OTX-64806ecb91cd4a55f0f1bf9b
high
📛 Threat Title
Havoc - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to Havoc Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 6 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (43)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
84.247.133.139
IOC database
- Type
- ipv4
- Value
84.247.133.139- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
15.235.204.51
VT 2 / 91
IOC database
- Type
- ipv4
- Value
15.235.204.51- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Cluster25 | malicious | malicious |
| Hunt.io Intelligence | malicious | malicious |
Details From VirusTotal
Basic Properties
| Network | 15.235.0.0/16 |
| Country | SG |
| AS owner | OVH SAS |
| ASN | 16276 |
| Regional registry | APNIC |
History
| Last analysis | 2026-07-29 06:00 UTC |
| Last modified on VirusTotal | 2026-08-02 06:30 UTC |
| WHOIS record date | 2026-07-27 17:06 UTC |
ipv4
101.33.76.127
IOC database
- Type
- ipv4
- Value
101.33.76.127- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
173.249.41.141
IOC database
- Type
- ipv4
- Value
173.249.41.141- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
104.251.181.73
IOC database
- Type
- ipv4
- Value
104.251.181.73- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
194.163.154.86
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/194.163.154.86
IOC database
- Type
- ipv4
- Value
194.163.154.86- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/194.163.154.86
ipv4
143.198.120.167
VT 8 / 91
IOC database
- Type
- ipv4
- Value
143.198.120.167- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 8 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | malicious | malicious |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| Fortinet | malicious | malware |
| Lionic | malicious | malicious |
| MalwareURL | malicious | malware |
| SOCRadar | malicious | malicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 143.198.0.0/17 |
| Country | US |
| AS owner | DigitalOcean, LLC |
| ASN | 14061 |
| Regional registry | ARIN |
History
| Last analysis | 2026-07-07 06:21 UTC |
| Last modified on VirusTotal | 2026-07-11 08:52 UTC |
| WHOIS record date | 2026-07-06 06:30 UTC |
ipv4
2.56.212.64
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/2.56.212.64
IOC database
- Type
- ipv4
- Value
2.56.212.64- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/2.56.212.64
ipv4
107.172.22.3
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/107.172.22.3
IOC database
- Type
- ipv4
- Value
107.172.22.3- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/107.172.22.3
ipv4
149.28.138.70
IOC database
- Type
- ipv4
- Value
149.28.138.70- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
146.190.80.105
VT 10 / 91
IOC database
- Type
- ipv4
- Value
146.190.80.105- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 10 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malicious |
| Fortinet | malicious | malware |
| Lionic | malicious | malicious |
| MalwareURL | malicious | malware |
| SOCRadar | malicious | malicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 146.190.0.0/17 |
| Country | SG |
| AS owner | DigitalOcean, LLC |
| ASN | 14061 |
| Regional registry | APNIC |
History
| Last analysis | 2026-07-05 20:42 UTC |
| Last modified on VirusTotal | 2026-07-11 08:48 UTC |
| WHOIS record date | 2026-06-24 11:39 UTC |
ipv4
139.180.190.68
IOC database
- Type
- ipv4
- Value
139.180.190.68- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
185.115.161.32
VT 10 / 91
IOC database
- Type
- ipv4
- Value
185.115.161.32- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 10 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malicious |
| Fortinet | malicious | malware |
| Hunt.io Intelligence | malicious | malicious |
| MalwareURL | malicious | malware |
| SOCRadar | malicious | malicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 185.115.161.0/24 |
| Country | US |
| AS owner | LuraHosting Datacenter LTDA |
| ASN | 198585 |
| Regional registry | ARIN |
History
| Last analysis | 2026-07-05 11:42 UTC |
| Last modified on VirusTotal | 2026-07-15 07:08 UTC |
| WHOIS record date | 2026-07-05 11:49 UTC |
ipv4
8.222.192.153
IOC database
- Type
- ipv4
- Value
8.222.192.153- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
186.246.17.208
IOC database
- Type
- ipv4
- Value
186.246.17.208- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
164.90.206.5
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/164.90.206.5
IOC database
- Type
- ipv4
- Value
164.90.206.5- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/164.90.206.5
ipv4
139.59.106.160
VT 7 / 91
IOC database
- Type
- ipv4
- Value
139.59.106.160- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 7 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| Fortinet | malicious | malware |
