Home/APT41/IOCs
IOCs

Indicators for APT41

1,677 indicators · scoped to malware families · back to APT41
Live IOCs from URLhaus, ThreatFox, MalwareBazaar, and abuse.ch SSLBL for malware families this actor uses. All indicators are defanged for safe handling.

Indicators

100 of 1,677
ip:port
106[.]52[.]208[.]143:443
family Cobalt Strike source threatfox
ip:port
106[.]13[.]137[.]229:443
family Cobalt Strike source threatfox
ip:port
101[.]43[.]2[.]116:443
family Cobalt Strike source threatfox
ip:port
101[.]133[.]148[.]66:443
family Cobalt Strike source threatfox
ip:port
115[.]190[.]178[.]249:443
family Cobalt Strike source threatfox
ip:port
114[.]132[.]150[.]96:443
family Cobalt Strike source threatfox
ip:port
110[.]40[.]176[.]194:443
family Cobalt Strike source threatfox
ip:port
120[.]48[.]50[.]33:443
family Cobalt Strike source threatfox
ip:port
117[.]72[.]214[.]50:443
family Cobalt Strike source threatfox
ip:port
124[.]223[.]199[.]39:443
family Cobalt Strike source threatfox
ip:port
124[.]221[.]32[.]87:443
family Cobalt Strike source threatfox
ip:port
124[.]220[.]48[.]168:443
family Cobalt Strike source threatfox
ip:port
124[.]220[.]164[.]98:443
family Cobalt Strike source threatfox
ip:port
121[.]41[.]167[.]80:443
family Cobalt Strike source threatfox
ip:port
152[.]136[.]139[.]105:443
family Cobalt Strike source threatfox
ip:port
129[.]204[.]103[.]151:443
family Cobalt Strike source threatfox
ip:port
124[.]223[.]47[.]219:443
family Cobalt Strike source threatfox
ip:port
172[.]245[.]215[.]43:443
family Cobalt Strike source threatfox
ip:port
165[.]154[.]125[.]212:443
family Cobalt Strike source threatfox
ip:port
156[.]233[.]233[.]134:443
family Cobalt Strike source threatfox
ip:port
154[.]201[.]91[.]224:443
family Cobalt Strike source threatfox
ip:port
38[.]190[.]224[.]63:443
family Cobalt Strike source threatfox
ip:port
222[.]255[.]214[.]236:443
family Cobalt Strike source threatfox
ip:port
192[.]252[.]187[.]60:443
family Cobalt Strike source threatfox
ip:port
178[.]16[.]52[.]194:443
family Cobalt Strike source threatfox
ip:port
43[.]139[.]146[.]100:443
family Cobalt Strike source threatfox
ip:port
43[.]133[.]41[.]106:443
family Cobalt Strike source threatfox
ip:port
42[.]192[.]49[.]72:443
family Cobalt Strike source threatfox
ip:port
39[.]107[.]85[.]83:443
family Cobalt Strike source threatfox
ip:port
39[.]106[.]144[.]162:443
family Cobalt Strike source threatfox
ip:port
47[.]100[.]168[.]4:443
family Cobalt Strike source threatfox
ip:port
43[.]139[.]169[.]60:443
family Cobalt Strike source threatfox
ip:port
47[.]111[.]146[.]110:443
family Cobalt Strike source threatfox
ip:port
47[.]243[.]175[.]24:443
family Cobalt Strike source threatfox
ip:port
47[.]239[.]188[.]48:443
family Cobalt Strike source threatfox
ip:port
47[.]122[.]30[.]177:443
family Cobalt Strike source threatfox
ip:port
47[.]122[.]1[.]243:443
family Cobalt Strike source threatfox
ip:port
61[.]166[.]154[.]109:443
family Cobalt Strike source threatfox
ip:port
49[.]235[.]177[.]231:443
family Cobalt Strike source threatfox
ip:port
81[.]70[.]255[.]195:443
family Cobalt Strike source threatfox
ip:port
81[.]69[.]98[.]230:443
family Cobalt Strike source threatfox
ip:port
8[.]210[.]78[.]137:443
family Cobalt Strike source threatfox
ip:port
83[.]229[.]126[.]65:443
family Cobalt Strike source threatfox
ip:port
81[.]71[.]159[.]99:443
family Cobalt Strike source threatfox
ip:port
83[.]229[.]123[.]61:443
family Cobalt Strike source threatfox
ip:port
83[.]229[.]126[.]183:443
family Cobalt Strike source threatfox
ip:port
8[.]153[.]205[.]30:443
family Cobalt Strike source threatfox
ip:port
8[.]137[.]149[.]67:443
family Cobalt Strike source threatfox
ip:port
47[.]93[.]28[.]103:443
family Cobalt Strike source threatfox
