TF-MAL-elf.raspberrypibotnet |
Malware family: RaspberryPiBotnet |
|
RaspberryPiBotnet |
1 |
10 |
|
|
|
TF-MAL-elf.rapper_bot |
Malware family: RapperBot |
|
RapperBot |
1 |
10 |
|
|
|
TF-MAL-elf.ransomexx2 |
Malware family: RansomExx2 |
|
RansomExx2 |
1 |
10 |
|
|
|
TF-MAL-elf.ransomexx |
Malware family: RansomEXX |
|
RansomEXX |
1 |
10 |
|
|
|
TF-MAL-elf.rakos |
Malware family: Rakos |
|
Rakos |
1 |
10 |
|
|
|
TF-MAL-elf.ragnarlocker |
Malware family: RagnarLocker |
|
RagnarLocker |
1 |
10 |
|
|
|
TF-MAL-elf.r2r2 |
Malware family: r2r2 |
|
r2r2 |
1 |
10 |
|
|
|
TF-MAL-elf.qsnatch |
Malware family: QSnatch |
|
QSnatch |
1 |
10 |
|
|
|
TF-MAL-elf.qilin |
Malware family: Qilin |
|
Qilin |
1 |
10 |
|
|
|
TF-MAL-elf.pwnlnx |
Malware family: PWNLNX |
|
PWNLNX |
1 |
10 |
|
|
|
TF-MAL-elf.pumakit |
Malware family: PUMAKIT |
|
PUMAKIT |
1 |
10 |
|
|
|
TF-MAL-elf.prometei |
Malware family: Prometei |
|
Prometei |
1 |
8 |
|
|
|
TF-MAL-elf.privet_sanya |
Malware family: PrivetSanya |
|
PrivetSanya |
1 |
10 |
|
|
|
TF-MAL-elf.poseidon |
Malware family: Poseidon |
|
Poseidon |
1 |
10 |
|
|
|
TF-MAL-elf.polaredge |
Malware family: PolarEdge |
|
PolarEdge |
1 |
10 |
|
|
|
TF-MAL-elf.plead |
Malware family: PLEAD |
|
PLEAD |
1 |
10 |
|
|
|
TF-MAL-elf.plague |
Malware family: Plague |
|
Plague |
1 |
10 |
|
|
|
TF-MAL-elf.pitsock |
Malware family: PITSOCK |
|
PITSOCK |
1 |
10 |
|
|
|
TF-1811876 |
ClearFake: Domain name that delivers a malware payload unseen-zorenka.digital |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1811877 |
ClearFake: Domain name that delivers a malware payload cp53yk6u.unseen-zorenka.digital |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1811879 |
ClearFake: Domain name that delivers a malware payload m8n36lcp.unseen-zorenka.digital |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1811881 |
Unknown malware: URL that is used for botnet Command&control (C&C) http://109.199.111.106:5000/login |
high |
Unknown malware |
2 |
8 |
|
|
|
TF-1811888 |
ClearFake: Domain name that delivers a malware payload seducingdelirium.surf |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1811889 |
ClearFake: Domain name that delivers a malware payload m14rfe59.unseen-zorenka.digital |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1811892 |
Havoc: ip:port combination that is used for botnet Command&control (C&C) 34.155.134.233:443 |
high |
Havoc |
2 |
5 |
|
|
|
TF-1811893 |
Quasar RAT: Domain that is used for botnet Command&control (C&C) uu888.jp.net |
high |
Quasar RAT |
3 |
10 |
|
|
|
TF-1811895 |
ClearFake: Domain name that delivers a malware payload axr7hs51.$unp2idvalk.digital |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1811899 |
KongTuke: URL that delivers a malware payload https://bradtte.lol/api/v1/session |
high |
KongTuke |
3 |
10 |
|
|
|
TF-1811904 |
