ZeroHour

Indicators of compromise

160 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
ipv494.102.49.125continuing today. The only source IP for the scans is %%ip:94.102.49.125%%. This IP address is associated with IP Volume ( AS202425)Scans Targeting Hospitality Applications, (Wed, Sep 16th)
SANS Internet Storm Center
· 16h ago
ipv42.0.3.1y on July 1 and August 30. All versions up to and including 2.0.3.1 are affected. Researcher Teemu Saarentaus reported the flawPHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine
· 20h ago
ipv42.0.3.2Authentication Bypass What Site Owners Should Do Update to 2.0.3.2 or later. A firewall rule blocks known exploit attempts butPHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine
· 20h ago
ipv4178.16.54.148ving to the ClickFix distribution infrastructure IP address 178.16.54.148 ClickFix panel serving VectraRAT and NetSupport RAT IP addrHackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs
Cyber Security News
· 20h ago
ipv4195.20.115.77ckFix panel serving VectraRAT and NetSupport RAT IP address 195.20.115.77 Secondary VectraRAT cluster with exposed panel and directorHackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs
Cyber Security News
· 20h ago
ipv4195.63.145.106madey panel and VectraRAT staging infrastructure IP address 195.63.145.106 Infrastructure sharing the VectraRAT communication port witHackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs
Cyber Security News
· 20h ago
ipv486.109.75.161rol server and operator panel; exposed directory IP address 86.109.75.161 ClickFix distribution panel associated with the listed domaHackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs
Cyber Security News
· 20h ago
ipv486.109.75.168dcdfb3ef1ee07eb620 VectraRAT-related sample hash IP address 86.109.75.168 Primary command-and-control server and operator panel; expoHackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs
Cyber Security News
· 20h ago
ipv491.219.236.179ctraRAT cluster with exposed panel and directory IP address 91.219.236.179 Related ServerAstra infrastructure IP address 91.92.242.236Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs
Cyber Security News
· 20h ago
ipv491.92.242.2361.219.236.179 Related ServerAstra infrastructure IP address 91.92.242.236 Amadey panel and VectraRAT staging infrastructure IP addresHackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs
Cyber Security News
· 20h ago
ipv4124.230.195.242191.223.42.34 Source-listed network indicator IPv4 Address 124.230.195.242 Source-listed network indicator MD5 5b11b38bf0eb3f0952f306aHackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 21h ago
ipv4137.220.158.91ss 8.210.93.39 Source-listed network indicator IPv4 Address 137.220.158.91 Source-listed network indicator MD5 ba2ff4a8b689fab54670cf8Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 21h ago
ipv4191.223.42.34n shdufysuf.com Source-listed domain indicator IPv4 Address 191.223.42.34 Source-listed network indicator IPv4 Address 124.230.195.24Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 21h ago
ipv447.83.128.111bf79a65b9 Source-listed Noodle RAT sample hash IPv4 Address 47.83.128.111 Source-listed network indicator IPv4 Address 8.210.93.39 SoHackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 21h ago
ipv458.181.61.14275f843c29 Source-listed Noodle RAT sample hash IPv4 Address 58.181.61.142 Source-listed network indicator MD5 1a6dcfa8d4a429f5511ba3cHackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 21h ago
ipv464.118.132.233ain airuhuo.xyz Source-listed domain indicator IPv4 Address 64.118.132.233 Source-listed network indicator Domain shdufysuf.com SourceHackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 21h ago
ipv48.210.93.3947.83.128.111 Source-listed network indicator IPv4 Address 8.210.93.39 Source-listed network indicator IPv4 Address 137.220.158.91Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 21h ago
ipv4178.16.54.148ClickFix distribution panel, resolves verify-cloud.digital. 178.16.54.148 ClickFix panel serving VectraRAT and NetSupport RAT (OmegatVectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems
GBHackers
· 22h ago
ipv4195.20.115.77ing VectraRAT and NetSupport RAT (Omegatech LTD, AS202412). 195.20.115.77 Secondary cluster, exposed panel and directory (ServerAstraVectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems
GBHackers
· 22h ago
ipv486.109.75.161nd panel, exposed open directory (GorillaServers, AS53850). 86.109.75.161 ClickFix distribution panel, resolves verify-cloud.digital.VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems
GBHackers
· 22h ago
ipv486.109.75.168e. The entry point was an HTTP-accessible open directory on 86.109.75.168, a GorillaServers node in AS53850. That licensing architectVectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems
GBHackers
· 22h ago
ipv491.219.236.179luster, exposed panel and directory (ServerAstra, AS56322). 91.219.236.179 Related infrastructure (ServerAstra). Note: IP addresses anVectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems
GBHackers
· 22h ago
ipv4103.119.15.189ax Penalty Notice, Government of India lure Secondary C2 IP 103.119.15.189 C2 address used by a sibling sample Related certificate domPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 23h ago
ipv4103.23.172.15n , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving to 103.23.172.15 Sister lure title कर दंड सूचना – भारत सरकार Tax Penalty NotPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 23h ago
ipv4154.36.188.201xe Process targeted by the payload on reconnect C2 endpoint 154.36.188.201:4449 VenomRAT command-and-control endpoint VenomRAT campaigPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 23h ago
