ZeroHour

Indicators of compromise

34 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
urlhttp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF[.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 8h ago
urlhttp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DFnder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankinNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 9h ago
urlhttp://aa.amazingshield[per[.]info/aa.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agentHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 1d ago
urlhttps://drelto[yz/33244556546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain sHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 1d ago
urlhttps://stryper[sHelper\docro\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia RHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 1d ago
urlhttps://archive[498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemoryScaThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://connection[dpoint, passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage:The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://granderevolucao[r URL Malicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://ia601808[er.exe : legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/SentinelThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://volmira[intained. After retrieving the domains, the malware queries hxxps://volmira[.]site/api/ext/version to obtain the extension version. TheThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://zaviro[two C2 endpoints: hxxps://volmira[.]site//api/savecreds and hxxps://zaviro[.]online//api/v1/fingerprint . The following POST request waThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttp://www[attempting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not reThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://proof.gitprogram[gleBamboo Phishing, exploit delivery, and C2 infrastructure hxxps://proof.gitprogram[.]com/a4/j8 URL JungleBamboo September 2 phishing URL servinChina-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
GBHackers
· 3d ago
urlhttps://apimantax[cted outbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically rNew Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
Cyber Security News
· 4d ago
urlhttp://3.88.162[026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second-stage payload download URL 2026-09-07Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 4d ago
urlhttp://log.gitclone[Actor IP exploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-420Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 4d ago
urlhttp://3.88.162[]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a4JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 4d ago
urlhttp://log.gitclone[[.]88 , 137.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / HaJFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 4d ago
urlhttps://apimantax[lution. Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and publMantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
GBHackers
· 4d ago
urlhttp://3.88.162[026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second load of payload after CVE-2026-42018/Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 5d ago
urlhttp://log.gitclone[loiting CVE-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 5d ago
urlhttps://stro7121.blob.core.windows[xe interpreter to download and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py scriptSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 5d ago
urlhttp://167.148.195[172ec Brazilian financial campaign malware or tool hash URL hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Download location for SockTz versiHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 5d ago
urlhttp://45.142.193[ing followed by Base64 encoding using certutil Download URL hxxp://45.142.193[.]132:8000/lsa_collect.exe Download location for LSA bootkeyHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 5d ago
urlhttps://api-prod.secboxes[ad.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-prod.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://download.secboxes[ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://download.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://evidence.msbenefit[od.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidence.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zkiChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://project.secboxes[n[.]com Hostname TA412 BlueMoon exploit page September 2026 hxxps://project.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://recommendation-letter.secboxes[ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://zki0y83.msbenefit[.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki0y83.msbenefit[.]com:443/feed URL Download URL August 2026 extension-manageChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://kr[2 endpoint for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload fClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 6d ago
urlhttps://phys[for the verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved byClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 6d ago
urlhttps://telegra[loader observed at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branchClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 6d ago
urlhttps://146[s. The initial stager downloads a second-stage payload from hxxps://146[.]103[.]99[.]177:8443/0c5b76709523, decodes it, and XOR-decrHackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
GBHackers
· 6d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.