Indicators of compromise
34 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| url | http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF | [.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193 | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 8h ago |
| url | http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF | nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 9h ago |
| url | http://aa.amazingshield[ | per[.]info/aa.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 1d ago |
| url | https://drelto[ | yz/33244556546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain s | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 1d ago |
| url | https://stryper[ | sHelper\docro\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia R | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 1d ago |
| url | https://archive[ | 498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemorySca | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://connection[ | dpoint, passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage: | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://granderevolucao[ | r URL Malicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET P | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://ia601808[ | er.exe : legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://volmira[ | intained. After retrieving the domains, the malware queries hxxps://volmira[.]site/api/ext/version to obtain the extension version. The | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://zaviro[ | two C2 endpoints: hxxps://volmira[.]site//api/savecreds and hxxps://zaviro[.]online//api/v1/fingerprint . The following POST request wa | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | http://www[ | attempting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not re | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://proof.gitprogram[ | gleBamboo Phishing, exploit delivery, and C2 infrastructure hxxps://proof.gitprogram[.]com/a4/j8 URL JungleBamboo September 2 phishing URL servin | China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks GBHackers | · 3d ago |
| url | https://apimantax[ | cted outbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically r | New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims Cyber Security News | · 4d ago |
| url | http://3.88.162[ | 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second-stage payload download URL 2026-09-07 | Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access GBHackers | · 4d ago |
| url | http://log.gitclone[ | Actor IP exploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-420 | Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access GBHackers | · 4d ago |
| url | http://3.88.162[ | ]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a4 | JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control Cyber Security News | · 4d ago |
| url | http://log.gitclone[ | [.]88 , 137.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Ha | JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control Cyber Security News | · 4d ago |
| url | https://apimantax[ | lution. Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and publ | Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files GBHackers | · 4d ago |
| url | http://3.88.162[ | 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second load of payload after CVE-2026-42018/ | Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Blog | · 5d ago |
| url | http://log.gitclone[ | loiting CVE-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2 | Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Blog | · 5d ago |
| url | https://stro7121.blob.core.windows[ | xe interpreter to download and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 5d ago |
| url | http://167.148.195[ | 172ec Brazilian financial campaign malware or tool hash URL hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Download location for SockTz versi | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 5d ago |
| url | http://45.142.193[ | ing followed by Base64 encoding using certutil Download URL hxxp://45.142.193[.]132:8000/lsa_collect.exe Download location for LSA bootkey | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 5d ago |
| url | https://api-prod.secboxes[ | ad.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-prod.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evid | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://download.secboxes[ | ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://download.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api- | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://evidence.msbenefit[ | od.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidence.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://project.secboxes[ | n[.]com Hostname TA412 BlueMoon exploit page September 2026 hxxps://project.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps:// | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://recommendation-letter.secboxes[ | ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps:// | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://zki0y83.msbenefit[ | .msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki0y83.msbenefit[.]com:443/feed URL Download URL August 2026 extension-manage | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://kr[ | 2 endpoint for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload f | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 6d ago |
| url | https://phys[ | for the verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 6d ago |
| url | https://telegra[ | loader observed at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 6d ago |
| url | https://146[ | s. The initial stager downloads a second-stage payload from hxxps://146[.]103[.]99[.]177:8443/0c5b76709523, decodes it, and XOR-decr | Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT GBHackers | · 6d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.