ip:port
60[.]205[.]139[.]210:443
family Cobalt Strike source threatfox
domain
lcowpowerlite[.]italynorth[.]cloudapp[.]azure[.]com
family Cobalt Strike source threatfox
ip:port
47[.]109[.]198[.]8:443
family Cobalt Strike source threatfox
ip:port
47[.]120[.]70[.]161:443
family Cobalt Strike source threatfox
ip:port
47[.]121[.]137[.]8:443
family Cobalt Strike source threatfox
ip:port
47[.]121[.]29[.]60:443
family Cobalt Strike source threatfox
ip:port
45[.]115[.]236[.]152:443
family Cobalt Strike source threatfox
ip:port
47[.]107[.]136[.]106:443
family Cobalt Strike source threatfox
ip:port
47[.]109[.]145[.]121:443
family Cobalt Strike source threatfox
ip:port
192[.]140[.]176[.]79:443
family Cobalt Strike source threatfox
ip:port
36[.]140[.]162[.]173:443
family Cobalt Strike source threatfox
ip:port
39[.]105[.]165[.]37:443
family Cobalt Strike source threatfox
ip:port
152[.]32[.]251[.]78:443
family Cobalt Strike source threatfox
ip:port
154[.]201[.]74[.]112:443
family Cobalt Strike source threatfox
ip:port
179[.]43[.]186[.]214:443
family Cobalt Strike source threatfox
ip:port
139[.]196[.]41[.]201:443
family Cobalt Strike source threatfox
ip:port
139[.]224[.]16[.]185:443
family Cobalt Strike source threatfox
ip:port
14[.]103[.]175[.]50:443
family Cobalt Strike source threatfox
ip:port
150[.]187[.]25[.]242:443
family Cobalt Strike source threatfox
ip:port
120[.]48[.]168[.]57:443
family Cobalt Strike source threatfox
ip:port
121[.]40[.]18[.]128:443
family Cobalt Strike source threatfox
ip:port
122[.]51[.]93[.]94:443
family Cobalt Strike source threatfox
ip:port
134[.]122[.]140[.]185:443
family Cobalt Strike source threatfox
ip:port
117[.]72[.]102[.]110:443
family Cobalt Strike source threatfox
ip:port
117[.]72[.]242[.]9:443
family Cobalt Strike source threatfox
ip:port
113[.]44[.]67[.]52:443
family Cobalt Strike source threatfox
ip:port
115[.]190[.]161[.]178:443
family Cobalt Strike source threatfox
ip:port
106[.]38[.]201[.]95:443
family Cobalt Strike source threatfox
ip:port
106[.]75[.]162[.]108:443
family Cobalt Strike source threatfox
ip:port
106[.]75[.]215[.]96:443
family Cobalt Strike source threatfox
ip:port
106[.]75[.]224[.]31:443
family Cobalt Strike source threatfox
ip:port
106[.]12[.]219[.]245:443
family Cobalt Strike source threatfox
ip:port
106[.]13[.]29[.]104:443
family Cobalt Strike source threatfox
ip:port
47[.]239[.]230[.]84:20000
family Cobalt Strike source threatfox
ip:port
149[.]129[.]37[.]105:30002
family Cobalt Strike source threatfox
ip:port
192[.]140[.]176[.]79:12124
family Cobalt Strike source threatfox
ip:port
107[.]150[.]105[.]91:443
family Cobalt Strike source threatfox
ip:port
111[.]92[.]243[.]40:443
family Cobalt Strike source threatfox
ip:port
106[.]12[.]219[.]245:8072
family Cobalt Strike source threatfox
ip:port
47[.]120[.]46[.]230:443
family Cobalt Strike source threatfox
ip:port
121[.]40[.]37[.]253:50059
family Cobalt Strike source threatfox
ip:port
167[.]179[.]76[.]179:53
family Cobalt Strike source threatfox
domain
ns1[.]ns-apache[.]jo3[.]org
family Cobalt Strike source threatfox
ip:port
223[.]26[.]63[.]57:443
family Cobalt Strike source threatfox
ip:port
47[.]120[.]32[.]72:8075
family Cobalt Strike source threatfox
ip:port
121[.]4[.]92[.]72:5000
family Cobalt Strike source threatfox
ip:port
179[.]43[.]189[.]17:9443
family Cobalt Strike source threatfox
ip:port
113[.]250[.]188[.]15:8078
family Cobalt Strike source threatfox
ip:port
139[.]196[.]41[.]201:30001
family Cobalt Strike source threatfox
ip:port
117[.]72[.]178[.]246:4848
family Cobalt Strike source threatfox
ip:port
47[.]98[.]253[.]102:80
family Cobalt Strike source threatfox
Showing 401-500 of 1,677
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin