Indicators of compromise
1,946 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | lightningproxies.net | , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connections do not align with n | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
| domain | storjshare.io | .]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
| domain | vultrobjects.com | pected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.] | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
| ipv4 | 104.194.9.138 | 5c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a succes | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 114.10.43.203 | 0 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attac | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 187.75.114.36 | 1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack pe | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 23.137.105.214 | 41.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 23.180.120.140 | .129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Be | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 31.59.129.150 | originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.1 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 37.114.144.209 | 14 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacker to upload a | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 6.17.4.1 | the plugin, has addressed the flaws in version 6.17.3.1 and 6.17.4.1, respectively. Found this article interesting? Follow us on | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 92.241.13.140 | dresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 1 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 92.241.13.213 | attempts have originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.10 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| domain | github.com | ilable in the following pull requests for community users - github[.]com/wso2/carbon-apimgt/pull/13752 github[.]com/wso2/product-a | Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens The Hacker News | · 1d ago |
| domain | brevo.com | n a Brevo-sent campaign email AttackerBrevocode injected in brevo.com & sendibt1.comBrevo customers100k+ sites and mailing listsE | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | cdn10.sendibt1.com | om cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware host | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | cdn11.sendibt1.com | m 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware host /f.js the loader / | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | cdn2.sendibt1.com | hild (s); })(); These loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10 | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | cdn3.sendibt1.com | ese loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10.sendibt1.com cdn1 | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | sendibt1.com | s suggests a single Cloudflare account holding all of them, sendibt1.com included. That is the zone where the attacker created the c | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | sendinblue.com | udflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a single Cloudflare accoun | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | sibautomation.com | domains all use Cloudflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a single | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | sibforms.com | revo.com iframe page that backs the chat widget, and on the sibforms.com pages that serve hosted signup and unsubscribe forms: < scr | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| ipv4 | 104.21.77.104 | sts (all NXDOMAIN since 15 September 2026) cdn.sendibt1.com 104.21.77.104 created 2026-08-25 17:08 UTC cdn2.sendibt1.com cdn3.sendibt | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| ipv4 | 172.246.243.65 | endibt1.com itself is not proxied, answering on Brevo's own 172.246.243.65 in AS200484 with server: envoy , while only the attacker's | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| ipv4 | 188.114.97.3 | 1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1 | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca | tps://conversations-widget.brevo.com/brevo-conversations.js 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e3 | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7 | sponse, identical across every host and every observed scan 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7 {"s":0,"r":"https:\/\/www.google.com"} # Do not block sendi | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 | 71db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980 | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 | 7a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 injected -> cdn4 # The appended line (final line of each fi | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 | 588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 injected -> cdn11 https://conversations-widget.brevo.com/br | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 | e 15 September 2026) https://cdn.brevo.com/js/sdk-loader.js fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795f | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | vip311.cc | e. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc ass | Low-quality casino sites conceal highly dangerous threat actors The Register · Security | · 1d ago |
| domain | zenplay77-x.space | o sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem i | Low-quality casino sites conceal highly dangerous threat actors The Register · Security | · 1d ago |
| domain | zzyud.com | s of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with | Low-quality casino sites conceal highly dangerous threat actors The Register · Security | · 1d ago |
| domain | luizestrelhashapr.online | filtrating browser data for each profile to its C2 server ("luizestrelhashapr[.]online:443") but not before requesting extensive access to brows | KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens The Hacker News | · 1d ago |
| domain | volmira.site | to the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain th | KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens The Hacker News | · 1d ago |
| domain | zaviro.online | um smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extension | KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens The Hacker News | · 1d ago |
| domain | c2iznja.com | on the machine and exfiltrate them to the C2 server ("api80.c2iznja[.]com"). "The domains used Cloudflare as a proxy for their infr | BambooToken Malware Uses MQTT to Control Windows and Linux Systems The Hacker News | · 1d ago |
| domain | chat5188.tk | gather system details and transmit them to the C2 server ("chat5188[.]tk"). In response, the server issues commands to load a plug | BambooToken Malware Uses MQTT to Control Windows and Linux Systems The Hacker News | · 1d ago |
| ipv4 | 2.0.3.1 | aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload v | Hackers target WordPress sites via third-party WooCommerce plugin BleepingComputer | · 1d ago |
| domain | hunt.io | mand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host dis | Thai Broadband Provider Hacked via Fortinet Vulnerability SecurityWeek | · 2d ago |
