Indicators of compromise
2,805 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | vip311.cc | e. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc ass | Low-quality casino sites conceal highly dangerous threat actors The Register · Security | · 3h ago |
| domain | zenplay77-x.space | o sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem i | Low-quality casino sites conceal highly dangerous threat actors The Register · Security | · 3h ago |
| domain | zzyud.com | s of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with | Low-quality casino sites conceal highly dangerous threat actors The Register · Security | · 3h ago |
| domain | luizestrelhashapr.online | filtrating browser data for each profile to its C2 server ("luizestrelhashapr[.]online:443") but not before requesting extensive access to brows | KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens The Hacker News | · 4h ago |
| domain | volmira.site | to the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain th | KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens The Hacker News | · 4h ago |
| domain | zaviro.online | um smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extension | KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens The Hacker News | · 4h ago |
| domain | c2iznja.com | on the machine and exfiltrate them to the C2 server ("api80.c2iznja[.]com"). "The domains used Cloudflare as a proxy for their infr | BambooToken Malware Uses MQTT to Control Windows and Linux Systems The Hacker News | · 7h ago |
| domain | chat5188.tk | gather system details and transmit them to the C2 server ("chat5188[.]tk"). In response, the server issues commands to load a plug | BambooToken Malware Uses MQTT to Control Windows and Linux Systems The Hacker News | · 7h ago |
| ipv4 | 2.0.3.1 | aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload v | Hackers target WordPress sites via third-party WooCommerce plugin BleepingComputer | · 8h ago |
| domain | hunt.io | mand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host dis | Thai Broadband Provider Hacked via Fortinet Vulnerability SecurityWeek | · 9h ago |
| domain | 31-59-175-195.syd.nbn.aussiebb.net | gets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . Th | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 10h ago |
| domain | eightindigostove.com | 75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarew | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 10h ago |
| domain | loadswage.com | ture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was as | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 10h ago |
| domain | moolaah.com | d through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed Mahnschrei | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 10h ago |
| domain | opensea.io | itting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tes | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 10h ago |
| domain | web5-4s4c-online-garantibbva.vibtee.com | s IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificati | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 10h ago |
| domain | website-2df62808.mvplineup.com | ent reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing deco | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 10h ago |
| domain | xmasbrick.com | : Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxp | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 10h ago |
| url | http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF | [.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193 | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 10h ago |
| ipv4 | 104.194.9.138 | 5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentio | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 11h ago |
| ipv4 | 187.75.114.36 | .13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged ( | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 11h ago |
| ipv4 | 2.0.3.1 | bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 o | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 11h ago |
| ipv4 | 23.137.105.214 | 3 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP a | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 11h ago |
| ipv4 | 23.180.120.140 | 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and doma | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 11h ago |
| ipv4 | 31.59.129.150 | e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, fo | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 11h ago |
| ipv4 | 92.241.13.140 | r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75. | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 11h ago |
| ipv4 | 92.241.13.213 | and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 bl | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 11h ago |
| domain | 31-59-175-195.syd.nbn.aussiebb.net | of compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renew | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 11h ago |
| domain | eightindigostove.com | ssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus rene | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 11h ago |
| domain | loadswage.com | sed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus ren | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 11h ago |
| domain | moolaah.com | path in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-p | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 11h ago |
| domain | opensea.io | ing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser- | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 11h ago |
| domain | web5-4s4c-online-garantibbva.vibtee.com | Pv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking p | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 11h ago |
| domain | website-2df62808.mvplineup.com | omain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in th | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 11h ago |
| domain | xmasbrick.com | the cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the Roma | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 11h ago |
| url | http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF | nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 11h ago |
| domain | api.telegram.org | ing in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ip | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 11h ago |
| domain | backblazeb2.com | ctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightnin | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 11h ago |
| domain | iproyal.com | [.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is fo | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 11h ago |
| domain | lightningproxies.net | zeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to be | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 11h ago |
| domain | storjshare.io | : api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 11h ago |
| domain | vultrobjects.com | nvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Miti | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 11h ago |
| domain | ember-bridge.com | lution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate y | HBO Max’s verified Reddit account hijacked to spread malware Malwarebytes Labs | · 11h ago |
| ipv4 | 104.194.9.138 | urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 11h ago |
| ipv4 | 114.10.43.203 | source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests I | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 11h ago |
| ipv4 | 187.75.114.36 | urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests I | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 11h ago |
| ipv4 | 23.137.105.214 | urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 11h ago |
| ipv4 | 23.180.120.140 | urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 11h ago |
| ipv4 | 31.59.129.150 | rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit request | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 11h ago |
| ipv4 | 37.114.144.209 | source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests F | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 11h ago |
| ipv4 | 92.241.13.140 | rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 11h ago |
| ipv4 | 92.241.13.213 | f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit request | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 11h ago |
| domain | server.host | exposes the Vite dev server to the network using --host or server.host config option The sensitive file exists in the allowed dire | Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers The Hacker News | · 11h ago |
| domain | clean-disk-guide.com | oke down into 15 ads for a fake macOS disk utility at apple.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. O | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 13h ago |
| domain | code-desktop.com | .clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. One entry point into a larger system The HBO Max ads wer | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 13h ago |
| domain | codex-craft.com | -macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craft[.]com. The rest broke down into 15 ads for a fake macOS disk ut | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 13h ago |
| domain | hbomax-macos.com | s, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craf | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 13h ago |
| domain | hbomaxx.app | id . Of the 108 ads, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 13h ago |
| domain | hbomaxx.us | HBO Max subreddits,” wrote the user. Clicking the ad led to hbomaxx[.]us, “which looks somewhat legitimate, and has a join button | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 13h ago |
| domain | hbomaxx.us | ich does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also con | Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack SecurityWeek | · 14h ago |
| domain | biterflll.com | y tips in seconds. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com b | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitigift.com | s. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[. | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitrefall.com | f compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[. | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitrefill.com | ed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment. Be wary of domains containing a | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitrefill-payments.com | Cs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitr | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitrefill-pays.com | com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[ | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitregift.com | trefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[ | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitregill.com | trefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[ | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitretill.com | [.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[ | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitrgift.com | -pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitrgifts.com | regift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitre | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitrnfill.com | regill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-b | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | bitruflli.com | retill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pa | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | butrefill.com | rgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]co | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | example-pay.com | y’s main domain, as in pay.example.com . An address such as example-pay.com is a completely separate domain that anyone could register. | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | pay-bitigift.com | pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefl | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | pay-bitregill.com | gifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]co | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | pay-bitrgift.com | l[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]co | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | pay-bitrgifts.com | ]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[. | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | pay-butrefill.com | pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2 | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | xn--bitrefll-71a.com | pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bit | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | xn--bitrefll-h2a.com | y-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn- | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | xn--bitrefll-pay-kfb.com | itigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bit | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | xn--bitrefll-pay-xfb.com | 71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitrei | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | xn--bitrefll-q2a.com | .]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--b | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | xn--bitreill-cz9c.com | kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pa | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | xn--bitreill-pay-yq4f.com | ay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop th | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | xn--btrefill-l2a.com | a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can d | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | xn--pay-bitrefll-fgb.com | 9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can do any harm. Malwarebytes Br | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 14h ago |
| domain | aforvm.com | ; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com; | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | aidevmaster.com | ]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumb | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | alfredaps.com | ltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; co | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | applediag.com | m; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | arkypc.com | hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; gro | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | basequill9.com | Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekm | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | beaocnagent.com | aesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Dom | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | bright-links.com | e[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]g | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | broadwalkindia.com | com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.]com Teardown and deli | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | camaligsalvatrefoils.com | -command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | canvas-35.com | [.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery dom | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.