ipv4155.94.154.195aui[.]cc Observed sender address and DKIM domain Sending IP 155.94.154.195 Sending infrastructure IP address Sending MTA mos1.17dlz[.]PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 23h ago
ipv4146.103.91.133en accessing 1862.cc from a Hong Kong IP address IP address 146.103.91.133 Final destination observed when accessing 1862.cc from a JaHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 23h ago
ipv4157.185.143.150printed visitors and redirected them by location IP address 157.185.143.150 Final destination observed when accessing 1862.cc from a HoHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 23h ago
ipv4154.36.188.201ed process handling. The recovered configuration pointed to 154.36.188.201:4449 and identified the implant as Venom RAT + HVNC + StealPAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
GBHackers
· 1d ago
ipv4155.94.154.195Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth hosPAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
GBHackers
· 1d ago
ipv4104.194.9.1385c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a succesAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv4114.10.43.2030 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv4187.75.114.361 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack peAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv423.137.105.21441.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv423.180.120.140.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 BeAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv431.59.129.150originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.1Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv437.114.144.20914 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacker to upload aAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv46.17.4.1the plugin, has addressed the flaws in version 6.17.3.1 and 6.17.4.1, respectively. Found this article interesting? Follow us onAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv492.241.13.140dresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 1Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv492.241.13.213attempts have originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.10Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv4104.21.77.104sts (all NXDOMAIN since 15 September 2026) cdn.sendibt1.com 104.21.77.104 created 2026-08-25 17:08 UTC cdn2.sendibt1.com cdn3.sendibtBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
ipv4172.246.243.65endibt1.com itself is not proxied, answering on Brevo's own 172.246.243.65 in AS200484 with server: envoy , while only the attacker'sBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
ipv4188.114.97.31.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
ipv42.0.3.1aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload vHackers target WordPress sites via third-party WooCommerce plugin
BleepingComputer
· 1d ago
ipv4104.194.9.1385389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentioHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 1d ago
ipv4187.75.114.36.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged (Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 1d ago
ipv42.0.3.1bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 oHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 1d ago
ipv423.137.105.2143 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP aHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 1d ago
ipv423.180.120.1403 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domaHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 1d ago
ipv431.59.129.150e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, foHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 1d ago
ipv492.241.13.140r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 1d ago
ipv492.241.13.213and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 1d ago
ipv4104.194.9.138urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 1d ago
ipv4114.10.43.203source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests IHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 1d ago
ipv4187.75.114.36urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests IHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 1d ago
ipv423.137.105.214urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 1d ago
ipv423.180.120.140urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 1d ago
ipv431.59.129.150rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit requestHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 1d ago
ipv437.114.144.209source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests FHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 1d ago
ipv492.241.13.140rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 1d ago
ipv492.241.13.213f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit requestHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 1d ago
ipv4164.90.161.147lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September maHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 2d ago
ipv4165.22.199.85rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration SeptembHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 2d ago
ipv445.94.47.204omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemenHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 2d ago
ipv477.91.65.13nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP authoHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 2d ago
ipv489.34.96.56ompromise (IoCs):- Type Indicator Description C2 IP address 89.34.96.56 Hard-coded Cyclops Blink command-and-control server C2 TCPCyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning
Cyber Security News
· 2d ago
ipv48.218.50.207n Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging server hosted on Alibaba Cloud in Hong Kong DomainOne Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
