ZeroHour

Indicators of compromise

1,035 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainsteelseries-cn.com.cnapture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method CaliCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domaintranslate-youdao.hl.cnPDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk utCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainwww.gehie246.comns. pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com/712down → app_setup.6653004.zip → stage-one loader A deCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainyimxg25tiy.comnation page that served it and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins71Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainzh-diskgenius.com.cnictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn CCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainaguamammillaria.cfdh4htc0h0ggdh.canadacentral-01.azurewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain:Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
domainaguasedum.cfdurewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pinggGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
domainazurewebsites.nete text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortcut: SGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
domaincolombstracciatella.cfdr: "Contrato Via Docusing" <[email protected][.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: Assine coGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
domainpinggy.linkm[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pinggy[.]link:21601/ Note: I saw HTTPS traffic to WhatsApp and GitHub dGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
domaincentrodigestionedellarapina.lifeate. Indicators of compromise (IOCs) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address useFake GTA 6 leaked copy drains your crypto wallet
Malwarebytes Labs
· 16d ago
domaindasunerforschtelandamendederwelt.sbs) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address used by the page’s inline transfer 21iWU6FFake GTA 6 leaked copy drains your crypto wallet
Malwarebytes Labs
· 16d ago
domainip.me’t belong to the face on the video call. “The user accessed ip[.]me directly to determine their public-facing IP address justNorth Korea-linked IT Workers Are Getting Hired Inside Western Companies
Security Affairs
· 16d ago
domainclaude.aiso: How attackers hosted a fake Claude download page on the claude.ai domain Subscribe to our breaking news e-mail alert to neverAnthropic locks out Claude users after infostealers hijack login sessions
Help Net Security
· 17d ago
domainhunt.iooud and WordPress systems. The activity was uncovered after Hunt.io found an exposed server in Amsterdam that contained attackPhilippine Nuclear and Naval Targets Hit by Suspected Chinese Operator
Security Affairs
· 19d ago
domaindocopened.jpghxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. This serves as a document-open “canary,” alerting BlueDeRussian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
Security Affairs
· 20d ago
domainwebhook.siteins a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. ThiRussian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
Security Affairs
· 20d ago
domainajax.nettructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flU.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Security Affairs
· 20d ago
domaingetpdfdigital.clouder to a shortened URL that resolves through a redirector to getpdfdigital[.]cloud, a known attacker site used to stage malicious payloads.Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Security Affairs
· 21d ago
domainajax.net-2015-5287), a Microsoft SQL Server bug (CVE-2019-1068), an Ajax.NET deserialization flaw (CVE-2021-23758), and a Linux Kernel vPreviously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
Help Net Security
· 21d ago
domainnova-client.come official websites, only GitHub pages and Discord servers. Nova-client.com is a fake website for a client that has no real website; thFake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
Security Affairs
· 23d ago
domaintrycloudflare.comhenticated session. In the demo, the fake login page used a trycloudflare.com subdomain, giving the link a valid TLS certificate and a moiAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
Security Affairs
· 24d ago
domaincardoor.cnnstructions from a message broker hosted on a domain called cardoor[.]cn, which tells it which app files to download and install.Android car head units infected with proxy botnet malware through built-in software updaters
Help Net Security
· 24d ago
domainclasstandscrest.comewhere for suspected fraud. The public registration page at classtandscrest[.]com (Source: Allure Security) What to check Researchers recomA $25 template helped scammers build hundreds of phantom bank domains
Help Net Security
· 27d ago
domainremedycodes.siten form was set to send submitted data to a separate domain, remedycodes[.]site. Researchers did not submit the form. That same Remedy adA $25 template helped scammers build hundreds of phantom bank domains
Help Net Security
· 27d ago
domaindtm.kijangturbo88.topthat communicated with Telegram-based infrastructure, using dtm[.]kijangturbo88[.]top as its command-and-control endpoint. “While the malwareFake Gemini installer delivers Vidar infostealer via Google Colab lure
Help Net Security
· 28d ago
domainfd6fq54s6df541q23sdxfg.eummand is used to download a binary called nvr from http://y.fd6fq54s6df541q23sdxfg[.]eu/nvr 1 2 3 4 / bin / sh - c nvram set rc_firewall = "sleepMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
domainmods.net.156[.]190/.y/pty5 hxxp://159.89.156[.]190/.y/pty6 s.shadow.mods[.]net Samples Filename SHA256 File type tty0 492780a9ac9f033055Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
domaineleethub.coms from Eleethub The domain associated with the C2 server is eleethub[.]com . We visited the website and found a message announcing tEleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Palo Alto Unit 42
· 29d ago
domainlos.zetas.mx, and in the information from the botnet operators undead[@]los[.]zetas[.]mx (Figure 15). “Los Zetas” is a reference to a Mexican crEleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Palo Alto Unit 42
· 29d ago
domaindownloads.openwrt.orgin OpenWrt allowed attackers to impersonate downloads from downloads.openwrt.org and make the devices download malicious updates. This meansRisks in IoT Supply Chain
Palo Alto Unit 42
· 29d ago
domainiotlmao.xyz5889c244501288b9fa7c7dc7f1e8c5ef1291 Feb 26, 2021 13:14 UTC iotlmao[.]xyz/bins/dark.m68k a6cb6356432ca83467f6da2168be2aabbabe5d2f2dNew Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
domainvietdediserver.shop. This IP address is also associated with the domain ​​ cnc.vietdediserver[.]shop , which is a known, malicious domain associated with MiraA Deep Dive Into Attempted Exploitation of CVE-2023
Palo Alto Unit 42
· 29d ago
domaindigikalas.onlinebdirectory leaks the workstation hostname newtuxdev.sevielw.digikalas[.]online Aug. 6, 2025 Developer domain digikalas[.]online registerTuxBot v3: Inside an IoT Botnet Framework With LLM
Palo Alto Unit 42
· 29d ago
domainbynar.ioditing researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery. “An attacker on the network may be ableU.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
Security Affairs
· 29d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.