OTX-6a722dd4a132dc9e71bc11b2
high
📛 Threat Title
Infrastructure of Interest: High Confidence C2 - 2026-08
Description
IoI High Confidence C2 domains detected during 2026-08. Pulse contains 27 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (27)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
trainslive.uk
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/trainslive.uk
UrlVoid 2 / 35
1 feed
IOC database
- Type
- domain
- Value
trainslive.uk- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/trainslive.uk
domain
clovergroup.click
VT 3 / 91
UrlVoid 2 / 35
1 feed
IOC database
- Type
- domain
- Value
clovergroup.click- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Imported from threat-intel feed: threatview.io
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Flagged by 3 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| CRDF | malicious | malicious |
| alphaMountain.ai | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | NameSilo, LLC |
| TLD | click |
History
| Creation date | 2024-11-05 14:43 UTC |
| Last analysis | 2026-07-31 09:24 UTC |
| Last modified on VirusTotal | 2026-07-31 09:35 UTC |
| Last WHOIS update | 2026-06-08 21:43 UTC |
| WHOIS record date | 2026-07-31 09:30 UTC |
domain
okdelike.click
VT 1 / 91
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
okdelike.click- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| TLD | click |
History
| Creation date | 2025-10-11 00:00 UTC |
| Last analysis | 2026-07-27 06:00 UTC |
| Last modified on VirusTotal | 2026-08-03 16:01 UTC |
| Last WHOIS update | 2026-01-05 00:00 UTC |
| WHOIS record date | 2026-10-11 00:00 UTC |
domain
topazharbor.top
VT 18 / 91
UrlVoid 3 / 35
IOC database
- Type
- domain
- Value
topazharbor.top- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- Domain name that delivers a malware payload attributed to SmartApeSG
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 18 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AlphaSOC | malicious | malware |
| BitDefender | malicious | phishing |
| CRDF | malicious | malicious |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | phishing |
| LevelBlue | malicious | phishing |
| Lionic | malicious | malicious |
| Lumu | malicious | malware |
| MalwareURL | malicious | malware |
| Seclookup | malicious | malicious |
| SOCRadar | malicious | malicious |
| Sophos | malicious | phishing |
| Sucuri SiteCheck | malicious | malicious |
| VIPRE | malicious | malware |
| alphaMountain.ai | suspicious | suspicious |
| Certego | suspicious | suspicious |
| ESET | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | PDR Ltd |
| TLD | top |
History
| Creation date | 2026-07-09 08:30 UTC |
| Last analysis | 2026-07-31 11:33 UTC |
| Last modified on VirusTotal | 2026-07-31 11:43 UTC |
| Last WHOIS update | 2026-07-11 10:01 UTC |
| WHOIS record date | 2026-07-17 03:31 UTC |
domain
sbird.xyz
VT 1 / 91
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
sbird.xyz- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Forcepoint ThreatSeeker | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | Alibaba Cloud Computing Ltd. d/b/a HiChina (www.net.cn) |
| TLD | xyz |
History
| Creation date | 2015-12-18 07:00 UTC |
| Last analysis | 2026-06-29 15:39 UTC |
| Last modified on VirusTotal | 2026-08-04 18:27 UTC |
| Last WHOIS update | 2025-12-01 14:36 UTC |
| WHOIS record date | 2026-06-29 15:44 UTC |
domain
builderio.xyz
VT 2 / 91
IOC database
- Type
- domain
- Value
builderio.xyz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Forcepoint ThreatSeeker | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| TLD | xyz |
History
| Creation date | 2025-10-06 00:00 UTC |
| Last analysis | 2026-07-24 01:28 UTC |
| Last modified on VirusTotal | 2026-08-04 07:32 UTC |
| Last WHOIS update | 2025-10-06 00:00 UTC |
| WHOIS record date | 2026-10-06 00:00 UTC |
domain
kidfun.xyz
VT 16 / 91
UrlVoid 3 / 35
IOC database
- Type
- domain
- Value
kidfun.xyz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 16 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | phishing |
| BitDefender | malicious | phishing |
| Chong Lua Dao | malicious | malicious |
| CyRadar | malicious | phishing |
| Fortinet | malicious | phishing |
| G-Data | malicious | phishing |
| Gridinsoft | malicious | phishing |
| Kaspersky | malicious | phishing |
| Lionic | malicious | malicious |
