donut_injector
Malware Family8 indicators of compromise attributed to donut_injector across abuse.ch threat intelligence feeds.
Domains
5
IPs
2
URLs
0
Hashes
1
Download indicators
Indicator lists for this family. Free and anonymous downloads are a 10% sample.
Need continuous updates instead of static lists? The same IOCs ship in the STIX/TAXII threat feed, ready for OpenCTI and MISP.
Threat types
Botnet C&CpayloadPayload Delivery
Sample indicators
| Indicator | Type |
|---|---|
| opendocumentonline.com | domain |
| adhaehaht-42050.portmap.host | domain |
| vrstudio.life | domain |
| gamestudio.life | domain |
| senterprise2026.com | domain |
| 38.45.126.243 | ip |
| 118.107.29.135 | ip |
| 4acd7adff5c2193e7b0b9a6f8235534d67772ff3d7fa59b1215de011d7455ad9 | hash |
Another file to check? Run a file hash reputation check.