xuluxetas.com
Classification: Malicious
xuluxetas.com is a malicious hostname. Linked to Cobalt Strike malware. Reported by 1 threat source, last seen 2022-10-15.
Current activity
- Offline — no longer resolving. Last online 2023-10-07 21:26:29.
- Command & Control server — Used by cybercriminals to control victim computers.
MITRE ATT&CK associations
Malware families: COBALT STRIKE (S0154)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Cobalt Strike | ThreatFox Abuse.ch | 2022-10-03 21:18:55 | 2022-10-15 19:26:52 | malicious-activity | S0154 Cobalt Strike |
Tags
cobaltstrike leaseweb-usa-nyc agentemis beacon cobeaconIP addresses resolved by this hostname
- 23.19.227.177 (2023-07-26 22:19:50)
- 172.233.218.191 (2023-09-10 22:54:00)
- 172.232.4.89 (2023-09-14 23:38:11)
- 172.232.25.17 (2023-09-17 05:48:39)
- 172.234.26.236 (2023-09-24 09:20:48)
- 199.59.243.224 (2023-10-04 14:38:36)
- 172.234.25.151 (2023-10-07 17:02:59)
- 199.59.243.225 (2023-10-07 21:26:29)
Whois information
- AS name
- AS15003 Nobis Technology Group, LLC
- Domain
- xuluxetas.com
- TLD
- com
- First indexed
- 2022-10-03 21:18:55
- Last updated
- 2026-07-17 15:12:33