Indicators of compromise
4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4 | eset is enough. Selected indicators of compromise: SHA-256: adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4 (REVSTEALER) SHA-256: 13d7237d7289e67c2d806a65d52580b453ce4 | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| sha256 | c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 | 7dd9fff7de9719c2a43ad123fe843dd4e4e2 (SoftManager) SHA-256: c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 (LockAppHost) Domain: monitor5.roast-core85[.]click (REVSTE | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| domain | cdnflare.xyz | 69bf220 (running in memory on one Disrex store) Domain: 247.cdnflare[.]xyz (malware download host) IP: 99.84.67[.]186:443 (command-a | Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores The Hacker News | · 12d ago |
| sha256 | 251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220 | 705adec1902a1d06ef (on disk on both Disrex stores) SHA-256: 251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220 (running in memory on one Disrex store) Domain: 247.cdnflar | Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores The Hacker News | · 12d ago |
| sha256 | 8334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06ef | b2b05d81391285eebc2af664641a26a7 (Sansec's sample) SHA-256: 8334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06ef (on disk on both Disrex stores) SHA-256: 251fabd50d7b18a8b5 | Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores The Hacker News | · 12d ago |
| sha256 | e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 | /gvfsd-user , with a variant pointing at /tmp/.kw_ SHA-256: e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 (Sansec's sample) SHA-256: 8334b434fa3fe9f59cebe9609b11e0b1 | Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores The Hacker News | · 12d ago |
| domain | api.cadence.jetbrains.com | tween August 8 and 24, 2026. The exploited Cadence server ("api.cadence.jetbrains.com") has since been taken offline. The company conceded that t | Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials The Hacker News | · 12d ago |
| ipv4 | 150.109.230.104 | P addresses associated with observed exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 | Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials The Hacker News | · 12d ago |
| ipv4 | 152.233.30.18 | 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activity from unexpected IP address | Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials The Hacker News | · 12d ago |
| ipv4 | 15.235.225.205 | 50.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activity from unexpec | Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials The Hacker News | · 12d ago |
| ipv4 | 210.247.242.190 | tion activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication or other activi | Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials The Hacker News | · 12d ago |
| ipv4 | 43.153.227.206 | ciated with observed exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 | Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials The Hacker News | · 12d ago |
| ipv4 | 62.210.127.48 | erved exploitation activity: 150.109.230.104 43.153.227.206 62.210.127.48 210.247.242.190 15.235.225.205 152.233.30.18 Authentication | Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials The Hacker News | · 12d ago |
| sha1 | 286dd3ff41526b582ef48830de239dffbaa61f90 | Sep 05 Hi, https://github.com/util-linux/util-linux/commit/286dd3ff41526b582ef48830de239dffbaa61f90 Regards, Salvatore | Re: Vulnerability fixes in util-linux-2.42.3 oss-security | · 12d ago |
| domain | 457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site | rameter. Before writing that file, the dropper calls out to 457cfa2fb7p5.daf892t5qau4og8pi4cghbc6fhm1dim3u.oast.site , a subdomain of a public service that developers and teste | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| domain | ntp.timesysnc.net | k like NTP server replies. As of September 7 that name, and ntp.timesysnc.net , both resolve to 185.157.160.251 , which is the address to | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| domain | time.microsft.run | ) ntp.timesysnc.net:123 C2, custom NTP-shaped traffic (UDP) time.microsft.run:123 C2, custom NTP-shaped traffic (UDP) pool.microsft.studi | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| domain | windwsecurity.run | d host # C2 servers 99.84.67.186:443 C2, WebSocket over TLS windwsecurity.run:443 remote shell, WebSocket over TLS (TCP) ntp.timesysnc.ne | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| ipv4 | 182.182.152.48 | ces 88.216.72.181 attacker source, seen at multiple victims 182.182.152.48 attacker source 76.31.99.207 attacker source, failed exploi | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| ipv4 | 185.157.160.251 | tember 7 that name, and ntp.timesysnc.net , both resolve to 185.157.160.251 , which is the address to block if you cannot filter by nam | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| ipv4 | 209.141.43.95 | axfileupload/mag.txt 247.cdnflare.xyz malware download host 209.141.43.95 malware download host # C2 servers 99.84.67.186:443 C2, Web | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| ipv4 | 209.73.130.148 | source 76.31.99.207 attacker source, failed exploit attempt 209.73.130.148 attacker source, successful exploit attempt 77.239.124.107 | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| ipv4 | 76.31.99.207 | ce, seen at multiple victims 182.182.152.48 attacker source 76.31.99.207 attacker source, failed exploit attempt 209.73.130.148 atta | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| ipv4 | 77.239.124.107 | 209.73.130.148 attacker source, successful exploit attempt 77.239.124.107 attacker source, follow-up requests User-Agent: python-requ | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| ipv4 | 88.216.72.181 | llback ntp.syncstime.to:123 C2, fallback # attacker sources 88.216.72.181 attacker source, seen at multiple victims 182.182.152.48 at | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| ipv4 | 99.84.67.186 | launched. This is a small Rust program that connects to the 99.84.67.186 C2 server and waits for commands. So far, we have no indica | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| md5 | fced27f6d57702565353ecc11722533b | /cache/ss_<10hex>/sync_<10hex>.php web shell X-Cache-Token: fced27f6d57702565353ecc11722533b header the web shell requires, 404 without it 457cfa2fb7p5. | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | 1a3374ffac5b0a62467612f264c49792d206304d4514409c982325c91231375d | a3e82 kworker-linux-arm64 (new build, 209.141.43.95) sha256 1a3374ffac5b0a62467612f264c49792d206304d4514409c982325c91231375d chronyd variant, captured from /proc/<pid>/exe /tmp/.kw_<ra | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | 4352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e | 60e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 sha256 4352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e kworker-linux-x64 (new build, 209.141.43.95), 2270031 bytes | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 | 61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 sha256 b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 sha256 4352cabaa451e5a894535fbcc4d46628701303322a13745cb547 | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | d2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82 | -linux-x64 (new build, 209.141.43.95), 2270031 bytes sha256 d2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82 kworker-linux-arm64 (new build, 209.141.43.95) sha256 1a337 | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | d61217ca0bca83204302fa7b41935ce36f73764559c156d5c980f2fedddffb6e | d second attacker (unrelated tooling, same victims): sha256 d61217ca0bca83204302fa7b41935ce36f73764559c156d5c980f2fedddffb6e PHP dropper pub/media/catalog/product/cache/ss_<10hex>/sync | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 | n-requests 2.15.0 on the implant operator's requests sha256 e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 sha256 b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4e | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| domain | acemlnd.com | sage body to be routed via its own click-tracking domains ("acemlnd[.]com" and "activehosted[.]com"). ActiveCampaign, for its part, | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | activehosted.com | ed via its own click-tracking domains ("acemlnd[.]com" and "activehosted[.]com"). ActiveCampaign, for its part, said it has tested its c | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | advancefundingboost.com | ost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardiancapitalway[.]com harboradvancefunding[.]com unite | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | digitalcapitalboost.com | he most hits are listed below - guardiangrowthfunding[.]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advance | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | directcapitalboost.com | ay[.]com harboradvancefunding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedirectfinance[.]com What's more, these emails from | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | guardiancapitalway.com | xpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardiancapitalway[.]com harboradvancefunding[.]com unitedfundingwave[.]com direct | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | guardiangrowthfunding.com | e top 10 sender domains by the most hits are listed below - guardiangrowthfunding[.]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yo | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | harboradvancefunding.com | ng[.]com advancefundingboost[.]com guardiancapitalway[.]com harboradvancefunding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedi | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | onlinedirectfinance.com | ding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedirectfinance[.]com What's more, these emails from these finance-themed domai | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | thebusinessloanexpress.com | low - guardiangrowthfunding[.]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardianca | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | unitedfundingwave.com | t[.]com guardiancapitalway[.]com harboradvancefunding[.]com unitedfundingwave[.]com directcapitalboost[.]com onlinedirectfinance[.]com What's | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | yourlocfunding.com | ]com digitalcapitalboost[.]com thebusinessloanexpress[.]com yourlocfunding[.]com advancefundingboost[.]com guardiancapitalway[.]com harbor | Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters The Hacker News | · 13d ago |