| SafeToOpen | malicious | phishing |
| Sophos | malicious | phishing |
| VIPRE | malicious | phishing |
| Webroot | malicious | malicious |
| ESET | suspicious | suspicious |
| Forcepoint ThreatSeeker | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | NAMECHEAP INC |
| TLD | xyz |
History
| Creation date | 2024-08-31 16:47 UTC |
| Last analysis | 2026-08-03 10:33 UTC |
| Last modified on VirusTotal | 2026-08-04 21:53 UTC |
| Last WHOIS update | 2025-11-01 14:04 UTC |
| WHOIS record date | 2026-07-13 10:11 UTC |
domain
atukhyistak.xyz
VT 2 / 91
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
atukhyistak.xyz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | suspicious | suspicious |
| Forcepoint ThreatSeeker | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| TLD | xyz |
History
| Creation date | 2025-08-26 00:00 UTC |
| Last analysis | 2026-08-01 00:01 UTC |
| Last modified on VirusTotal | 2026-08-02 00:04 UTC |
| Last WHOIS update | 2025-08-26 00:00 UTC |
| WHOIS record date | 2026-08-26 00:00 UTC |
domain
thedailypost.xyz
VT 0 / 91
IOC database
- Type
- domain
- Value
thedailypost.xyz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Registrar | NAMECHEAP INC |
| TLD | xyz |
History
| Creation date | 2026-05-31 12:21 UTC |
| Last analysis | 2026-07-30 01:48 UTC |
| Last modified on VirusTotal | 2026-07-30 02:00 UTC |
| Last WHOIS update | 2026-07-01 08:12 UTC |
| WHOIS record date | 2026-07-29 20:56 UTC |
domain
streampsh.top
VT 6 / 91
UrlVoid 2 / 35
IOC database
- Type
- domain
- Value
streampsh.top- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 6 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | malicious | malicious |
| Chong Lua Dao | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malicious |
| Webroot | malicious | malicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | NAMECHEAP INC |
| TLD | top |
History
| Creation date | 2022-11-18 10:26 UTC |
| Last analysis | 2026-08-02 14:01 UTC |
| Last modified on VirusTotal | 2026-08-04 17:53 UTC |
| Last WHOIS update | 2025-10-23 11:32 UTC |
| WHOIS record date | 2026-07-24 17:26 UTC |
domain
aftrk.click
VT 0 / 91
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
aftrk.click- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Registrar | NAMECHEAP |
| TLD | click |
History
| Creation date | 2022-08-26 08:31 UTC |
| Last analysis | 2026-07-20 09:09 UTC |
| Last modified on VirusTotal | 2026-07-21 02:00 UTC |
| Last WHOIS update | 2025-08-01 05:45 UTC |
| WHOIS record date | 2026-07-20 09:13 UTC |
domain
32891098.xyz
VT 0 / 91
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
32891098.xyz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| TLD | xyz |
History
| Creation date | 2025-09-04 00:00 UTC |
| Last analysis | 2026-07-27 03:22 UTC |
| Last modified on VirusTotal | 2026-07-27 03:34 UTC |
| WHOIS record date | 2026-09-04 00:00 UTC |
domain
927ti.top
VT 2 / 91
IOC database
- Type
- domain
- Value
927ti.top- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | suspicious | spam |
| Fortinet | suspicious | spam |
Details From VirusTotal
Basic Properties
| Registrar | NameSilo,LLC |
| TLD | top |
History
| Creation date | 2026-03-23 13:21 UTC |
| Last analysis | 2026-06-21 08:59 UTC |
| Last modified on VirusTotal | 2026-07-19 09:02 UTC |
| Last WHOIS update | 2026-03-23 15:30 UTC |
| WHOIS record date | 2026-05-22 22:04 UTC |
domain
aquaaqua.top
VT 0 / 91
IOC database
- Type
- domain
- Value
aquaaqua.top- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| TLD | top |
History
| Creation date | 2024-10-21 00:00 UTC |
| Last analysis | 2026-08-04 16:18 UTC |
| Last modified on VirusTotal | 2026-08-04 16:29 UTC |
| Last WHOIS update | 2026-02-02 00:00 UTC |
| WHOIS record date | 2026-10-21 00:00 UTC |
domain
cdn-stream.top
VT 0 / 91
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
cdn-stream.top- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| TLD | top |
History
| Creation date | 2026-07-12 00:00 UTC |
| Last analysis | 2026-07-14 16:27 UTC |
| Last modified on VirusTotal | 2026-07-26 16:54 UTC |
| Last WHOIS update | 2026-07-12 00:00 UTC |
| WHOIS record date | 2027-07-12 00:00 UTC |
domain
dareplus.eu
VT 0 / 91
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
dareplus.eu- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| TLD | eu |
History
| Last analysis | 2025-09-18 21:35 UTC |