ClearFake: Domain name that delivers a malware payload containerorchestrationhub.wiki |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1811906 |
VShell: ip:port combination that is used for botnet Command&control (C&C) 103.195.188.212:8080 |
high |
VShell |
2 |
6 |
|
|
|
TF-1811908 |
Kimwolf: ip:port combination that is used for botnet Command&control (C&C) 142.93.143.10:25001 |
high |
Kimwolf |
2 |
5 |
|
|
|
TF-1811909 |
Kimwolf: ip:port combination that is used for botnet Command&control (C&C) 188.166.16.10:25001 |
high |
Kimwolf |
2 |
4 |
|
|
|
TF-1811910 |
Kimwolf: ip:port combination that is used for botnet Command&control (C&C) 188.166.22.238:25001 |
high |
Kimwolf |
2 |
5 |
|
|
|
TF-1811911 |
Kimwolf: ip:port combination that is used for botnet Command&control (C&C) 104.248.92.93:25001 |
high |
Kimwolf |
2 |
5 |
|
|
|
TF-1811913 |
Kimwolf: ip:port combination that is used for botnet Command&control (C&C) 188.166.8.75:25001 |
high |
Kimwolf |
2 |
5 |
|
|
|
TF-1811915 |
Unknown malware: URL that is used for botnet Command&control (C&C) https://virusblocker.it.com/11E6C6611E6C66 |
low |
Unknown malware |
3 |
10 |
|
|
|
TF-1811917 |
CountLoader: Domain that is used for botnet Command&control (C&C) bucket-aws-s2.com |
low |
CountLoader |
3 |
10 |
|
|
|
TF-1811916 |
CountLoader: Domain that is used for botnet Command&control (C&C) bucket-aws-s1.com |
low |
CountLoader |
3 |
10 |
|
|
|
TF-1811920 |
CountLoader: Domain that is used for botnet Command&control (C&C) health-smooth-eu1.com |
low |
CountLoader |
3 |
10 |
|
|
|
TF-1811922 |
CountLoader: Domain that is used for botnet Command&control (C&C) memory-protection-layer2.cc |
low |
CountLoader |
3 |
8 |
|
|
|
TF-1811923 |
CountLoader: URL that is used for botnet Command&control (C&C) https://edr-security-bucket1.cc/ |
low |
CountLoader |
3 |
10 |
|
|
|
TF-1811924 |
ClearFake: Domain name that delivers a malware payload virtual-session-broker.wiki |
high |
ClearFake |
2 |
10 |
|
|
|
MB-7fe6d020d4e2861541bce306bf96970e89783b4823b6b86d428fc6d5e4241678 |
AsyncRAT: 7fe6d020d4e2861541bce306bf96970e89783b4823b6b86d428fc6d5e4241678 |
high |
AsyncRAT |
1 |
10 |
|
|
|
MB-1e009e3c1b579103ddc8531c7cc24fff3dae304e0e82366e337ebce5fe906fb2 |
AsyncRAT: Copia de la transaccion.vbs |
high |
AsyncRAT |
1 |
10 |
|
|
|
MB-ac58ac8e713e3720ce88a1243bde150ad4541b30ca3d8ddd72dbacd464d1a515 |
AsyncRAT: WhatsApp image New PO 38359257N0..vbs |
high |
AsyncRAT |
1 |
10 |
|
|
|
TF-MAL-elf.pingpull |
Malware family: PingPull |
|
PingPull |
1 |
10 |
|
|
|
TF-MAL-elf.pigmy_goat |
Malware family: PigmyGoat |
|
PigmyGoat |
1 |
10 |
|
|
|
TF-MAL-elf.persirai |
Malware family: Persirai |
|
Persirai |
1 |
10 |
|
|
|
TF-MAL-elf.perlbot |
Malware family: PerlBot |
|
PerlBot |
1 |
10 |
|
|
|
TF-MAL-elf.perfctl |
Malware family: perfctl |
|
perfctl |
1 |
10 |
|
|
|