Indicators of compromise
1,035 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | broker.hivemq.com | gin. The first version uses the public HiveMQ MQTT broker ( broker.hivemq.com ) as its C2 server. The free tier of this broker supports u | Angry Birds: Toy Ghouls’ new toys Kaspersky Securelist | · 13d ago |
| domain | element.tw | eir own Element server running on the Matrix protocol, meet.element[.]tw , as the C2 server. On this server, they created a room u | Angry Birds: Toy Ghouls’ new toys Kaspersky Securelist | · 13d ago |
| domain | crpx0.su | the group has advertised the operation on a clearnet site ("crpx0[.]su/v3.txt") as an offensive control panel to manage compromi | ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories The Hacker News | · 14d ago |
| domain | www.mxsetuplogi.com | fake "privacy browser" downloaded from a counterfeit site ("www.mxsetuplogi.com") that turns remote attacker commands into simulated mouse | ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories The Hacker News | · 14d ago |
| domain | acemlnd.com | ssage body to route through its own click-tracking domains (acemlnd[.]com and activehosted[.]com), so the URLs the recipient clicks | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | acems10.com | aped acems<N>[.]com and emsd<N>[.]com (e.g. emsd4[.]com, s9.acems10[.]com). Across the measured activity, ~98.5% of messages matche | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | activehosted.com | e through its own click-tracking domains (acemlnd[.]com and activehosted[.]com), so the URLs the recipient clicks do not point at the br | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | advancefundingboost.com | usinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefundi | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | catalystboostfunding.com | rbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapi | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | catalystcapitalharbor.com | tcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapital | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | digitalcapitalboost.com | omain Hits (Feb 9, 2026) guardiangrowthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfunding | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | digitalrushcapital.com | tcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[ | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | directcapitalboost.com | radvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalha | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | directcapitalpulse.com | uardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalru | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | elevatecapitalrush.com | capitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapital[.]com 18,695 Table 1. Top 20 | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | emsd4.com | ending pool , shaped acems<N>[.]com and emsd<N>[.]com (e.g. emsd4[.]com, s9.acems10[.]com). Across the measured activity, ~98.5% | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | fundingexpresscapital.com | stboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapital[.]com 18,695 Table 1. Top 20 (by signature hits) of the 148 fin | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | guardiancapitalway.com | ourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwav | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | guardiangrowthfunding.com | and the per-domain volume: Sender domain Hits (Feb 9, 2026) guardiangrowthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanex | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | guardianloccapital.com | etboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.] | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | guardianlocchoice.com | talrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[. | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | harboradvancefunding.com | cefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[ | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | onlinedirectfinance.com | tedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfund | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | ourbusinessloans.com | rdianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfundi | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | rocketboostfunding.com | rectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapital | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | thebusinessloanexpress.com | growthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.] | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | unitedfundingwave.com | ancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinanc | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | yourlocfunding.com | pitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalwa | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | caixaentradas1inboxshop.site | ft Edge and is downloaded from a distribution domain named "caixaentradas1inboxshop[.]site." An analysis of the files associated with the domain has | BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory The Hacker News | · 14d ago |
| domain | infect.online | tion for the Infected Marketplace (aka "Banco de Infects," "infect[.]online"), a platform where the threat actor monetizes initial ac | BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory The Hacker News | · 14d ago |
| domain | draw.io | sers and security tools to utilities such as Baidu Netdisk, draw.io, and Sejda PDF, to trick users into downloading malicious i | Counterfeit installers turn routine software downloads into enterprise breaches CSO Online | · 14d ago |
| domain | nodejs.org | y, attackers downloaded the official Node.js installer from nodejs[.]org and used the trusted, signed runtime to deploy a maliciou | Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks The Hacker News | · 14d ago |
| domain | duckdns.org | Let's Encrypt TLS certificate using the domain m-doxa-apodo.duckdns[.]org and following a unique dynamic DNS naming standard. Share | Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Palo Alto Unit 42 | · 14d ago |
| domain | anondns.net | nnected back to an attacker-controlled domain ( borertors92.anondns[.]net ). While the attack chain here also involved the ScreenCo | Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress | · 14d ago |
| domain | opik.net | l, this IP address was associated with the domain tele-sync.opik[.]net during the month of August. Figure 3: According to VirusT | Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress | · 14d ago |
| domain | app-microsoft-edge.com.cn | .]com." Some of the counterfeit websites are listed below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | baidu-pan.com.cn | t websites are listed below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[ | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | calibre-ebook.com.cn | below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[ | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | cn-drawio.com.cn | ge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[ | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | gehie246.com | lure content to trigger the download of a ZIP archive from "gehie246[.]com." Some of the counterfeit websites are listed below - app | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | gw-sogou.com.cn | an[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[. | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | iualef.net | and 28300. Two C2 domains associated with the activity are "iualef[.]net" and "oijfwe[.]net." It's unclear what the end goal of th | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | kaspersky-lab.hl.cn | e-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[. | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | mindmoster.com.cn | awio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[. | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | ocam-pc.com.cn | ou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[ | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | oijfwe.net | omains associated with the activity are "iualef[.]net" and "oijfwe[.]net." It's unclear what the end goal of the campaign is, as M | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | pc-razerzone.com.cn | rsky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-you | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | sejda.hl.cn | oster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | steelseries-cn.com.cn | ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | translate-youdao.hl.cn | erzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The web pages are high-fidelit | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | zh-diskgenius.com.cn | l[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The web pages are high-fidelity clones of the legitimat | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | gov.br | t it had found more than 630,000 URLs generated on hijacked gov.br subdomains, serving keyword-stuffed government-style pages | Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages The Hacker News | · 15d ago |
