ZeroHour

Indicators of compromise

55 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
ipv42.0.3.1aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload vHackers target WordPress sites via third-party WooCommerce plugin
BleepingComputer
· 6h ago
ipv4104.194.9.1385389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentioHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 9h ago
ipv4187.75.114.36.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged (Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 9h ago
ipv42.0.3.1bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 oHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 9h ago
ipv423.137.105.2143 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP aHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 9h ago
ipv423.180.120.1403 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domaHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 9h ago
ipv431.59.129.150e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, foHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 9h ago
ipv492.241.13.140r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 9h ago
ipv492.241.13.213and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 9h ago
ipv4104.194.9.138urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 9h ago
ipv4114.10.43.203source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests IHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 9h ago
ipv4187.75.114.36urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests IHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 9h ago
ipv423.137.105.214urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 9h ago
ipv423.180.120.140urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 9h ago
ipv431.59.129.150rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit requestHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 9h ago
ipv437.114.144.209source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests FHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 9h ago
ipv492.241.13.140rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 9h ago
ipv492.241.13.213f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit requestHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 9h ago
ipv4164.90.161.147lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September maHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
ipv4165.22.199.85rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration SeptembHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
ipv445.94.47.204omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemenHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
ipv477.91.65.13nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP authoHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
ipv489.34.96.56ompromise (IoCs):- Type Indicator Description C2 IP address 89.34.96.56 Hard-coded Cyclops Blink command-and-control server C2 TCPCyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning
Cyber Security News
· 1d ago
ipv48.218.50.207n Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging server hosted on Alibaba Cloud in Hong Kong DomainOne Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
Cyber Security News
· 1d ago
ipv48.8.8.8entire framework. The module also uses Google Public DNS at 8.8.8.8 over DNS-over-HTTPS access to resolve transfer-host names,Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities
GBHackers
· 1d ago
ipv445.142.193.132irm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31. “The adversary went from an empty workspace tHundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
The Register · Security
· 5d ago
ipv41.0.0.1ct() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additionaRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 5d ago
ipv4109.91.184.21resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known public resolver serviRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 5d ago
ipv41.1.1.1nal connect() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and severalRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 5d ago
ipv480.152.203.134ons were public DNS resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known pubRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 5d ago
ipv48.8.4.4port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/8Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 5d ago
ipv48.8.8.8erified while attempts to reach an external address such as 8.8.8.8 returned Network is unreachable. This design allowed the maRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 5d ago
ipv49.9.9.10tions included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is commonly assoRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 5d ago
ipv49.9.9.9. Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is comRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 5d ago
ipv445.142.193.132he actors utilized infrastructure, including the IP address 45.142.193.132, which GreyNoise had tracked since early July for attacks aHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 5d ago
ipv445.158.196.75paign orchestration and execution infrastructure IP address 45.158.196.75 Infrastructure used to execute campaign activity File hashHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 5d ago
ipv49.20.4.14ewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions UCisco security advisory (AV26-197) – Update 3
Canadian Centre for Cyber Security
· 6d ago
ipv462.60.130.193ll log failed login attempts with a 401 status code: ::ffff:62.60.130.193 - - [09/09/2026:15:26:14 +0000] "POST /api2/json/access/ticScans for Proxmox Servers, (Wed, Sep 9th)
SANS Internet Storm Center
· 6d ago
ipv445.142.193.132nfrastructure. The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for probHackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide
Cyber Security News
· 6d ago
ipv4146.103.99.177Incident responders should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js filHackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
GBHackers
· 6d ago
ipv446.151.29.58s should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js files, and review ruHackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
GBHackers
· 6d ago
ipv4173.212.244.25IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA targets IP address 2Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 6d ago
ipv4188.245.99.156f compromise (IoCs):- Type Indicator Description IP address 188.245.99.156 Operator host used for rogue Redis replication, command-andHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 6d ago
ipv4194.48.248.105Recurring WordPress exploitation target IP address and port 194.48.248.105:8081 Earlier open directory linked by cryptocurrency walletHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 6d ago
ipv420.198.10.42target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed develoHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 6d ago
ipv4213.6.207.123hip unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA tarHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 6d ago
ipv423.235.223.495 Additional observed development and QA targets IP address 23.235.223.49 Recurring WordPress exploitation target IP address and portHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 6d ago
ipv434.166.99.116eused QA or test target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 AdditionalHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 6d ago
ipv445.155.102.89stname> Victim check-in request pattern IP address and port 45.155.102.89:10128 Local mining pool proxy used on the operator host DomHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 6d ago
ipv447.250.92.230-controlled hostname resolving to 188.245.99.156 IP address 47.250.92.230 Frequently reused QA or test target, ownership unconfirmedHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 6d ago
ipv415.1.10.80 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nearly a year old. Ireland's NF5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
The Hacker News
· 6d ago
ipv416.1.6.1.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is neaF5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
The Hacker News
· 6d ago
ipv417.5.1.3s. Versions known to be vulnerable Fixed in 17.5.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
The Hacker News
· 6d ago
ipv445.142.193.132investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against inAgents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 6d ago
ipv445.158.196.7545.142.193.132 Used to orchestrate and execute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 6d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.