Indicators of compromise
1,985 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | simultaneouslypower.com | cceptable.com Historical Ethereum resolver C2 domain Domain simultaneouslypower.com Historical Ethereum resolver C2 domain Domain wiselystartin | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| domain | wiselystarting.com | uslypower.com Historical Ethereum resolver C2 domain Domain wiselystarting.com Historical Ethereum resolver C2 domain Domain itemrange.com | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| ipv4 | 146.103.127.44 | rd-tier fallback address, designated hunt-only IPv4 address 146.103.127.44 Historical operator-used address from April 2026, designate | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| ipv4 | 193.233.202.17 | compromise (IoCs):- Type Indicator Description IPv4 address 193.233.202.17 Primary Sliver command-and-control and staging-server addre | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| ipv4 | 77.110.126.46 | command-and-control and staging-server address IPv4 address 77.110.126.46 Hardcoded third-tier fallback address, designated hunt-only | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| ipv4 | 99.84.67.186 | launched. This is a small Rust program that connects to the 99.84.67.186 C2 server and waits for commands,” Sansec researchers said | Adobe Commerce max-severity bug comes under active attack CSO Online | · 9d ago |
| ipv4 | 82.192.72.4 | attacks have been originating from two IP addresses, namely 82.192.72.4 and 103.102.31.18. “The presence of any of these artifacts | MikroTik Patches Critical Flaws Chained to Hack Routers SecurityWeek | · 9d ago |
| ipv4 | 23.234.64.0 | ctivity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your log | N-able Patches Critical Zero-Day in N-central SecurityWeek | · 9d ago |
| domain | gerenciadorcaixa.digital | letely separate banking-phishing cluster A related domain — gerenciadorcaixa.digital, cloning Caixa Econômica Federal’s corporate banking portal | HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures ANY.RUN | · 9d ago |
| ipv4 | 5.230.249.49 | : 02 19 05 04 07 19 05 03 0E 19 03 0E XOR key: 0x37 Result: 5.230.249.49 The destination port is stored in plaintext: 27015 – the de | HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures ANY.RUN | · 9d ago |
| domain | bsc.rpc.blxrbdn.com | ad. The payload makes a separate JSON-RPC eth_call through "bsc[.]rpc[.]blxrbdn[.]com" to BNB Smart Chain contract 0x7CC3cFC1Ac007B8c6566fD | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | bsc-testnet-rpc.publicnode.com | ontract 0x886d310Ac23e05EA705e24E513D19f53793832A9 through "bsc-testnet-rpc[.]publicnode[.]com". BNB Smart Chain is a public, Ethereum-compatible bloc | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | fd.gstats-api-contact.cc | ly: Effective period in UTC Contract value June 30 – July 5 fd[.]gstats-api-contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.] | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | github.com | connects to it directly on TCP port 443, while presenting "github[.]com" as the TLS server name and HTTP Host value. Unlike the " | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | kffd3.vexlatech.cc | ier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 static[.]quorashift[.]cc July 26 – 30 lb[. | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | kffd3.vogueatelier.cc | contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 static | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | lb.propertyfind.cc | ring) function. During our analysis, the contract returned "lb[.]propertyfind[.]cc", which ZigCryptoStealer then used as its C2 domain. Th | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | leaguejazire.com | d command opens a WebDAV path on a randomized subdomain of "leaguejazire[.]com", places the victim identifier in the path, and executes | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | pkg.vogueatelier.cc | ue June 30 – July 5 fd[.]gstats-api-contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | riyazinikokar.xyz | acOS user-agent string. The request goes to a subdomain of "riyazinikokar[.]xyz". Since the subject of our initial research was a custome | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | static.quorashift.cc | elier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 static[.]quorashift[.]cc July 26 – 30 lb[.]propertyfind[.]cc Talos used Cisco Um | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | telegra.ph | n "pf.ch" branch constructs the dead drop C2 URL "https[:]//telegra[.]ph/Functions-04-03". At the time of analysis, the page looke | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| sha256 | 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 | most recently observed response was a ZIP archive, SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92. The archive included the file "platform_experience_helper. | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | google.com | s — like a random executable making a DNS request for “docs.google[.]com”. But when the requests are made from within a browser se | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | obfuscator.io | r variable and function names, consistent with output from “Obfuscator[.]io” and similar Javascript obfuscation tools. However, it wa | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | pastebin.com | ined a link to the lure document. Figure 4. A comment on a “Pastebin[.]com” post advertising the lure, warning against trying more t | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | paste.sh | to the lure document, was copy the script shared through a “paste[.]sh” link into the navigation bar of the Chrome browser prece | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | simpleswap.io | ure but was rewritten to target a different trading site — “SimpleSwap[.]io”, another cryptocurrency trading aggregator. The fake exp | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | swapzone.io | rsion we observed targeted the cryptocurrency trading site “SwapZone[.]io”. It was formatted in the style of a vulnerability report | ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 Cisco Talos | · 9d ago |
| domain | magento.com | tfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip "To help resolve th | Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell The Hacker News | · 9d ago |
| domain | dll.lat | for payload delivery are listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present w | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | github.io | hyperlinks to the lure pages (e.g., "viziocomsetupentercode.github[.]io"), urging readers to set up their smart TV "easily" by fo | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | pltechoo.pro | echnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present within the ZIP file is a JavaScript dropper for M | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | readthedocs.io | central how to login" to serve a fraudulent link hosted on readthedocs[.]io. The page features a prominent "Get Started" button that | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | reficon.pro | are listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present within the ZIP file is a | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | u320.my | d delivery are listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present within the | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | urlscan.io | ts.us3[.]org." A search for the domain "stats.us3[.]org" on urlscan.io yields 1,112 results as of writing, down from 1,190 at the | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | us3.org | e client-side and send the information to the domain "stats.us3[.]org." A search for the domain "stats.us3[.]org" on urlscan.io | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | ustechnio.com | of the domains used for payload delivery are listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[. | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | wapp.live | ins." One account managing some of the redirector domains ("wapp[.]live") was suspended by Hostmaza earlier this year. The disclo | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | wc.ci | red email addresses linking them to Garage2Global domains ("wc[.]ci"). A sample of some of the GitHub accounts and their asso | BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams The Hacker News | · 9d ago |
| domain | annastudios-paros.com | shing domain Domain ccpipharma[.]com Phishing domain Domain annastudios-paros[.]com Phishing domain Domain dnsforward[.]com Phishing domain D | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | arrmmy.com | omain daengrentacar[.]com Historical phishing domain Domain arrmmy[.]com Historical phishing domain Domain captelind[.]com Histori | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | captelind.com | omain Domain arrmmy[.]com Historical phishing domain Domain captelind[.]com Historical phishing domain Domain planisteradmin[.]com Hi | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | ccpipharma.com | node Domain konceptenterprises[.]com Phishing domain Domain ccpipharma[.]com Phishing domain Domain annastudios-paros[.]com Phishing d | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | cifutura.com | ishing domain Domain dataclust[.]com Phishing domain Domain cifutura[.]com Phishing domain Domain hoaivt[.]com Phishing domain Domai | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | daengrentacar.com | domain Domain soil-management[.]com Phishing domain Domain daengrentacar[.]com Historical phishing domain Domain arrmmy[.]com Historical | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | dataclust.com | omain Domain hotelmidtownsurat[.]com Phishing domain Domain dataclust[.]com Phishing domain Domain cifutura[.]com Phishing domain Dom | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | dnsforward.com | omain Domain annastudios-paros[.]com Phishing domain Domain dnsforward[.]com Phishing domain Domain hotelmidtownsurat[.]com Phishing d | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | dronalms.com | Phishing domain Domain hoaivt[.]com Phishing domain Domain dronalms[.]com Phishing domain Domain virextec[.]com Phishing domain Dom | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | haliotisbar.com | in hnospascualfadon[.]com Historical phishing domain Domain haliotisbar[.]com Historical phishing domain Domain knowncontractor[.]com H | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | hnospascualfadon.com | main planisteradmin[.]com Historical phishing domain Domain hnospascualfadon[.]com Historical phishing domain Domain haliotisbar[.]com