CYBERRAKSHAK LABS · DAILY THREAT FEED

Active Threat Indicators — 18 September 2026

Selected indicators from the supplied threat-intelligence feed. Public IOCs are defanged for safe sharing and preserved as searchable HTML text.

13Indicators shown
100/100Source confidence shown
CriticalSource severity
C2 / BotnetPrimary threat context

Today's Active IoC Feed

Scrollable table · 13 selected indicators

The 100/100 value reflects source confidence and is not an independently calculated CyberRakshakLabs threat score.

IoCSeverityConfidenceInvolved Threat TypeBrief Attack Description
queue[.]fastclimate[.]clickCritical100/100Botnet / C2Feed-classified botnet/C2 infrastructure. A matching connection should be reviewed in DNS, proxy and endpoint telemetry.
tndr-panel[.]onlineCritical100/100Botnet / C2Feed-classified botnet/C2 domain. Investigate internal systems communicating with the indicator.
hxxps://tndr-panel[.]online/api[.]phpCritical100/100Botnet / C2 URLReported as part of the botnet/C2 infrastructure. Review network telemetry for access to the endpoint.
foldludge[.]xyzCritical100/100Botnet / C2Feed-classified botnet/C2 infrastructure carrying an OffLoader-related tag.
rmm[.]smartscreen[.]lifestyleCritical100/100Botnet / C2Feed-classified botnet/C2 infrastructure carrying MiniRMM/RMM-related tags.
39[.]100[.]66[.]238:81Critical100/100Botnet / C2IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed.
117[.]72[.]202[.]154:80Critical100/100Botnet / C2IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed.
103[.]117[.]137[.]230:9999Critical100/100Botnet / C2IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed.
121[.]43[.]194[.]200:8080Critical100/100Botnet / C2IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed.
hxxps://vmi3554101[.]contaboserver[.]net/…Critical100/100Payload DeliveryVisible feed entry is associated with payload-delivery activity and carries Grandoreiro/MEX tags. The original URL is truncated in the supplied screenshot.
47[.]243[.]191[.]83:88Critical100/100Botnet / C2IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed.
144[.]225[.]246[.]14:80Critical100/100Botnet / C2IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed.
144[.]225[.]246[.]14:443Critical100/100Botnet / C2IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed.
No matching indicators found.

Defensive Recommendations

  • Search DNS, proxy, firewall and endpoint telemetry for matches.
  • Investigate systems that communicated with a matching indicator.
  • Block confirmed malicious indicators according to your security policy.
  • Review endpoint processes, persistence and outbound connections after a confirmed match.

Source & Methodology

Source: supplied threat-intelligence feed screenshot. Descriptions are limited to information visible in the supplied data. No unsupported threat-actor attribution has been added.

Indicators are defanged and published as HTML so security teams and search engines can discover the textual intelligence.