Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the ninja-forms-zoho-crm domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/scoutdns_226/public/wp-includes/functions.php on line 6121
Kaseya REvil C2 Domain List - ScoutDNS
REvil C2 Domains

Kaseya REvil C2 Domain List

The number of infected devices and networks from the Kaseya REvil supply chain attack continue to mount. We have parsed out the complete list of domains marked as Command and Control from the decrypted JSON config file provided by Fabian Woser.

There are 1223 domains listed in the file. Keep in mind, we cannot confirm that any or all of these hosts are compromised at this time, they are simply pulled from the REvil malware configuration file.

These domains were only recently made aware to the community after the fact. As a result, many were likely not marked as malicious prior. ScoutDNS customers can use domain search to check the past 30 days for any hits from this list.

Is your domain on this list?

If you can verify that your domain/server is not compromised let us know and we may release a second list of sanitized/safe domains.

Cleared Domains

Download the list of previously reported but now cleared domains here

Other Important Links

Official Kasyea detection tool. 

More To Explore

ScoutDNS G2 Spring 24′ Awards

I am pleased to share that G2 has released their Spring 2024 awards for DNS Security products and as a result ScoutDNS has earned 12

Have any questions? Just Ask