Indicators of compromise
160 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| ipv4 | 94.102.49.125 | continuing today. The only source IP for the scans is %%ip:94.102.49.125%%. This IP address is associated with IP Volume ( AS202425) | Scans Targeting Hospitality Applications, (Wed, Sep 16th) SANS Internet Storm Center | · 16h ago |
| ipv4 | 2.0.3.1 | y on July 1 and August 30. All versions up to and including 2.0.3.1 are affected. Researcher Teemu Saarentaus reported the flaw | PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug Infosecurity Magazine | · 20h ago |
| ipv4 | 2.0.3.2 | Authentication Bypass What Site Owners Should Do Update to 2.0.3.2 or later. A firewall rule blocks known exploit attempts but | PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug Infosecurity Magazine | · 20h ago |
| ipv4 | 178.16.54.148 | ving to the ClickFix distribution infrastructure IP address 178.16.54.148 ClickFix panel serving VectraRAT and NetSupport RAT IP addr | Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs Cyber Security News | · 20h ago |
| ipv4 | 195.20.115.77 | ckFix panel serving VectraRAT and NetSupport RAT IP address 195.20.115.77 Secondary VectraRAT cluster with exposed panel and director | Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs Cyber Security News | · 20h ago |
| ipv4 | 195.63.145.106 | madey panel and VectraRAT staging infrastructure IP address 195.63.145.106 Infrastructure sharing the VectraRAT communication port wit | Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs Cyber Security News | · 20h ago |
| ipv4 | 86.109.75.161 | rol server and operator panel; exposed directory IP address 86.109.75.161 ClickFix distribution panel associated with the listed doma | Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs Cyber Security News | · 20h ago |
| ipv4 | 86.109.75.168 | dcdfb3ef1ee07eb620 VectraRAT-related sample hash IP address 86.109.75.168 Primary command-and-control server and operator panel; expo | Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs Cyber Security News | · 20h ago |
| ipv4 | 91.219.236.179 | ctraRAT cluster with exposed panel and directory IP address 91.219.236.179 Related ServerAstra infrastructure IP address 91.92.242.236 | Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs Cyber Security News | · 20h ago |
| ipv4 | 91.92.242.236 | 1.219.236.179 Related ServerAstra infrastructure IP address 91.92.242.236 Amadey panel and VectraRAT staging infrastructure IP addres | Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs Cyber Security News | · 20h ago |
| ipv4 | 124.230.195.242 | 191.223.42.34 Source-listed network indicator IPv4 Address 124.230.195.242 Source-listed network indicator MD5 5b11b38bf0eb3f0952f306a | Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems Cyber Security News | · 21h ago |
| ipv4 | 137.220.158.91 | ss 8.210.93.39 Source-listed network indicator IPv4 Address 137.220.158.91 Source-listed network indicator MD5 ba2ff4a8b689fab54670cf8 | Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems Cyber Security News | · 21h ago |
| ipv4 | 191.223.42.34 | n shdufysuf.com Source-listed domain indicator IPv4 Address 191.223.42.34 Source-listed network indicator IPv4 Address 124.230.195.24 | Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems Cyber Security News | · 21h ago |
| ipv4 | 47.83.128.111 | bf79a65b9 Source-listed Noodle RAT sample hash IPv4 Address 47.83.128.111 Source-listed network indicator IPv4 Address 8.210.93.39 So | Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems Cyber Security News | · 21h ago |
| ipv4 | 58.181.61.142 | 75f843c29 Source-listed Noodle RAT sample hash IPv4 Address 58.181.61.142 Source-listed network indicator MD5 1a6dcfa8d4a429f5511ba3c | Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems Cyber Security News | · 21h ago |
| ipv4 | 64.118.132.233 | ain airuhuo.xyz Source-listed domain indicator IPv4 Address 64.118.132.233 Source-listed network indicator Domain shdufysuf.com Source | Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems Cyber Security News | · 21h ago |
| ipv4 | 8.210.93.39 | 47.83.128.111 Source-listed network indicator IPv4 Address 8.210.93.39 Source-listed network indicator IPv4 Address 137.220.158.91 | Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems Cyber Security News | · 21h ago |
| ipv4 | 178.16.54.148 | ClickFix distribution panel, resolves verify-cloud.digital. 178.16.54.148 ClickFix panel serving VectraRAT and NetSupport RAT (Omegat | VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems GBHackers | · 22h ago |
| ipv4 | 195.20.115.77 | ing VectraRAT and NetSupport RAT (Omegatech LTD, AS202412). 195.20.115.77 Secondary cluster, exposed panel and directory (ServerAstra | VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems GBHackers | · 22h ago |
| ipv4 | 86.109.75.161 | nd panel, exposed open directory (GorillaServers, AS53850). 86.109.75.161 ClickFix distribution panel, resolves verify-cloud.digital. | VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems GBHackers | · 22h ago |
| ipv4 | 86.109.75.168 | e. The entry point was an HTTP-accessible open directory on 86.109.75.168, a GorillaServers node in AS53850. That licensing architect | VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems GBHackers | · 22h ago |
| ipv4 | 91.219.236.179 | luster, exposed panel and directory (ServerAstra, AS56322). 91.219.236.179 Related infrastructure (ServerAstra). Note: IP addresses an | VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems GBHackers | · 22h ago |
| ipv4 | 103.119.15.189 | ax Penalty Notice, Government of India lure Secondary C2 IP 103.119.15.189 C2 address used by a sibling sample Related certificate dom | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 23h ago |
| ipv4 | 103.23.172.15 | n , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving to 103.23.172.15 Sister lure title कर दंड सूचना – भारत सरकार Tax Penalty Not | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 23h ago |
| ipv4 | 154.36.188.201 | xe Process targeted by the payload on reconnect C2 endpoint 154.36.188.201:4449 VenomRAT command-and-control endpoint VenomRAT campaig | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 23h ago |
