OTX-686e30a5be3d8a2ff6c9bac0
high
📛 Threat Title
Supershell - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to Supershell Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 13 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (88)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
110.40.147.249
IOC database
- Type
- ipv4
- Value
110.40.147.249- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Cobalt Strike
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
107.175.227.55
IOC database
- Type
- ipv4
- Value
107.175.227.55- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
146.71.85.53
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/146.71.85.53
IOC database
- Type
- ipv4
- Value
146.71.85.53- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/146.71.85.53
ipv4
156.227.232.98
IOC database
- Type
- ipv4
- Value
156.227.232.98- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
43.240.12.128
IOC database
- Type
- ipv4
- Value
43.240.12.128- First seen
- Last seen
- Attached to this threat
- Appears in
- 5 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
24.144.93.255
IOC database
- Type
- ipv4
- Value
24.144.93.255- First seen
- Last seen
- Attached to this threat
- Appears in
- 6 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
83.147.15.95
IOC database
- Type
- ipv4
- Value
83.147.15.95- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
66.92.249.136
IOC database
- Type
- ipv4
- Value
66.92.249.136- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
165.245.188.69
IOC database
- Type
- ipv4
- Value
165.245.188.69- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
206.238.68.123
IOC database
- Type
- ipv4
- Value
206.238.68.123- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
43.133.253.4
IOC database
- Type
- ipv4
- Value
43.133.253.4- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
143.110.142.104
IOC database
- Type
- ipv4
- Value
143.110.142.104- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
117.72.72.254
IOC database
- Type
- ipv4
- Value
117.72.72.254- First seen
- Last seen
- Attached to this threat
- Appears in
- 24 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
43.173.114.89
IOC database
- Type
- ipv4
- Value
43.173.114.89- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
47.254.73.23
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/47.254.73.23
IOC database
- Type
- ipv4
- Value
47.254.73.23- First seen
- Last seen
- Attached to this threat
- Appears in
- 6 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/47.254.73.23
ipv4
45.197.12.73
IOC database
- Type
- ipv4
- Value
45.197.12.73- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.122.106
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.122.106
IOC database
- Type
- ipv4
- Value
154.220.122.106- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.122.106
ipv4
154.220.123.166
IOC database
- Type
- ipv4
- Value
154.220.123.166- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.95.100
IOC database
- Type
- ipv4
- Value
154.220.95.100- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
8.138.180.67
IOC database
- Type
- ipv4
- Value
8.138.180.67- First seen
- Last seen
- Attached to this threat
- Appears in
- 5 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.94.43
IOC database
- Type
- ipv4
- Value
154.220.94.43- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.122.119
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.122.119
IOC database
- Type
- ipv4
- Value
154.220.122.119- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.122.119
ipv4
154.220.94.50
IOC database
- Type
- ipv4
- Value
154.220.94.50- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.95.122
IOC database
- Type
- ipv4
- Value
154.220.95.122- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.120.247
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.120.247
IOC database
- Type
- ipv4
- Value
154.220.120.247- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.120.247
ipv4
154.220.123.171
IOC database
- Type
- ipv4
- Value
154.220.123.171- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.92.185
IOC database
- Type
- ipv4
- Value
154.220.92.185- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.92.171
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.92.171
IOC database
- Type
- ipv4
- Value
154.220.92.171- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.92.171
ipv4
154.220.94.46
IOC database
- Type
- ipv4
- Value
154.220.94.46- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.120.253
IOC database
- Type
- ipv4
- Value
154.220.120.253- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.92.184
IOC database
- Type
- ipv4
- Value
154.220.92.184- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.95.114
IOC database
- Type
- ipv4
- Value
154.220.95.114- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.94.55
IOC database
- Type
- ipv4
- Value
154.220.94.55- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.121.61
IOC database
- Type
- ipv4
- Value
154.220.121.61- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.122.115
IOC database
- Type
- ipv4
- Value