| domain | 31-59-175-195.syd.nbn.aussiebb.net | gets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . Th | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | eightindigostove.com | 75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarew | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | loadswage.com | ture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was as | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | moolaah.com | d through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed Mahnschrei | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | opensea.io | itting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tes | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | web5-4s4c-online-garantibbva.vibtee.com | s IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificati | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | website-2df62808.mvplineup.com | ent reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing deco | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | xmasbrick.com | : Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxp | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| url | http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF | [.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193 | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| ipv4 | 104.194.9.138 | 5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentio | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 187.75.114.36 | .13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged ( | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 2.0.3.1 | bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 o | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 23.137.105.214 | 3 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP a | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 23.180.120.140 | 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and doma | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 31.59.129.150 | e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, fo | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 92.241.13.140 | r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75. | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 92.241.13.213 | and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 bl | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| domain | 31-59-175-195.syd.nbn.aussiebb.net | of compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renew | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | eightindigostove.com | ssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus rene | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | loadswage.com | sed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus ren | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | moolaah.com | path in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-p | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | opensea.io | ing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser- | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | web5-4s4c-online-garantibbva.vibtee.com | Pv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking p | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | website-2df62808.mvplineup.com | omain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in th | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | xmasbrick.com | the cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the Roma | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| url | http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF | nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | api.telegram.org | ing in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ip | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | backblazeb2.com | ctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightnin | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | iproyal.com | [.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is fo | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | lightningproxies.net | zeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to be | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | storjshare.io | : api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | vultrobjects.com | nvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Miti | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | ember-bridge.com | lution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate y | HBO Max’s verified Reddit account hijacked to spread malware Malwarebytes Labs | · 2d ago |
| ipv4 | 104.194.9.138 | urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| ipv4 | 114.10.43.203 | source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests I | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| ipv4 | 187.75.114.36 | urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests I | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| ipv4 | 23.137.105.214 | urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| ipv4 | 23.180.120.140 | urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| ipv4 | 31.59.129.150 | rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit request | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| ipv4 | 37.114.144.209 | source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests F | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| ipv4 | 92.241.13.140 | rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| ipv4 | 92.241.13.213 | f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit request | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| domain | server.host | exposes the Vite dev server to the network using --host or server.host config option The sensitive file exists in the allowed dire | Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers The Hacker News | · 2d ago |
| domain | clean-disk-guide.com | oke down into 15 ads for a fake macOS disk utility at apple.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. O | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 2d ago |
| domain | code-desktop.com | .clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. One entry point into a larger system The HBO Max ads wer | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 2d ago |
| domain | codex-craft.com | -macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craft[.]com. The rest broke down into 15 ads for a fake macOS disk ut | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 2d ago |
| domain | hbomax-macos.com | s, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craf | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 2d ago |
| domain | hbomaxx.app | id . Of the 108 ads, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 2d ago |
| domain | hbomaxx.us | HBO Max subreddits,” wrote the user. Clicking the ad led to hbomaxx[.]us, “which looks somewhat legitimate, and has a join button | Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Help Net Security | · 2d ago |
| domain | hbomaxx.us | ich does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also con | Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack SecurityWeek | · 2d ago |
| domain | biterflll.com | y tips in seconds. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com b | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 2d ago |
| domain | bitigift.com | s. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[. | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 2d ago |
| domain | bitrefall.com | f compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[. | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 2d ago |
| domain | bitrefill.com | ed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment. Be wary of domains containing a | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 2d ago |
| domain | bitrefill-payments.com | Cs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitr | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 2d ago |
| domain | bitrefill-pays.com | com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[ | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 2d ago |
| domain | bitregift.com | trefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[ | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 2d ago |
| domain | bitregill.com | trefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[ | Search results are sending people to fake Bitrefill checkouts Malwarebytes Labs | · 2d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.