IOCs

Indicators for Bumblebee Operators / EXOTIC LILY

180 indicators · scoped to malware families · back to Bumblebee Operators / EXOTIC LILY
Live IOCs from URLhaus, ThreatFox, MalwareBazaar, and abuse.ch SSLBL for malware families this actor uses. All indicators are defanged for safe handling.

Indicators

100 of 180
url
hxxp://5.180.253.105:8000/beacon.exe
family Sliver source urlhaus first seen 2026-06-02 15:45:44 UTC
url
hxxp://46.8.226.70/sliver_implant.exe
family Sliver source urlhaus first seen 2026-06-02 15:45:27 UTC
url
hxxp://46.8.226.70/implant_http.exe
family Sliver source urlhaus first seen 2026-06-02 15:45:27 UTC
url
hxxp://46.8.226.70/implant_linux
family Sliver source urlhaus first seen 2026-06-02 15:45:25 UTC
url
hxxps://167.250.49.155/bin/x64/mimidrv.sys
family mimikatz source urlhaus first seen 2026-05-30T19:39:41Z
url
hxxps://167.250.49.155/bin/mimikatz.exe
family mimikatz source urlhaus first seen 2026-05-30T19:39:41Z
url
hxxps://167.250.49.155/bin/Win32/mimilib.dll
family mimikatz source urlhaus first seen 2026-05-30T19:39:41Z
url
hxxps://167.250.49.155/bin/Win32/mimidrv.sys
family mimikatz source urlhaus first seen 2026-05-30T19:39:41Z
url
hxxp://167.250.49.155/bin/mimikatz.exe
family mimikatz source urlhaus first seen 2026-05-30T19:39:41Z
url
hxxp://167.250.49.155/bin/x64/mimilib.dll
family mimikatz source urlhaus first seen 2026-05-30T19:39:41Z
url
hxxp://167.250.49.155/bin/Win32/mimidrv.sys
family mimikatz source urlhaus first seen 2026-05-30T19:39:41Z
url
hxxp://167.250.49.155/bin/Win32/mimispool.dll
family mimikatz source urlhaus first seen 2026-05-30T19:39:41Z
url
hxxp://167.250.49.155/bin/Win32/mimilib.dll
family mimikatz source urlhaus first seen 2026-05-30T19:39:41Z
url
hxxp://167.148.183.75:8000/test.exe
family Sliver source urlhaus first seen 2026-03-26 15:33:38 UTC
url
hxxp://167.148.183.75:8000/setup.exe
family Sliver source urlhaus first seen 2026-03-26 15:33:34 UTC
url
hxxp://188.166.173.36:8090/beacon_for_109.exe
family Sliver source urlhaus first seen 2026-03-26 15:32:29 UTC
url
hxxp://188.166.173.36:8090/upx_beacon.exe
family Sliver source urlhaus first seen 2026-03-26 15:32:17 UTC
url
hxxp://165.232.186.159:9000/Desktop/sys.exe
family Sliver source urlhaus first seen 2026-03-10 19:41:13 UTC
url
hxxp://162.212.153.138:8080/sliver-client_linux-amd64
family Sliver source urlhaus first seen 2026-03-01 07:43:20 UTC
url
hxxp://195.16.44.75:8080/DavRelayUp.exe
family mimikatz source urlhaus first seen 2026-02-23 07:12:17 UTC
url
hxxps://github.com/MisterLobster22/mimik/blob/main/mimikatz.exe?raw=true
family mimikatz source urlhaus first seen 2025-04-11 06:24:06 UTC
url
hxxp://92.127.156.174:8880/master.exe
family mimikatz source urlhaus first seen 2024-12-17 07:01:27 UTC
url
hxxps://167.250.49.155/bin/Win32/mimikatz.exe
family mimikatz source urlhaus first seen 2024-12-17 07:01:24 UTC
url
hxxps://codeload.github.com/54N4L/mimikatzWindows/zip/refs/heads/master
family mimikatz source urlhaus first seen 2024-12-06 14:08:25 UTC
url
hxxps://raw.githubusercontent.com/khangdz1801/raw/refs/heads/main/sound.exe
family Sliver source urlhaus first seen 2024-12-03 11:15:36 UTC
url
hxxp://167.250.49.155/bin/x64/mimispool.dll
family mimikatz source urlhaus first seen 2024-07-19 09:05:06 UTC
sslbl_sha1
1bd1fee41dac6fda021becc6ed67c26e7e7315ed
family Sliver source sslbl first seen 2024-07-11 07:15:27
ip:port
46[.]8[.]226[.]70:31337
family Sliver source threatfox
ip:port
46[.]8[.]226[.]70:443
family Sliver source threatfox
ip:port
45[.]142[.]107[.]41:1030
family Sliver source threatfox
ip:port
45[.]142[.]107[.]41:31337
family Sliver source threatfox
ip:port
207[.]148[.]2[.]115:60060
family Sliver source threatfox
ip:port
207[.]148[.]2[.]115:60061
family Sliver source threatfox
ip:port
64[.]23[.]231[.]32:9001
family Sliver source threatfox
ip:port
57[.]158[.]27[.]132:8080
family Sliver source threatfox
ip:port
82[.]165[.]79[.]60:31337
family Sliver source threatfox
ip:port
82[.]165[.]79[.]60:1337
family Sliver source threatfox
ip:port
103[.]110[.]65[.]166:52223
family Sliver source threatfox
ip:port
