ZeroHour

Indicators of compromise

4,250 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
ipv485.93.0.32ly reappeared well after their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-1EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.3315-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.3416-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.438 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.682 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.724 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.813 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
domainaba98.com85.93.0[.]33 - mvcvideo[.]tk 2016-03-14: 85.93.0[.]33 - bab.aba98[.]com 2016-03-29: 85.93.0[.]34 - folesd[.]tk When we first notiHow the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainbobibo.tk85.93.0[.]32 - feedero[.]tk 2016-01-25: 85.93.0[.]32 - www.bobibo[.]tk 2016-01-26: 85.93.0[.]32 - en.robertkuzma[.]com 2016-02-0How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainco.ukst gate URL 2014-09-22: 148.251.56[.]156 - flv.79highstreet.co[.]uk 2014-10-02: 148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 19How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domaindofned.tk2-03: 85.93.0[.]32 - vyetbr[.]tk 2016-02-10: 85.93.0[.]32 - dofned[.]tk 2016-02-15: 85.93.0[.]32 - zeboms[.]tk 2016-02-18: 85.93.How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainfeedero.tk31.184.192[.]206 - vecexeze[.]tk 2016-01-19: 85.93.0[.]32 - feedero[.]tk 2016-01-25: 85.93.0[.]32 - www.bobibo[.]tk 2016-01-26: 85How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainfix-mo.tk6 - flv.79highstreet.co[.]uk 2014-10-02: 148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 194.15.126[.]7 - joans[.]ga 2015-11-10: 31.18How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainfolesd.tk: 85.93.0[.]33 - bab.aba98[.]com 2016-03-29: 85.93.0[.]34 - folesd[.]tk When we first noticed the EITest gate in September 2014,How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainjoans.ga148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 194.15.126[.]7 - joans[.]ga 2015-11-10: 31.184.192[.]206 - ymest[.]ml 2015-12-04: 31.How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainmvcvideo.tk3-07: 85.93.0[.]33 - nixsys[.]tk 2016-03-09: 85.93.0[.]33 - mvcvideo[.]tk 2016-03-14: 85.93.0[.]33 - bab.aba98[.]com 2016-03-29: 85How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainnixsys.tk3-04: 85.93.0[.]33 - vovevy[.]tk 2016-03-07: 85.93.0[.]33 - nixsys[.]tk 2016-03-09: 85.93.0[.]33 - mvcvideo[.]tk 2016-03-14: 85.9How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainrobertkuzma.com5.93.0[.]32 - www.bobibo[.]tk 2016-01-26: 85.93.0[.]32 - en.robertkuzma[.]com 2016-02-03: 85.93.0[.]32 - vyetbr[.]tk 2016-02-10: 85.93.How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainsyte4.com: 85.93.0[.]32 - zeboms[.]tk 2016-02-18: 85.93.0[.]32 - 14s.syte4[.]com 2016-03-04: 85.93.0[.]33 - vovevy[.]tk 2016-03-07: 85.93.How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainvecexeze.tk1.184.192[.]206 - ymest[.]ml 2015-12-04: 31.184.192[.]206 - vecexeze[.]tk 2016-01-19: 85.93.0[.]32 - feedero[.]tk 2016-01-25: 85.93How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainvovevy.tk: 85.93.0[.]32 - 14s.syte4[.]com 2016-03-04: 85.93.0[.]33 - vovevy[.]tk 2016-03-07: 85.93.0[.]33 - nixsys[.]tk 2016-03-09: 85.93.How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainvyetbr.tk93.0[.]32 - en.robertkuzma[.]com 2016-02-03: 85.93.0[.]32 - vyetbr[.]tk 2016-02-10: 85.93.0[.]32 - dofned[.]tk 2016-02-15: 85.93.How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainymest.ml194.15.126[.]7 - joans[.]ga 2015-11-10: 31.184.192[.]206 - ymest[.]ml 2015-12-04: 31.184.192[.]206 - vecexeze[.]tk 2016-01-19:How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainzeboms.tk2-10: 85.93.0[.]32 - dofned[.]tk 2016-02-15: 85.93.0[.]32 - zeboms[.]tk 2016-02-18: 85.93.0[.]32 - 14s.syte4[.]com 2016-03-04: 85How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainafraid.orgare. This campaign uses gates registered through FreeDNS at afraid.org. We are calling this the Afraidgate campaign. Although we cAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainallofuslikesforums.com.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oqpwldjc.mjobrkn3[.]eu (using a VMAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainbreastcanceroutreach.comstate[.]com 192.169.190.97 port 80 - frageboegen-plletyksin.breastcanceroutreach[.]com 192.169.190.97 port 80 - reikleivn-azarashi.orlandohomesbAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domaincetinhechinhis.com.