ZeroHour

Indicators of compromise

4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainsimultaneouslypower.comcceptable.com Historical Ethereum resolver C2 domain Domain simultaneouslypower.com Historical Ethereum resolver C2 domain Domain wiselystartinHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
domainwiselystarting.comuslypower.com Historical Ethereum resolver C2 domain Domain wiselystarting.com Historical Ethereum resolver C2 domain Domain itemrange.comHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
ipv4146.103.127.44rd-tier fallback address, designated hunt-only IPv4 address 146.103.127.44 Historical operator-used address from April 2026, designateHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
ipv4193.233.202.17compromise (IoCs):- Type Indicator Description IPv4 address 193.233.202.17 Primary Sliver command-and-control and staging-server addreHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
ipv477.110.126.46command-and-control and staging-server address IPv4 address 77.110.126.46 Hardcoded third-tier fallback address, designated hunt-onlyHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
ipv499.84.67.186launched. This is a small Rust program that connects to the 99.84.67.186 C2 server and waits for commands,” Sansec researchers saidAdobe Commerce max-severity bug comes under active attack
CSO Online
· 9d ago
ipv482.192.72.4attacks have been originating from two IP addresses, namely 82.192.72.4 and 103.102.31.18. “The presence of any of these artifactsMikroTik Patches Critical Flaws Chained to Hack Routers
SecurityWeek
· 9d ago
ipv423.234.64.0ctivity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logN-able Patches Critical Zero-Day in N-central
SecurityWeek
· 9d ago
domaingerenciadorcaixa.digitalletely separate banking-phishing cluster A related domain — gerenciadorcaixa.digital, cloning Caixa Econômica Federal’s corporate banking portalHVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures
ANY.RUN
· 9d ago
ipv45.230.249.49: 02 19 05 04 07 19 05 03 0E 19 03 0E XOR key: 0x37 Result: 5.230.249.49 The destination port is stored in plaintext: 27015 – the deHVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures
ANY.RUN
· 9d ago
domainbsc.rpc.blxrbdn.comad. The payload makes a separate JSON-RPC eth_call through "bsc[.]rpc[.]blxrbdn[.]com" to BNB Smart Chain contract 0x7CC3cFC1Ac007B8c6566fDClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainbsc-testnet-rpc.publicnode.comontract 0x886d310Ac23e05EA705e24E513D19f53793832A9 through "bsc-testnet-rpc[.]publicnode[.]com". BNB Smart Chain is a public, Ethereum-compatible blocClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainfd.gstats-api-contact.ccly: Effective period in UTC Contract value June 30 – July 5 fd[.]gstats-api-contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domaingithub.comconnects to it directly on TCP port 443, while presenting "github[.]com" as the TLS server name and HTTP Host value. Unlike the "ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainkffd3.vexlatech.ccier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 static[.]quorashift[.]cc July 26 – 30 lb[.ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainkffd3.vogueatelier.cccontact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 staticClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainlb.propertyfind.ccring) function. During our analysis, the contract returned "lb[.]propertyfind[.]cc", which ZigCryptoStealer then used as its C2 domain. ThClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainleaguejazire.comd command opens a WebDAV path on a randomized subdomain of "leaguejazire[.]com", places the victim identifier in the path, and executesClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainpkg.vogueatelier.ccue June 30 – July 5 fd[.]gstats-api-contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffdClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainriyazinikokar.xyzacOS user-agent string. The request goes to a subdomain of "riyazinikokar[.]xyz". Since the subject of our initial research was a customeClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainstatic.quorashift.ccelier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 static[.]quorashift[.]cc July 26 – 30 lb[.]propertyfind[.]cc Talos used Cisco UmClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domaintelegra.phn "pf.ch" branch constructs the dead drop C2 URL "https[:]//telegra[.]ph/Functions-04-03". At the time of analysis, the page lookeClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
sha256279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92most recently observed response was a ZIP archive, SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92. The archive included the file "platform_experience_helper.ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domaingoogle.coms — like a random executable making a DNS request for “docs.google[.]com”. But when the requests are made from within a browser seClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos
· 9d ago
domainobfuscator.ior variable and function names, consistent with output from “Obfuscator[.]io” and similar Javascript obfuscation tools. However, it waClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos
· 9d ago
domainpastebin.comined a link to the lure document. Figure 4. A comment on a “Pastebin[.]com” post advertising the lure, warning against trying more tClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos
· 9d ago
domainpaste.shto the lure document, was copy the script shared through a “paste[.]sh” link into the navigation bar of the Chrome browser preceClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos
· 9d ago
domainsimpleswap.ioure but was rewritten to target a different trading site — “SimpleSwap[.]io”, another cryptocurrency trading aggregator. The fake expClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos
· 9d ago
domainswapzone.iorsion we observed targeted the cryptocurrency trading site “SwapZone[.]io”. It was formatted in the style of a vulnerability reportClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos
· 9d ago
domainmagento.comtfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip "To help resolve thAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
The Hacker News
· 9d ago
domaindll.latfor payload delivery are listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present wBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The Hacker News
· 9d ago
domaingithub.iohyperlinks to the lure pages (e.g., "viziocomsetupentercode.github[.]io"), urging readers to set up their smart TV "easily" by foBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The Hacker News
· 9d ago
domainpltechoo.proechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present within the ZIP file is a JavaScript dropper for MBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The Hacker News
· 9d ago
domainreadthedocs.iocentral how to login" to serve a fraudulent link hosted on readthedocs[.]io. The page features a prominent "Get Started" button thatBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The Hacker News
· 9d ago
domainreficon.proare listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present within the ZIP file is aBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The Hacker News
· 9d ago
domainu320.myd delivery are listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.]pro Present within theBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The Hacker News
· 9d ago
domainurlscan.iots.us3[.]org." A search for the domain "stats.us3[.]org" on urlscan.io yields 1,112 results as of writing, down from 1,190 at theBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The Hacker News
· 9d ago
domainus3.orge client-side and send the information to the domain "stats.us3[.]org." A search for the domain "stats.us3[.]org" on urlscan.ioBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The Hacker News
· 9d ago
domainustechnio.comof the domains used for payload delivery are listed below - ustechnio[.]com tax.dll[.]lat u320[.]my reficon[.]pro ñ[.]link pltechoo[.BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The Hacker News
· 9d ago
domainwapp.liveins." One account managing some of the redirector domains ("wapp[.]live") was suspended by Hostmaza earlier this year. The discloBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The Hacker News
· 9d ago
domainwc.cired email addresses linking them to Garage2Global domains ("wc[.]ci"). A sample of some of the GitHub accounts and their assoBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
The Hacker News
· 9d ago
domainannastudios-paros.comshing domain Domain ccpipharma[.]com Phishing domain Domain annastudios-paros[.]com Phishing domain Domain dnsforward[.]com Phishing domain DBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainarrmmy.comomain daengrentacar[.]com Historical phishing domain Domain arrmmy[.]com Historical phishing domain Domain captelind[.]com HistoriBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domaincaptelind.comomain Domain arrmmy[.]com Historical phishing domain Domain captelind[.]com Historical phishing domain Domain planisteradmin[.]com HiBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainccpipharma.comnode Domain konceptenterprises[.]com Phishing domain Domain ccpipharma[.]com Phishing domain Domain annastudios-paros[.]com Phishing dBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domaincifutura.comishing domain Domain dataclust[.]com Phishing domain Domain cifutura[.]com Phishing domain Domain hoaivt[.]com Phishing domain DomaiBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domaindaengrentacar.comdomain Domain soil-management[.]com Phishing domain Domain daengrentacar[.]com Historical phishing domain Domain arrmmy[.]com HistoricalBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domaindataclust.comomain Domain hotelmidtownsurat[.]com Phishing domain Domain dataclust[.]com Phishing domain Domain cifutura[.]com Phishing domain DomBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domaindnsforward.comomain Domain annastudios-paros[.]com Phishing domain Domain dnsforward[.]com Phishing domain Domain hotelmidtownsurat[.]com Phishing dBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domaindronalms.comPhishing domain Domain hoaivt[.]com Phishing domain Domain dronalms[.]com Phishing domain Domain virextec[.]com Phishing domain DomBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainhaliotisbar.comin hnospascualfadon[.]com Historical phishing domain Domain haliotisbar[.]com Historical phishing domain Domain knowncontractor[.]com HBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainhnospascualfadon.commain planisteradmin[.]com Historical phishing domain Domain hnospascualfadon[.]com Historical phishing domain Domain haliotisbar[.]com HistoBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainhoaivt.comhishing domain Domain cifutura[.]com Phishing domain Domain hoaivt[.]com Phishing domain Domain dronalms[.]com Phishing domain DomBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainhotelmidtownsurat.comshing domain Domain dnsforward[.]com Phishing domain Domain hotelmidtownsurat[.]com Phishing domain Domain dataclust[.]com Phishing domain DoBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainkgsscans.comn management[.]michaelmarcotte[.]com Phishing domain Domain kgsscans[.]com Phishing domain Domain soil-management[.]com Phishing domBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainknowncontractor.comDomain haliotisbar[.]com Historical phishing domain Domain knowncontractor[.]com Historical phishing domain Domain valtteri[.]net HistoricBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainkonceptenterprises.coms 45[.]32[.]64[.]165 Historical BigBear 2.0 VPS node Domain konceptenterprises[.]com Phishing domain Domain ccpipharma[.]com Phishing domain DBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainmanagement.daengrentacar.comdomain Domain valtteri[.]net Historical phishing domain URL management[.]daengrentacar[.]com/meetings Observed live Microsoft 365 phishing page FileBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainmanagement.michaelmarcotte.coming domain Domain rootreseller[.]com Phishing domain Domain management[.]michaelmarcotte[.]com Phishing domain Domain kgsscans[.]com Phishing domain DBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainofftic.comhishing domain Domain virextec[.]com Phishing domain Domain offtic[.]com Phishing domain Domain rootreseller[.]com Phishing domainBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainplanisteradmin.comin Domain captelind[.]com Historical phishing domain Domain planisteradmin[.]com Historical phishing domain Domain hnospascualfadon[.]comBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainrootreseller.comPhishing domain Domain offtic[.]com Phishing domain Domain rootreseller[.]com Phishing domain Domain management[.]michaelmarcotte[.]comBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainsoil-management.comhishing domain Domain kgsscans[.]com Phishing domain Domain soil-management[.]com Phishing domain Domain daengrentacar[.]com Historical phiBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainvaltteri.netain knowncontractor[.]com Historical phishing domain Domain valtteri[.]net Historical phishing domain URL management[.]daengrentacarBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainvirextec.comhishing domain Domain dronalms[.]com Phishing domain Domain virextec[.]com Phishing domain Domain offtic[.]com Phishing domain DomaiBigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Cyber Security News
· 9d ago
domainxfjcc.funts command-and-control (C2) server ("206.237.30[.]232" or " xfjcc[.]fun ") every 30 seconds over plaintext HTTP for new commands,PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
The Hacker News
· 10d ago
domain457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.sitescans. “Before writing that file, the dropper calls out to 457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site , a subdomain of a public service that developers and testeStyleSmuggler: The Magento Zero-Day Behind New Store Attacks
Security Affairs
· 10d ago
ipv4185.157.160.251TP-like domains and UDP port 123 destinations, particularly 185.157.160.251 , which Sansec linked to the observed domains on SeptemberStyleSmuggler: The Magento Zero-Day Behind New Store Attacks
Security Affairs
· 10d ago
domainassignpasskey.comthe lure domains flagged by Arctic Wolf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The Hacker News
· 10d ago
domainmfaregister.comagged by Arctic Wolf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The Hacker News
· 10d ago
domainnowsso.comlf are listed below - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The Hacker News
· 10d ago
domainoskeysetup.combelow - assignpasskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The Hacker News
· 10d ago
domainoursso.comsskey[.]com mfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]comFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The Hacker News
· 10d ago
domainpasskeydeploy.comowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead toFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The Hacker News
· 10d ago
domainpasskey-mfa.comfaregister[.]com nowsso[.]com oskeysetup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]comFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The Hacker News
· 10d ago
domainregistermymfa.comup[.]com oursso[.]com passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead to an operator-controllFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The Hacker News
· 10d ago
domainsetpasskey.comm passkey-mfa[.]com passkeydeploy[.]com registermymfa[.]com setpasskey[.]com The attacks lead to an operator-controlled AitM MicrosoftFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The Hacker News
· 10d ago
domaincoder-infra.comrds. The data was then exfiltrated to the lookalike domain "coder-infra[.]com." "An unidentified malicious actor gained access to Coder⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
The Hacker News
· 10d ago
ipv4103.102.31.18September," CERT Polska said. "In addition, the IP address 103.102.31.18 was used in attempts to exploit the described chain." Unpat⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