Histo | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | hoaivt.com | hishing domain Domain cifutura[.]com Phishing domain Domain hoaivt[.]com Phishing domain Domain dronalms[.]com Phishing domain Dom | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | hotelmidtownsurat.com | shing domain Domain dnsforward[.]com Phishing domain Domain hotelmidtownsurat[.]com Phishing domain Domain dataclust[.]com Phishing domain Do | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | kgsscans.com | n management[.]michaelmarcotte[.]com Phishing domain Domain kgsscans[.]com Phishing domain Domain soil-management[.]com Phishing dom | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | knowncontractor.com | Domain haliotisbar[.]com Historical phishing domain Domain knowncontractor[.]com Historical phishing domain Domain valtteri[.]net Historic | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | konceptenterprises.com | s 45[.]32[.]64[.]165 Historical BigBear 2.0 VPS node Domain konceptenterprises[.]com Phishing domain Domain ccpipharma[.]com Phishing domain D | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | management.daengrentacar.com | domain Domain valtteri[.]net Historical phishing domain URL management[.]daengrentacar[.]com/meetings Observed live Microsoft 365 phishing page File | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | management.michaelmarcotte.com | ing domain Domain rootreseller[.]com Phishing domain Domain management[.]michaelmarcotte[.]com Phishing domain Domain kgsscans[.]com Phishing domain D | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | offtic.com | hishing domain Domain virextec[.]com Phishing domain Domain offtic[.]com Phishing domain Domain rootreseller[.]com Phishing domain | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | planisteradmin.com | in Domain captelind[.]com Historical phishing domain Domain planisteradmin[.]com Historical phishing domain Domain hnospascualfadon[.]com | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | rootreseller.com | Phishing domain Domain offtic[.]com Phishing domain Domain rootreseller[.]com Phishing domain Domain management[.]michaelmarcotte[.]com | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | soil-management.com | hishing domain Domain kgsscans[.]com Phishing domain Domain soil-management[.]com Phishing domain Domain daengrentacar[.]com Historical phi | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | valtteri.net | ain knowncontractor[.]com Historical phishing domain Domain valtteri[.]net Historical phishing domain URL management[.]daengrentacar | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | virextec.com | hishing domain Domain dronalms[.]com Phishing domain Domain virextec[.]com Phishing domain Domain offtic[.]com Phishing domain Domai | BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Cyber Security News | · 9d ago |
| domain | xfjcc.fun | ts command-and-control (C2) server ("206.237.30[.]232" or " xfjcc[.]fun ") every 30 seconds over plaintext HTTP for new commands, | PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution The Hacker News | · 10d ago |
| domain | 457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site | scans. “Before writing that file, the dropper calls out to 457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site , a subdomain of a public service that developers and teste | StyleSmuggler: The Magento Zero-Day Behind New Store Attacks Security Affairs | · 10d ago |
| ipv4 | 185.157.160.251 | TP-like domains and UDP port 123 destinations, particularly 185.157.160.251 , which Sansec linked to the observed domains on September | StyleSmuggler: The Magento Zero-Day Behind New Store Attacks Security Affairs | · 10d ago |
| domain | assignpasskey.com | the lure domains flagged by Arctic Wolf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.] | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | mfaregister.com | agged by Arctic Wolf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.] | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | nowsso.com | lf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeyde | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | oskeysetup.com | below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com regist | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | oursso.com | sskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | passkeydeploy.com | owsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead to | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | passkey-mfa.com | faregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | registermymfa.com | up[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead to an operator-controll | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | setpasskey.com | m passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead to an operator-controlled AitM Microsoft | Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News | · 10d ago |
| domain | coder-infra.com | rds. The data was then exfiltrated to the lookalike domain "coder-infra[.]com." "An unidentified malicious actor gained access to Coder | ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More The Hacker News | · 10d ago |
| ipv4 | 103.102.31.18 | September," CERT Polska said. "In addition, the IP address 103.102.31.18 was used in attempts to exploit the described chain." Unpat | ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More The Hacker News | · 10d ago |
