Indicators of compromise
1,035 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | steelseries-cn.com.cn | apture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method Cali | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | translate-youdao.hl.cn | PDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk ut | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | www.gehie246.com | ns. pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com/712down → app_setup.6653004.zip → stage-one loader A de | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | yimxg25tiy.com | nation page that served it and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins71 | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | zh-diskgenius.com.cn | ictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn C | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | aguamammillaria.cfd | h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain: | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| domain | aguasedum.cfd | urewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pingg | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| domain | azurewebsites.net | e text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortcut: S | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| domain | colombstracciatella.cfd | r: "Contrato Via Docusing" <[email protected][.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: Assine co | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| domain | pinggy.link | m[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pinggy[.]link:21601/ Note: I saw HTTPS traffic to WhatsApp and GitHub d | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| domain | centrodigestionedellarapina.life | ate. Indicators of compromise (IOCs) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address use | Fake GTA 6 leaked copy drains your crypto wallet Malwarebytes Labs | · 16d ago |
| domain | dasunerforschtelandamendederwelt.sbs | ) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address used by the page’s inline transfer 21iWU6F | Fake GTA 6 leaked copy drains your crypto wallet Malwarebytes Labs | · 16d ago |
| domain | ip.me | ’t belong to the face on the video call. “The user accessed ip[.]me directly to determine their public-facing IP address just | North Korea-linked IT Workers Are Getting Hired Inside Western Companies Security Affairs | · 16d ago |
| domain | claude.ai | so: How attackers hosted a fake Claude download page on the claude.ai domain Subscribe to our breaking news e-mail alert to never | Anthropic locks out Claude users after infostealers hijack login sessions Help Net Security | · 17d ago |
| domain | hunt.io | oud and WordPress systems. The activity was uncovered after Hunt.io found an exposed server in Amsterdam that contained attack | Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator Security Affairs | · 19d ago |
| domain | docopened.jpg | hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. This serves as a document-open “canary,” alerting BlueDe | Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations Security Affairs | · 20d ago |
| domain | webhook.site | ins a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. Thi | Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations Security Affairs | · 20d ago |
| domain | ajax.net | tructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler fl | U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog Security Affairs | · 20d ago |
| domain | getpdfdigital.cloud | er to a shortened URL that resolves through a redirector to getpdfdigital[.]cloud, a known attacker site used to stage malicious payloads. | Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback Security Affairs | · 21d ago |
| domain | ajax.net | -2015-5287), a Microsoft SQL Server bug (CVE-2019-1068), an Ajax.NET deserialization flaw (CVE-2021-23758), and a Linux Kernel v | Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) Help Net Security | · 21d ago |
| domain | nova-client.com | e official websites, only GitHub pages and Discord servers. Nova-client.com is a fake website for a client that has no real website; th | Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown Security Affairs | · 23d ago |
| domain | trycloudflare.com | henticated session. In the demo, the fake login page used a trycloudflare.com subdomain, giving the link a valid TLS certificate and a mo | iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset Security Affairs | · 24d ago |
| domain | cardoor.cn | nstructions from a message broker hosted on a domain called cardoor[.]cn, which tells it which app files to download and install. | Android car head units infected with proxy botnet malware through built-in software updaters Help Net Security | · 24d ago |
| domain | classtandscrest.com | ewhere for suspected fraud. The public registration page at classtandscrest[.]com (Source: Allure Security) What to check Researchers recom | A $25 template helped scammers build hundreds of phantom bank domains Help Net Security | · 27d ago |
| domain | remedycodes.site | n form was set to send submitted data to a separate domain, remedycodes[.]site. Researchers did not submit the form. That same Remedy ad | A $25 template helped scammers build hundreds of phantom bank domains Help Net Security | · 27d ago |
| domain | dtm.kijangturbo88.top | that communicated with Telegram-based infrastructure, using dtm[.]kijangturbo88[.]top as its command-and-control endpoint. “While the malware | Fake Gemini installer delivers Vidar infostealer via Google Colab lure Help Net Security | · 28d ago |
| domain | fd6fq54s6df541q23sdxfg.eu | mmand is used to download a binary called nvr from http://y.fd6fq54s6df541q23sdxfg[.]eu/nvr 1 2 3 4 / bin / sh - c nvram set rc_firewall = "sleep | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| domain | mods.net | .156[.]190/.y/pty5 hxxp://159.89.156[.]190/.y/pty6 s.shadow.mods[.]net Samples Filename SHA256 File type tty0 492780a9ac9f033055 | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| domain | eleethub.com | s from Eleethub The domain associated with the C2 server is eleethub[.]com . We visited the website and found a message announcing t | Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self Palo Alto Unit 42 | · 29d ago |
| domain | los.zetas.mx | , and in the information from the botnet operators undead[@]los[.]zetas[.]mx (Figure 15). “Los Zetas” is a reference to a Mexican cr | Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self Palo Alto Unit 42 | · 29d ago |
| domain | downloads.openwrt.org | in OpenWrt allowed attackers to impersonate downloads from downloads.openwrt.org and make the devices download malicious updates. This means | Risks in IoT Supply Chain Palo Alto Unit 42 | · 29d ago |
| domain | iotlmao.xyz | 5889c244501288b9fa7c7dc7f1e8c5ef1291 Feb 26, 2021 13:14 UTC iotlmao[.]xyz/bins/dark.m68k a6cb6356432ca83467f6da2168be2aabbabe5d2f2d | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| domain | vietdediserver.shop | . This IP address is also associated with the domain cnc.vietdediserver[.]shop , which is a known, malicious domain associated with Mira | A Deep Dive Into Attempted Exploitation of CVE-2023 Palo Alto Unit 42 | · 29d ago |
| domain | digikalas.online | bdirectory leaks the workstation hostname newtuxdev.sevielw.digikalas[.]online Aug. 6, 2025 Developer domain digikalas[.]online register | TuxBot v3: Inside an IoT Botnet Framework With LLM Palo Alto Unit 42 | · 29d ago |
| domain | bynar.io | diting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery. “An attacker on the network may be able | U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog Security Affairs | · 29d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.