The Hacker News
· 10d ago
ipv482.192.72.4eation of the 'ops' account, originated from the IP address 82.192.72.4 and have been occurring since at least 2 September," CERT P⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
The Hacker News
· 10d ago
domainpstatic.netelivery traffic into normal web browsing, mimicking Naver’s pstatic.net static content domain. “Ted backdoor and curlRAT were desigNorth Korean Hackers Deploy New Linux Espionage Toolkit
SecurityWeek
· 10d ago
domainanondns.netnConnect.Client.exe"), which then connected to "borertors92.anondns[.]net." The session then uses "wscript.exe" to execute the fourRogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
The Hacker News
· 10d ago
domainopik.netontrol (C2) server located at "45.13.237[.]190" ("tele-sync.opik[.]net"). Hosted on the IP address is a RAR archive containing tRogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
The Hacker News
· 10d ago
domainasp.netg exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to executeTelerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
The Hacker News
· 10d ago
ipv4103.102.31.18ccount 82.192.72.4 — linked to confirmed successful attacks 103.102.31.18 — observed attempting to exploit MikroTrick If compromise iHackers exploit new MikroTik RouterOS flaws to hijack routers
BleepingComputer
· 10d ago
ipv482.192.72.4by ssh:-2@<ip>’ Presence of a highly privileged ops account 82.192.72.4 — linked to confirmed successful attacks 103.102.31.18 — obHackers exploit new MikroTik RouterOS flaws to hijack routers
BleepingComputer
· 10d ago
md5581e2e2265d0c1509b3799c5a9039374encrypted payload we observed was generated on 2025-11-11 ( 581e2e2265d0c1509b3799c5a9039374 ). The AES key is not stored in the malware bundle itself.JSCeal Hides Crypto Malware in V8 Bytecode
Security Affairs
· 10d ago
ipv4103.102.31.18ince at least September 2, and it flagged a second address, 103.102.31.18, used in attempts to exploit the same chain. Patches and deHackers exploit RouterOS flaws to hijack MikroTik devices without authentication
Help Net Security
· 10d ago
ipv482.192.72.4including creation of that “ops” account, to the IP address 82.192.72.4, active since at least September 2, and it flagged a secondHackers exploit RouterOS flaws to hijack MikroTik devices without authentication
Help Net Security
· 10d ago
sha2566dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89eb8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e (serve.py). Follow me on Twitter: @securityaffairs and FaceYour MikroTik Router May Already Be Compromised: Look for SSH User “-2”
Security Affairs
· 11d ago
sha2566e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729dnalysis: IPs 82.192.72[.]4 and 103.102.31[.]18; file hashes 6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3bYour MikroTik Router May Already Be Compromised: Look for SSH User “-2”
Security Affairs
· 11d ago
sha256972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcdb3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36fYour MikroTik Router May Already Be Compromised: Look for SSH User “-2”
Security Affairs
· 11d ago
md55568cd69c754b392121f1dbb8f900fdar IPv4 (Tzulo VPN) 23.234.97[.]68 Intruder IPv4 (Tzulo VPN) 5568cd69c754b392121f1dbb8f900fda Malicious Cloudflare tunnel account tag Update: 8/6/26 @ 5:Critical N-able N-central Vulnerability and Active Exploitation
Huntress
· 11d ago
domaingardenpark.click: health.journal-metric[.]lol (WinUpdate C2) Domain: metric.gardenpark[.]click (SoftManager C2) Gen Threat Labs first documented REVSTEAFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
The Hacker News
· 11d ago
domainhubdisplay.lolonitor5.roast-core85[.]click (REVSTEALER C2) Domain: config.hubdisplay[.]lol (ProManager C2) Domain: health.journal-metric[.]lol (WinUFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
The Hacker News
· 11d ago
domainjournal-metric.lolain: config.hubdisplay[.]lol (ProManager C2) Domain: health.journal-metric[.]lol (WinUpdate C2) Domain: metric.gardenpark[.]click (SoftManFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
The Hacker News
· 11d ago
domainroast-core85.click66f4b11c6a431e78884a5b2651e5 (LockAppHost) Domain: monitor5.roast-core85[.]click (REVSTEALER C2) Domain: config.hubdisplay[.]lol (ProManagFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
The Hacker News
· 11d ago
sha25613d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa4987ae9eb21bf5e67de5e9461b09655165ee4 (REVSTEALER) SHA-256: 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa (ProManager) SHA-256: 7c08cf409194056a8517865e5d3433d1499bbFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
The Hacker News
· 11d ago
sha25614b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e23433d1499bb8262263b55b49b8b07d9d182fcb (WinUpdate) SHA-256: 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2 (SoftManager) SHA-256: c66d2b77b9e85c53391891212413ad9a99ebFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
The Hacker News
· 11d ago
sha2567c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb580b453ce4987acbe2c4c4d04833f55ebccfa (ProManager) SHA-256: 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb (WinUpdate) SHA-256: 14b2ac356ed75d10ef40bbaaa48e7dd9fff7deFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
The Hacker News
· 11d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.