| Last modified on VirusTotal | 2025-10-16 21:40 UTC |
| WHOIS record date | 2025-08-13 21:03 UTC |
domain
dihimystore.top
VT 1 / 91
UrlVoid 1 / 35
IOC database
- Type
- domain
- Value
dihimystore.top- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | NameSilo,LLC |
| TLD | top |
History
| Creation date | 2026-07-25 19:00 UTC |
| Last analysis | 2026-08-04 21:48 UTC |
| Last modified on VirusTotal | 2026-08-04 22:01 UTC |
| Last WHOIS update | 2026-07-25 19:00 UTC |
| WHOIS record date | 2026-07-25 20:31 UTC |
domain
fdskjfcmcc.xyz
VT 12 / 91
IOC database
- Type
- domain
- Value
fdskjfcmcc.xyz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 12 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| BitDefender | malicious | phishing |
| CRDF | malicious | malicious |
| Fortinet | malicious | phishing |
| G-Data | malicious | phishing |
| Kaspersky | malicious | phishing |
| Lionic | malicious | phishing |
| SafeToOpen | malicious | phishing |
| Sophos | malicious | phishing |
| VIPRE | malicious | phishing |
| Webroot | malicious | malicious |
| alphaMountain.ai | suspicious | suspicious |
| ESET | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | NameCheap, Inc. |
| TLD | xyz |
History
| Creation date | 2026-07-22 08:28 UTC |
| Last analysis | 2026-08-04 15:40 UTC |
| Last modified on VirusTotal | 2026-08-04 15:46 UTC |
| Last WHOIS update | 2026-07-22 08:28 UTC |
| WHOIS record date | 2026-07-22 10:33 UTC |
domain
genuggut.buzz
VT 0 / 91
IOC database
- Type
- domain
- Value
genuggut.buzz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Registrar | Spaceship, Inc. |
| TLD | buzz |
History
| Creation date | 2026-07-27 12:10 UTC |
| Last analysis | 2026-08-04 22:42 UTC |
| Last modified on VirusTotal | 2026-08-04 22:58 UTC |
| Last WHOIS update | 2026-07-27 12:11 UTC |
| WHOIS record date | 2026-07-27 13:29 UTC |
domain
hotwheelsasdas.xyz
VT 10 / 91
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
hotwheelsasdas.xyz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 10 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| BitDefender | malicious | phishing |
| CRDF | malicious | malicious |
| CyRadar | malicious | phishing |
| Fortinet | malicious | phishing |
| G-Data | malicious | phishing |
| Kaspersky | malicious | phishing |
| SafeToOpen | malicious | phishing |
| Sophos | malicious | phishing |
| alphaMountain.ai | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | NAMECHEAP INC |
| TLD | xyz |
History
| Creation date | 2026-07-27 14:41 UTC |
| Last analysis | 2026-08-04 16:32 UTC |
| Last modified on VirusTotal | 2026-08-04 21:40 UTC |
| Last WHOIS update | 2026-07-27 14:41 UTC |
| WHOIS record date | 2026-07-27 16:29 UTC |
domain
j2m20.xyz
VT 1 / 91
UrlVoid 1 / 35
IOC database
- Type
- domain
- Value
j2m20.xyz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Forcepoint ThreatSeeker | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| TLD | xyz |
History
| Creation date | 2025-01-24 00:00 UTC |
| Last analysis | 2026-06-20 20:58 UTC |
| Last modified on VirusTotal | 2026-06-24 20:27 UTC |
| Last WHOIS update | 2026-01-25 00:00 UTC |
| WHOIS record date | 2027-01-24 00:00 UTC |
domain
quickvaultflow.click
VT 2 / 91
IOC database
- Type
- domain
- Value
quickvaultflow.click- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| CRDF | malicious | malicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | Spaceship, Inc. |
| TLD | click |
History
| Creation date | 2026-07-23 06:04 UTC |
| Last analysis | 2026-07-29 13:47 UTC |
| Last modified on VirusTotal | 2026-08-04 11:58 UTC |
| Last WHOIS update | 2026-07-23 06:07 UTC |
| WHOIS record date | 2026-07-23 07:08 UTC |
domain
swiftfilebridge.click
VT 0 / 91
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
swiftfilebridge.click- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Registrar | Spaceship, Inc. |
| TLD | click |
History
| Creation date | 2026-07-23 06:04 UTC |
| Last analysis | 2026-07-23 08:03 UTC |
| Last modified on VirusTotal | 2026-08-04 18:34 UTC |
| Last WHOIS update | 2026-07-23 06:07 UTC |
| WHOIS record date | 2026-07-23 07:08 UTC |
domain
x5ly4jmy.xyz
VT 2 / 91
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
x5ly4jmy.xyz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | suspicious | suspicious |
| Forcepoint ThreatSeeker | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| TLD | xyz |
