Indicators of compromise
4,250 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| ipv4 | 85.93.0.32 | ly reappeared well after their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-1 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.33 | 15-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.34 | 16-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.43 | 8 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.68 | 2 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.72 | 4 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.81 | 3 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | aba98.com | 85.93.0[.]33 - mvcvideo[.]tk 2016-03-14: 85.93.0[.]33 - bab.aba98[.]com 2016-03-29: 85.93.0[.]34 - folesd[.]tk When we first noti | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bobibo.tk | 85.93.0[.]32 - feedero[.]tk 2016-01-25: 85.93.0[.]32 - www.bobibo[.]tk 2016-01-26: 85.93.0[.]32 - en.robertkuzma[.]com 2016-02-0 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | co.uk | st gate URL 2014-09-22: 148.251.56[.]156 - flv.79highstreet.co[.]uk 2014-10-02: 148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 19 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | dofned.tk | 2-03: 85.93.0[.]32 - vyetbr[.]tk 2016-02-10: 85.93.0[.]32 - dofned[.]tk 2016-02-15: 85.93.0[.]32 - zeboms[.]tk 2016-02-18: 85.93. | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | feedero.tk | 31.184.192[.]206 - vecexeze[.]tk 2016-01-19: 85.93.0[.]32 - feedero[.]tk 2016-01-25: 85.93.0[.]32 - www.bobibo[.]tk 2016-01-26: 85 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | fix-mo.tk | 6 - flv.79highstreet.co[.]uk 2014-10-02: 148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 194.15.126[.]7 - joans[.]ga 2015-11-10: 31.18 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | folesd.tk | : 85.93.0[.]33 - bab.aba98[.]com 2016-03-29: 85.93.0[.]34 - folesd[.]tk When we first noticed the EITest gate in September 2014, | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | joans.ga | 148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 194.15.126[.]7 - joans[.]ga 2015-11-10: 31.184.192[.]206 - ymest[.]ml 2015-12-04: 31. | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | mvcvideo.tk | 3-07: 85.93.0[.]33 - nixsys[.]tk 2016-03-09: 85.93.0[.]33 - mvcvideo[.]tk 2016-03-14: 85.93.0[.]33 - bab.aba98[.]com 2016-03-29: 85 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | nixsys.tk | 3-04: 85.93.0[.]33 - vovevy[.]tk 2016-03-07: 85.93.0[.]33 - nixsys[.]tk 2016-03-09: 85.93.0[.]33 - mvcvideo[.]tk 2016-03-14: 85.9 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | robertkuzma.com | 5.93.0[.]32 - www.bobibo[.]tk 2016-01-26: 85.93.0[.]32 - en.robertkuzma[.]com 2016-02-03: 85.93.0[.]32 - vyetbr[.]tk 2016-02-10: 85.93. | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | syte4.com | : 85.93.0[.]32 - zeboms[.]tk 2016-02-18: 85.93.0[.]32 - 14s.syte4[.]com 2016-03-04: 85.93.0[.]33 - vovevy[.]tk 2016-03-07: 85.93. | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | vecexeze.tk | 1.184.192[.]206 - ymest[.]ml 2015-12-04: 31.184.192[.]206 - vecexeze[.]tk 2016-01-19: 85.93.0[.]32 - feedero[.]tk 2016-01-25: 85.93 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | vovevy.tk | : 85.93.0[.]32 - 14s.syte4[.]com 2016-03-04: 85.93.0[.]33 - vovevy[.]tk 2016-03-07: 85.93.0[.]33 - nixsys[.]tk 2016-03-09: 85.93. | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | vyetbr.tk | 93.0[.]32 - en.robertkuzma[.]com 2016-02-03: 85.93.0[.]32 - vyetbr[.]tk 2016-02-10: 85.93.0[.]32 - dofned[.]tk 2016-02-15: 85.93. | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ymest.ml | 194.15.126[.]7 - joans[.]ga 2015-11-10: 31.184.192[.]206 - ymest[.]ml 2015-12-04: 31.184.192[.]206 - vecexeze[.]tk 2016-01-19: | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | zeboms.tk | 2-10: 85.93.0[.]32 - dofned[.]tk 2016-02-15: 85.93.0[.]32 - zeboms[.]tk 2016-02-18: 85.93.0[.]32 - 14s.syte4[.]com 2016-03-04: 85 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | afraid.org | are. This campaign uses gates registered through FreeDNS at afraid.org. We are calling this the Afraidgate campaign. Although we c | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | allofuslikesforums.com | .11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oqpwldjc.mjobrkn3[.]eu (using a VM | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | breastcanceroutreach.com | state[.]com 192.169.190.97 port 80 - frageboegen-plletyksin.breastcanceroutreach[.]com 192.169.190.97 port 80 - reikleivn-azarashi.orlandohomesb | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cetinhechinhis.com | .203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.2 | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com.ar | in this campaign: 185.118.164.42 port 80 - host.vivialvarez.com[.]ar - GET /widget.js 185.118.164.42 port 80 - kw.projetoraize | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com.br | - GET /widget.js 185.118.164.42 port 80 - kw.projetoraizes.com[.]br - GET /js/script.js 185.118.164.42 port 80 - net.jacquiel | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | co.uk | hevets[.]org 85.25.160.124 port 80 - mcimaildmz.dinnerplate.co[.]uk 192.169.189.167 port 80 - candidulumbestuurlijk.newlandsi | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | esteroscreen.com | landohomesbydevito[.]com 209.126.120.8 port 80 - litigators.esteroscreen[.]com Bedep post-infection traffic: 104.193.252.241 port 80 - q | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | helpthevets.org | ET /js/script.js Angler EK: 85.25.160.124 port 80 - bintiye.helpthevets[.]org 85.25.160.124 port 80 - mcimaildmz.dinnerplate.co[.]uk 19 | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | mjobrkn3.eu | - allofuslikesforums[.]com 85.25.79.211 port 80 - oqpwldjc.mjobrkn3[.]eu (using a VM) CryptXXX post-infection traffic: 217.23.6.40 | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | newlandsierrarealestate.com | ate.co[.]uk 192.169.189.167 port 80 - candidulumbestuurlijk.newlandsierrarealestate[.]com 192.169.190.97 port 80 - frageboegen-plletyksin.breastcan | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | orlandohomesbydevito.com | routreach[.]com 192.169.190.97 port 80 - reikleivn-azarashi.orlandohomesbydevito[.]com 209.126.120.8 port 80 - litigators.esteroscreen[.]com Bed | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | qrwzoxcjatynejejsz.com | com Bedep post-infection traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - yfczmludodohkdqnij[.]com (using | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ranetardinghap.com | m (using a VM) Click-fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.2 | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | rerobloketbo.com | .218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148. | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | tedgeroatref.com | .27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.1 | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | tonthishessici.com | 52.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.7 | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | yfczmludodohkdqnij.com | port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - yfczmludodohkdqnij[.]com (using a VM) Click-fraud traffic: 5.199.141.203 port 80 - | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 104.193.252.236 | hechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthi | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 104.193.252.241 | litigators.esteroscreen[.]com Bedep post-infection traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 162.244.34.11 | eroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - all | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.118.164.42 | the Afraidgate campaign are shown below. Figure 3: Gate on 185.118.164.42 leads to Angler EK/Bedep/CryptXXX on Friday 2016-04-22. Fig | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 192.169.189.167 | ]org 85.25.160.124 port 80 - mcimaildmz.dinnerplate.co[.]uk 192.169.189.167 port 80 - candidulumbestuurlijk.newlandsierrarealestate[.]c | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 192.169.190.97 | rt 80 - candidulumbestuurlijk.newlandsierrarealestate[.]com 192.169.190.97 port 80 - frageboegen-plletyksin.breastcanceroutreach[.]com | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 207.182.148.92 | bloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - o | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 209.126.120.8 | .97 port 80 - reikleivn-azarashi.orlandohomesbydevito[.]com 209.126.120.8 port 80 - litigators.esteroscreen[.]com Bedep post-infectio | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 217.23.6.40 | mjobrkn3[.]eu (using a VM) CryptXXX post-infection traffic: 217.23.6.40 port 443 (custom encoding) | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 5.199.141.203 | yfczmludodohkdqnij[.]com (using a VM) Click-fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - ceti | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.25.160.124 | et.jacquieleebrasil.com[.]br - GET /js/script.js Angler EK: 85.25.160.124 port 80 - bintiye.helpthevets[.]org 85.25.160.124 port 80 - | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.25.79.211 | ici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oqpwldjc.mjobrkn3[.]eu (using a VM) CryptXXX post | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 93.190.141.27 | fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - ted | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 95.211.205.218 | rdinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rero | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 95.211.205.228 | traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - yfczmludodohkdqnij[.]com (using a VM) Click-fraud | Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | dyndns.org | nfo - gate pointing to Rig EK 5.61.37[.]139 - kjyrxilohcowy.dyndns[.]org - Rig EK on 2016-06-23 5.61.32[.]163 - smobutdobesy.dyndn | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | laoismacau.com | sy.dyndns.org[.]org - Rig EK on 2016-06-24 58.64.142[.]89 - laoismacau[.]com - post-infection traffic from CryptoBit The gate checked | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | org.org | - Rig EK on 2016-06-23 5.61.32[.]163 - smobutdobesy.dyndns.org[.]org - Rig EK on 2016-06-24 58.64.142[.]89 - laoismacau[.]com | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | realstatistics.info | , this particular campaign used a gate with the domain name realstatistics[.]info that pointed to Rig EK. If a vulnerable Windows host enco | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | smobutdobesy.dyndns.org | lohcowy.dyndns[.]org - Rig EK on 2016-06-23 5.61.32[.]163 - smobutdobesy.dyndns.org[.]org - Rig EK on 2016-06-24 58.64.142[.]89 - laoismacau[.] | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 2477db8c1a6882212921ce396d85964d182f9993a0786fb7ccc497b0af78fd3b | on 58.64.142[.]89. SHA256 hashes for these samples follow: 2477db8c1a6882212921ce396d85964d182f9993a0786fb7ccc497b0af78fd3b 4eb75511b34cc276251dff1007328477836da59458e1f89c607c2590fe2 | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4eb75511b34cc276251dff1007328477836da59458e1f89c607c2590fe2ebdaf | b8c1a6882212921ce396d85964d182f9993a0786fb7ccc497b0af78fd3b 4eb75511b34cc276251dff1007328477836da59458e1f89c607c2590fe2ebdaf 5351c106e578453993d20b10bd71301c831a2a0cea3aa45d911fde7a94b | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 5351c106e578453993d20b10bd71301c831a2a0cea3aa45d911fde7a94b9247a | 511b34cc276251dff1007328477836da59458e1f89c607c2590fe2ebdaf 5351c106e578453993d20b10bd71301c831a2a0cea3aa45d911fde7a94b9247a 642a3067a35348a833e82e7c08eb53c27f6d2bc68c61bc6e81f135e9927 | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 642a3067a35348a833e82e7c08eb53c27f6d2bc68c61bc6e81f135e9927969c7 | 106e578453993d20b10bd71301c831a2a0cea3aa45d911fde7a94b9247a 642a3067a35348a833e82e7c08eb53c27f6d2bc68c61bc6e81f135e9927969c7 6cb7ceca202fccbb8592728b030127eff7a5661b80131d2a40dc637b76d | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 6cb7ceca202fccbb8592728b030127eff7a5661b80131d2a40dc637b76d82fa8 | 067a35348a833e82e7c08eb53c27f6d2bc68c61bc6e81f135e9927969c7 6cb7ceca202fccbb8592728b030127eff7a5661b80131d2a40dc637b76d82fa8 8fe6b7f52033794d97aa58605ba3eb306c537abeeaf6d14f45ba3204bf1 | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 8fe6b7f52033794d97aa58605ba3eb306c537abeeaf6d14f45ba3204bf112f70 | eca202fccbb8592728b030127eff7a5661b80131d2a40dc637b76d82fa8 8fe6b7f52033794d97aa58605ba3eb306c537abeeaf6d14f45ba3204bf112f70 90e1ea707f97105a99cd7e960fc26deb91aba68f50ec80e40bf915822c4 | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 90e1ea707f97105a99cd7e960fc26deb91aba68f50ec80e40bf915822c4e3998 | 7f52033794d97aa58605ba3eb306c537abeeaf6d14f45ba3204bf112f70 90e1ea707f97105a99cd7e960fc26deb91aba68f50ec80e40bf915822c4e3998 bd7e11ecdf7308a4173bdaff82b38c2fba47939ac0356a1878a52fff203 | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | bd7e11ecdf7308a4173bdaff82b38c2fba47939ac0356a1878a52fff203656ab | a707f97105a99cd7e960fc26deb91aba68f50ec80e40bf915822c4e3998 bd7e11ecdf7308a4173bdaff82b38c2fba47939ac0356a1878a52fff203656ab Palo Alto Networks customers are protected from Rig EK and | CryptoBit: Another Ransomware Family Gets an Update Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | activebeliever.com | om - GET /rokmediaqueries.js 188.166.38.125 port 80 - siber.activebeliever[.]com - GET /plugins/fancybox-for-wordpress/js/jquery.easing.1. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | afraid.org | n continues to utilize gate domains using name servers from afraid.org. Changing Payloads As early as June 29, 2016 , we saw the A | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | atchisoncountyrecorder.com | - GET /scripts/jquery.form.js 46.101.26.161 port 80 - motor.atchisoncountyrecorder[.]com - GET /js/blog.js 46.101.26.161 port 80 - motor.atchisonc | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | blautechnology.com | om[.]br - GET /gantry-totop.js 46.101.26.161 port 80 - snow.blautechnology[.]com - GET /scripts/libs.js 46.101.26.161 port 80 - start.pute | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bluechristian.top | rdfngwg.blueelizabeth[.]top 185.140.33.99 port 80 - clfdkbl.bluechristian[.]top 185.140.33.99 port 80 - drhffhveq.greenjessica[.]top 185. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | blueelizabeth.top | hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 185.140.33.99 port 80 - clfdkbl.bluechristian[.]top 185.1 | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bsuperpink.top | rt 80 - azbepfasz.yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com.br | cripts/custom.js 46.101.26.161 port 80 - oskol.migustapizza.com[.]br - GET /gantry-totop.js 46.101.26.161 port 80 - snow.blaut | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | greenjessica.top | fdkbl.bluechristian[.]top 185.140.33.99 port 80 - drhffhveq.greenjessica[.]top 185.140.33.99 port 80 - rklfdprel.blueelizabeth[.]top Loc | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | hautumngreen.top | 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.236 port 80 - mxoug.yintored[.]top 5.2.72.236 port | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | laderatutors.com | .]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.js 188.166.38.125 port 80 - siber. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | mafterred.top | egoxmvzpx.bsuperpink[.]top 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | oautumnyellow.top | - GET /to_top.js Neutrino EK: 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top 5.2.72.236 port 80 - azbepfasz.yintored[.]top 5.2.72.236 | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | onion.to | structions: mphtadhci5mrdlju.tor2web[.]org mphtadhci5mrdlju.onion[.]to zjfq4lnfbs7pncr5.tor2web[.]org zjfq4lnfbs7pncr5.onion[.]t | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | polatoglumimarlik.com | ery.easing.1.3.min.js?ver=1.3 188.166.38.125 port 80 - zine.polatoglumimarlik[.]com - GET /scripts/jquery.sliderkit.1.9.2.pack.js 188.166.38. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | puterasyawal.com | [.]com - GET /scripts/libs.js 46.101.26.161 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.lad | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | rautumngreen.top | 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 18 | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | stmaryschooldmt.com | he Afraidgate campaign: Gates: 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery.form.js 46.101.26.161 port 80 - mot | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | tor2web.org | Domains from the decryption instructions: mphtadhci5mrdlju.tor2web[.]org mphtadhci5mrdlju.onion[.]to zjfq4lnfbs7pncr5.tor2web[.]or | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | yintored.top | avukytj.oautumnyellow[.]top 5.2.72.236 port 80 - azbepfasz.yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 po | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.117.153.176 | 50.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.117.153.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.118.66.83 | .176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.118.66.83 port 80 - 185.118.66.83 - POST /upload/_dispatch.php Domain | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.140.33.76 | ored[.]top 5.2.72.236 port 80 - yegoxmvzpx.bsuperpink[.]top 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 - | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.140.33.99 | rred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 185.140.33.99 port | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.5.250.135 | 54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.250.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.11 | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 188.166.38.125 | 1 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.j | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 46.101.26.161 | compromise associated with the Afraidgate campaign: Gates: 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 5.187.0.137 | .253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.5 | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 5.2.72.114 | .yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.236 port 80 - | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 5.2.72.236 | zine.polatoglumimarlik[.]com - GET /to_top.js Neutrino EK: 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top 5.2.72.236 port 80 - | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.