{"type":"bundle","id":"bundle--7cbbdb0c-0a92-432e-b01d-29d6688e1812","objects":[{"type":"identity","spec_version":"2.1","id":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","created":"2026-09-15T22:16:20.082Z","modified":"2026-09-15T22:16:20.082Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--39febb0f-ea54-4173-9be9-4d48d0b6cd65","created":"2026-09-15T14:45:10.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers target WordPress sites via third-party WooCommerce plugin\" (BleepingComputer). Context: aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload v","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T14:45:10.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9cda135c-87a1-4686-b137-47cb54c4e872","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentio","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7dfa63dd-b3f7-47f3-bda0-961bdb086fcd","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: .13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged (","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--017478d5-6ccc-48e3-8724-9a8674df2fd9","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 o","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--602d2b23-0b3b-4065-be38-6f289472600f","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP a","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f137cc66-2bae-4cd1-bd0e-3b3a859cbc09","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and doma","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e2794e5-4e3b-408b-a83c-254b2949a055","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, fo","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a46934c6-2874-4615-be63-5f6f5e65dc55","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e75614e0-6f42-46d1-8672-7ab08accec93","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 bl","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--93b4a994-0be7-472c-8ff2-b0a7b8630d9d","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requests","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7c9b384a-7e8f-47c8-8a54-aa043877926d","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 114.10.43.203","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests I","pattern":"[ipv4-addr:value = '114.10.43.203']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e7448de3-88a7-4004-b456-15c2373a0230","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests I","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d1378e75-5a86-4aeb-b56b-a1c18c636f49","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requests","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e76a4f2-f195-4c36-9519-bedbc0ee15f9","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requests","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8011b66-b360-4065-97f1-dfd244043929","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit request","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--408ef49c-7ef3-47d1-81ba-6d78628df1f7","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 37.114.144.209","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests F","pattern":"[ipv4-addr:value = '37.114.144.209']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--22e4cbea-082e-4e71-87d6-bbd6f58f7169","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requests","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12468b37-3abd-4a15-8cc4-5740e3b44e33","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit request","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2146c00f-e694-403f-9849-24430d096fc6","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 164.90.161.147","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September ma","pattern":"[ipv4-addr:value = '164.90.161.147']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9049b2f2-e396-41be-9ff7-29c7644a9baf","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 165.22.199.85","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration Septemb","pattern":"[ipv4-addr:value = '165.22.199.85']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2eed63b9-992e-4a3a-93e3-6387d2af277f","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 45.94.47.204","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemen","pattern":"[ipv4-addr:value = '45.94.47.204']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8867ba04-8854-48c8-b4bd-e9d1427fa5f5","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 77.91.65.13","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP autho","pattern":"[ipv4-addr:value = '77.91.65.13']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cf5a30bb-2765-4fe8-ba73-4703c83a80ee","created":"2026-09-14T13:33:25.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 89.34.96.56","description":"Seen in \"Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning\" (Cyber Security News). Context: ompromise (IoCs):- Type Indicator Description C2 IP address 89.34.96.56 Hard-coded Cyclops Blink command-and-control server C2 TCP","pattern":"[ipv4-addr:value = '89.34.96.56']","pattern_type":"stix","valid_from":"2026-09-14T13:33:25.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cyclops-blink-evolves/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2809da60-6e5d-4eb6-83b6-26a7ce09e3a7","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 8.218.50.207","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: n Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging server hosted on Alibaba Cloud in Hong Kong Domain","pattern":"[ipv4-addr:value = '8.218.50.207']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cd8aaa83-8f8d-4ab2-9c11-d69636606a11","created":"2026-09-14T09:27:43.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 8.8.8.8","description":"Seen in \"Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities\" (GBHackers). Context: entire framework. The module also uses Google Public DNS at 8.8.8.8 over DNS-over-HTTPS access to resolve transfer-host names,","pattern":"[ipv4-addr:value = '8.8.8.8']","pattern_type":"stix","valid_from":"2026-09-14T09:27:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/cyclops-blink-variant/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d81415a4-b26d-4b8c-a02e-90d02bd51f03","created":"2026-09-10T18:49:43.