warrior.gl.at.ply.gg", "domain", "botnet_cc", "win.asyncrat", "None", "AsyncRAT", "", "50", "", "asyncrat,c2", "0", "juroots" "2025-06-20 06:12:47", "1547834", "foepsa.com", "domain", "payload_delivery", "unknown", "None", "Unknown malware", "", "100", "", "ClickFix,CoreSecThree", "0", "HuntYethHounds" "2025-06-20 06:12:47", "1547833", "security.fweragyrads.com", "domain", "payload_delivery", "unknown", "None", "Unknown malware", "", "100", "", "ClickFix,CoreSecThree", "0", "HuntYethHounds" "2025-06-20 06:12:47", "1547831", "analytticasnoden.com", "domain", "payload_delivery", "unknown", "None", "Unknown malware", "", "100", "", "ClickFix,CoreSecThree", "0", "HuntYethHounds" "2025-06-20 04:00:40", "1547896", "update.applefilesync.com", "domain", "botnet_cc", "unknown", "None", "Unknown malware", "", "100", "https://search.censys.io/hosts/135.222.128.238+update.applefilesync.com", "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Mythic", "0", "dyingbreeds_" "2025-06-20 04:00:40", "1547897", "mathiasputzola.com", "domain", "botnet_cc", "unknown", "None", "Unknown malware", "", "100", "https://search.censys.io/hosts/212.83.148.39+mathiasputzola.com", "AS12876,C2,censys,Mythic", "0", "dyingbreeds_" "2025-06-20 02:53:00", "1547884", "c2.moustartline.com", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:41", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 02:53:00", "1547883", "c.testcs888.com", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:41", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-20 00:03:19", "1547876", "v361422.hosted-by-vdsina.com", "domain", "botnet_cc", "unknown_stealer", "None", "Unknown Stealer", "", "100", "https://search.censys.io/hosts/91.84.109.91+v361422.hosted-by-vdsina.com", "Amatera,AS216071,C2,censys,Panel,Stealer,VDSINA", "0", "DonPasci" "2025-06-19 22:54:27", "1547850", "www.uyghur.eu.org", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:56:18", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-19 22:53:57", "1547849", "8xney90cqcr5m.cfc-execute.su.baidubce.com", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:37", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-19 21:26:56", "1547837", "sleach.zapto.org", "domain", "botnet_cc", "win.quasar_rat", "CinaRAT,QuasarRAT,Yggdrasil", "Quasar RAT", "", "100", "https://tria.ge/250619-ylwjnabl61", "c2,domain,Quasar,RAT", "0", "DonPasci" "2025-06-19 21:24:41", "1547836", "nyzzrat-64271.portmap.io", "domain", "botnet_cc", "win.quasar_rat", "CinaRAT,QuasarRAT,Yggdrasil", "Quasar RAT", "", "100", "https://tria.ge/250619-yn8l1abm3w", "c2,domain,Quasar,RAT", "0", "DonPasci" "2025-06-19 21:13:17", "1547830", "catherinekey1965-40831.portmap.io", "domain", "botnet_cc", "win.quasar_rat", "CinaRAT,QuasarRAT,Yggdrasil", "Quasar RAT", "", "100", "https://tria.ge/250619-y8ngkazmy3", "c2,domain,Quasar,RAT", "0", "DonPasci" "2025-06-19 21:11:23", "1547829", "finix.newsnewth365.com", "domain", "botnet_cc", "win.poshc2", "None", "PoshC2", "", "100", "https://tria.ge/250619-zawkysbr3v/behavioral1", "c2,domain,Posh", "0", "DonPasci" "2025-06-19 21:08:38", "1547828", "mygokerman.casacam.net", "domain", "botnet_cc", "win.njrat", "Bladabindi,Lime-Worm", "NjRAT", "", "100", "https://tria.ge/250619-zlkylafk2t", "c2,domain,NjRAT", "0", "DonPasci" "2025-06-19 21:07:12", "1547821", "wedbest02.ddns.net", "domain", "botnet_cc", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "", "100", "https://tria.ge/250619-zpynvsx1b1", "c2,domain,RAT,remcos", "0", "DonPasci" "2025-06-19 21:07:12", "1547822", "wedbest001.duckdns.org", "domain", "botnet_cc", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "", "100", "https://tria.ge/250619-zpynvsx1b1", "c2,domain,RAT,remcos", "0", "DonPasci" "2025-06-19 21:07:12", "1547823", "wedbest002.duckdns.org", "domain", "botnet_cc", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "", "100", "https://tria.ge/250619-zpynvsx1b1", "c2,domain,RAT,remcos", "0", "DonPasci" "2025-06-19 21:07:12", "1547824", "wedbest004.kozow.com", "domain", "botnet_cc", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "", "100", "https://tria.ge/250619-zpynvsx1b1", "c2,domain,RAT,remcos", "0", "DonPasci" "2025-06-19 21:07:12", "1547826", "wedbest012.duckdns.org", "domain", "botnet_cc", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "", "100", "https://tria.ge/250619-zpynvsx1b1", "c2,domain,RAT,remcos", "0", "DonPasci" "2025-06-19 