| domain | cleanos.online | in.primgs[.]lol, grip-cdns[.]space, show.grip-cdns[.]space, cleanos[.]online and app.cleanos[.]online. Rapid7 has not said whether the | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | darklights.store | erhouse[.]space Domain - img.smartnords[.]site Domain - img.darklights[.]store Domain - img.responsive.pstatic[.]autos Domain - img.soci | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | grip-cdns.space | but not in Rapid7's list: primgs[.]lol, admin.primgs[.]lol, grip-cdns[.]space, show.grip-cdns[.]space, cleanos[.]online and app.cleanos | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | monderhouse.space | he following indicators of compromise (IoCs) - Domain - img.monderhouse[.]space Domain - img.smartnords[.]site Domain - img.darklights[.] | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | primgs.lol | in the same two maltrail entries but not in Rapid7's list: primgs[.]lol, admin.primgs[.]lol, grip-cdns[.]space, show.grip-cdns[.] | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | pstatic.autos | ite Domain - img.darklights[.]store Domain - img.responsive.pstatic[.]autos Domain - img.socialteams[.]store Domain - img.worksongo[. | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | smartnords.site | mise (IoCs) - Domain - img.monderhouse[.]space Domain - img.smartnords[.]site Domain - img.darklights[.]store Domain - img.responsive.p | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | socialteams.store | ]store Domain - img.responsive.pstatic[.]autos Domain - img.socialteams[.]store Domain - img.worksongo[.]store File - ~/cache/haproxy-100 | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | worksongo.store | tatic[.]autos Domain - img.socialteams[.]store Domain - img.worksongo[.]store File - ~/cache/haproxy-1000.cache File - /var/lib/sshd/c8 | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| md5 | c8c68e629bba773a10ac80012d10bf19 | tore File - ~/cache/haproxy-1000.cache File - /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 File - /var/lib/snapd/g580 File - /tmp/jasper-log SHA-256 - | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| sha256 | 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 | 9142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 SHA-256 - 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 The Hacker News confirmed on September 4 that none of the s | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| sha256 | 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 | File - /var/lib/snapd/g580 File - /tmp/jasper-log SHA-256 - 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 SHA-256 - 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1 | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 13d ago |
| domain | img.darklights.store | previously recorded, it reaches out to a secondary domain – img.darklights.store – authenticating with api_token/ecd427ea8330a4ff73618483e00 | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| domain | img.monderhouse.space | d fast-poll flag. If the validation fails, the C2 resets to img.monderhouse.space 2 staged payload drop Issues an authenticated HTTP POST to | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| md5 | c8c68e629bba773a10ac80012d10bf19 | and saves them to an encrypted log file under /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 . Figure 2: hardcoded master passwords in userauth_passwd() | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| md5 | ecd427ea8330a4ff73618483e00b9b41 | main – img.darklights.store – authenticating with api_token/ecd427ea8330a4ff73618483e00b9b41 and setting the User-token header to the victim ID to fetch | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| sha256 | 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe | audit / audit.log , cmd.log , secure , syslog , auth.log . 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe and fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ad | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| sha256 | 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 | hrough it, completing the watering-hole loop. SSH keylogger 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 intercepts legitimate users' plaintext passwords and saves | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| sha256 | 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91 | ound to be delivered by a stager. CurlRAT Stager The stager 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91 starts by decrypting its configuration strings using a 1-by | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| sha256 | 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 | er. Ted backdoor The TA recompiled the HAProxy build 2.8.12 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 (18MB) to include a custom plugin (named ted_plugin ) leavi | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| sha256 | 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c | ryption (Figure 8). Figure 8: Default configuration curlRAT 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c ⠀ The atd_get_info() is a recon routine likely used to deci | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| sha256 | fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61 | d4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe and fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61 are a different variant of the stager that fetches backdoor | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| sha256 | feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3 | epath used to hide config/staging files. As for the stager, feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3 starts by decrypting configuration strings using a 1-byte X | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 13d ago |
