ZeroHour

Indicators of compromise

1,193 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domaingraph.checkeligibitily.workers.devnline Exfiltration and fingerprinting infrastructure Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainharialurdes.siteialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.]site Intermediate KREMLIN campaign domain IP address 178.92.16KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainlojinhadoluiz.onlinecom Earlier campaign lure and payload-hosting domain Domain lojinhadoluiz[.]online FrameSync campaign extension infrastructure Domain orangeKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainluizestrelhashapr.onlinegibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[.]online Resolved WebSocket command-and-control host Domain seguraKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainmarialurdes.sitetos[.]site Earlier extension-delivery infrastructure Domain marialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainorange-sun-195a.checkeligibitily.workers.dev.]online FrameSync campaign extension infrastructure Domain orange-sun-195a[.]checkeligibitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QRKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainseguranca.versionnova.site.]online Resolved WebSocket command-and-control host Domain seguranca[.]versionnova[.]site Infrastructure associated with a related KREMLIN branchKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainvolmira.sitederevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Extension hosting and credential-exfiltration infrastructKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainwww.creamp1eonlyfans.netader beaconing and extension-delivery infrastructure Domain www[.]creamp1eonlyfans[.]net Network canary domain checked by KREMLIN Domain granderKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainzaviro.onlinen hosting and credential-exfiltration infrastructure Domain zaviro[.]online Exfiltration and fingerprinting infrastructure Domain graKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42s of compromise (IoCs):- Type Indicator Description SHA-256 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8aKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c70e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca81bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa4KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha25642a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 PowerShell extension-installer implementation Domain connecKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha2565ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7cKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f3811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a426889910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648bKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
sha256cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bcKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 1d ago
domainapi.telegram.orgorjShare. Defenders should investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago
domainbackblazeb2.comuld investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com anHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago
domainiproyal.combackblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago
domainlightningproxies.net, vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connections do not align with nHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago
domainstorjshare.io.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularlyHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago
domainvultrobjects.compected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago
ipv4104.194.9.1385c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a succesAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv4114.10.43.2030 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv4187.75.114.361 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack peAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv423.137.105.21441.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv423.180.120.140.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 BeAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv431.59.129.150originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.1Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv437.114.144.20914 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacker to upload aAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv46.17.4.1the plugin, has addressed the flaws in version 6.17.3.1 and 6.17.4.1, respectively. Found this article interesting? Follow us onAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv492.241.13.140dresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 1Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv492.241.13.213attempts have originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.10Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
domaingithub.comilable in the following pull requests for community users - github[.]com/wso2/carbon-apimgt/pull/13752 github[.]com/wso2/product-aActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
The Hacker News
· 1d ago
domainbrevo.comn a Brevo-sent campaign email AttackerBrevocode injected in brevo.com & sendibt1.comBrevo customers100k+ sites and mailing listsEBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn10.sendibt1.comom cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware hostBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn11.sendibt1.comm 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware host /f.js the loader /Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn2.sendibt1.comhild (s); })(); These loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn3.sendibt1.comese loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10.sendibt1.com cdn1Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsendibt1.coms suggests a single Cloudflare account holding all of them, sendibt1.com included. That is the zone where the attacker created the cBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsendinblue.comudflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a single Cloudflare accounBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsibautomation.comdomains all use Cloudflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a singleBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsibforms.comrevo.com iframe page that backs the chat widget, and on the sibforms.com pages that serve hosted signup and unsubscribe forms: < scrBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
ipv4104.21.77.104sts (all NXDOMAIN since 15 September 2026) cdn.sendibt1.com 104.21.77.104 created 2026-08-25 17:08 UTC cdn2.sendibt1.com cdn3.sendibtBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
ipv4172.246.243.65endibt1.com itself is not proxied, answering on Brevo's own 172.246.243.65 in AS200484 with server: envoy , while only the attacker'sBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
ipv4188.114.97.31.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha25626166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddcatps://conversations-widget.brevo.com/brevo-conversations.js 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e3Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha2564af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7sponse, identical across every host and every observed scan 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7 {"s":0,"r":"https:\/\/www.google.com"} # Do not block sendiBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha25658a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a43230871db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha2569b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a57a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 injected -> cdn4 # The appended line (final line of each fiBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha256f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 injected -> cdn11 https://conversations-widget.brevo.com/brBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha256fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09e 15 September 2026) https://cdn.brevo.com/js/sdk-loader.js fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795fBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainvip311.cce. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc assLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 1d ago
domainzenplay77-x.spaceo sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem iLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 1d ago
domainzzyud.coms of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated withLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 1d ago
domainluizestrelhashapr.onlinefiltrating browser data for each profile to its C2 server ("luizestrelhashapr[.]online:443") but not before requesting extensive access to browsKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 1d ago
domainvolmira.siteto the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain thKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 1d ago
domainzaviro.onlineum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extensionKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 1d ago
domainc2iznja.comon the machine and exfiltrate them to the C2 server ("api80.c2iznja[.]com"). "The domains used Cloudflare as a proxy for their infrBambooToken Malware Uses MQTT to Control Windows and Linux Systems
The Hacker News
· 1d ago
domainchat5188.tkgather system details and transmit them to the C2 server ("chat5188[.]tk"). In response, the server issues commands to load a plugBambooToken Malware Uses MQTT to Control Windows and Linux Systems
The Hacker News
· 1d ago
ipv42.0.3.1aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload vHackers target WordPress sites via third-party WooCommerce plugin
BleepingComputer
· 2d ago
domainhunt.iomand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host disThai Broadband Provider Hacked via Fortinet Vulnerability
SecurityWeek
· 2d ago
domain31-59-175-195.syd.nbn.aussiebb.netgets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . ThPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domaineightindigostove.com75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarewPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainloadswage.comture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was asPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainmoolaah.comd through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed MahnschreiPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainopensea.ioitting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tesPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainweb5-4s4c-online-garantibbva.vibtee.coms IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificatiPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainwebsite-2df62808.mvplineup.coment reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing decoPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainxmasbrick.com: Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxpPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
urlhttp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF[.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
ipv4104.194.9.1385389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentioHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv4187.75.114.36.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged (Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv42.0.3.1bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 oHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv423.137.105.2143 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP aHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv423.180.120.1403 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domaHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv431.59.129.150e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, foHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv492.241.13.140r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv492.241.13.213and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
domain31-59-175-195.syd.nbn.aussiebb.netof compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renewNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domaineightindigostove.comssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus reneNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainloadswage.comsed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus renNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainmoolaah.compath in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-pNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainopensea.ioing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser-New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainweb5-4s4c-online-garantibbva.vibtee.comPv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking pNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainwebsite-2df62808.mvplineup.comomain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in thNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainxmasbrick.comthe cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the RomaNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
urlhttp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DFnder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankinNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainapi.telegram.orging in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ipIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainbackblazeb2.comctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightninIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainiproyal.com[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is foIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainlightningproxies.netzeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to beIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainstorjshare.io: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The bestIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainvultrobjects.comnvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net MitiIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainember-bridge.comlution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate yHBO Max’s verified Reddit account hijacked to spread malware
Malwarebytes Labs
· 2d ago
ipv4104.194.9.138urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
ipv4114.10.43.203source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests IHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
ipv4187.75.114.36urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests IHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
ipv423.137.105.214urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.