| ipv4 | 155.94.154.195 | aui[.]cc Observed sender address and DKIM domain Sending IP 155.94.154.195 Sending infrastructure IP address Sending MTA mos1.17dlz[.] | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 23h ago |
| ipv4 | 146.103.91.133 | en accessing 1862.cc from a Hong Kong IP address IP address 146.103.91.133 Final destination observed when accessing 1862.cc from a Ja | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 23h ago |
| ipv4 | 157.185.143.150 | printed visitors and redirected them by location IP address 157.185.143.150 Final destination observed when accessing 1862.cc from a Ho | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 23h ago |
| ipv4 | 154.36.188.201 | ed process handling. The recovered configuration pointed to 154.36.188.201:4449 and identified the implant as Venom RAT + HVNC + Steal | PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users GBHackers | · 1d ago |
| ipv4 | 155.94.154.195 | Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth hos | PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users GBHackers | · 1d ago |
| ipv4 | 104.194.9.138 | 5c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a succes | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 114.10.43.203 | 0 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attac | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 187.75.114.36 | 1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack pe | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 23.137.105.214 | 41.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 23.180.120.140 | .129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Be | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 31.59.129.150 | originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.1 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 37.114.144.209 | 14 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacker to upload a | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 6.17.4.1 | the plugin, has addressed the flaws in version 6.17.3.1 and 6.17.4.1, respectively. Found this article interesting? Follow us on | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 92.241.13.140 | dresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 1 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 92.241.13.213 | attempts have originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.10 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 104.21.77.104 | sts (all NXDOMAIN since 15 September 2026) cdn.sendibt1.com 104.21.77.104 created 2026-08-25 17:08 UTC cdn2.sendibt1.com cdn3.sendibt | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| ipv4 | 172.246.243.65 | endibt1.com itself is not proxied, answering on Brevo's own 172.246.243.65 in AS200484 with server: envoy , while only the attacker's | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| ipv4 | 188.114.97.3 | 1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1 | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| ipv4 | 2.0.3.1 | aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload v | Hackers target WordPress sites via third-party WooCommerce plugin BleepingComputer | · 1d ago |
| ipv4 | 104.194.9.138 | 5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentio | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 1d ago |
| ipv4 | 187.75.114.36 | .13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged ( | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 1d ago |
| ipv4 | 2.0.3.1 | bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 o | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 1d ago |
| ipv4 | 23.137.105.214 | 3 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP a | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 1d ago |
| ipv4 | 23.180.120.140 | 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and doma | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 1d ago |
| ipv4 | 31.59.129.150 | e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, fo | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 1d ago |
| ipv4 | 92.241.13.140 | r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75. | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 1d ago |
| ipv4 | 92.241.13.213 | and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 bl | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 1d ago |
| ipv4 | 104.194.9.138 | urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 1d ago |
| ipv4 | 114.10.43.203 | source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests I | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 1d ago |
| ipv4 | 187.75.114.36 | urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests I | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 1d ago |
| ipv4 | 23.137.105.214 | urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 1d ago |
| ipv4 | 23.180.120.140 | urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 1d ago |
| ipv4 | 31.59.129.150 | rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit request | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 1d ago |
| ipv4 | 37.114.144.209 | source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests F | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 1d ago |
| ipv4 | 92.241.13.140 | rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 1d ago |
| ipv4 | 92.241.13.213 | f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit request | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 1d ago |
| ipv4 | 164.90.161.147 | lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September ma | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 2d ago |
| ipv4 | 165.22.199.85 | rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration Septemb | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 2d ago |
| ipv4 | 45.94.47.204 | omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemen | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 2d ago |
| ipv4 | 77.91.65.13 | nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP autho | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 2d ago |
| ipv4 | 89.34.96.56 | ompromise (IoCs):- Type Indicator Description C2 IP address 89.34.96.56 Hard-coded Cyclops Blink command-and-control server C2 TCP | Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning Cyber Security News | · 2d ago |