| Lionic | malicious | malicious |
| SOCRadar | malicious | malicious |
Details From VirusTotal
Basic Properties
| Network | 139.59.0.0/16 |
| Country | SG |
| AS owner | DigitalOcean, LLC |
| ASN | 14061 |
| Regional registry | APNIC |
History
| Last analysis | 2026-07-07 20:46 UTC |
| Last modified on VirusTotal | 2026-07-11 08:55 UTC |
| WHOIS record date | 2026-06-11 18:17 UTC |
ipv4
158.247.194.144
IOC database
- Type
- ipv4
- Value
158.247.194.144- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
82.156.224.184
IOC database
- Type
- ipv4
- Value
82.156.224.184- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
45.150.34.117
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/45.150.34.117
IOC database
- Type
- ipv4
- Value
45.150.34.117- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/45.150.34.117
ipv4
207.154.243.85
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/207.154.243.85
IOC database
- Type
- ipv4
- Value
207.154.243.85- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/207.154.243.85
ipv4
137.184.102.191
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/137.184.102.191
IOC database
- Type
- ipv4
- Value
137.184.102.191- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/137.184.102.191
ipv4
216.250.96.155
VT 7 / 91
IOC database
- Type
- ipv4
- Value
216.250.96.155- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 7 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| CRDF | malicious | malicious |
| Fortinet | malicious | malware |
| Gridinsoft | suspicious | suspicious |
| SOCRadar | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 216.250.96.0/23 |
| Country | HK |
| AS owner | HostHatch, LLC |
| ASN | 63473 |
| Regional registry | APNIC |
History
| Last analysis | 2026-07-07 20:51 UTC |
| Last modified on VirusTotal | 2026-07-08 00:54 UTC |
| WHOIS record date | 2026-07-07 23:42 UTC |
ipv4
43.106.14.139
IOC database
- Type
- ipv4
- Value
43.106.14.139- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
62.171.190.148
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/62.171.190.148
IOC database
- Type
- ipv4
- Value
62.171.190.148- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/62.171.190.148
ipv4
202.181.24.236
IOC database
- Type
- ipv4
- Value
202.181.24.236- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
2.26.96.209
VT 16 / 91
IOC database
- Type
- ipv4
- Value
2.26.96.209- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 16 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | malware |
| Chong Lua Dao | malicious | malicious |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malware |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| Lionic | malicious | malware |
| MalwareURL | malicious | malware |
| SOCRadar | malicious | malicious |
| VIPRE | malicious | malware |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 2.26.96.0/21 |
| Country | NL |
| AS owner | Play2go International Limited |
| ASN | 215439 |
| Regional registry | RIPE NCC |
History
| Last analysis | 2026-07-06 11:59 UTC |
| Last modified on VirusTotal | 2026-07-11 08:53 UTC |
| WHOIS record date | 2026-06-18 10:39 UTC |
ipv4
172.245.152.57
IOC database
- Type
- ipv4
- Value
172.245.152.57- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
186.212.30.231
IOC database
- Type
- ipv4
- Value
186.212.30.231- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
5.75.185.142
IOC database
- Type
- ipv4
- Value
5.75.185.142- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
178.105.40.204
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/178.105.40.204
IOC database
- Type
- ipv4
- Value
178.105.40.204- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/178.105.40.204
ipv4
88.99.184.97
IOC database
- Type
- ipv4
- Value
88.99.184.97- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
66.85.27.18
IOC database
- Type
- ipv4
- Value
66.85.27.18- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
202.171.43.176
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/202.171.43.176
IOC database
- Type
- ipv4
- Value
202.171.43.176- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/202.171.43.176
ipv4
142.93.88.220
IOC database
- Type
- ipv4
- Value
142.93.88.220- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
155.138.246.5
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/155.138.246.5
IOC database
- Type
- ipv4
- Value
155.138.246.5- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/155.138.246.5
ipv4
178.128.125.237
IOC database
- Type
- ipv4
- Value
178.128.125.237- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
195.177.94.157
VT 14 / 91
IOC database
- Type
- ipv4
- Value
195.177.94.157- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 14 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| BitDefender | malicious | phishing |