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 45.142.193.132","description":"Seen in \"Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script\" (The Register · Security). Context: irm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31. “The adversary went from an empty workspace t","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-10T18:49:43.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/10/hundreds-of-ai-agents-helped-papercut-attacker-hit-395-orgs-and-some-went-off-script/5295650"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b5b15cd1-e304-46ca-8c3a-67b52caf80ee","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 1.0.0.1","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: ct() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additiona","pattern":"[ipv4-addr:value = '1.0.0.1']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cf4b4d2a-9b21-4aee-b69d-e12a96df2773","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 109.91.184.21","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known public resolver servi","pattern":"[ipv4-addr:value = '109.91.184.21']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--50a11cf4-ca35-4538-aa43-d11e97c88d02","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 1.1.1.1","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: nal connect() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several","pattern":"[ipv4-addr:value = '1.1.1.1']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--df67f8ba-35e9-4d09-acaa-79e4a937ed7f","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 80.152.203.134","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: ons were public DNS resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known pub","pattern":"[ipv4-addr:value = '80.152.203.134']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b0e7dbac-1da9-4491-b657-43a974bf0994","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 8.8.4.4","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/8","pattern":"[ipv4-addr:value = '8.8.4.4']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b30e77ab-b6b3-425d-a7ae-a5a30917b71e","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 8.8.8.8","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: erified while attempts to reach an external address such as 8.8.8.8 returned Network is unreachable. This design allowed the ma","pattern":"[ipv4-addr:value = '8.8.8.8']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cd377979-d063-4866-b910-f64ee9378f3a","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 9.9.9.10","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: tions included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is commonly asso","pattern":"[ipv4-addr:value = '9.9.9.10']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bb87d6da-a09f-4a5d-9b45-8769fd743dfa","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 9.9.9.9","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is com","pattern":"[ipv4-addr:value = '9.9.9.9']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce8de351-4a9a-4888-b7d0-aba0b1fa5531","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 45.142.193.132","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: he actors utilized infrastructure, including the IP address 45.142.193.132, which GreyNoise had tracked since early July for attacks a","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b59598cd-a609-485f-82e5-859ef959df1d","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 45.158.196.75","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: paign orchestration and execution infrastructure IP address 45.158.196.75 Infrastructure used to execute campaign activity File hash","pattern":"[ipv4-addr:value = '45.158.196.75']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--67006a8c-9a93-4184-a16c-ea2836d52bec","created":"2026-09-09T20:04:27.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 9.20.4.14","description":"Seen in \"Cisco security advisory (AV26-197) – Update 3\" (Canadian Centre for Cyber Security). Context: ewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions U","pattern":"[ipv4-addr:value = '9.20.4.14']","pattern_type":"stix","valid_from":"2026-09-09T20:04:27.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Canadian Centre for Cyber Security","url":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-197"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--acdde232-26b5-4130-9e35-d0aae852150b","created":"2026-09-09T17:46:24.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 62.60.130.193","description":"Seen in \"Scans for Proxmox Servers, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: ll log failed login attempts with a 401 status code: ::ffff:62.60.130.193 - - [09/09/2026:15:26:14 +0000] \"POST /api2/json/access/tic","pattern":"[ipv4-addr:value = '62.60.130.193']","pattern_type":"stix","valid_from":"2026-09-09T17:46:24.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33324"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4665d2ec-ca69-465d-910c-15935d47761d","created":"2026-09-09T14:40:47.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 45.142.193.132","description":"Seen in \"Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide\" (Cyber Security News). Context: nfrastructure. The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for prob","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-09T14:40:47.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papercut-flaws-compromised-using-ai/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b8d9c3ff-cd5f-40d0-a6e8-e575e974a29c","created":"2026-09-09T08:57:51.