CYBERRAKSHAK LABS · DAILY THREAT FEED
Active Threat Indicators — 18 September 2026
Selected indicators from the supplied threat-intelligence feed. Public IOCs are defanged for safe sharing and preserved as searchable HTML text.
13Indicators shown
100/100Source confidence shown
CriticalSource severity
C2 / BotnetPrimary threat context
Today's Active IoC Feed
Scrollable table · 13 selected indicators
The 100/100 value reflects source confidence and is not an independently calculated CyberRakshakLabs threat score.
| IoC | Severity | Confidence | Involved Threat Type | Brief Attack Description |
|---|---|---|---|---|
queue[.]fastclimate[.]click | Critical | 100/100 | Botnet / C2 | Feed-classified botnet/C2 infrastructure. A matching connection should be reviewed in DNS, proxy and endpoint telemetry. |
tndr-panel[.]online | Critical | 100/100 | Botnet / C2 | Feed-classified botnet/C2 domain. Investigate internal systems communicating with the indicator. |
hxxps://tndr-panel[.]online/api[.]php | Critical | 100/100 | Botnet / C2 URL | Reported as part of the botnet/C2 infrastructure. Review network telemetry for access to the endpoint. |
foldludge[.]xyz | Critical | 100/100 | Botnet / C2 | Feed-classified botnet/C2 infrastructure carrying an OffLoader-related tag. |
rmm[.]smartscreen[.]lifestyle | Critical | 100/100 | Botnet / C2 | Feed-classified botnet/C2 infrastructure carrying MiniRMM/RMM-related tags. |
39[.]100[.]66[.]238:81 | Critical | 100/100 | Botnet / C2 | IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed. |
117[.]72[.]202[.]154:80 | Critical | 100/100 | Botnet / C2 | IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed. |
103[.]117[.]137[.]230:9999 | Critical | 100/100 | Botnet / C2 | IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed. |
121[.]43[.]194[.]200:8080 | Critical | 100/100 | Botnet / C2 | IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed. |
hxxps://vmi3554101[.]contaboserver[.]net/… | Critical | 100/100 | Payload Delivery | Visible feed entry is associated with payload-delivery activity and carries Grandoreiro/MEX tags. The original URL is truncated in the supplied screenshot. |
47[.]243[.]191[.]83:88 | Critical | 100/100 | Botnet / C2 | IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed. |
144[.]225[.]246[.]14:80 | Critical | 100/100 | Botnet / C2 | IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed. |
144[.]225[.]246[.]14:443 | Critical | 100/100 | Botnet / C2 | IP and port classified as botnet/C2 infrastructure with Cobalt Strike-related information in the supplied feed. |
No matching indicators found.
Defensive Recommendations
- Search DNS, proxy, firewall and endpoint telemetry for matches.
- Investigate systems that communicated with a matching indicator.
- Block confirmed malicious indicators according to your security policy.
- Review endpoint processes, persistence and outbound connections after a confirmed match.
Source & Methodology
Source: supplied threat-intelligence feed screenshot. Descriptions are limited to information visible in the supplied data. No unsupported threat-actor attribution has been added.
Indicators are defanged and published as HTML so security teams and search engines can discover the textual intelligence.