History
| Creation date | 2025-08-21 00:00 UTC |
| Last analysis | 2026-07-18 09:58 UTC |
| Last modified on VirusTotal | 2026-08-04 16:59 UTC |
| Last WHOIS update | 2025-08-21 00:00 UTC |
| WHOIS record date | 2026-08-21 00:00 UTC |
domain
xw20z.top
VT 0 / 91
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
xw20z.top- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| TLD | top |
History
| Creation date | 2025-10-13 00:00 UTC |
| Last analysis | 2026-07-31 17:37 UTC |
| Last modified on VirusTotal | 2026-07-31 17:45 UTC |
| Last WHOIS update | 2025-10-13 00:00 UTC |
| WHOIS record date | 2026-10-13 00:00 UTC |
domain
yifacai.top
VT 4 / 91
IOC database
- Type
- domain
- Value
yifacai.top- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| CRDF | malicious | malicious |
| ESET | malicious | malware |
| Fortinet | malicious | malware |
| alphaMountain.ai | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | NameSilo, LLC |
| TLD | top |
History
| Creation date | 2026-07-01 04:02 UTC |
| Last analysis | 2026-07-25 14:04 UTC |
| Last modified on VirusTotal | 2026-07-25 15:53 UTC |
| Last WHOIS update | 2026-07-01 07:00 UTC |
| WHOIS record date | 2026-07-01 15:35 UTC |
domain
zznq.buzz
VT 0 / 91
UrlVoid 1 / 35
IOC database
- Type
- domain
- Value
zznq.buzz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| TLD | buzz |
History
| Creation date | 2022-03-29 00:00 UTC |
| Last analysis | 2026-07-29 01:51 UTC |
| Last modified on VirusTotal | 2026-07-29 02:10 UTC |
| Last WHOIS update | 2026-03-26 00:00 UTC |
| WHOIS record date | 2027-03-29 00:00 UTC |
References (1)
-
OTX pulse
AlienVaulkt OTX
IoI High Confidence C2 domains detected during 2026-08.
Remediations (9)
-
web:about.att.com
Communications Cybersecurity Information Sharing and Analysis Center, known as C2 ISAC, is dedicated to strengthening cybersecurity across the communications sector.
-
web:acsmi.org
Critical infrastructure cybersecurity report with 2026 -2027 threat assessment, OT risks, ransomware exposure, and defense priorities.
-
web:blog.netmanageit.com
The IOCs included in this pulse are associated with command and control ( C2 ) infrastructure , facilitating malware communication, data exfiltration, and persistent threat actor operations. Use this data to enhance detection rules, block malicious infrastructure , or correlate with existing incident investigations. OPENCTI LABELS :
-
web:blog.netmanageit.com
These indicators of compromise (IOCs) were identified through LevelBlue Labs' proprietary collection and threat hunting processes, leveraging AI-driven heuristics to detect anomalous patterns, behavioral analysis of malicious activity, and cross-referenced intelligence from endpoint telemetry and external sources. Use this data to enhance detection rules, block malicious infrastructure , or ...
-
web:informatix.systems
Discover how CTI monitors command and control servers using IOCs, AI detection, and threat intel frameworks. Learn advanced techniques for 2026 enterprise security from Informatix.Systems experts.
-
web:informatix.systems
Discover expert techniques for tracking malware infrastructure using Cyber Threat Intelligence (CTI). Learn OSINT methods, C2 detection, tools, and enterprise strategies to hunt malicious networks in 2026 .
-
web:www.microsoft.com
On March 31, 2026 , the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control ( C2 ) that Microsoft Threat Intelligence has attributed to the North Korean state actor Sapphire Sleet. Although the malicious versions are no longer available for download, since Axios is one of the most widely ...
-
web:www.securitricks.com
These indicators of compromise (IOCs) were identified through LevelBlue Labs' proprietary collection and threat hunting processes, leveraging AI-driven heuristics to detect anomalous patterns, behavioral analysis of malicious activity, and cross-referenced intelligence from endpoint telemetry and external sources. The IOCs included in this pulse are associated with infostealer malware ...
-
web:www.vulncheck.com
Command and control ( C2 or C&C) infrastructure is the technical foundation of these attacks. By understanding what C2 is and how C2 -based attacks work, security teams can improve their effectiveness and reduce an attack's impact.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.