ZeroHour

Indicators of compromise

1,797 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainluizestrelhashapr.onlinegibitily[.]workers[.]dev Extension endpoint resolver Domain luizestrelhashapr[.]online Resolved WebSocket command-and-control host Domain seguraKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 20h ago
domainmarialurdes.sitetos[.]site Earlier extension-delivery infrastructure Domain marialurdes[.]site Intermediate KREMLIN campaign domain Domain harialurdes[.KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 20h ago
domainorange-sun-195a.checkeligibitily.workers.dev.]online FrameSync campaign extension infrastructure Domain orange-sun-195a[.]checkeligibitily[.]workers[.]dev FrameSync campaign C2 resolver Domain cremeb[.]com QRKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 20h ago
domainseguranca.versionnova.site.]online Resolved WebSocket command-and-control host Domain seguranca[.]versionnova[.]site Infrastructure associated with a related KREMLIN branchKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 20h ago
domainvolmira.sitederevolucao[.]store Installer payload-hosting domain Domain volmira[.]site Extension hosting and credential-exfiltration infrastructKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 20h ago
domainwww.creamp1eonlyfans.netader beaconing and extension-delivery infrastructure Domain www[.]creamp1eonlyfans[.]net Network canary domain checked by KREMLIN Domain granderKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 20h ago
domainzaviro.onlinen hosting and credential-exfiltration infrastructure Domain zaviro[.]online Exfiltration and fingerprinting infrastructure Domain graKREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension
Cyber Security News
· 20h ago
domainapi.telegram.orgorjShare. Defenders should investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 21h ago
domainbackblazeb2.comuld investigate unexpected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com anHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 21h ago
domainiproyal.combackblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 21h ago
domainlightningproxies.net, vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connections do not align with nHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 21h ago
domainstorjshare.io.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularlyHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 21h ago
domainvultrobjects.compected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 21h ago
domaingithub.comilable in the following pull requests for community users - github[.]com/wso2/carbon-apimgt/pull/13752 github[.]com/wso2/product-aActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
The Hacker News
· 23h ago
domainbrevo.comn a Brevo-sent campaign email AttackerBrevocode injected in brevo.com & sendibt1.comBrevo customers100k+ sites and mailing listsEBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn10.sendibt1.comom cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware hostBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn11.sendibt1.comm 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware host /f.js the loader /Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn2.sendibt1.comhild (s); })(); These loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn3.sendibt1.comese loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10.sendibt1.com cdn1Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsendibt1.coms suggests a single Cloudflare account holding all of them, sendibt1.com included. That is the zone where the attacker created the cBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsendinblue.comudflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a single Cloudflare accounBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsibautomation.comdomains all use Cloudflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a singleBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsibforms.comrevo.com iframe page that backs the chat widget, and on the sibforms.com pages that serve hosted signup and unsubscribe forms: < scrBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainvip311.cce. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc assLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 1d ago
domainzenplay77-x.spaceo sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem iLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 1d ago
domainzzyud.coms of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated withLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 1d ago
domainluizestrelhashapr.onlinefiltrating browser data for each profile to its C2 server ("luizestrelhashapr[.]online:443") but not before requesting extensive access to browsKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 1d ago
domainvolmira.siteto the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain thKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 1d ago
domainzaviro.onlineum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extensionKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 1d ago
domainc2iznja.comon the machine and exfiltrate them to the C2 server ("api80.c2iznja[.]com"). "The domains used Cloudflare as a proxy for their infrBambooToken Malware Uses MQTT to Control Windows and Linux Systems
The Hacker News
· 1d ago
domainchat5188.tkgather system details and transmit them to the C2 server ("chat5188[.]tk"). In response, the server issues commands to load a plugBambooToken Malware Uses MQTT to Control Windows and Linux Systems
The Hacker News
· 1d ago
domainhunt.iomand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host disThai Broadband Provider Hacked via Fortinet Vulnerability
SecurityWeek
· 1d ago
domain31-59-175-195.syd.nbn.aussiebb.netgets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . ThPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 1d ago
domaineightindigostove.com75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarewPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 1d ago
domainloadswage.comture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was asPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 1d ago
domainmoolaah.comd through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed MahnschreiPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 1d ago
domainopensea.ioitting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tesPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 1d ago
domainweb5-4s4c-online-garantibbva.vibtee.coms IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificatiPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 1d ago
domainwebsite-2df62808.mvplineup.coment reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing decoPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 1d ago
domainxmasbrick.com: Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxpPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 1d ago
domain31-59-175-195.syd.nbn.aussiebb.netof compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renewNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 1d ago
domaineightindigostove.comssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus reneNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 1d ago
domainloadswage.comsed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus renNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 1d ago
domainmoolaah.compath in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-pNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 1d ago
domainopensea.ioing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser-New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 1d ago