154.220.122.115- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.122.122
IOC database
- Type
- ipv4
- Value
154.220.122.122- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.95.112
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.95.112
IOC database
- Type
- ipv4
- Value
154.220.95.112- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.95.112
ipv4
154.220.92.163
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.92.163
IOC database
- Type
- ipv4
- Value
154.220.92.163- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.92.163
ipv4
154.220.121.45
IOC database
- Type
- ipv4
- Value
154.220.121.45- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.94.41
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.94.41
IOC database
- Type
- ipv4
- Value
154.220.94.41- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.94.41
ipv4
154.220.94.45
IOC database
- Type
- ipv4
- Value
154.220.94.45- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.122.117
IOC database
- Type
- ipv4
- Value
154.220.122.117- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.123.180
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.123.180
IOC database
- Type
- ipv4
- Value
154.220.123.180- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.123.180
ipv4
154.220.123.168
IOC database
- Type
- ipv4
- Value
154.220.123.168- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.92.166
IOC database
- Type
- ipv4
- Value
154.220.92.166- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.123.188
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.123.188
IOC database
- Type
- ipv4
- Value
154.220.123.188- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.123.188
ipv4
154.220.122.114
IOC database
- Type
- ipv4
- Value
154.220.122.114- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.92.165
IOC database
- Type
- ipv4
- Value
154.220.92.165- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.94.48
IOC database
- Type
- ipv4
- Value
154.220.94.48- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.122.109
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.122.109
IOC database
- Type
- ipv4
- Value
154.220.122.109- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/154.220.122.109
ipv4
154.220.120.241
IOC database
- Type
- ipv4
- Value
154.220.120.241- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.220.123.186
IOC database
- Type
- ipv4
- Value
154.220.123.186- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
115.190.127.112
IOC database
- Type
- ipv4
- Value
115.190.127.112- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.201.72.194
IOC database
- Type
- ipv4
- Value
154.201.72.194- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
124.223.53.112
VT 19 / 91
IOC database
- Type
- ipv4
- Value
124.223.53.112- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 19 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| Criminal IP | malicious | malicious |
| CyRadar | malicious | malicious |
| Dr.Web | malicious | malicious |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| Lionic | malicious | malicious |
| MalwareURL | malicious | malware |
| Netcraft | malicious | malicious |
| SOCRadar | malicious | malicious |
| Sophos | malicious | malware |
| VIPRE | malicious | malware |
| ViriBack | malicious | malware |
| Gridinsoft | suspicious | suspicious |
| URLQuery | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 124.220.0.0/14 |
| Country | CN |
| AS owner | Shenzhen Tencent Computer Systems Company Limited |
| ASN | 45090 |
| Regional registry | APNIC |
History
| Last analysis | 2026-08-07 09:50 UTC |
| Last modified on VirusTotal | 2026-08-07 10:02 UTC |
| WHOIS record date | 2026-07-23 16:56 UTC |
ipv4
154.40.58.52
IOC database
- Type
- ipv4
- Value
154.40.58.52- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
154.219.120.101
IOC database
- Type
- ipv4
- Value
154.219.120.101- First seen
- Last seen
- Attached to this threat
- Appears in
- 6 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
165.154.203.234
IOC database
- Type
- ipv4
- Value
165.154.203.234- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
111.229.193.141
VT 15 / 91
IOC database
- Type
- ipv4
- Value
111.229.193.141- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 15 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malicious |
| Dr.Web | malicious | malicious |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| Lionic | malicious | malicious |
| MalwareURL | malicious | malware |
| Netcraft | malicious | malicious |
| SOCRadar | malicious | malicious |
| ViriBack | malicious | malware |
| Gridinsoft | suspicious | suspicious |
| URLQuery | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 111.229.0.0/16 |
| Country | CN |
| AS owner | Shenzhen Tencent Computer Systems Company Limited |
| ASN | 45090 |
| Regional registry | APNIC |
History
| Last analysis | 2026-07-09 06:40 UTC |
| Last modified on VirusTotal | 2026-07-11 08:53 UTC |
| WHOIS record date | 2026-07-07 08:15 UTC |
ipv4
111.119.234.82
IOC database
- Type
- ipv4
- Value
111.119.234.82- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