| Chong Lua Dao | malicious | malicious |
| CRDF | malicious | malicious |
| Criminal IP | malicious | malicious |
| CyRadar | malicious | malicious |
| ESET | malicious | malware |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | phishing |
| Kaspersky | malicious | malware |
| Lionic | malicious | malicious |
| SOCRadar | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 195.177.94.0/24 |
| Country | FR |
| AS owner | Stellar Group SAS |
| ASN | 214961 |
| Regional registry | RIPE NCC |
History
| Last analysis | 2026-06-16 21:02 UTC |
| Last modified on VirusTotal | 2026-07-08 16:13 UTC |
| WHOIS record date | 2026-06-16 21:23 UTC |
ipv4
89.147.108.161
IOC database
- Type
- ipv4
- Value
89.147.108.161- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
192.227.232.124
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/192.227.232.124
IOC database
- Type
- ipv4
- Value
192.227.232.124- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/192.227.232.124
ipv4
85.120.252.124
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/85.120.252.124
IOC database
- Type
- ipv4
- Value
85.120.252.124- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Havoc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/85.120.252.124
ipv4
107.175.189.195
VT 17 / 91
IOC database
- Type
- ipv4
- Value
107.175.189.195- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 17 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | malware |
| Chong Lua Dao | malicious | malicious |
| CyRadar | malicious | malware |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| Hunt.io Intelligence | malicious | malicious |
| Kaspersky | malicious | malware |
| Lionic | malicious | malicious |
| MalwareURL | malicious | malware |
| SOCRadar | malicious | phishing |
| Sophos | malicious | malware |
| VIPRE | malicious | malware |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 107.175.184.0/21 |
| Country | US |
| AS owner | HostPapa |
| ASN | 36352 |
| Regional registry | ARIN |
History
| Last analysis | 2026-08-01 07:06 UTC |
| Last modified on VirusTotal | 2026-08-07 07:00 UTC |
| WHOIS record date | 2026-07-16 11:29 UTC |
ipv4
43.106.4.215
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/43.106.4.215
IOC database
- Type
- ipv4
- Value
43.106.4.215- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/43.106.4.215
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to Havoc Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:attack.mitre.org
Havoc is an open-source post-exploitation command and control ( C2 ) framework first released on GitHub in October 2022 by C5pider (Paul Ungur), who continues to maintain and develop it with community contributors. Havoc provides a wide range of offensive security capabilities and has been adopted by multiple threat actors to establish and maintain control over compromised systems.
-
web:dailysecurityreview.com
A new ClickFix attack is exploiting Microsoft SharePoint to deploy the Havoc framework, tricking users into running malicious PowerShell commands.
-
web:github.com
The Havoc Framework. Contribute to HavocFramework/ Havoc development by creating an account on GitHub.
-
web:thehackernews.com
Fake IT support calls delivered Havoc C2 , enabling credential theft, lateral movement, and ransomware prep across five organizations.
-
web:www.derp.ca
First released in October 2022, the Havoc C2 Framework is a flexible post-exploitation framework written in Golang, C++, and Qt, with agents called 'Demons' written in C and ASM, created by @C5pider. Designed to support red team engagements and adversary emulation, it offers a robust set of capabilities tailored for offensive security operations.
-
web:www.microsoft.com
Customers can also refer to our Tech community blog post for guidance on validating functionality and more information on C2 detection and remediation . In addition to enabling network protection C2 blocking, it's recommended to follow the general best practices to defend your network against human-operated ransomware attacks.
-
web:www.stepsecurity.io
We have responsibly disclosed the issue to the project maintainers. StepSecurity Harden-Runner, whose community tier is free for public repos and is used by over 12,000 public repositories, detected the compromised axios package making anomalous outbound connections to the attacker's C2 domain across multiple open source projects.
-
web:www.zscaler.com
The Havoc C2 framework campaign highlights the importance of proper cybersecurity measures in today's digital world. The use of payloads and CnC servers to execute malicious commands and gather sensitive information showcases the ever-present threat of cyber attacks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.