domainweb5-4s4c-online-garantibbva.vibtee.comPv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking pNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 1d ago
domainwebsite-2df62808.mvplineup.comomain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in thNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 1d ago
domainxmasbrick.comthe cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the RomaNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 1d ago
domainapi.telegram.orging in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ipIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 1d ago
domainbackblazeb2.comctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightninIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 1d ago
domainiproyal.com[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is foIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 1d ago
domainlightningproxies.netzeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to beIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 1d ago
domainstorjshare.io: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The bestIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 1d ago
domainvultrobjects.comnvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net MitiIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 1d ago
domainember-bridge.comlution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate yHBO Max’s verified Reddit account hijacked to spread malware
Malwarebytes Labs
· 1d ago
domainserver.hostexposes the Vite dev server to the network using --host or server.host config option The sensitive file exists in the allowed direMass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
The Hacker News
· 1d ago
domainclean-disk-guide.comoke down into 15 ads for a fake macOS disk utility at apple.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. OAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 1d ago
domaincode-desktop.com.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. One entry point into a larger system The HBO Max ads werAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 1d ago
domaincodex-craft.com-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craft[.]com. The rest broke down into 15 ads for a fake macOS disk utAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 1d ago
domainhbomax-macos.coms, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-crafAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 1d ago
domainhbomaxx.appid . Of the 108 ads, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex,Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 1d ago
domainhbomaxx.usHBO Max subreddits,” wrote the user. Clicking the ad led to hbomaxx[.]us, “which looks somewhat legitimate, and has a join buttonAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 1d ago
domainhbomaxx.usich does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also conHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
SecurityWeek
· 1d ago
domainbiterflll.comy tips in seconds. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitigift.coms. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitrefall.comf compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitrefill.comed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment. Be wary of domains containing aSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitrefill-payments.comCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitrSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitrefill-pays.comcom bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitregift.comtrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitregill.comtrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitretill.com[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitrgift.com-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefillSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitrgifts.comregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitreSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitrnfill.comregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbitruflli.comretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com paSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainbutrefill.comrgift[.]com bitrgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]coSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainexample-pay.comy’s main domain, as in pay.example.com . An address such as example-pay.com is a completely separate domain that anyone could register.Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainpay-bitigift.compay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitreflSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainpay-bitregill.comgifts[.]com bitrnfill[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]coSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainpay-bitrgift.coml[.]com bitruflli[.]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]coSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainpay-bitrgifts.com]com butrefill[.]com pay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainpay-butrefill.compay-bitregill[.]com pay-bitrgift[.]com pay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainxn--bitrefll-71a.compay-bitrgifts[.]com pay-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainxn--bitrefll-h2a.comy-butrefill[.]com pay-bitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn-Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainxn--bitrefll-pay-kfb.comitigift[.]com xn--bitrefll-71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainxn--bitrefll-pay-xfb.com71a[.]com xn--bitrefll-h2a[.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreiSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainxn--bitrefll-q2a.com.]com xn--bitrefll-pay-kfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--bSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainxn--bitreill-cz9c.comkfb[.]com xn--bitrefll-pay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--paSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainxn--bitreill-pay-yq4f.comay-xfb[.]com xn--bitrefll-q2a[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop thSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainxn--btrefill-l2a.coma[.]com xn--bitreill-cz9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can dSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainxn--pay-bitrefll-fgb.com9c[.]com xn--bitreill-pay-yq4f[.]com xn--btrefill-l2a[.]com xn--pay-bitrefll-fgb[.]com Stop threats before they can do any harm. Malwarebytes BrSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 1d ago
domainaforvm.com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com;Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 1d ago
domainaidevmaster.com]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 1d ago
domainalfredaps.comltration Domain filequanticore[.]com; filesiriuscore[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; coHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 1d ago
domainapplediag.comm; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hubHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 1d ago
domainarkypc.comhbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; groHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 1d ago
domainbasequill9.comClick-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 1d ago
domainbeaocnagent.comaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains DomHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 1d ago
domainbright-links.come[.]com; alfredaps[.]com; hbomaxx[.]us; hbomax-macos[.]com; bright-links[.]com; codex-notes[.]com; storageprofiler[.]com; cladesktop[.]gHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 1d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.