Malware Tracker — 1st Edn June 21

Vishal Thakur
3 min readJun 14, 2021

G’day Cyber Warrior,
Here are the latest IOC lists.

Please note:
You can use this information to create block-lists.
All C2i published here is active at the time of publishing but some of these C2s can go offline at any time after that.
All information provided here is free to use.
C2i published on this site or shared via email could cause some FPs as these IPs/URIs get recycled frequently, you agree to that before using any C2i from this site.
Lists are NOT de-duped.
You agree that any false positives or outages caused by use of this list will be your responsibility. To get this list emailed to you (free service), please subscribe here:
https://www.malienist.com/p/subscribe-to-free-ioc-list.htmlThanks,
_malienist_

Emotet

hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://46.249.199.233:8080
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://46.249.199.233:8080
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://46.249.199.233:8080
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://94.130.176.44:443
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://46.249.199.233:8080
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080
hxxp://74.50.52.11:8080
hxxp://88.217.172.79:8080
hxxp://190.3.183.18:443
hxxp://175.207.12.52:8080
hxxp://103.216.216.95:443
hxxp://72.44.93.233:8080

Azorult

hxxp://viewmanage101.tk/webaz.php
hxxp://195.245.112.115/index.php
hxxp://195.245.112.115/index.php

REvil

hxxp://cityorchardhtx.com
hxxp://tanciu.com
hxxp://yassir.pro
hxxp://skanah.com
hxxp://craigvalentineacademy.com
hxxp://linnankellari.fi
hxxp://bhwlawfirm.com
hxxp://pmc-services.de
hxxp://vermoote.de
hxxp://kampotpepper.gives
hxxp://worldhealthbasicinfo.com
hxxp://bee4win.com
hxxp://westdeptfordbuyrite.com
hxxp://sportverein-tambach.de
hxxp://tandartspraktijkhartjegroningen.nl
hxxp://seitzdruck.com
hxxp://cite4me.org
hxxp://celularity.com
hxxp://allentownpapershow.com
hxxp://sweering.fr
hxxp://roygolden.com
hxxp://aarvorg.com
hxxp://praxis-foerderdiagnostik.de
hxxp://stupbratt.no
hxxp://hushavefritid.dk
hxxp://lionware.de
hxxp://maxadams.london
hxxp://mindpackstudios.com
hxxp://gmto.fr
hxxp://assurancesalextrespaille.fr
hxxp://creative-waves.co.uk
hxxp://dekkinngay.com
hxxp://grelot-home.com
hxxp://talentwunder.com
hxxp://uimaan.fi
hxxp://presseclub-magdeburg.de
hxxp://bayoga.co.uk
hxxp://dsl-ip.de
hxxp://kojima-shihou.com
hxxp://bodyforwife.com
hxxp://urmasiimariiuniri.ro
hxxp://ungsvenskarna.se
hxxp://dontpassthepepper.com
hxxp://completeweddingkansas.com
hxxp://triactis.com
hxxp://teczowadolina.bytom.pl
hxxp://cirugiauretra.es
hxxp://girlillamarketing.com
hxxp://bookspeopleplaces.com
hxxp://spacecitysisters.org
hxxp://partnertaxi.sk
hxxp://dlc.berlin
hxxp://blacksirius.de
hxxp://edrcreditservices.nl
hxxp://exenberger.at
hxxp://phantastyk.com
hxxp://mirkoreisser.de
hxxp://abogados-en-alicante.es
hxxp://wraithco.com
hxxp://seevilla-dr-sturm.at
hxxp://web.ion.ag
hxxp://ladelirante.fr
hxxp://edv-live.de
hxxp://schraven.de
hxxp://bloggyboulga.net
hxxp://greenfieldoptimaldentalcare.com
hxxp://homecomingstudio.com
hxxp://craigmccabe.fun
hxxp://podsosnami.ru
hxxp://id-et-d.fr
hxxp://c-a.co.in
hxxp://alhashem.net
hxxp://ncid.bc.ca
hxxp://stingraybeach.com
hxxp://manutouchmassage.com
hxxp://tetinfo.in
hxxp://irishmachineryauctions.com
hxxp://ianaswanson.com
hxxp://hashkasolutindo.com
hxxp://saarland-thermen-resort.com
hxxp://celeclub.org
hxxp://deprobatehelp.com
hxxp://dezatec.es
hxxp://vitalyscenter.es
hxxp://idemblogs.com
hxxp://pferdebiester.de
hxxp://imaginado.de
hxxp://remcakram.com
hxxp://campusoutreach.org
hxxp://physiofischer.de
hxxp://architecturalfiberglass.org
hxxp://bundabergeyeclinic.com.au
hxxp://ussmontanacommittee.us
hxxp://skiltogprint.no
hxxp://logopaedie-blomberg.de
hxxp://art2gointerieurprojecten.nl
hxxp://consultaractadenacimiento.com
hxxp://nancy-informatique.fr
hxxp://analiticapublica.es
hxxp://tongdaifpthaiphong.net
hxxp://carriagehousesalonvt.com
hxxp://leeuwardenstudentcity.nl
hxxp://lascuola.nl
hxxp://izzi360.com
hxxp://fax-payday-loans.com
hxxp://longislandelderlaw.com
hxxp://braffinjurylawfirm.com
hxxp://nakupunafoundation.org
hxxp://withahmed.com
hxxp://coastalbridgeadvisors.com
hxxp://datacenters-in-europe.com
hxxp://zweerscreatives.nl
hxxp://lorenacarnero.com
hxxp://ino-professional.ru
hxxp://frontierweldingllc.com
hxxp://pocket-opera.de
hxxp://gasolspecialisten.se
hxxp://shsthepapercut.com
hxxp://neuschelectrical.co.za
hxxp://syndikat-asphaltfieber.de
hxxp://paradicepacks.com
hxxp://spinheal.ru
hxxp://stormwall.se
hxxp://burkert-ideenreich.de
hxxp://psnacademy.in
hxxp://seminoc.com
hxxp://atmos-show.com
hxxp://carolinepenn.com
hxxp://ikads.org
hxxp://tulsawaterheaterinstallation.com
hxxp://upplandsspar.se
hxxp://woodworkersolution.com
hxxp://lecantou-coworking.com
hxxp://jobmap.at
hxxp://ilive.lt
hxxp://wari.com.pe
hxxp://softsproductkey.com
hxxp://argenblogs.com.ar
hxxp://pierrehale.com
hxxp://loprus.pl
hxxp://eco-southafrica.com
hxxp://finediningweek.pl
hxxp://easytrans.com.au
hxxp://sanyue119.com
hxxp://greenko.pl
hxxp://em-gmbh.ch
hxxp://selfoutlet.com
hxxp://faroairporttransfers.net
hxxp://webhostingsrbija.rs
hxxp://slimidealherbal.com
hxxp://milltimber.aberdeen.sch.uk
hxxp://nsec.se
hxxp://eglectonk.online
hxxp://bildungsunderlebnis.haus
hxxp://rozemondcoaching.nl
hxxp://denovofoodsgroup.com
hxxp://effortlesspromo.com
hxxp://madinblack.com
hxxp://elpa.se
hxxp://chrissieperry.com
hxxp://castillobalduz.es
hxxp://havecamerawilltravel2017.wordpress.com
hxxp://hokagestore.com
hxxp://dr-pipi.de
hxxp://higadograsoweb.com
hxxp://copystar.co.uk
hxxp://lapmangfpt.info.vn
hxxp://fiscalsort.com
hxxp://levihotelspa.fi
hxxp://advokathuset.dk
hxxp://drinkseed.com
hxxp://southeasternacademyofprosthodontics.org
hxxp://kidbucketlist.com.au
hxxp://webcodingstudio.com
hxxp://carlosja.com
hxxp://beautychance.se
hxxp://finde-deine-marke.de
hxxp://manijaipur.com
hxxp://ausbeverage.com.au
hxxp://austinlchurch.com
hxxp://marathonerpaolo.com
