TF-1932595 |
SNOWLIGHT: SHA256 hash of a malware sample (payload) e09af9f084075caf754e2cbefbb360c851bb279c2dd8b4d383209aef64af20ef |
high |
SNOWLIGHT |
2 |
10 |
|
|
|
TF-1932594 |
Mirai: SHA256 hash of a malware sample (payload) d3ea92ab0f5e52edcbf797cb18a70d83d387c121ae84959f2bf50ab446615e65 |
high |
Mirai |
2 |
10 |
|
|
|
TF-1932593 |
Mirai: SHA256 hash of a malware sample (payload) b98acd3501298a53de20e4924f92cc1981a3e0bf70451f0eb2d06bcb66f939af |
high |
Mirai |
2 |
10 |
|
|
|
TF-1932592 |
Mirai: SHA256 hash of a malware sample (payload) d07dca6ae1a68831a3a69398de8defc1d0fef99596c912fc5d1bb18c141da6f6 |
high |
Mirai |
2 |
8 |
|
|
|
TF-1932591 |
Mirai: SHA256 hash of a malware sample (payload) b0d715ed43425e92111fdc9e211d52106b90ed58e9a06d0fc0a3f2b9da8a62f0 |
high |
Mirai |
2 |
8 |
|
|
|
TF-1932590 |
Mirai: SHA256 hash of a malware sample (payload) 6caa85a5e69e21f529dc2b246b38e13ba24902dc5721309c70d7c1fdf2d4367f |
high |
Mirai |
2 |
10 |
|
|
|
TF-1932589 |
Mirai: SHA256 hash of a malware sample (payload) e677c9a6eeaad9cb02f4aa55eb1d264617cbac7e07091939b6f517446b5f17ae |
high |
Mirai |
2 |
10 |
|
|
|
TF-1932588 |
VShell: SHA256 hash of a malware sample (payload) 610d3e3bfef18e116a7de3aae9d8d7a941cb5664a0af78304d6fbaef62a2dc03 |
high |
VShell |
2 |
10 |
|
|
|
CVE-2026-97730 |
CVE-2026-97730 |
high |
cve |
0 |
0 |
|
|
|
TF-1932587 |
php.shin_webshell: Domain that is used for botnet Command&control (C&C) mowohe.workers.dev |
medium |
php.shin_webshell |
2 |
10 |
|
|
|
TF-1932586 |
VShell: URL that delivers a malware payload http://123.254.106.168/?h=123.254.106.168&p=80&t=ws&a=w64&stage=true |
high |
VShell |
2 |
10 |
|
|
|
TF-1932585 |
VShell: URL that delivers a malware payload http://123.254.106.168/?h=123.254.106.168&p=80&t=tcp&a=w32&stage=true |
high |
VShell |
2 |
10 |
|
|
|
TF-1932584 |
VShell: URL that delivers a malware payload http://193.160.32.138:8085/?h=193.160.32.138&p=8085&t=ws&a=w32&stage=true |
high |
VShell |
2 |
10 |
|
|
|
TF-1932583 |
VShell: URL that delivers a malware payload http://123.254.106.168/?h=123.254.106.168&p=80&t=tcp&a=w64&stage=true |
high |
VShell |
2 |
10 |
|
|
|
TF-1932582 |
php.shin_webshell: Domain that is used for botnet Command&control (C&C) eunoz4hz4m.workers.dev |
medium |
php.shin_webshell |
2 |
10 |
|
|
|
TF-1932581 |
php.shin_webshell: Domain that is used for botnet Command&control (C&C) lyqafuqi.workers.dev |
medium |
php.shin_webshell |
2 |
10 |
|
|
|
TF-1932580 |
ClearFake: Domain name that delivers a malware payload greywolfservices.net |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932579 |
ClearFake: Domain name that delivers a malware payload pnw4rjw2.takvarzesh.ir |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932578 |
ClearFake: Domain name that delivers a malware payload takvarzesh.ir |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932576 |
ClearFake: Domain name that delivers a malware payload g0flf7f0.jet90betyek.bet |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932573 |
ClearFake: Domain name that delivers a malware payload www.gabriellaponte.com.br |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932572 |
XMRIG: SHA256 hash of a malware sample (payload) 0ad68d5804804c25a6f6f3d87cc3a3886583f69b7115ba01ab7c6dd96a186404 |
high |
XMRIG |
2 |
10 |
|
|
|
TF-1932571 |
VShell: SHA256 hash of a malware sample (payload) 6be8c092507dc1e7105e56f5c5aaae527be511884105b1b3895ba6ce1d869d91 |
high |
VShell |
2 |
10 |
|
|
|
TF-1932570 |
Bashlite: SHA256 hash of a malware sample (payload) deb1c78ca154989f89979b9b0126f3781a0c6ac8cad6ef121598a4cceb7bc6f0 |
high |
Bashlite |
2 |
10 |
|
|
|
TF-1932569 |
Mirai: SHA256 hash of a malware sample (payload) c1c1046c507058c0ca6d14bb5369a84a45791d58475ce12fc6995451f0c5eb14 |
high |
Mirai |
2 |
10 |
|
|
|
TF-1932568 |
