ZeroHour

Indicators of compromise

2,805 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainvip311.cce. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc assLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 3h ago
domainzenplay77-x.spaceo sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem iLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 3h ago
domainzzyud.coms of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated withLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 3h ago
domainluizestrelhashapr.onlinefiltrating browser data for each profile to its C2 server ("luizestrelhashapr[.]online:443") but not before requesting extensive access to browsKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 4h ago
domainvolmira.siteto the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain thKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 4h ago
domainzaviro.onlineum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extensionKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 4h ago
domainc2iznja.comon the machine and exfiltrate them to the C2 server ("api80.c2iznja[.]com"). "The domains used Cloudflare as a proxy for their infrBambooToken Malware Uses MQTT to Control Windows and Linux Systems
The Hacker News
· 7h ago
domainchat5188.tkgather system details and transmit them to the C2 server ("chat5188[.]tk"). In response, the server issues commands to load a plugBambooToken Malware Uses MQTT to Control Windows and Linux Systems
The Hacker News
· 7h ago
ipv42.0.3.1aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload vHackers target WordPress sites via third-party WooCommerce plugin
BleepingComputer
· 8h ago
domainhunt.iomand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host disThai Broadband Provider Hacked via Fortinet Vulnerability
SecurityWeek
· 9h ago
domain31-59-175-195.syd.nbn.aussiebb.netgets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . ThPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 10h ago
domaineightindigostove.com75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarewPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 10h ago
domainloadswage.comture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was asPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 10h ago
domainmoolaah.comd through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed MahnschreiPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 10h ago
domainopensea.ioitting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tesPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 10h ago
domainweb5-4s4c-online-garantibbva.vibtee.coms IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificatiPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 10h ago
domainwebsite-2df62808.mvplineup.coment reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing decoPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 10h ago
domainxmasbrick.com: Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxpPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 10h ago
urlhttp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF[.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 10h ago
ipv4104.194.9.1385389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentioHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 11h ago
ipv4187.75.114.36.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged (Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 11h ago
ipv42.0.3.1bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 oHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 11h ago
ipv423.137.105.2143 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP aHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 11h ago
ipv423.180.120.1403 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domaHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 11h ago
ipv431.59.129.150e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, foHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 11h ago
ipv492.241.13.140r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 11h ago
ipv492.241.13.213and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 11h ago
domain31-59-175-195.syd.nbn.aussiebb.netof compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renewNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 11h ago
domaineightindigostove.comssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus reneNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 11h ago
domainloadswage.comsed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus renNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 11h ago
domainmoolaah.compath in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-pNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 11h ago
domainopensea.ioing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser-New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 11h ago
domainweb5-4s4c-online-garantibbva.vibtee.comPv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking pNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 11h ago
domainwebsite-2df62808.mvplineup.comomain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in thNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 11h ago
domainxmasbrick.comthe cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the RomaNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 11h ago
urlhttp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DFnder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankinNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 11h ago
domainapi.telegram.orging in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ipIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 11h ago
domainbackblazeb2.comctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightninIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 11h ago
domainiproyal.com[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is foIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 11h ago
domainlightningproxies.netzeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to beIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 11h ago
domainstorjshare.io: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The bestIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 11h ago
domainvultrobjects.comnvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net MitiIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 11h ago
domainember-bridge.comlution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate yHBO Max’s verified Reddit account hijacked to spread malware
Malwarebytes Labs
· 11h ago
ipv4104.194.9.138urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 11h ago
ipv4114.10.43.203source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests IHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 11h ago
ipv4187.75.114.36urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests IHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 11h ago
ipv423.137.105.214urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 11h ago
ipv423.180.120.140urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 11h ago
ipv431.59.129.150rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit requestHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 11h ago
ipv437.114.144.209source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests FHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 11h ago
ipv492.241.13.140rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 11h ago
ipv492.241.13.213f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit requestHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 11h ago
domainserver.hostexposes the Vite dev server to the network using --host or server.host config option The sensitive file exists in the allowed direMass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
The Hacker News
· 11h ago
domainclean-disk-guide.comoke down into 15 ads for a fake macOS disk utility at apple.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. OAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 13h ago
domaincode-desktop.com.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. One entry point into a larger system The HBO Max ads werAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 13h ago
domaincodex-craft.com-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craft[.]com. The rest broke down into 15 ads for a fake macOS disk utAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 13h ago
domainhbomax-macos.coms, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-crafAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 13h ago
domainhbomaxx.appid . Of the 108 ads, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex,Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 13h ago
domainhbomaxx.usHBO Max subreddits,” wrote the user. Clicking the ad led to hbomaxx[.]us, “which looks somewhat legitimate, and has a join buttonAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 13h ago
domainhbomaxx.usich does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also conHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
SecurityWeek
· 14h ago
domainbiterflll.comy tips in seconds. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitigift.coms. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitrefall.comf compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitrefill.comed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment. Be wary of domains containing aSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitrefill-payments.comCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitrSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitrefill-pays.comcom bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitregift.comtrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitregill.comtrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitretill.com[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitrgift.com-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefillSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitrgifts.comregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitreSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitrnfill.comregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbitruflli.comretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com paSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainbutrefill.comrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]coSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainexample-pay.comy’s main domain, as in pay.example.com . An address such as example-pay.com is a completely separate domain that anyone could register.Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainpay-bitigift.compay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitreflSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainpay-bitregill.comgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]coSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainpay-bitrgift.coml[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]coSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainpay-bitrgifts.com]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainpay-butrefill.compay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainxn--bitrefll-71a.compay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainxn--bitrefll-h2a.comy-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn-Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainxn--bitrefll-pay-kfb.comitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainxn--bitrefll-pay-xfb.com71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreiSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainxn--bitrefll-q2a.com.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--bSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainxn--bitreill-cz9c.comkfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--paSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainxn--bitreill-pay-yq4f.comay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop thSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainxn--btrefill-l2a.coma[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can dSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainxn--pay-bitrefll-fgb.com9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can do any harm. Malwarebytes BrSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 14h ago
domainaforvm.com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com;Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
domainaidevmaster.com]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
domainalfredaps.comltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; coHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
domainapplediag.comm; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hubHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
domainarkypc.comhbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; groHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
domainbasequill9.comClick-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
domainbeaocnagent.comaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains DomHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
domainbright-links.come[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
domainbroadwalkindia.comcom; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]com; cim-kolea[.]com; hindustanagency[.]com Teardown and deliHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
domaincamaligsalvatrefoils.com-command lure domains Domain flutelikelurkerunsinewy[.]com; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]comHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
domaincanvas-35.com[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.