PULSE NAME
Oz Batch: 50 IOCs (avg BDE: 85)
WHITE pduggusa 2026-02-01 Modified: 2026-03-03
26
IOCs
MEDIUM VOLUME
**Pulse Description:** This pulse identifies 50 indicators associated with various C2 frameworks, including XWorm, Sliver, Koi Loader, and NjRAT, with an average BDE (Big Data analytics Energy) Score of 85. While specific countries weren't noted, the presence of these frameworks often correlates with threat actors operating from regions such as China or Russia, frequently utilizing ISPs known for hosting malicious activities. Security teams should stay vigilant against these threats, particularly in relation to MITRE ATT&CK techniques like "Command and Control" (T1071). BDE Score: 85, Detection Timestamp: [insert timestamp here]
Indicators of Compromise (26)
All hostname domain
TYPEINDICATORDESCRIPTIONCREATED
hostname r7j-44928.portmap.host BDE: 85 2026-02-01
hostname chromewi99000-49071.portmap.host BDE: 85 2026-02-01
hostname r8bw6dylh.localto.net BDE: 85 2026-02-01
hostname nightspace-57464.portmap.host BDE: 85 2026-02-01
hostname yov1os2mn.localto.net BDE: 85 2026-02-01
hostname inn-ht.gl.at.ply.gg BDE: 85 2026-02-01
hostname yoenacevedo7-38238.portmap.host BDE: 85 2026-02-01
domain telephoned.su BDE: 85 2026-02-01
domain gaphmxpa.cyou BDE: 85 2026-02-01
domain shorted.cyou BDE: 85 2026-02-01
domain yelloww.cyou BDE: 85 2026-02-01
domain scirpvu.cyou BDE: 85 2026-02-01
domain garnevf.cyou BDE: 85 2026-02-01
domain elmtrce.cyou BDE: 85 2026-02-01
domain liliiqo.cyou BDE: 85 2026-02-01
domain diffusn.cyou BDE: 85 2026-02-01
domain offdutd.cyou BDE: 85 2026-02-01
domain adm-toolkit.live BDE: 85 2026-02-01
domain foodservicer.com BDE: 85 2026-02-01
domain cloudboxmac.com BDE: 85 2026-02-01
domain driveport38.com BDE: 85 2026-02-01
domain fastsendportal02.com BDE: 85 2026-02-01
hostname yoenacevedo7-52605.portmap.host BDE: 85 2026-02-01
hostname defender.ydns.eu BDE: 85 2026-02-01
domain transfernow.website BDE: 85 2026-02-01
hostname www.scholze.family BDE: 85 2026-02-01