{"type":"bundle","id":"bundle--6e130e39-4ff8-42e3-a867-f928190afb1b","objects":[{"type":"identity","spec_version":"2.1","id":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","created":"2026-09-16T10:08:17.489Z","modified":"2026-09-16T10:08:17.489Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--920fd983-6501-4878-9b85-6258eeec30ba","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 154.36.188.201","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: ed process handling. The recovered configuration pointed to 154.36.188.201:4449 and identified the implant as Venom RAT + HVNC + Steal","pattern":"[ipv4-addr:value = '154.36.188.201']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--148173d3-344f-4b5c-945d-1f536edcfa10","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 155.94.154.195","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth hos","pattern":"[ipv4-addr:value = '155.94.154.195']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3365356e-c798-427b-867a-eab16f578cc7","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 104.194.9.138","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 5c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a succes","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--489c178d-bb7d-4fd6-8c96-f782f7c1e3ce","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 114.10.43.203","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 0 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attac","pattern":"[ipv4-addr:value = '114.10.43.203']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--295ceff1-47e1-4dd2-9a80-80aa45e57172","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 187.75.114.36","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack pe","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9fc89017-4d79-474c-9f07-3dabab41b90d","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 23.137.105.214","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 41.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe71c2e7-f8b3-49f9-903f-332d74fe7939","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 23.180.120.140","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: .129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Be","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--36da2b0e-ebef-4f46-8e68-256925b18a38","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 31.59.129.150","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.1","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7dbcbb12-08f4-478f-ad8e-067c30913dd0","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 37.114.144.209","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 14 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacker to upload a","pattern":"[ipv4-addr:value = '37.114.144.209']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--86ce151b-78cc-4ff1-a738-baf6c0d03e4a","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 6.17.4.1","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: the plugin, has addressed the flaws in version 6.17.3.1 and 6.17.4.1, respectively. Found this article interesting? Follow us on","pattern":"[ipv4-addr:value = '6.17.4.1']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--98a0fb3b-737c-4048-9f41-16cd0b490ba7","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 92.241.13.140","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: dresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 1","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--319ea97a-665d-4c91-b44c-17dc6fe7050f","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 92.241.13.213","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: attempts have originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.10","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--800ad0b8-2f8f-466e-a738-c278b73c228b","created":"2026-09-15T14:45:10.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers target WordPress sites via third-party WooCommerce plugin\" (BleepingComputer). Context: aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload v","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T14:45:10.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4966a8af-50e9-49bd-a1dc-e2c4b08108b8","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentio","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3dfbbd99-29cb-40b1-93ed-dee325c1a7aa","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: .13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged (","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--265fe90a-7c07-445b-95ec-060ee4080073","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 o","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c9a2431-de85-46d7-bca3-f3e19e6e872b","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP a","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--64567375-087f-4fbb-a57a-e64784476595","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and doma","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8bfe0d2-4305-43c0-8316-4b2452ab308f","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, fo","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9334a80e-820a-4748-8941-71bb471ef39c","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b893b26-abb3-4379-a9c1-2f09d8de9a15","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 bl","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f1355002-9bac-48c1-b02e-5b4abf660671","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requests","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2555594d-3620-4772-8bc7-d96f079dd01e","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 114.10.43.203","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests I","pattern":"[ipv4-addr:value = '114.10.43.203']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--96cc7b7d-c0f5-42c4-b22e-17c3b20d454b","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests I","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dc26a7ce-77d4-4c37-a48e-9906cc6e33ba","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requests","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4f148f00-17ae-4947-91f1-15db2eea36df","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requests","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e8b48ba8-5637-4d5f-b690-634a6740a398","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit request","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--459f6a5f-6ca8-4874-ba3f-859fb69ff4ea","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 37.114.144.209","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests F","pattern":"[ipv4-addr:value = '37.114.144.209']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f124aa67-f507-4692-82a1-50289c03bc10","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requests","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97311913-8e36-4a9f-9402-812157e12f15","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:08:17.489Z","created_by_ref":"identity--77029375-bc8a-46c1-813c-782c4e5234a4","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit request","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]}]}