Indicators of compromise
1,193 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | graph.checkeligibitily.workers.dev | nline Exfiltration and fingerprinting infrastructure Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[ | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | harialurdes.site | ialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.]site Intermediate KREMLIN campaign domain IP address 178.92.16 | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | lojinhadoluiz.online | com Earlier campaign lure and payload-hosting domain Domain lojinhadoluiz[.]online FrameSync campaign extension infrastructure Domain orange | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | luizestrelhashapr.online | gibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[.]online Resolved WebSocket command-and-control host Domain segura | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | marialurdes.site | tos[.]site Earlier extension-delivery infrastructure Domain marialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[. | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | orange-sun-195a.checkeligibitily.workers.dev | .]online FrameSync campaign extension infrastructure Domain orange-sun-195a[.]checkeligibitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | seguranca.versionnova.site | .]online Resolved WebSocket command-and-control host Domain seguranca[.]versionnova[.]site Infrastructure associated with a related KREMLIN branch | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | volmira.site | derevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Extension hosting and credential-exfiltration infrastruct | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | www.creamp1eonlyfans.net | ader beaconing and extension-delivery infrastructure Domain www[.]creamp1eonlyfans[.]net Network canary domain checked by KREMLIN Domain grander | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | zaviro.online | n hosting and credential-exfiltration infrastructure Domain zaviro[.]online Exfiltration and fingerprinting infrastructure Domain gra | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 | s of compromise (IoCs):- Type Indicator Description SHA-256 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8a | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c | 70e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127 | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca | 81bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa4 | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 | fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 PowerShell extension-installer implementation Domain connec | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 | aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f | 3811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2 | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 | 89910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648b | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| sha256 | cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 | a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 1d ago |
| domain | api.telegram.org | orjShare. Defenders should investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[. | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
| domain | backblazeb2.com | uld investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com an | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
| domain | iproyal.com | backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such conn | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
| domain | lightningproxies.net | , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connections do not align with n | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
| domain | storjshare.io | .]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
| domain | vultrobjects.com | pected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.] | Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results GBHackers | · 1d ago |
| ipv4 | 104.194.9.138 | 5c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a succes | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 114.10.43.203 | 0 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attac | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 187.75.114.36 | 1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack pe | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 23.137.105.214 | 41.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 23.180.120.140 | .129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Be | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 31.59.129.150 | originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.1 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 37.114.144.209 | 14 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacker to upload a | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 6.17.4.1 | the plugin, has addressed the flaws in version 6.17.3.1 and 6.17.4.1, respectively. Found this article interesting? Follow us on | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 92.241.13.140 | dresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 1 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| ipv4 | 92.241.13.213 | attempts have originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.10 | Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells The Hacker News | · 1d ago |
| domain | github.com | ilable in the following pull requests for community users - github[.]com/wso2/carbon-apimgt/pull/13752 github[.]com/wso2/product-a | Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens The Hacker News | · 1d ago |
| domain | brevo.com | n a Brevo-sent campaign email AttackerBrevocode injected in brevo.com & sendibt1.comBrevo customers100k+ sites and mailing listsE | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | cdn10.sendibt1.com | om cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware host | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | cdn11.sendibt1.com | m 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware host /f.js the loader / | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | cdn2.sendibt1.com | hild (s); })(); These loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10 | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | cdn3.sendibt1.com | ese loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10.sendibt1.com cdn1 | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | sendibt1.com | s suggests a single Cloudflare account holding all of them, sendibt1.com included. That is the zone where the attacker created the c | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | sendinblue.com | udflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a single Cloudflare accoun | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | sibautomation.com | domains all use Cloudflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a single | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | sibforms.com | revo.com iframe page that backs the chat widget, and on the sibforms.com pages that serve hosted signup and unsubscribe forms: < scr | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| ipv4 | 104.21.77.104 | sts (all NXDOMAIN since 15 September 2026) cdn.sendibt1.com 104.21.77.104 created 2026-08-25 17:08 UTC cdn2.sendibt1.com cdn3.sendibt | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| ipv4 | 172.246.243.65 | endibt1.com itself is not proxied, answering on Brevo's own 172.246.243.65 in AS200484 with server: envoy , while only the attacker's | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| ipv4 | 188.114.97.3 | 1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1 | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca | tps://conversations-widget.brevo.com/brevo-conversations.js 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e3 | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7 | sponse, identical across every host and every observed scan 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7 {"s":0,"r":"https:\/\/www.google.com"} # Do not block sendi | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 | 71db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980 | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 | 7a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 injected -> cdn4 # The appended line (final line of each fi | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 | 588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 injected -> cdn11 https://conversations-widget.brevo.com/br | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| sha256 | fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 | e 15 September 2026) https://cdn.brevo.com/js/sdk-loader.js fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795f | Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware Sansec (Magento / e-commerce security) | · 1d ago |