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.2Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domaincom.arin this campaign: 185.118.164.42 port 80 - host.vivialvarez.com[.]ar - GET /widget.js 185.118.164.42 port 80 - kw.projetoraizeAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domaincom.br- GET /widget.js 185.118.164.42 port 80 - kw.projetoraizes.com[.]br - GET /js/script.js 185.118.164.42 port 80 - net.jacquielAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainco.ukhevets[.]org 85.25.160.124 port 80 - mcimaildmz.dinnerplate.co[.]uk 192.169.189.167 port 80 - candidulumbestuurlijk.newlandsiAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainesteroscreen.comlandohomesbydevito[.]com 209.126.120.8 port 80 - litigators.esteroscreen[.]com Bedep post-infection traffic: 104.193.252.241 port 80 - qAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainhelpthevets.orgET /js/script.js Angler EK: 85.25.160.124 port 80 - bintiye.helpthevets[.]org 85.25.160.124 port 80 - mcimaildmz.dinnerplate.co[.]uk 19Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainmjobrkn3.eu- allofuslikesforums[.]com 85.25.79.211 port 80 - oqpwldjc.mjobrkn3[.]eu (using a VM) CryptXXX post-infection traffic: 217.23.6.40Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainnewlandsierrarealestate.comate.co[.]uk 192.169.189.167 port 80 - candidulumbestuurlijk.newlandsierrarealestate[.]com 192.169.190.97 port 80 - frageboegen-plletyksin.breastcanAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainorlandohomesbydevito.comroutreach[.]com 192.169.190.97 port 80 - reikleivn-azarashi.orlandohomesbydevito[.]com 209.126.120.8 port 80 - litigators.esteroscreen[.]com BedAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainqrwzoxcjatynejejsz.comcom Bedep post-infection traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - yfczmludodohkdqnij[.]com (usingAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainranetardinghap.comm (using a VM) Click-fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.2Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainrerobloketbo.com.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domaintedgeroatref.com.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.1Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domaintonthishessici.com52.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.7Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domainyfczmludodohkdqnij.comport 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - yfczmludodohkdqnij[.]com (using a VM) Click-fraud traffic: 5.199.141.203 port 80 -Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4104.193.252.236hechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthiAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4104.193.252.241litigators.esteroscreen[.]com Bedep post-infection traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 -Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4162.244.34.11eroatref[.]com 104.193.252.236 port 80 - rerobloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.118.164.42the Afraidgate campaign are shown below. Figure 3: Gate on 185.118.164.42 leads to Angler EK/Bedep/CryptXXX on Friday 2016-04-22. FigAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4192.169.189.167]org 85.25.160.124 port 80 - mcimaildmz.dinnerplate.co[.]uk 192.169.189.167 port 80 - candidulumbestuurlijk.newlandsierrarealestate[.]cAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4192.169.190.97rt 80 - candidulumbestuurlijk.newlandsierrarealestate[.]com 192.169.190.97 port 80 - frageboegen-plletyksin.breastcanceroutreach[.]comAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4207.182.148.92bloketbo[.]com 162.244.34.11 port 80 - tonthishessici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4209.126.120.8.97 port 80 - reikleivn-azarashi.orlandohomesbydevito[.]com 209.126.120.8 port 80 - litigators.esteroscreen[.]com Bedep post-infectioAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv4217.23.6.40mjobrkn3[.]eu (using a VM) CryptXXX post-infection traffic: 217.23.6.40 port 443 (custom encoding)Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv45.199.141.203yfczmludodohkdqnij[.]com (using a VM) Click-fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetiAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv485.25.160.124et.jacquieleebrasil.com[.]br - GET /js/script.js Angler EK: 85.25.160.124 port 80 - bintiye.helpthevets[.]org 85.25.160.124 port 80 -Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv485.25.79.211ici[.]com 207.182.148.92 port 80 - allofuslikesforums[.]com 85.25.79.211 port 80 - oqpwldjc.mjobrkn3[.]eu (using a VM) CryptXXX postAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv493.190.141.27fraud traffic: 5.199.141.203 port 80 - ranetardinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv495.211.205.218rdinghap[.]com 93.190.141.27 port 80 - cetinhechinhis[.]com 95.211.205.218 port 80 - tedgeroatref[.]com 104.193.252.236 port 80 - reroAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
