84343096 | URLhaus Known malware download URL detected (3479996) | abuse.ch/urlhaus |
84342250 | URLhaus Known malware download URL detected (3479150) | abuse.ch/urlhaus |
2045885 | ET ATTACK_RESPONSE Mana Tools-Lone Wolf Admin Panel Inbound | et/open |
84339922 | URLhaus Known malware download URL detected (3476822) | abuse.ch/urlhaus |
84338504 | URLhaus Known malware download URL detected (3475404) | abuse.ch/urlhaus |
84338489 | URLhaus Known malware download URL detected (3475389) | abuse.ch/urlhaus |
84338486 | URLhaus Known malware download URL detected (3475386) | abuse.ch/urlhaus |
84338481 | URLhaus Known malware download URL detected (3475381) | abuse.ch/urlhaus |
84337799 | URLhaus Known malware download URL detected (3474699) | abuse.ch/urlhaus |
84337221 | URLhaus Known malware download URL detected (3474121) | abuse.ch/urlhaus |
84337220 | URLhaus Known malware download URL detected (3474120) | abuse.ch/urlhaus |
2009120 | ET ACTIVEX FlexCell Grid ActiveX Multiple Arbitrary File Overwrite | et/open |
2044430 | ET ATTACK_RESPONSE VBS/TrojanDownloader.Agent.YLH Payload Inbound | et/open |
84330904 | URLhaus Known malware download URL detected (3467804) | abuse.ch/urlhaus |
84329327 | URLhaus Known malware download URL detected (3466227) | abuse.ch/urlhaus |
84329085 | URLhaus Known malware download URL detected (3465985) | abuse.ch/urlhaus |
84329035 | URLhaus Known malware download URL detected (3465935) | abuse.ch/urlhaus |
84328965 | URLhaus Known malware download URL detected (3465865) | abuse.ch/urlhaus |
2018059 | ET MALWARE Possible KAPTOXA Encoded Data Transferred Over SMB 1 | et/open |
2018060 | ET MALWARE Possible KAPTOXA Encoded Data Transferred Over SMB 2 | et/open |
2018061 | ET MALWARE Possible KAPTOXA Encoded Data Transferred Over SMB 3 | et/open |
2018062 | ET MALWARE Possible KAPTOXA Encoded Data Transferred Over SMB 4 | et/open |
2018063 | ET MALWARE Possible KAPTOXA Encoded Data Transferred Over SMB 5 | et/open |
2018064 | ET MALWARE Possible KAPTOXA Encoded Data Transferred Over SMB 6 | et/open |
2018065 | ET MALWARE Possible KAPTOXA Encoded Data Transferred Over SMB 7 | et/open |
2018066 | ET MALWARE Possible KAPTOXA Encoded Data Transferred Over SMB 8 | et/open |
2018067 | ET MALWARE Possible KAPTOXA Encoded Data Transferred Over SMB 9 | et/open |
2018068 | ET MALWARE Possible KAPTOXA Encoded Data Transferred Over SMB 10 | et/open |
2018058 | ET MALWARE Possible KAPTOXA SMB Naming Format | et/open |
2054815 | ET MOBILE_MALWARE Android/Mandrake CnC Domain in DNS Lookup (toxicodendron .ru) | et/open |
2054823 | ET MOBILE_MALWARE Observed Android/Mandrake CnC Domain (toxicodendron .ru) in TLS SNI | et/open |
2021204 | ET MALWARE DNS Query to TOX Ransomware onion (toxicola7qwv37qj) | et/open |
2021163 | ET MALWARE DNS Query to TOX Ransomware onion (wdthvb6jut2rupu4) | et/open |
2021164 | ET MALWARE DNS Query to TOX Ransomware onion (xwxwninkssujglja) | et/open |
2021165 | ET MALWARE DNS Query to TOX Ransomware onion (7fa6gldxg64t5wnt) | et/open |
84101128 | URLhaus Known malware download URL detected (3238028) | abuse.ch/urlhaus |
2049167 | ET INFO Tox Chat Domain in DNS Lookup (tox .chat) | et/open |
2049168 | ET INFO Observed Tox Chat Domain (tox .chat in TLS SNI) | et/open |
84214486 | URLhaus Known malware download URL detected (3351386) | abuse.ch/urlhaus |
2048917 | ET INFO Observed DNS Over HTTPS Domain (doh-primary-pool .detoxifypornblocker .com in TLS SNI) | et/open |
2034334 | ET MALWARE APT-C-59 Related Domain in DNS Lookup | et/open |
2023581 | ET MALWARE ABUSE.CH Ransomware/Cerber Onion Domain Lookup | et/open |
84282664 | URLhaus Known malware download URL detected (3419564) | abuse.ch/urlhaus |
2044974 | ET MALWARE PlutoCrypt Decryption Key Exfil | et/open |
2045841 | ET MALWARE Kraken Stealer SMTP Data Exfiltration Attempt | et/open |
84219217 | URLhaus Known malware download URL detected (3356117) | abuse.ch/urlhaus |
3313386 | 🐾 - ☠ DNS request 🌐 --> 🎛 Possible C2 🔒 REvil/Sodinokibi ransomware | pawpatrules |
2045184 | ET MALWARE DNS Query to Blind Eagle Domain (dfdagsdsag .con-ip .com) | et/open |
84354127 | URLhaus Known malware download URL detected (3491027) | abuse.ch/urlhaus |
84354131 | URLhaus Known malware download URL detected (3491031) | abuse.ch/urlhaus |