| domain | hunt.io | because its own AI infrastructure was not properly secured. Hunt.io found a backend that anyone could access without authentica | Chinese Hackers Use AI Agents in Multi Security Affairs | · 13d ago |
| domain | niestools.com | routed requests through private proxy servers linked to the niestools.com domain. The AI models did not break into systems on their o | Chinese Hackers Use AI Agents in Multi Security Affairs | · 13d ago |
| domain | broker.hivemq.com | gin. The first version uses the public HiveMQ MQTT broker ( broker.hivemq.com ) as its C2 server. The free tier of this broker supports u | Angry Birds: Toy Ghouls’ new toys Kaspersky Securelist | · 13d ago |
| domain | element.tw | eir own Element server running on the Matrix protocol, meet.element[.]tw , as the C2 server. On this server, they created a room u | Angry Birds: Toy Ghouls’ new toys Kaspersky Securelist | · 13d ago |
| md5 | 7916c33688385525078bee504c90f359 | upport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.toml Registry keys: HKLM\Software\synapse\Config\S | Angry Birds: Toy Ghouls’ new toys Kaspersky Securelist | · 13d ago |
| md5 | bfadbeee63a4f0bf19ec9deb8fa58f58 | t.Zapchast.abwo File names and MD5 hashes: cplsupport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.tom | Angry Birds: Toy Ghouls’ new toys Kaspersky Securelist | · 13d ago |
| ipv4 | 103.154.152.178 | he following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64. | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 103.164.182.122 | 7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said to have begun on | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 103.168.146.131 | riginated from the following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 12 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 103.168.147.235 | ms plugin have originated from the following IP addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 103.170.97.7 | addresses - 103.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 1 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 103.84.230.85 | the below IP addresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.1 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 103.90.148.202 | ddresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.25 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 114.10.17.253 | 3.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress site owners usi | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 114.10.45.151 | 16.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress site owners using the two plu | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 129.227.46.143 | 31 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious act | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 167.254.240.75 | 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d1 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 167.254.241.119 | 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 2406:ef80:2:7d19::1 WordPress s | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 182.10.130.51 | 03.168.147.235 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 185.196.220.85 | riginated from the below IP addresses - 2602:fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 189.4.122.140 | 103.168.146.131 103.154.152.178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 Th | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 216.126.225.208 | :fa59:10:7a1::1 185.196.220.85 103.84.230.85 103.90.148.202 216.126.225.208 167.254.240.75 167.254.241.119 114.10.17.253 114.10.45.151 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 37.9.33.62 | 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said to have begun on July 14, 20 | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| ipv4 | 64.176.209.104 | 178 103.170.97.7 182.10.130.51 189.4.122.140 129.227.46.143 64.176.209.104 103.164.182.122 37.9.33.62 The malicious activity is said t | Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws The Hacker News | · 13d ago |
| domain | crpx0.su | the group has advertised the operation on a clearnet site ("crpx0[.]su/v3.txt") as an offensive control panel to manage compromi | ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories The Hacker News | · 14d ago |
| domain | www.mxsetuplogi.com | fake "privacy browser" downloaded from a counterfeit site ("www.mxsetuplogi.com") that turns remote attacker commands into simulated mouse | ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories The Hacker News | · 14d ago |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 14d ago |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 14d ago |
| md5 | 41444d7018601b599beac0c60ed1bf83 | dceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 MD5: 41444d7018601b599beac0c60ed1bf83 Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 14d ago |
| md5 | 61e046145ee5cf45aeb033cd71e8b07c | d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 MD5: 61e046145ee5cf45aeb033cd71e8b07c Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 14d ago |
| md5 | 7bdbd180c081fa63ca94f9c22c457376 | 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 14d ago |
| md5 | 9a47c4d379998ade2f8f99e23a630c06 | a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 14d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.