| ipv4 | 8.218.50.207 | n Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging server hosted on Alibaba Cloud in Hong Kong Domain | One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users Cyber Security News | · 2d ago |
| ipv4 | 8.8.8.8 | entire framework. The module also uses Google Public DNS at 8.8.8.8 over DNS-over-HTTPS access to resolve transfer-host names, | Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities GBHackers | · 3d ago |
| ipv4 | 45.142.193.132 | irm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31. “The adversary went from an empty workspace t | Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script The Register · Security | · 6d ago |
| ipv4 | 1.0.0.1 | ct() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additiona | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 6d ago |
| ipv4 | 109.91.184.21 | resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known public resolver servi | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 6d ago |
| ipv4 | 1.1.1.1 | nal connect() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 6d ago |
| ipv4 | 80.152.203.134 | ons were public DNS resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known pub | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 6d ago |
| ipv4 | 8.8.4.4 | port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/8 | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 6d ago |
| ipv4 | 8.8.8.8 | erified while attempts to reach an external address such as 8.8.8.8 returned Network is unreachable. This design allowed the ma | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 6d ago |
| ipv4 | 9.9.9.10 | tions included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is commonly asso | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 6d ago |
| ipv4 | 9.9.9.9 | . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is com | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 6d ago |
| ipv4 | 45.142.193.132 | he actors utilized infrastructure, including the IP address 45.142.193.132, which GreyNoise had tracked since early July for attacks a | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| ipv4 | 45.158.196.75 | paign orchestration and execution infrastructure IP address 45.158.196.75 Infrastructure used to execute campaign activity File hash | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| ipv4 | 9.20.4.14 | ewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions U | Cisco security advisory (AV26-197) – Update 3 Canadian Centre for Cyber Security | · 7d ago |
| ipv4 | 62.60.130.193 | ll log failed login attempts with a 401 status code: ::ffff:62.60.130.193 - - [09/09/2026:15:26:14 +0000] "POST /api2/json/access/tic | Scans for Proxmox Servers, (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| ipv4 | 45.142.193.132 | nfrastructure. The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for prob | Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide Cyber Security News | · 7d ago |
| ipv4 | 146.103.99.177 | Incident responders should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js fil | Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT GBHackers | · 8d ago |
| ipv4 | 46.151.29.58 | s should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js files, and review ru | Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT GBHackers | · 8d ago |
| ipv4 | 173.212.244.25 | IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA targets IP address 2 | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 188.245.99.156 | f compromise (IoCs):- Type Indicator Description IP address 188.245.99.156 Operator host used for rogue Redis replication, command-and | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 194.48.248.105 | Recurring WordPress exploitation target IP address and port 194.48.248.105:8081 Earlier open directory linked by cryptocurrency wallet | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 20.198.10.42 | target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed develo | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 213.6.207.123 | hip unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA tar | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 23.235.223.49 | 5 Additional observed development and QA targets IP address 23.235.223.49 Recurring WordPress exploitation target IP address and port | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 34.166.99.116 | eused QA or test target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 45.155.102.89 | stname> Victim check-in request pattern IP address and port 45.155.102.89:10128 Local mining pool proxy used on the operator host Dom | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 47.250.92.230 | -controlled hostname resolving to 188.245.99.156 IP address 47.250.92.230 Frequently reused QA or test target, ownership unconfirmed | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 15.1.10.8 | 0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nearly a year old. Ireland's N | F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News | · 8d ago |
| ipv4 | 16.1.6.1 | .0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nea | F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News | · 8d ago |
| ipv4 | 17.5.1.3 | s. Versions known to be vulnerable Fixed in 17.5.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15 | F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News | · 8d ago |
| ipv4 | 45.142.193.132 | investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against in | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 8d ago |
| ipv4 | 45.158.196.75 | 45.142.193.132 Used to orchestrate and execute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667 | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 8d ago |
| ipv4 | 20.12.5.3 | end of software maintenance); all versions 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.1 | 2026-002: Multiple Vulnerabilities in Cisco Products CERT-EU Advisories | · 8d ago |
| ipv4 | 20.12.6.1 | s 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.13 (end of software maintenance); all vers | 2026-002: Multiple Vulnerabilities in Cisco Products CERT-EU Advisories | · 8d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.