21:07:12", "1547827", "wedbest021.zapto.org", "domain", "botnet_cc", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "", "100", "https://tria.ge/250619-zpynvsx1b1", "c2,domain,RAT,remcos", "0", "DonPasci" "2025-06-19 21:07:12", "1547825", "wedbest004.camdvr.org", "domain", "botnet_cc", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "", "100", "https://tria.ge/250619-zpynvsx1b1", "c2,domain,RAT,remcos", "0", "DonPasci" "2025-06-19 21:01:03", "1547819", "amaprox.icu", "domain", "botnet_cc", "unknown_stealer", "None", "Unknown Stealer", "", "100", "https://search.censys.io/hosts/194.48.248.57+amaprox.icu", "ALEXHOST,Amatera,AS200019,C2,censys,Panel,Stealer", "0", "DonPasci" "2025-06-19 19:40:13", "1547790", "nmsl.onen.site", "domain", "botnet_cc", "elf.moobot", "None", "MooBot", "2025-06-19 19:40:13", "100", "https://bazaar.abuse.ch/sample/b0b3f18e27da4b15829af6b95e3273b1f109b2543114c20fec97e631cab8c580/", "MooBot", "0", "abuse_ch" "2025-06-19 19:34:31", "1547777", "aave-crypto.com", "domain", "botnet_cc", "unknown", "None", "Unknown malware", "", "100", "None", "c2,LummaStealer", "0", "PUNISHERD" "2025-06-19 19:34:30", "1547770", "baseswap-new.typedream.app", "domain", "botnet_cc", "unknown", "None", "Unknown malware", "", "100", "None", "c2,LummaStealer", "0", "PUNISHERD" "2025-06-19 19:34:29", "1547738", "swedrent.com", "domain", "payload_delivery", "js.kongtuke", "TAG-124,js.LandUpdate808", "KongTuke", "", "100", "", "Kongtuke", "0", "rmceoin" "2025-06-19 19:34:17", "1547786", "b1.gawkheading.lat", "domain", "botnet_cc", "win.acr_stealer", "None", "ACR Stealer", "", "100", "https://bazaar.abuse.ch/sample/b26a5ee987461beab66a64d82ef48d37ad75e9108938d71f553003199cc12c28/", "ACRStealer", "0", "aachum" "2025-06-19 18:21:30", "1547788", "talktuahthehand-42154.portmap.io", "domain", "botnet_cc", "win.quasar_rat", "CinaRAT,QuasarRAT,Yggdrasil", "Quasar RAT", "", "100", "https://tria.ge/250619-wjh5fawyaz", "c2,domain,Quasar,RAT", "0", "DonPasci" "2025-06-19 18:14:22", "1547787", "behind-welcome.gl.at.ply.gg", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "100", "https://tria.ge/250619-ctvrfazly9", "c2,domain,xworm", "0", "DonPasci" "2025-06-19 17:51:39", "1547785", "source-determination.gl.at.ply.gg", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "100", "https://tria.ge/250618-zjk6ksxlz7", "c2,domain,xworm", "0", "DonPasci" "2025-06-19 17:50:51", "1547784", "calendar-background.gl.at.ply.gg", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "100", "https://tria.ge/250619-g2sn9szvbw", "c2,domain,xworm", "0", "DonPasci" "2025-06-19 17:49:02", "1547783", "fat-changes.gl.at.ply.gg", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "100", "https://tria.ge/250619-nzl72afp9s", "c2,domain,xworm", "0", "DonPasci" "2025-06-19 17:48:25", "1547782", "other-mins.gl.at.ply.gg", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "100", "https://tria.ge/250619-p2a38aszht", "c2,domain,xworm", "0", "DonPasci" "2025-06-19 17:45:49", "1547767", "kalitest.ddns.net", "domain", "botnet_cc", "win.xworm", "None", "XWorm", "", "100", "https://tria.ge/250619-sf1crsel9s", "c2,domain,xworm", "0", "DonPasci" "2025-06-19 16:56:10", "1547759", "doc.sougou365.online", "domain", "botnet_cc", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "2025-06-21 11:55:48", "75", "None", "CobaltStrike,drb-ra", "0", "abuse_ch" "2025-06-19 16:03:30", "1547756", "www.domainup6l9.xyz", "domain", "botnet_cc", "unknown", "None", "Unknown malware", "2025-06-20 04:01:13", "100", "https://search.censys.io/hosts/203.161.45.11+www.domainup6l9.xyz", "AS22612,C2,censys,NAMECHEAP-NET,panel,Unam", "0", "DonPasci" "2025-06-19 13:52:49", "1547733", "sleach.dns.army", "domain", "botnet_cc", "win.njrat", "Bladabindi,Lime-Worm", "NjRAT", "", "50", "", "c2,njrat", "0", "juroots" "2025-06-19 13:19:12", "1547718", "www.stirngo.com", "domain", "botnet_cc", "js.fakeupdates", "FakeUpdate,SocGholish", "FAKEUPDATES", "2025-06-19 13:15:38", "100", "https://infosec.exchange/@monitorsg/114710198570959381", "SocGholish", "0", "monitorsg" "2025-06-19 13:03:18", "1547717", "lumma-market.ru", "domain", "botnet_cc", "win.lumma", "LummaC2 Stealer", "Lumma Stealer", "", "50", "", "c2,lumma", "0", "juroots" "2025-06-19 13:03:17", "1547716", "reexmv.top", "domain", "botnet_cc", "win.lumma", "LummaC2 Stealer", "Lumma Stealer", "2025-06-19 13:03:18", "50", "", "c2,lumma", "0", "juroots" # Number of entries: 78