ipv495.211.205.228traffic: 104.193.252.241 port 80 - qrwzoxcjatynejejsz[.]com 95.211.205.228 port 80 - yfczmludodohkdqnij[.]com (using a VM) Click-fraudAfraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX
Palo Alto Unit 42
· Aug 17, 2026
domaindyndns.orgnfo - gate pointing to Rig EK 5.61.37[.]139 - kjyrxilohcowy.dyndns[.]org - Rig EK on 2016-06-23 5.61.32[.]163 - smobutdobesy.dyndnCryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
domainlaoismacau.comsy.dyndns.org[.]org - Rig EK on 2016-06-24 58.64.142[.]89 - laoismacau[.]com - post-infection traffic from CryptoBit The gate checkedCryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
domainorg.org- Rig EK on 2016-06-23 5.61.32[.]163 - smobutdobesy.dyndns.org[.]org - Rig EK on 2016-06-24 58.64.142[.]89 - laoismacau[.]comCryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
domainrealstatistics.info, this particular campaign used a gate with the domain name realstatistics[.]info that pointed to Rig EK. If a vulnerable Windows host encoCryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
domainsmobutdobesy.dyndns.orglohcowy.dyndns[.]org - Rig EK on 2016-06-23 5.61.32[.]163 - smobutdobesy.dyndns.org[.]org - Rig EK on 2016-06-24 58.64.142[.]89 - laoismacau[.]CryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
sha2562477db8c1a6882212921ce396d85964d182f9993a0786fb7ccc497b0af78fd3bon 58.64.142[.]89. SHA256 hashes for these samples follow: 2477db8c1a6882212921ce396d85964d182f9993a0786fb7ccc497b0af78fd3b 4eb75511b34cc276251dff1007328477836da59458e1f89c607c2590fe2CryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
sha2564eb75511b34cc276251dff1007328477836da59458e1f89c607c2590fe2ebdafb8c1a6882212921ce396d85964d182f9993a0786fb7ccc497b0af78fd3b 4eb75511b34cc276251dff1007328477836da59458e1f89c607c2590fe2ebdaf 5351c106e578453993d20b10bd71301c831a2a0cea3aa45d911fde7a94bCryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
sha2565351c106e578453993d20b10bd71301c831a2a0cea3aa45d911fde7a94b9247a511b34cc276251dff1007328477836da59458e1f89c607c2590fe2ebdaf 5351c106e578453993d20b10bd71301c831a2a0cea3aa45d911fde7a94b9247a 642a3067a35348a833e82e7c08eb53c27f6d2bc68c61bc6e81f135e9927CryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
sha256642a3067a35348a833e82e7c08eb53c27f6d2bc68c61bc6e81f135e9927969c7106e578453993d20b10bd71301c831a2a0cea3aa45d911fde7a94b9247a 642a3067a35348a833e82e7c08eb53c27f6d2bc68c61bc6e81f135e9927969c7 6cb7ceca202fccbb8592728b030127eff7a5661b80131d2a40dc637b76dCryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
sha2566cb7ceca202fccbb8592728b030127eff7a5661b80131d2a40dc637b76d82fa8067a35348a833e82e7c08eb53c27f6d2bc68c61bc6e81f135e9927969c7 6cb7ceca202fccbb8592728b030127eff7a5661b80131d2a40dc637b76d82fa8 8fe6b7f52033794d97aa58605ba3eb306c537abeeaf6d14f45ba3204bf1CryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
sha2568fe6b7f52033794d97aa58605ba3eb306c537abeeaf6d14f45ba3204bf112f70eca202fccbb8592728b030127eff7a5661b80131d2a40dc637b76d82fa8 8fe6b7f52033794d97aa58605ba3eb306c537abeeaf6d14f45ba3204bf112f70 90e1ea707f97105a99cd7e960fc26deb91aba68f50ec80e40bf915822c4CryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
sha25690e1ea707f97105a99cd7e960fc26deb91aba68f50ec80e40bf915822c4e39987f52033794d97aa58605ba3eb306c537abeeaf6d14f45ba3204bf112f70 90e1ea707f97105a99cd7e960fc26deb91aba68f50ec80e40bf915822c4e3998 bd7e11ecdf7308a4173bdaff82b38c2fba47939ac0356a1878a52fff203CryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
sha256bd7e11ecdf7308a4173bdaff82b38c2fba47939ac0356a1878a52fff203656aba707f97105a99cd7e960fc26deb91aba68f50ec80e40bf915822c4e3998 bd7e11ecdf7308a4173bdaff82b38c2fba47939ac0356a1878a52fff203656ab Palo Alto Networks customers are protected from Rig EK andCryptoBit: Another Ransomware Family Gets an Update
Palo Alto Unit 42
· Aug 17, 2026