Cyber Security News
· 2d ago
ipv48.8.8.8entire framework. The module also uses Google Public DNS at 8.8.8.8 over DNS-over-HTTPS access to resolve transfer-host names,Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities
GBHackers
· 3d ago
ipv445.142.193.132irm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31. “The adversary went from an empty workspace tHundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
The Register · Security
· 6d ago
ipv41.0.0.1ct() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additionaRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 6d ago
ipv4109.91.184.21resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known public resolver serviRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 6d ago
ipv41.1.1.1nal connect() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and severalRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 6d ago
ipv480.152.203.134ons were public DNS resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known pubRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 6d ago
ipv48.8.4.4port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/8Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 6d ago
ipv48.8.8.8erified while attempts to reach an external address such as 8.8.8.8 returned Network is unreachable. This design allowed the maRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 6d ago
ipv49.9.9.10tions included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is commonly assoRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 6d ago
ipv49.9.9.9. Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is comRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 6d ago
ipv445.142.193.132he actors utilized infrastructure, including the IP address 45.142.193.132, which GreyNoise had tracked since early July for attacks aHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
ipv445.158.196.75paign orchestration and execution infrastructure IP address 45.158.196.75 Infrastructure used to execute campaign activity File hashHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
ipv49.20.4.14ewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions UCisco security advisory (AV26-197) – Update 3
Canadian Centre for Cyber Security
· 7d ago
ipv462.60.130.193ll log failed login attempts with a 401 status code: ::ffff:62.60.130.193 - - [09/09/2026:15:26:14 +0000] "POST /api2/json/access/ticScans for Proxmox Servers, (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
ipv445.142.193.132nfrastructure. The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for probHackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide
Cyber Security News
· 7d ago
ipv4146.103.99.177Incident responders should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js filHackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
GBHackers
· 8d ago
ipv446.151.29.58s should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js files, and review ruHackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
GBHackers
· 8d ago
ipv4173.212.244.25IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA targets IP address 2Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv4188.245.99.156f compromise (IoCs):- Type Indicator Description IP address 188.245.99.156 Operator host used for rogue Redis replication, command-andHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv4194.48.248.105Recurring WordPress exploitation target IP address and port 194.48.248.105:8081 Earlier open directory linked by cryptocurrency walletHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv420.198.10.42target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed develoHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv4213.6.207.123hip unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA tarHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv423.235.223.495 Additional observed development and QA targets IP address 23.235.223.49 Recurring WordPress exploitation target IP address and portHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv434.166.99.116eused QA or test target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 AdditionalHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv445.155.102.89stname> Victim check-in request pattern IP address and port 45.155.102.89:10128 Local mining pool proxy used on the operator host DomHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv447.250.92.230-controlled hostname resolving to 188.245.99.156 IP address 47.250.92.230 Frequently reused QA or test target, ownership unconfirmedHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv415.1.10.80 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nearly a year old. Ireland's NF5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
The Hacker News
· 8d ago
ipv416.1.6.1.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is neaF5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
The Hacker News
· 8d ago
ipv417.5.1.3s. Versions known to be vulnerable Fixed in 17.5.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
The Hacker News
· 8d ago
ipv445.142.193.132investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against inAgents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
ipv445.158.196.7545.142.193.132 Used to orchestrate and execute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
ipv420.12.5.3end of software maintenance); all versions 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.12026-002: Multiple Vulnerabilities in Cisco Products
CERT-EU Advisories
· 8d ago
ipv420.12.6.1s 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.13 (end of software maintenance); all vers2026-002: Multiple Vulnerabilities in Cisco Products
CERT-EU Advisories
· 8d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.