ZeroHour

Indicators of compromise

652 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domaingrok.com: shared, indexable conversations hosted on chatgpt.com and grok.com that can rank for troubleshooting searches. Each of these sHow Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
BleepingComputer
· 6d ago
domaindomainlify.netom Sender email address used to send campaign emails Domain domainlify[.]net Newly registered domain used in the Reply-To address NoteHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domaineemusicclass.co.ukaddress used to send campaign emails Email address contact@eemusicclass[.]co[.]uk Sender email address used to send campaign emails EmailHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainlifeones.comail address used to send campaign emails Email address info@lifeones[.]com Sender email address used to send campaign emails DomainHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainlohnsteuerhilfe-aktuell-verein.deail address used to send campaign emails Email address info@lohnsteuerhilfe-aktuell-verein[.]de Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainlumalisboa.comaddress used to send campaign emails Email address no-reply@lumalisboa[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainmctci.comaddress used to send campaign emails Email address noreply@mctci[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainnuf.co.jpail address used to send campaign emails Email address info@nuf[.]co[.]jp Sender email address used to send campaign emails EmailHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainservice-nowinc.comrs of compromise (IoCs):- Type Indicator Description Domain service-nowinc[.]com Domain impersonating ServiceNow Email address gomez@serviHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domaintivityhealth.comail address used to send campaign emails Email address info@tivityhealth[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domaintovimbatista.ptail address used to send campaign emails Email address info@tovimbatista[.]pt Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainuinsure.co.ukassociated with a bank account Email address notifications@uinsure[.]co[.]uk Sender email address used to send campaign emails EmailHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainapimantax.otax.funbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically retrievedNew Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
Cyber Security News
· 6d ago
domaingitclone.orgxploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-42018/Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 6d ago
domainbackup-ubt.s3.us-east-1.amazonaws.comws[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east-1[.]amazonaws[.]com/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.bloHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainhostfxr.dllL URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-eastHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainlinked4x.comfffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoaderHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainskipraid.comDomain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader domain URL hxxps[://]skipraid[.]com/dsVGmQTrHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainstro7121.blob.core.windows.netid[.]com/dsVGmQTrzX/default2 CastleLoader URL URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/config.py Python loader URL URL hxxps[://]stroHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domaintelephoneip.netible; DLLMemLoader/1.0) Python loader User-Agent Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRATHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domaintruesmart.orgDomain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT C2 domain Note: IP addresses and domains are inHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainwindows.netm/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blob.core.windows[.]net Python downloader C2 IP address 62.106.66[.]148:443 SloppHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domaingitclone.org.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / HashJFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 6d ago
domaindomainlify.nett in the fake invoice as a contact address. Another domain, domainlify[.]net, was used in Reply-To fields. The short preparation perioHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domaineemusicclass.co.ukuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email addressHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainlifeones.cominfo@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out emailHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainlohnsteuerhilfe-aktuell-verein.deumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk infHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainlumalisboa.comications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainmctci.comk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainnuf.co.jpth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatiHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainservice-nowinc.comonsumer goods’ and others (Source : Microsoft). One domain, service-nowinc[.]com, was registered on July 31, shortly before the phishing aHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domaintivityhealth.comated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domaintovimbatista.ptnuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com EmailHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainuinsure.co.ukss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norepHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainnoht1ng.topil.uaiubifas[.]top backdoor command server, port 443 Domain noht1ng[.]top hosted the exploit page IP 8.218.50[.]207 staging server,China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 6d ago
domainuaiubifas.tophind is GRAYRABBIT. The backdoor reaches its server at mail.uaiubifas[.]top on port 443, and the traffic there is plain TCP scrambledChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 6d ago
domainapimantax.otax.funMantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and published asMantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
GBHackers
· 6d ago
domainhunt.ioe automated campaigns was effectively less than three days. Hunt.io’s AttackCapture system crawled the attacker’s open directorUK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Security Affairs
· 6d ago
domainlinked4x.comirectories. Security teams should also hunt for the domains linked4x[.]com , skipraid[.]com , and the observed Azure Blob Storage paHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 6d ago
domainskipraid.comthe download of CastleLoader and CastleRAT components from skipraid[.]com , using the distinctive K8VGmQTrzX User-Agent string. CasHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 6d ago
domaingitclone.org-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2026Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 6d ago
domaindomainlify.netalso registered another domain on the same day. The domain domainlify[.]net was used in the Reply-To email. Figure 7. Account informaProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domaineemusicclass.co.ukuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email addressProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainlifeones.cominfo@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out emailProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainlohnsteuerhilfe-aktuell-verein.deumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk infProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainlumalisboa.comications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainmctci.comk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]Protecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainnuf.co.jpth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatiProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainservice-nowinc.comregistered several domains. A ‘ServiceNow’ lookalike domain service-nowinc[.]com was registered on July 31, shortly before the campaign acProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domaintivityhealth.comated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]Protecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domaintovimbatista.ptnuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com EmailProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago
domainuinsure.co.ukss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norepProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 6d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.