108.187.42.63
IOC database
- Type
- ipv4
- Value
108.187.42.63- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
101.42.104.134
IOC database
- Type
- ipv4
- Value
101.42.104.134- First seen
- Last seen
- Attached to this threat
- Appears in
- 5 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
165.154.236.119
VT 21 / 91
IOC database
- Type
- ipv4
- Value
165.154.236.119- First seen
- Last seen
- Attached to this threat
- Appears in
- 5 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 21 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | malware |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malicious |
| Dr.Web | malicious | malicious |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| GreyNoise | malicious | malicious |
| Lionic | malicious | malicious |
| MalwareURL | malicious | malware |
| Netcraft | malicious | malicious |
| SOCRadar | malicious | malicious |
| Sophos | malicious | malware |
| VIPRE | malicious | malware |
| ViriBack | malicious | malware |
| ESET | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 165.154.224.0/19 |
| Country | SG |
| AS owner | Scloud Pte Ltd |
| ASN | 142002 |
| Regional registry | APNIC |
History
| Last analysis | 2026-08-04 08:15 UTC |
| Last modified on VirusTotal | 2026-08-05 08:22 UTC |
| WHOIS record date | 2026-07-27 07:41 UTC |
ipv4
159.194.201.51
IOC database
- Type
- ipv4
- Value
159.194.201.51- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
207.56.138.77
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/207.56.138.77
IOC database
- Type
- ipv4
- Value
207.56.138.77- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/207.56.138.77
ipv4
108.187.42.64
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/108.187.42.64
IOC database
- Type
- ipv4
- Value
108.187.42.64- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/108.187.42.64
ipv4
165.154.244.210
VT 18 / 91
IOC database
- Type
- ipv4
- Value
165.154.244.210- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 18 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | malware |
| Chong Lua Dao | malicious | malicious |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malicious |
| Dr.Web | malicious | malicious |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| Lionic | malicious | malicious |
| MalwareURL | malicious | malware |
| SOCRadar | malicious | malicious |
| VIPRE | malicious | malware |
| ViriBack | malicious | malware |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 165.154.224.0/19 |
| Country | HK |
| AS owner | Scloud Pte Ltd |
| ASN | 142002 |
| Regional registry | APNIC |
History
| Last analysis | 2026-07-07 08:04 UTC |
| Last modified on VirusTotal | 2026-07-09 09:05 UTC |
| WHOIS record date | 2026-07-07 08:15 UTC |
ipv4
103.144.245.73
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/103.144.245.73
IOC database
- Type
- ipv4
- Value
103.144.245.73- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/103.144.245.73
ipv4
43.173.100.69
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/43.173.100.69
IOC database
- Type
- ipv4
- Value
43.173.100.69- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/43.173.100.69
ipv4
23.239.12.184
IOC database
- Type
- ipv4
- Value
23.239.12.184- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
104.248.203.61
IOC database
- Type
- ipv4
- Value
104.248.203.61- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
114.132.190.121
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/114.132.190.121
IOC database
- Type
- ipv4
- Value
114.132.190.121- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to AdaptixC2
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/114.132.190.121
ipv4
144.48.124.90
IOC database
- Type
- ipv4
- Value
144.48.124.90- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Cobalt Strike
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
144.48.124.92
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/144.48.124.92
IOC database
- Type
- ipv4
- Value
144.48.124.92- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/144.48.124.92
ipv4
144.48.124.94
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/144.48.124.94
IOC database
- Type
- ipv4
- Value
144.48.124.94- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/144.48.124.94
ipv4
103.242.12.143
IOC database
- Type
- ipv4
- Value
103.242.12.143- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Cobalt Strike
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
43.156.175.5
IOC database
- Type
- ipv4
- Value
43.156.175.5- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
202.61.137.210
IOC database
- Type
- ipv4
- Value
202.61.137.210- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
47.238.118.2
IOC database
- Type
- ipv4
- Value
47.238.118.2- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
43.247.135.185
VT 18 / 91
IOC database
- Type
- ipv4
- Value
43.247.135.185- First seen
- Last seen
- Attached to this threat
- Appears in
- 7 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 18 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | malware |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malware |
