◈
Indicators of Compromise
Aggregated IOC feed from 20+ open-source threat intelligence sources including ThreatFox, URLhaus, MalwareBazaar, and Feodo Tracker. Search, filter, and export IPs, domains, URLs, and hashes linked to active malware campaigns.
Unique IOCs
250,401
deduplicated across all sources
Multi-Source
7,195
confirmed by 2+ feeds
Enriched
3,092
VT / AbuseIPDB / GreyNoise
By Type
url
115k
sha256
30k
domain
30k
md5
28k
sha1
25k
◈ IOC Browser195 results
Deduplicated · cross-source confirmed
🔍
195 IOCsPage 1 / 4 · showing 1–50
| Type | Value | Sources | Threat / Family | Confidence | Enrichment | Last Seen |
|---|---|---|---|---|---|---|
| domain | download.poop-tree.christmas | 1×threatfox | botnet_cc | 100 | 2026-08-12 fresh | |
| domain | download.turd-lovers.lat | 1×threatfox | botnet_cc | 100 | 2026-08-12 fresh | |
| domain | download.pooping.pics | 1×threatfox | botnet_cc | 100 | 2026-08-12 fresh | |
| domain | download.poop-diaper.buzz | 1×threatfox | botnet_cc | 100 | 2026-08-12 fresh | |
| domain | download.sf8edhuhy8e21juiz8dujh.lol | 1×threatfox | botnet_cc | 100 | 2026-08-11 fresh | |
| domain | download.dancefloor.top | 1×threatfox | botnet_cc | 100 | 2026-08-11 fresh | |
| domain | fix.unknower.win | 1×threatfox | botnet_cc | 100 | 2026-08-08 fresh | |
| url | http://69.169.99.158:7100/WTogA9Ctxs/x522 | 1×urlhaus | malware_download | 80 | not yet enrichedCheck on VirusTotal | 2026-07-30 recent |
| url | http://69.169.99.158:7100/lKzmNXeqFe/x521 | 1×urlhaus | malware_download | 80 | not yet enrichedCheck on VirusTotal | 2026-07-30 recent |
| url | http://69.169.99.158:7100/wHy7ROvJ4R/x640 | 1×urlhaus | malware_download | 80 | not yet enrichedCheck on VirusTotal | 2026-07-30 recent |
| domain | download.stopbanningmydomains.ru | 1×threatfox | botnet_cc | 100 | 2026-07-30 recent | |
| ip | 217.216.66.74 | 1×threatfox | payload_delivery | 80 | 2026-06-29 aging | |
| ip | 185.76.9.35 | 1×threatfox | payload_delivery | 80 | 2026-06-29 aging | |
| ip | 139.59.67.197 | 1×threatfox | payload_delivery | 80 | 2026-06-29 aging | |
| ip | 172.104.63.215 | 1×threatfox | payload_delivery | 80 | 2026-06-29 aging | |
| ip | 165.22.8.2 | 1×threatfox | payload_delivery | 80 | 2026-06-29 aging | |
| ip | 134.122.1.61 | 1×threatfox | payload_delivery | 80 | 2026-06-29 aging | |
| ip | 103.214.9.20 | 1×threatfox | payload_delivery | 80 | 2026-06-29 aging | |
| url | http://91.239.211.89/init.sh | 1×urlhaus | malware_download | 50 | not yet enrichedCheck on VirusTotal | 2026-06-21 aging |
| sha256 | 16d3440fcc…127086 | 2×malwarebazaarthreatfox | malware_sample | 85 | not yet enrichedCheck on VirusTotal | 2026-06-14 aging |
| sha256 | 8a68d1c08e…49878b | 1×threatfox | payload | 85 | not yet enrichedCheck on VirusTotal | 2026-06-14 aging |
| sha256 | f38504f53f…90f1c9 | 2×malwarebazaarthreatfox | malware_sample | 80 | not yet enrichedCheck on VirusTotal | 2026-06-04 aging |
| url | https://s.littleshabby.net/payloads/indexi.png | 2×threatfoxurlhaus | malware_download | 80 | not yet enrichedCheck on VirusTotal | 2026-06-04 aging |
| sha256 | adfa14deed…3bdabc | 2×malwarebazaarthreatfox | malware_sample | 90 | not yet enrichedCheck on VirusTotal | 2026-06-02 aging |
| ip | 94.154.35.215 | 1×threatfox | payload_delivery | 90 | 2026-05-29 aging | |
| sha256 | a437ad7a52…c32ae8 | 2×malwarebazaarthreatfox | malware_sample | 90 | not yet enrichedCheck on VirusTotal | 2026-05-29 aging |
| sha256 | e20b8e1d83…747421 | 2×malwarebazaarthreatfox | malware_sample | 90 | not yet enrichedCheck on VirusTotal | 2026-05-29 aging |
| domain | kworker.eth.limo | 1×threatfox | payload_delivery | 100 | — — | |
| domain | kworker.eth.link | 1×threatfox | payload_delivery | 100 | — — | |
| domain | s.littleshabby.net | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 104.28.154.251 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 116.162.216.223 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 116.34.14.135 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 116.62.220.96 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 117.150.62.177 | 1×threatfox | payload_delivery | 90 | — — | |
| ip | 124.90.54.135 | 1×threatfox | botnet_cc | 80 | — — | |
| ip | 129.211.222.51 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 13.58.162.150 | 1×threatfox | botnet_cc | 80 | — — | |
| ip | 138.199.15.156 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 138.199.15.161 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 138.199.15.175 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 146.70.184.43 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 156.229.165.166 | 1×threatfox | botnet_cc | 100 | — — | |
| ip | 156.246.94.183 | 1×threatfox | botnet_cc | 100 | — — | |
| ip | 159.89.172.54 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 159.89.83.151 | 1×threatfox | payload_delivery | 85 | — — | |
| ip | 177.104.165.104 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 178.128.51.84 | 1×threatfox | payload_delivery | 80 | AB 100 | — — |
| ip | 185.214.96.142 | 1×threatfox | payload_delivery | 80 | — — | |
| ip | 185.214.96.152 | 1×threatfox | payload_delivery | 80 | — — |