Mirai: SHA256 hash of a malware sample (payload) ff4d54d5368f07b42ba40fc52051a9a14c81407406717eb9188fef7a343ebc66 |
high |
Mirai |
2 |
10 |
|
|
|
TF-1932567 |
Mirai: SHA256 hash of a malware sample (payload) 5f3152e5bdafababf1312ba047cfb4bbf91438d85404fccb4f4349cf54024257 |
high |
Mirai |
2 |
10 |
|
|
|
TF-1932566 |
Mirai: SHA256 hash of a malware sample (payload) 93991708c741b6f73ecc5b0245702e07f42fbc71ee5ac0d8c39085574eb4b6a8 |
high |
Mirai |
2 |
10 |
|
|
|
TF-1932565 |
SalatStealer: SHA256 hash of a malware sample (payload) 7c04a11b72485957f38a65a92666de7d0a6f80fee78e45638a5db5505ae318e1 |
high |
SalatStealer |
2 |
10 |
|
|
|
TF-1932564 |
Unknown Loader: SHA256 hash of a malware sample (payload) 42118bc3daa2d2c439bb54c329f2184be65b9c89ba87aa1a705beb2f79a22e69 |
high |
Unknown Loader |
2 |
10 |
|
|
|
TF-1932563 |
Unknown Loader: SHA256 hash of a malware sample (payload) 8f64802237d484eb45bda626da5f5501209a36384acc88950e3f5f79c86cc938 |
high |
Unknown Loader |
2 |
10 |
|
|
|
TF-1932562 |
VShell: SHA256 hash of a malware sample (payload) 7a1af320c9474415699030039ebc7fac0e34ff66e4e10e55fcf30b211b7c94d4 |
high |
VShell |
2 |
10 |
|
|
|
TF-1932561 |
VShell: SHA256 hash of a malware sample (payload) 3e6c9b6f61e5cb0c9e95f43ad28cf7ee3bdcd993a7f2a7dd8adf5c5919401d5c |
high |
VShell |
2 |
10 |
|
|
|
TF-1932560 |
Unknown Loader: SHA256 hash of a malware sample (payload) ccdfe35e50578e7b82671466154cdfae207455b4139b26bd93016c0144c857fd |
high |
Unknown Loader |
2 |
10 |
|
|
|
TF-1932559 |
Unknown Loader: SHA256 hash of a malware sample (payload) cdc89db3e28be5e16e6ca5cc635fbb479a4e5564357f66240a9c5b191ed51b9a |
high |
Unknown Loader |
2 |
10 |
|
|
|
TF-1932558 |
Unknown Loader: SHA256 hash of a malware sample (payload) c736403737ad8bf3577514003774d4d844297d900d6fbed6cd3d57bb51bc43a9 |
high |
Unknown Loader |
2 |
10 |
|
|
|
TF-1932557 |
VShell: URL that delivers a malware payload http://v.teruishuo.net:8443/?h=v.teruishuo.net&p=8443&t=tcp&a=w32&stage=true |
high |
VShell |
2 |
10 |
|
|
|
TF-1932556 |
VShell: URL that delivers a malware payload http://107.151.233.120:8084/?h=107.151.233.120&p=8084&t=ws&a=w32&stage=true |
high |
VShell |
2 |
10 |
|
|
|
TF-1932552 |
Unknown malware: URL that delivers a malware payload https://opti-pc.com/telechargement/OptiPC-Setup-1.0.0.exe |
high |
Unknown malware |
2 |
10 |
|
|
|
TF-1932551 |
Unknown malware: URL that delivers a malware payload https://fj9988.com/VoltTrade.apk |
high |
Unknown malware |
2 |
10 |
|
|
|
TF-1932550 |
ClearFake: Domain name that delivers a malware payload bwil48h8.baxus.net |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932549 |
ClearFake: Domain name that delivers a malware payload baxbet.bet |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932548 |
VShell: ip:port combination that is used for botnet Command&control (C&C) 39.96.15.121:8083 |
high |
VShell |
2 |
9 |
|
|
|
TF-1932547 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 23.27.143.19:8080 |
high |
Cobalt Strike |
2 |
8 |
|
|
|
TF-1932546 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 23.27.143.19:443 |
high |
Cobalt Strike |
2 |
8 |
|
|
|
TF-1932544 |
Unknown malware: URL that delivers a malware payload https://openai-credits.com/ |
high |
Unknown malware |
3 |
10 |
|
|
|
TF-1932543 |
Unknown malware: URL that delivers a malware payload https://strategyvote.com/ |
high |
Unknown malware |
3 |
10 |
|
|
|
TF-1932542 |
ClearFake: Domain name that delivers a malware payload gandsonscfo.com |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932541 |
ClearFake: Domain name that delivers a malware payload fullhairbydhtclinic.com |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932540 |
php.shin_webshell: Domain that is used for botnet Command&control (C&C) hudyqiko.workers.dev |
medium |
php.shin_webshell |
2 |
10 |
|
|
|