| ipv4 | 82.192.72.4 | eation of the 'ops' account, originated from the IP address 82.192.72.4 and have been occurring since at least 2 September," CERT P | ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More The Hacker News | · 10d ago |
| domain | pstatic.net | elivery traffic into normal web browsing, mimicking Naver’s pstatic.net static content domain. “Ted backdoor and curlRAT were desig | North Korean Hackers Deploy New Linux Espionage Toolkit SecurityWeek | · 10d ago |
| domain | anondns.net | nConnect.Client.exe"), which then connected to "borertors92.anondns[.]net." The session then uses "wscript.exe" to execute the four | Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts The Hacker News | · 10d ago |
| domain | opik.net | ontrol (C2) server located at "45.13.237[.]190" ("tele-sync.opik[.]net"). Hosted on the IP address is a RAR archive containing t | Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts The Hacker News | · 10d ago |
| domain | asp.net | g exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to execute | Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released The Hacker News | · 10d ago |
| ipv4 | 103.102.31.18 | ccount 82.192.72.4 — linked to confirmed successful attacks 103.102.31.18 — observed attempting to exploit MikroTrick If compromise i | Hackers exploit new MikroTik RouterOS flaws to hijack routers BleepingComputer | · 10d ago |
| ipv4 | 82.192.72.4 | by ssh:-2@<ip>’ Presence of a highly privileged ops account 82.192.72.4 — linked to confirmed successful attacks 103.102.31.18 — ob | Hackers exploit new MikroTik RouterOS flaws to hijack routers BleepingComputer | · 10d ago |
| md5 | 581e2e2265d0c1509b3799c5a9039374 | encrypted payload we observed was generated on 2025-11-11 ( 581e2e2265d0c1509b3799c5a9039374 ). The AES key is not stored in the malware bundle itself. | JSCeal Hides Crypto Malware in V8 Bytecode Security Affairs | · 10d ago |
| ipv4 | 103.102.31.18 | ince at least September 2, and it flagged a second address, 103.102.31.18, used in attempts to exploit the same chain. Patches and de | Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication Help Net Security | · 10d ago |
| ipv4 | 82.192.72.4 | including creation of that “ops” account, to the IP address 82.192.72.4, active since at least September 2, and it flagged a second | Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication Help Net Security | · 10d ago |
| sha256 | 6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e | b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e (serve.py). Follow me on Twitter: @securityaffairs and Face | Your MikroTik Router May Already Be Compromised: Look for SSH User “-2” Security Affairs | · 11d ago |
| sha256 | 6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d | nalysis: IPs 82.192.72[.]4 and 103.102.31[.]18; file hashes 6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b | Your MikroTik Router May Already Be Compromised: Look for SSH User “-2” Security Affairs | · 11d ago |
| sha256 | 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd | b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36f | Your MikroTik Router May Already Be Compromised: Look for SSH User “-2” Security Affairs | · 11d ago |
| md5 | 5568cd69c754b392121f1dbb8f900fda | r IPv4 (Tzulo VPN) 23.234.97[.]68 Intruder IPv4 (Tzulo VPN) 5568cd69c754b392121f1dbb8f900fda Malicious Cloudflare tunnel account tag Update: 8/6/26 @ 5: | Critical N-able N-central Vulnerability and Active Exploitation Huntress | · 11d ago |
| domain | gardenpark.click | : health.journal-metric[.]lol (WinUpdate C2) Domain: metric.gardenpark[.]click (SoftManager C2) Gen Threat Labs first documented REVSTEA | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| domain | hubdisplay.lol | onitor5.roast-core85[.]click (REVSTEALER C2) Domain: config.hubdisplay[.]lol (ProManager C2) Domain: health.journal-metric[.]lol (WinU | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| domain | journal-metric.lol | ain: config.hubdisplay[.]lol (ProManager C2) Domain: health.journal-metric[.]lol (WinUpdate C2) Domain: metric.gardenpark[.]click (SoftMan | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| domain | roast-core85.click | 66f4b11c6a431e78884a5b2651e5 (LockAppHost) Domain: monitor5.roast-core85[.]click (REVSTEALER C2) Domain: config.hubdisplay[.]lol (ProManag | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| sha256 | 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa | 4987ae9eb21bf5e67de5e9461b09655165ee4 (REVSTEALER) SHA-256: 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa (ProManager) SHA-256: 7c08cf409194056a8517865e5d3433d1499bb | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| sha256 | 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2 | 3433d1499bb8262263b55b49b8b07d9d182fcb (WinUpdate) SHA-256: 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2 (SoftManager) SHA-256: c66d2b77b9e85c53391891212413ad9a99eb | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| sha256 | 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb | 580b453ce4987acbe2c4c4d04833f55ebccfa (ProManager) SHA-256: 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb (WinUpdate) SHA-256: 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.