Indicators of compromise
55 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| ipv4 | 2.0.3.1 | aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload v | Hackers target WordPress sites via third-party WooCommerce plugin BleepingComputer | · 6h ago |
| ipv4 | 104.194.9.138 | 5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentio | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 9h ago |
| ipv4 | 187.75.114.36 | .13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged ( | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 9h ago |
| ipv4 | 2.0.3.1 | bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 o | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 9h ago |
| ipv4 | 23.137.105.214 | 3 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP a | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 9h ago |
| ipv4 | 23.180.120.140 | 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and doma | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 9h ago |
| ipv4 | 31.59.129.150 | e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, fo | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 9h ago |
| ipv4 | 92.241.13.140 | r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75. | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 9h ago |
| ipv4 | 92.241.13.213 | and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 bl | Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors GBHackers | · 9h ago |
| ipv4 | 104.194.9.138 | urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 9h ago |
| ipv4 | 114.10.43.203 | source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests I | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 9h ago |
| ipv4 | 187.75.114.36 | urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests I | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 9h ago |
| ipv4 | 23.137.105.214 | urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 9h ago |
| ipv4 | 23.180.120.140 | urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 9h ago |
| ipv4 | 31.59.129.150 | rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit request | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 9h ago |
| ipv4 | 37.114.144.209 | source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests F | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 9h ago |
| ipv4 | 92.241.13.140 | rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requests | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 9h ago |
| ipv4 | 92.241.13.213 | f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit request | Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login Cyber Security News | · 9h ago |
| ipv4 | 164.90.161.147 | lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September ma | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 16h ago |
| ipv4 | 165.22.199.85 | rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration Septemb | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 16h ago |
| ipv4 | 45.94.47.204 | omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemen | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 16h ago |
| ipv4 | 77.91.65.13 | nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP autho | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 16h ago |
| ipv4 | 89.34.96.56 | ompromise (IoCs):- Type Indicator Description C2 IP address 89.34.96.56 Hard-coded Cyclops Blink command-and-control server C2 TCP | Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning Cyber Security News | · 1d ago |
| ipv4 | 8.218.50.207 | n Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging server hosted on Alibaba Cloud in Hong Kong Domain | One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users Cyber Security News | · 1d ago |
| ipv4 | 8.8.8.8 | entire framework. The module also uses Google Public DNS at 8.8.8.8 over DNS-over-HTTPS access to resolve transfer-host names, | Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities GBHackers | · 1d ago |
| ipv4 | 45.142.193.132 | irm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31. “The adversary went from an empty workspace t | Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script The Register · Security | · 5d ago |
| ipv4 | 1.0.0.1 | ct() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additiona | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 5d ago |
| ipv4 | 109.91.184.21 | resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known public resolver servi | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 5d ago |
| ipv4 | 1.1.1.1 | nal connect() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 5d ago |
| ipv4 | 80.152.203.134 | ons were public DNS resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known pub | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 5d ago |
| ipv4 | 8.8.4.4 | port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/8 | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 5d ago |
| ipv4 | 8.8.8.8 | erified while attempts to reach an external address such as 8.8.8.8 returned Network is unreachable. This design allowed the ma | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 5d ago |
| ipv4 | 9.9.9.10 | tions included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is commonly asso | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 5d ago |
| ipv4 | 9.9.9.9 | . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is com | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 5d ago |
| ipv4 | 45.142.193.132 | he actors utilized infrastructure, including the IP address 45.142.193.132, which GreyNoise had tracked since early July for attacks a | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 5d ago |
| ipv4 | 45.158.196.75 | paign orchestration and execution infrastructure IP address 45.158.196.75 Infrastructure used to execute campaign activity File hash | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 5d ago |
| ipv4 | 9.20.4.14 | ewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions U | Cisco security advisory (AV26-197) – Update 3 Canadian Centre for Cyber Security | · 6d ago |
| ipv4 | 62.60.130.193 | ll log failed login attempts with a 401 status code: ::ffff:62.60.130.193 - - [09/09/2026:15:26:14 +0000] "POST /api2/json/access/tic | Scans for Proxmox Servers, (Wed, Sep 9th) SANS Internet Storm Center | · 6d ago |
| ipv4 | 45.142.193.132 | nfrastructure. The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for prob | Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide Cyber Security News | · 6d ago |
| ipv4 | 146.103.99.177 | Incident responders should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js fil | Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT GBHackers | · 6d ago |
| ipv4 | 46.151.29.58 | s should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js files, and review ru | Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT GBHackers | · 6d ago |
| ipv4 | 173.212.244.25 | IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA targets IP address 2 | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 6d ago |
| ipv4 | 188.245.99.156 | f compromise (IoCs):- Type Indicator Description IP address 188.245.99.156 Operator host used for rogue Redis replication, command-and | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 6d ago |
| ipv4 | 194.48.248.105 | Recurring WordPress exploitation target IP address and port 194.48.248.105:8081 Earlier open directory linked by cryptocurrency wallet | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 6d ago |
| ipv4 | 20.198.10.42 | target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed develo | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 6d ago |
| ipv4 | 213.6.207.123 | hip unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA tar | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 6d ago |
| ipv4 | 23.235.223.49 | 5 Additional observed development and QA targets IP address 23.235.223.49 Recurring WordPress exploitation target IP address and port | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 6d ago |
| ipv4 | 34.166.99.116 | eused QA or test target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 6d ago |
| ipv4 | 45.155.102.89 | stname> Victim check-in request pattern IP address and port 45.155.102.89:10128 Local mining pool proxy used on the operator host Dom | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 6d ago |
| ipv4 | 47.250.92.230 | -controlled hostname resolving to 188.245.99.156 IP address 47.250.92.230 Frequently reused QA or test target, ownership unconfirmed | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 6d ago |
| ipv4 | 15.1.10.8 | 0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nearly a year old. Ireland's N | F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News | · 6d ago |
| ipv4 | 16.1.6.1 | .0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nea | F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News | · 6d ago |
| ipv4 | 17.5.1.3 | s. Versions known to be vulnerable Fixed in 17.5.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15 | F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News | · 6d ago |
| ipv4 | 45.142.193.132 | investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against in | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 6d ago |
| ipv4 | 45.158.196.75 | 45.142.193.132 Used to orchestrate and execute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667 | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 6d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.