| Dr.Web | malicious | malicious |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| Lionic | malicious | malware |
| MalwareURL | malicious | malware |
| Netcraft | malicious | malicious |
| SOCRadar | malicious | phishing |
| Sophos | malicious | malware |
| ViriBack | malicious | malware |
| URLQuery | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 43.247.132.0/22 |
| Country | HK |
| AS owner | XNNET LLC |
| ASN | 932 |
| Regional registry | APNIC |
History
| Last analysis | 2026-07-16 10:18 UTC |
| Last modified on VirusTotal | 2026-07-16 10:27 UTC |
| WHOIS record date | 2026-06-17 21:35 UTC |
ipv4
47.76.181.119
IOC database
- Type
- ipv4
- Value
47.76.181.119- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
102.220.91.114
VT 17 / 91
IOC database
- Type
- ipv4
- Value
102.220.91.114- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 17 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | malware |
| Chong Lua Dao | malicious | malicious |
| Cluster25 | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malware |
| Dr.Web | malicious | malicious |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| Lionic | malicious | malware |
| MalwareURL | malicious | malware |
| SOCRadar | malicious | malicious |
| VIPRE | malicious | malware |
| ViriBack | malicious | malware |
Details From VirusTotal
Basic Properties
| Network | 102.220.88.0/22 |
| Country | SC |
| AS owner | sun-asn |
| ASN | 328543 |
| Regional registry | AFRINIC |
History
| Last analysis | 2026-05-24 10:23 UTC |
| Last modified on VirusTotal | 2026-05-28 01:19 UTC |
| WHOIS record date | 2026-05-07 10:35 UTC |
ipv4
206.82.6.110
IOC database
- Type
- ipv4
- Value
206.82.6.110- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
83.229.121.154
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/83.229.121.154
IOC database
- Type
- ipv4
- Value
83.229.121.154- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/83.229.121.154
ipv4
23.27.28.133
VT 13 / 91
IOC database
- Type
- ipv4
- Value
23.27.28.133- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 13 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | malware |
| CRDF | malicious | malicious |
| CyRadar | malicious | malware |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| Kaspersky | malicious | malware |
| Lionic | malicious | malware |
| MalwareURL | malicious | malware |
| SOCRadar | malicious | malware |
| alphaMountain.ai | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 23.27.28.0/24 |
| Country | MY |
| AS owner | Evoxt Sdn. Bhd. |
| ASN | 149440 |
| Regional registry | APNIC |
History
| Last analysis | 2026-06-09 08:14 UTC |
| Last modified on VirusTotal | 2026-06-13 16:12 UTC |
| WHOIS record date | 2026-05-24 23:27 UTC |
ipv4
134.122.169.42
IOC database
- Type
- ipv4
- Value
134.122.169.42- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
199.68.217.18
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/199.68.217.18
IOC database
- Type
- ipv4
- Value
199.68.217.18- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/199.68.217.18
ipv4
8.218.254.115
IOC database
- Type
- ipv4
- Value
8.218.254.115- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to Supershell Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:cyberpress.org
The investigation further uncovered that the broader C2 infrastructure leveraged additional ports, such as 5003, associated with Asset Reconnaissance Lighthouse (ARL), an offensive tool for mapping and exploiting network weaknesses. The SuperShell administrative interface was identified on port 8888, confirming the presence of an actively managed C2 panel.
-
web:cybersecuritynews.com
Technical Analysis of SuperShell Infrastructure Deeper inspection of the identified C2 server revealed a complex infrastructure with multiple services, including the SuperShell administrative panel hosted on port 8888 and Asset Reconnaissance Lighthouse (ARL) on port 5003.
-
web:darkwebinformer.com
An IP-based indicator has been identified hosting a Supershell v2.0.0 panel, a remote access and botnet management framework. The panel is exposed over HTTP on a non-standard port, suggesting use for C2 operations.
-
web:github.com
C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/botnet/ C2 infrastructure.
-
web:hunt.io
Beginner's guide to hunting exposed C2 dashboards like Supershell , HookBot, Chaos, Unam, Mythic, and Metasploit using paths, titles, and hashes
-
web:www.broadcom.com
Supershell is a C2 remote control platform. Successfully payload execution will allow attackers establishing a reverse SSH tunnel, a fully interactive shell to execute arbitrary code within the context of the application.
-
web:www.derp.ca
Supershell malware profile with daily C2 host tracking and infrastructure analysis.
-
web:www.redteamnews.com
SuperShell and Cobalt Strike Payloads Found in Open Directories: Analysis and Mitigation Cybersecurity researchers from Hunt have identified a server hosting advanced malicious tools, including SuperShell command-and-control ( C2 ) payloads and a Linux ELF Cobalt Strike beacon.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.