| domain | hunt.io | reverse-proxy technique on IIS servers in September 2025 . Hunt.io said in July 2025 that it had found more than 630,000 URLs | Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages The Hacker News | · 15d ago |
| domain | registro.br | thorized operators to run on .bet.br domains issued through Registro.br, Brazil's domain registry. Check Point did not say whether | Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages The Hacker News | · 15d ago |
| domain | cdn.nerat.cc | le - /usr/local/virtualizor/zzvirtservice Injected string - cdn[.]nerat[.]cc/installer/widdow.jar Injected string - connect[.]ne-rat | BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access The Hacker News | · 15d ago |
| domain | connect.ne-rat.xyz | g - cdn[.]nerat[.]cc/installer/widdow.jar Injected string - connect[.]ne-rat[.]xyz Injected string - jre-runtime.dat Command-and-control ( | BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access The Hacker News | · 15d ago |
| domain | advancedplacyncement.vu | .51[.]x) and 104.37.188[.]94 Observed replay infrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunio | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | amstardmzsmc.vu | 94 Observed replay infrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalf | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | arandasoftzfdware.vu | infrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]v | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | avisoretentiunionllc.vu | dplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]v | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | capitalflwxinancialpartners.vu | mzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcea | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | certififiycationedge.vu | avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafww | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | connectivnqzityltd.vu | capitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu excelte | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | crrbcearegroup.vu | ners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolution | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | digitaltrafwwrficsystems.vu | cationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[. | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | exceltecbusinessbwpsolutions.vu | yltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmi | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | genamewwgdiamarketing.vu | taltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]v | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | globaieflsoftinc.vu | xceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | globalmixeucbdmodetechnologyinc.vu | tions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeul | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | globalprojectspvtltd.vu | globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufactu | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | idoej.com | l panel host found by pivoting from the phishing page title idoej[.]com Domain of the phishing control panel host found via rever | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | joinbusinessmanagementconsdjeulting.vu | balmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[ | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | kentmanqhfufacturingcompany.vu | rojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu mon | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | kleepxrnlinecorporation.vu | nagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprorm | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | knsinternacshtional.vu | ntmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestate | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | monday.com | k the true destination by using an open direct parameter on Monday[.]com's tracking service. When clicked the link routes the vict | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | monttmmlrustcompany.vu | [.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[ | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | mtprormtductions.vu | tion[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrap | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | realestatecotblrp.vu | htional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techc | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | siottxgroup.vu | stcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | summitcapitaltrapojininggroup.vu | prormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu Phis | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | techcompositnkoes.vu | rp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu Phishing domains used by th | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | techromixsolutionlonsinc.vu | u summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu Phishing domains used by the threat actors involved in th | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | playfootball.info | d by the second Apache module brought us to a domain called playfootball[.]info that has a phishing page similar to the earlier ones. Unl | Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon Check Point Research | · 15d ago |
| domain | app-microsoft-edge.com.cn | c-razerzone[.]com[.]cn Peripherals / drivers Microsoft Edge app-microsoft-edge[.]com[.]cn Browser Kaspersky kaspersky-lab[.]hl[.]cn Security soft | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | baidu-pan.com.cn | s zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn S | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | calibre-ebook.com.cn | pc-razerzone[.]com[.]cn → hxxp://www.gehie246[.]com/712down calibre-ebook[.]com[.]cn → hxxp://www.gehie246[.]com/712down Brand-impersonation | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | cc8ttkv35b.com | and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attack | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | cn-drawio.com.cn | m Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Perip | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | com.cn | bapc, zh-tbtool, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains im | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | gehie246.com | nd downloading app_setup.6653004.zip from the delivery host gehie246[.]com/712down ; two content-distinct copies of the same-named a | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | gw-sogou.com.cn | ing SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method Calibre calibre-ebook[.]com[.]cn E-book Mi | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | hl.cn | l, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains impersonate unr | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | kaspersky-lab.hl.cn | alidated hash set is in the indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[ | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | mindmoster.com.cn | ibre calibre-ebook[.]com[.]cn E-book MindMaster (typosquat) mindmoster[.]com[.]cn Mind-mapping Others pc-codex, jinshan-cibapc, zh-tbtool | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | n7b8t85zsg.com | hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attacker-controlled Alibaba Clou | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | ocam-pc.com.cn | an) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn Diagramming | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | oijfwe.net | led Multiple C:\ProgramData\ payloads 103.183.3[.]162:5090 (oijfwe[.]net) Connection failed Stage-one / persistent payloads Alibab | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | pc-razerzone.com.cn | lemetry captured a device navigating to the fake Razer page pc-razerzone[.]com[.]cn and downloading app_setup.6653004.zip from the delivery | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | sejda.hl.cn | spersky kaspersky-lab[.]hl[.]cn Security software Sejda PDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.