3[.]19[.]238[.]211:31337
family Sliver source threatfox
ip:port
103[.]140[.]238[.]45:8887
family Sliver source threatfox
ip:port
103[.]140[.]238[.]45:8888
family Sliver source threatfox
ip:port
103[.]140[.]238[.]45:31337
family Sliver source threatfox
ip:port
57[.]158[.]27[.]132:31337
family Sliver source threatfox
ip:port
64[.]23[.]231[.]32:31337
family Sliver source threatfox
ip:port
122[.]114[.]10[.]199:443
family Sliver source threatfox
ip:port
122[.]114[.]10[.]199:8001
family Sliver source threatfox
ip:port
103[.]110[.]65[.]166:443
family Sliver source threatfox
ip:port
159[.]223[.]0[.]103:31337
family Sliver source threatfox
ip:port
3[.]19[.]238[.]211:443
family Sliver source threatfox
ip:port
8[.]216[.]80[.]229:443
family Sliver source threatfox
ip:port
167[.]99[.]51[.]2:31337
family Sliver source threatfox
ip:port
167[.]99[.]51[.]2:443
family Sliver source threatfox
ip:port
8[.]216[.]80[.]229:31337
family Sliver source threatfox
ip:port
167[.]71[.]13[.]103:31337
family Sliver source threatfox
ip:port
167[.]71[.]13[.]103:443
family Sliver source threatfox
ip:port
91[.]199[.]154[.]103:443
family Sliver source threatfox
ip:port
146[.]70[.]158[.]198:31337
family Sliver source threatfox
ip:port
146[.]70[.]158[.]198:443
family Sliver source threatfox
ip:port
91[.]199[.]154[.]103:34211
family Sliver source threatfox
ip:port
143[.]110[.]151[.]209:443
family Sliver source threatfox
ip:port
143[.]110[.]151[.]209:31337
family Sliver source threatfox
ip:port
172[.]245[.]185[.]195:9988
family Sliver source threatfox
ip:port
46[.]8[.]226[.]70:80
family Sliver source threatfox
ip:port
5[.]180[.]253[.]105:8000
family Sliver source threatfox
ip:port
24[.]12[.]218[.]134:9090
family Sliver source threatfox
ip:port
185[.]246[.]223[.]72:5000
family Sliver source threatfox
ip:port
165[.]245[.]181[.]147:8000
family Sliver source threatfox
ip:port
164[.]90[.]231[.]249:31337
family Sliver source threatfox
ip:port
173[.]254[.]211[.]245:31337
family Sliver source threatfox
ip:port
157[.]245[.]235[.]51:31337
family Sliver source threatfox
ip:port
82[.]153[.]138[.]218:31337
family Sliver source threatfox
ip:port
217[.]60[.]248[.]115:31337
family Sliver source threatfox
ip:port
117[.]148[.]177[.]48:31337
family Sliver source threatfox
ip:port
38[.]242[.]215[.]217:31337
family Sliver source threatfox
ip:port
77[.]111[.]101[.]101:31337
family Sliver source threatfox
ip:port
163[.]123[.]183[.]125:443
family Sliver source threatfox
ip:port
13[.]222[.]116[.]11:31337
family Sliver source threatfox
ip:port
169[.]40[.]135[.]133:31337
family Sliver source threatfox
ip:port
120[.]53[.]244[.]68:31337
family Sliver source threatfox
ip:port
42[.]193[.]120[.]28:31337
family Sliver source threatfox
ip:port
31[.]204[.]128[.]108:31337
family Sliver source threatfox
ip:port
107[.]174[.]64[.]130:31337
family Sliver source threatfox
ip:port
37[.]60[.]231[.]121:31337
family Sliver source threatfox
ip:port
38[.]242[.]227[.]177:31337
family Sliver source threatfox
ip:port
188[.]244[.]117[.]112:31337
family Sliver source threatfox
ip:port
147[.]45[.]60[.]103:31337
family Sliver source threatfox
ip:port
204[.]168[.]210[.]199:31337
family Sliver source threatfox
ip:port
192[.]210[.]193[.]106:31337
family Sliver source threatfox
ip:port
89[.]125[.]255[.]44:31337
family Sliver source threatfox
ip:port
134[.]199[.]231[.]101:31337
family Sliver source threatfox
ip:port
143[.]244[.]208[.]126:31337
family Sliver source threatfox
ip:port
5[.]180[.]253[.]105:31337
family Sliver source threatfox
ip:port
45[.]77[.]13[.]129:31337
family Sliver source threatfox
ip:port
157[.]245[.]101[.]92:31337
family Sliver source threatfox
ip:port
158[.]178[.]141[.]79:31337
family Sliver source threatfox
ip:port
104[.]251[.]180[.]167:31337
family Sliver source threatfox
ip:port
143[.]198[.]183[.]46:31337
family Sliver source threatfox
ip:port
38[.]109[.]11[.]65:31337
family Sliver source threatfox
ip:port
64[.]225[.]49[.]99:31337
family Sliver source threatfox
ip:port
172[.]236[.]10[.]230:31337
family Sliver source threatfox
Showing 1-100 of 180
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin