PULSE NAME
Oz Batch: 50 IOCs (avg BDE: 85)
WHITE pduggusa 2026-01-25 Modified: 2026-02-24
29
IOCs
MEDIUM VOLUME
**OTX Pulse Description:** This pulse identifies 50 indicators associated with various C2 frameworks including Meterpreter, Vidar, and DeimosC2, which are linked to potential exfiltration and control activities. The average BDE (Big Data analytics Energy) score of 85 suggests a high level of threat sophistication, but no specific adversary has been identified at this time. Security teams should monitor for abnormal behaviors indicative of these frameworks and consider MITRE ATT&CK techniques such as T1071 (Application Layer Protocol) for further analysis. BDE Score: 85, Detection Timestamp: [Insert Current Timestamp].
Indicators of Compromise (29)
All hostname domain FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
hostname www.lyra-connect.us BDE: 85 2026-01-25
hostname www.lyraconnect.xyz BDE: 85 2026-01-25
hostname 51b7d1a091.nxcli.net BDE: 85 2026-01-25
hostname acc.ottobarkhuis.nl BDE: 85 2026-01-25
domain 812blog.com BDE: 85 2026-01-25
hostname barricrafts.sidechain.es BDE: 85 2026-01-25
domain binbinartgallery.com BDE: 85 2026-01-25
hostname blagoveshchensk.logomebel.ru BDE: 85 2026-01-25
domain bibianaalves.com.br BDE: 85 2026-01-25
hostname blog.infogenius.fr BDE: 85 2026-01-25
domain jaskolkki.com BDE: 85 2026-01-25
domain homencck.com BDE: 85 2026-01-25
domain helsibreak.com BDE: 85 2026-01-25
domain elimnasir.com BDE: 85 2026-01-25
hostname blog.kevoxtech.com BDE: 85 2026-01-25
hostname cbb.borendrokontho.com BDE: 85 2026-01-25
hostname cbb.lidiia.com.ua BDE: 85 2026-01-25
FileHash-SHA256 179491983dccbc70ff193275063377b1908fd5b375bbe1bacae8972fd71a4279 BDE: 85 2026-01-25
hostname hl2k-32291.portmap.host BDE: 85 2026-01-25
hostname western-willow.gl.at.ply.gg BDE: 85 2026-01-25
hostname sdfgfhj.ddns.net BDE: 85 2026-01-25
hostname dmkuswt341-49475.portmap.host BDE: 85 2026-01-25
hostname dvd-directly.gl.at.ply.gg BDE: 85 2026-01-25
hostname karlinhosdauva-30182.portmap.host BDE: 85 2026-01-25
hostname conference-protect.gl.at.ply.gg BDE: 85 2026-01-25
hostname goodnessger-50564.portmap.host BDE: 85 2026-01-25
domain bemuseqy.cyou BDE: 85 2026-01-25
domain capitamx.cyou BDE: 85 2026-01-25
domain personrg.cyou BDE: 85 2026-01-25