domainactivebeliever.comom - GET /rokmediaqueries.js 188.166.38.125 port 80 - siber.activebeliever[.]com - GET /plugins/fancybox-for-wordpress/js/jquery.easing.1.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainafraid.orgn continues to utilize gate domains using name servers from afraid.org. Changing Payloads As early as June 29, 2016 , we saw the AAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainatchisoncountyrecorder.com- GET /scripts/jquery.form.js 46.101.26.161 port 80 - motor.atchisoncountyrecorder[.]com - GET /js/blog.js 46.101.26.161 port 80 - motor.atchisoncAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainblautechnology.comom[.]br - GET /gantry-totop.js 46.101.26.161 port 80 - snow.blautechnology[.]com - GET /scripts/libs.js 46.101.26.161 port 80 - start.puteAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainbluechristian.toprdfngwg.blueelizabeth[.]top 185.140.33.99 port 80 - clfdkbl.bluechristian[.]top 185.140.33.99 port 80 - drhffhveq.greenjessica[.]top 185.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainblueelizabeth.tophxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 185.140.33.99 port 80 - clfdkbl.bluechristian[.]top 185.1Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainbsuperpink.toprt 80 - azbepfasz.yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domaincom.brcripts/custom.js 46.101.26.161 port 80 - oskol.migustapizza.com[.]br - GET /gantry-totop.js 46.101.26.161 port 80 - snow.blautAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domaingreenjessica.topfdkbl.bluechristian[.]top 185.140.33.99 port 80 - drhffhveq.greenjessica[.]top 185.140.33.99 port 80 - rklfdprel.blueelizabeth[.]top LocAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainhautumngreen.top80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.236 port 80 - mxoug.yintored[.]top 5.2.72.236 portAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainladeratutors.com.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.js 188.166.38.125 port 80 - siber.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainmafterred.topegoxmvzpx.bsuperpink[.]top 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainoautumnyellow.top- GET /to_top.js Neutrino EK: 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top 5.2.72.236 port 80 - azbepfasz.yintored[.]top 5.2.72.236Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainonion.tostructions: mphtadhci5mrdlju.tor2web[.]org mphtadhci5mrdlju.onion[.]to zjfq4lnfbs7pncr5.tor2web[.]org zjfq4lnfbs7pncr5.onion[.]tAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainpolatoglumimarlik.comery.easing.1.3.min.js?ver=1.3 188.166.38.125 port 80 - zine.polatoglumimarlik[.]com - GET /scripts/jquery.sliderkit.1.9.2.pack.js 188.166.38.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainputerasyawal.com[.]com - GET /scripts/libs.js 46.101.26.161 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.ladAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainrautumngreen.top80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 18Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainstmaryschooldmt.comhe Afraidgate campaign: Gates: 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery.form.js 46.101.26.161 port 80 - motAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domaintor2web.orgDomains from the decryption instructions: mphtadhci5mrdlju.tor2web[.]org mphtadhci5mrdlju.onion[.]to zjfq4lnfbs7pncr5.tor2web[.]orAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domainyintored.topavukytj.oautumnyellow[.]top 5.2.72.236 port 80 - azbepfasz.yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 poAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.117.153.17650.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.117.153.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.118.66.83.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.118.66.83 port 80 - 185.118.66.83 - POST /upload/_dispatch.php DomainAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.140.33.76ored[.]top 5.2.72.236 port 80 - yegoxmvzpx.bsuperpink[.]top 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 -Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.140.33.99rred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 185.140.33.99 portAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.5.250.13554.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.250.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.11Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv4188.166.38.1251 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.jAfraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv446.101.26.161compromise associated with the Afraidgate campaign: Gates: 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv45.187.0.137.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.5Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv45.2.72.114.yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.236 port 80 -Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv45.2.72.236zine.polatoglumimarlik[.]com - GET /to_top.js Neutrino EK: 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top 5.2.72.236 port 80 -Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.