hxxp://oslomf.no
hxxp://norpol-yachting.com
hxxp://makeitcount.at
hxxp://autofolierung-lu.de
hxxp://gw2guilds.org
hxxp://radaradvies.nl
hxxp://airconditioning-waalwijk.nl
hxxp://unim.su
hxxp://plv.media
hxxp://tenacitytenfold.com
hxxp://sandd.nl
hxxp://smartypractice.com
hxxp://ncuccr.org
hxxp://fotoscondron.com
hxxp://atalent.fi
hxxp://profectis.de
hxxp://ai-spt.jp
hxxp://pinkexcel.com
hxxp://systemate.dk
hxxp://delawarecorporatelaw.com
hxxp://gadgetedges.com
hxxp://ateliergamila.com
hxxp://mbxvii.com
hxxp://maureenbreezedancetheater.org
hxxp://lescomtesdemean.be
hxxp://ventti.com.ar
hxxp://baronloan.org
hxxp://lukeshepley.wordpress.com
hxxp://vickiegrayimages.com
hxxp://nokesvilledentistry.com
hxxp://testzandbakmetmening.online
hxxp://osterberg.fi
hxxp://hardinggroup.com
hxxp://team-montage.dk
hxxp://merzi.info
hxxp://lenreactiv-shop.ru
hxxp://bingonearme.org
hxxp://mirjamholleman.nl
hxxp://kevinjodea.com
hxxp://ki-lowroermond.nl
hxxp://shadebarandgrillorlando.com
hxxp://ziegler-praezisionsteile.de
hxxp://limassoldriving.com
hxxp://amerikansktgodis.se
hxxp://myteamgenius.com
hxxp://enovos.de
hxxp://sexandfessenjoon.wordpress.com
hxxp://solinegraphic.com
hxxp://i-arslan.de
hxxp://layrshift.eu
hxxp://baustb.de
hxxp://mytechnoway.com
hxxp://drfoyle.com
hxxp://hatech.io
hxxp://dutchcoder.nl
hxxp://kuntokeskusrok.fi
hxxp://x-ray.ca
hxxp://perbudget.com
hxxp://devlaur.com
hxxp://stacyloeb.com
hxxp://handi-jack-llc.com
hxxp://12starhd.online
hxxp://associacioesportivapolitg.cat
hxxp://answerstest.ru
hxxp://the-domain-trader.com
hxxp://vannesteconstruct.be
hxxp://urist-bogatyr.ru
hxxp://upmrkt.co
hxxp://hkr-reise.de
hxxp://johnsonfamilyfarmblog.wordpress.com
hxxp://fitnessbazaar.com
hxxp://pridoxmaterieel.nl
hxxp://1kbk.com.ua
hxxp://hoteledenpadova.it
hxxp://piajeppesen.dk
hxxp://tux-espacios.com
hxxp://echtveilig.nl
hxxp://calxplus.eu
hxxp://iyengaryogacharlotte.com
hxxp://sobreholanda.com
hxxp://agence-chocolat-noir.com
hxxp://id-vet.com
hxxp://rehabilitationcentersinhouston.net
hxxp://eadsmurraypugh.com
hxxp://extensionmaison.info
hxxp://roadwarrior.app
hxxp://revezlimage.com
hxxp://promesapuertorico.com
hxxp://hotelzentral.at
hxxp://bowengroup.com.au
hxxp://latestmodsapks.com
hxxp://torgbodenbollnas.se
hxxp://dr-seleznev.com
hxxp://caribbeansunpoker.com
hxxp://zflas.com
hxxp://huehnerauge-entfernen.de
hxxp://verbisonline.com
hxxp://love30-chanko.com
hxxp://lapinlviasennus.fi
hxxp://opatrovanie-ako.sk
hxxp://julis-lsa.de
hxxp://asteriag.com
hxxp://cafemattmeera.com
hxxp://pubweb.carnet.hr
hxxp://blumenhof-wegleitner.at
hxxp://knowledgemuseumbd.com
hxxp://lebellevue.fr
hxxp://officehymy.com
hxxp://leather-factory.co.jp
hxxp://kedak.de
hxxp://kikedeoliveira.com
hxxp://wacochamber.com
hxxp://theadventureedge.com
hxxp://flexicloud.hk
hxxp://baptisttabernacle.com
hxxp://uranus.nl
hxxp://rota-installations.co.uk
hxxp://i-trust.dk
hxxp://xtptrack.com

--

--

Vishal Thakur

DFIR enthusiast. Founder of HCKSYD. Founder of Security BSides Sydney Australia. Malware Analyst.