| domain | vip311.cc | e. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc ass | Low-quality casino sites conceal highly dangerous threat actors The Register · Security | · 1d ago |
| domain | zenplay77-x.space | o sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem i | Low-quality casino sites conceal highly dangerous threat actors The Register · Security | · 1d ago |
| domain | zzyud.com | s of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with | Low-quality casino sites conceal highly dangerous threat actors The Register · Security | · 1d ago |
| domain | luizestrelhashapr.online | filtrating browser data for each profile to its C2 server ("luizestrelhashapr[.]online:443") but not before requesting extensive access to brows | KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens The Hacker News | · 1d ago |
| domain | volmira.site | to the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain th | KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens The Hacker News | · 1d ago |
| domain | zaviro.online | um smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extension | KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens The Hacker News | · 1d ago |
| domain | c2iznja.com | on the machine and exfiltrate them to the C2 server ("api80.c2iznja[.]com"). "The domains used Cloudflare as a proxy for their infr | BambooToken Malware Uses MQTT to Control Windows and Linux Systems The Hacker News | · 1d ago |
| domain | chat5188.tk | gather system details and transmit them to the C2 server ("chat5188[.]tk"). In response, the server issues commands to load a plug | BambooToken Malware Uses MQTT to Control Windows and Linux Systems The Hacker News | · 1d ago |
| ipv4 | 2.0.3.1 | aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload v | Hackers target WordPress sites via third-party WooCommerce plugin BleepingComputer | · 2d ago |
| domain | hunt.io | mand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host dis | Thai Broadband Provider Hacked via Fortinet Vulnerability SecurityWeek | · 2d ago |
| domain | 31-59-175-195.syd.nbn.aussiebb.net | gets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . Th | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | eightindigostove.com | 75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarew | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | loadswage.com | ture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was as | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | moolaah.com | d through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed Mahnschrei | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | opensea.io | itting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tes | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | web5-4s4c-online-garantibbva.vibtee.com | s IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificati | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | website-2df62808.mvplineup.com | ent reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing deco | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| domain | xmasbrick.com | : Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxp | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| url | http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF | [.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193 | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 2d ago |
| ipv4 | 104.194.9.138 | 5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentio | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 187.75.114.36 | .13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged ( | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 2.0.3.1 | bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 o | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 23.137.105.214 | 3 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP a | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 23.180.120.140 | 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and doma | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 31.59.129.150 | e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, fo | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 92.241.13.140 | r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75. | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| ipv4 | 92.241.13.213 | and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 bl | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 2d ago |
| domain | 31-59-175-195.syd.nbn.aussiebb.net | of compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renew | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | eightindigostove.com | ssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus rene | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | loadswage.com | sed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus ren | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | moolaah.com | path in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-p | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | opensea.io | ing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser- | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | web5-4s4c-online-garantibbva.vibtee.com | Pv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking p | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | website-2df62808.mvplineup.com | omain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in th | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | xmasbrick.com | the cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the Roma | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| url | http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF | nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 2d ago |
| domain | api.telegram.org | ing in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ip | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | backblazeb2.com | ctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightnin | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | iproyal.com | [.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is fo | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | lightningproxies.net | zeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to be | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | storjshare.io | : api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | vultrobjects.com | nvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Miti | Iranian cyber targeting of dissidents, activists and journalists NCSC UK | · 2d ago |
| domain | ember-bridge.com | lution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate y | HBO Max’s verified Reddit account hijacked to spread malware Malwarebytes Labs | · 2d ago |
| ipv4 | 104.194.9.138 | urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| ipv4 | 114.10.43.203 | source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests I | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| ipv4 | 187.75.114.36 | urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests I | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
| ipv4 | 23.137.105.214 | urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 2d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.