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 146.103.99.177","description":"Seen in \"Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT\" (GBHackers). Context: Incident responders should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js fil","pattern":"[ipv4-addr:value = '146.103.99.177']","pattern_type":"stix","valid_from":"2026-09-09T08:57:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-critical-fortigate-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--667ca6ed-98df-41e9-af8a-e5fe263cb0ba","created":"2026-09-09T08:57:51.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 46.151.29.58","description":"Seen in \"Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT\" (GBHackers). Context: s should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js files, and review ru","pattern":"[ipv4-addr:value = '46.151.29.58']","pattern_type":"stix","valid_from":"2026-09-09T08:57:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-critical-fortigate-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e09393e2-4cc7-462e-bcae-42035ee1cf30","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 173.212.244.25","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA targets IP address 2","pattern":"[ipv4-addr:value = '173.212.244.25']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--485e0cb3-1e71-4369-b1fa-8b323e37f5ba","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 188.245.99.156","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description IP address 188.245.99.156 Operator host used for rogue Redis replication, command-and","pattern":"[ipv4-addr:value = '188.245.99.156']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ef420ab8-2724-4b2d-b145-d4cc93aa7ff2","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 194.48.248.105","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: Recurring WordPress exploitation target IP address and port 194.48.248.105:8081 Earlier open directory linked by cryptocurrency wallet","pattern":"[ipv4-addr:value = '194.48.248.105']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ab76ec26-07de-4527-a2d6-98e8f5700b2f","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 20.198.10.42","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed develo","pattern":"[ipv4-addr:value = '20.198.10.42']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99a008b8-a7d1-432a-bf2a-e025ad1c39f0","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 213.6.207.123","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: hip unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA tar","pattern":"[ipv4-addr:value = '213.6.207.123']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55156268-8c5d-4cce-a16f-c9e5cc6b612c","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 23.235.223.49","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: 5 Additional observed development and QA targets IP address 23.235.223.49 Recurring WordPress exploitation target IP address and port","pattern":"[ipv4-addr:value = '23.235.223.49']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--321e952b-309c-4df7-9f7b-540a684413f8","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 34.166.99.116","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: eused QA or test target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional","pattern":"[ipv4-addr:value = '34.166.99.116']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9ae6ba79-ca7b-4e65-a6d1-9b6b2c230369","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 45.155.102.89","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: stname> Victim check-in request pattern IP address and port 45.155.102.89:10128 Local mining pool proxy used on the operator host Dom","pattern":"[ipv4-addr:value = '45.155.102.89']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e6a8d7f4-135d-41ec-b344-5f1193bf4895","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 47.250.92.230","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: -controlled hostname resolving to 188.245.99.156 IP address 47.250.92.230 Frequently reused QA or test target, ownership unconfirmed","pattern":"[ipv4-addr:value = '47.250.92.230']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--178713ca-3fcf-4b07-998a-a436ba727c0f","created":"2026-09-09T07:36:49.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 15.1.10.8","description":"Seen in \"F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans\" (The Hacker News). Context: 0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nearly a year old. Ireland's N","pattern":"[ipv4-addr:value = '15.1.10.8']","pattern_type":"stix","valid_from":"2026-09-09T07:36:49.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--463bd2a3-e594-4215-bedd-0478e28ef438","created":"2026-09-09T07:36:49.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 16.1.6.1","description":"Seen in \"F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans\" (The Hacker News). Context: .0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nea","pattern":"[ipv4-addr:value = '16.1.6.1']","pattern_type":"stix","valid_from":"2026-09-09T07:36:49.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9a54c98-0143-4147-a665-7aae7993ba24","created":"2026-09-09T07:36:49.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 17.5.1.3","description":"Seen in \"F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans\" (The Hacker News). Context: s. Versions known to be vulnerable Fixed in 17.5.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15","pattern":"[ipv4-addr:value = '17.5.1.3']","pattern_type":"stix","valid_from":"2026-09-09T07:36:49.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--828d5f39-f81f-415f-a4cf-f98f6a31ea43","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 45.142.193.132","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against in","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca773796-7a04-475f-98ad-f4ac830b49f4","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-15T22:16:20.082Z","created_by_ref":"identity--8aa78fed-7f20-4598-8c64-4f6ab9fb80c4","name":"ipv4: 45.158.196.75","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: 45.142.193.132 Used to orchestrate and execute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667","pattern":"[ipv4-addr:value = '45.158.196.75']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]}]}