Indicators of compromise
4,250 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| ipv4 | 82.114.160.98 | : 82.114.160.93 and 82.114.160.94. The device identified on 82.114.160.98 was still up at the time of this analysis. The re-emergence | Yemeni War Emphasizes Importance of Internet Control in Statecraft and Conflict/yemen-internet Recorded Future | · Jul 16, 2026 |
| domain | agent01.xeox.com | Three entries it originally listed as malicious indicators, agent01.xeox.com , ws01.xeox.com , and 80.80.250.0/24 , are legitimate XEOX | Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 The Hacker News | · Jul 15, 2026 |
| domain | asp.net | romising an internet-facing IIS web server and uploading an ASP.NET web shell. Over the next three hours, they established pers | ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories The Hacker News | · Jul 15, 2026 |
| domain | extensions-hub.com | pdate, and uninstall, the extension pinged a second domain, extensions-hub[.]com, with the product, version, and browser. And a script tha | Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found The Hacker News | · Jul 15, 2026 |
| domain | geeked.wtf | ts were registered seconds apart, tied to a commit email at geeked[.]wtf and a Discord handle. Ninety of the 93 deployment hostnam | 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet The Hacker News | · Jul 15, 2026 |
| domain | gov.br | sed systems observed during the investigation were timon.ma.gov[.]br, loginam.sesp.es.gov[.]br (state public security), aplica | 20+ Hijacked Government Websites Became an Attack Channel The Hacker News | · Jul 15, 2026 |
| domain | gsnc.eu | instead. Group-IB traced this copy to an operator relay at gsnc[.]eu:67 , with the binary pulled from gsocket.io itself. The s | New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password The Hacker News | · Jul 15, 2026 |
| domain | gsocket.io | perator relay at gsnc[.]eu:67 , with the binary pulled from gsocket.io itself. The stealer payloads sit on three compromised domai | New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password The Hacker News | · Jul 15, 2026 |
| domain | hunt.io | filtration. 3,900 threat servers mapped A new analysis from Hunt.io has uncovered more than 3,900 threat activities enabling se | ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories The Hacker News | · Jul 15, 2026 |
| domain | ipfs.io | system-specific paths and executed. The downloader URL is "ipfs[.]io/ipfs/QmQobZSp1wRPrpSEQ56qnyq7ecZh5Bg5k1fnjt4SUwwHb9." The | Compromised AsyncAPI npm Packages Deliver Multi The Hacker News | · Jul 15, 2026 |
| domain | logfriend.com | on utilize an operator panel accessible over the clearnet ("logfriend[.]com/login"), from where they can generate lures, set up campa | Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft The Hacker News | · Jul 15, 2026 |
| domain | lunaron.top | aimed each browser at 30 connections to a Wisp endpoint on lunaron[.]top, itself a live proxy busy injecting malvertising. Wisp is | 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet The Hacker News | · Jul 15, 2026 |
| domain | moonsand.store | hooks the app's Electron internals. Then it asks its C2 at moonsand[.]store . If the server sets a Wait flag, SeedHunter scans USB by | OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps The Hacker News | · Jul 15, 2026 |
| domain | picis.net | ms since 2018, now running a Microsoft 365 AiTM platform on picis[.]net and monetizing access through a bulk mailer he wrote call | Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 The Hacker News | · Jul 15, 2026 |
| domain | pipicka.xyz | tion with the remote server, including the server details ("pipicka[.]xyz") and the polling interval used by the implant. Alternati | LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts The Hacker News | · Jul 15, 2026 |
| domain | romnor.ca | ns alive on its own. Both phishing domains, picis[.]net and romnor[.]ca, were offline when The Hacker News checked ahead of publi | Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 The Hacker News | · Jul 15, 2026 |
| domain | stanfordstudies.com | s the encrypted list with your fingerprint, posts it to api.stanfordstudies[.]com, and wipes the local copy. The upload time is offset per | Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found The Hacker News | · Jul 15, 2026 |
| domain | torproject.org | .122[.]124 C2 IP: 57.128.246[.]79 Tor infrastructure: check.torproject[.]org, archive.torproject[.]org On-host artifacts: a randomly n | Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install The Hacker News | · Jul 15, 2026 |
| domain | vipersfutbol.com | nt build still reaches, among them woofbeginner[.]com and c.vipersfutbol[.]com, are the ones to block first. Anyone who has loaded one o | 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet The Hacker News | · Jul 15, 2026 |
| domain | werkbit.app | ized dropper that's distributed as a disk image file named "Werkbit.app." Because both the disk image and binary are notarized and | CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks The Hacker News | · Jul 15, 2026 |
| domain | werkbit.io | r checks. The disk image itself originates from the domain "werkbit[.]io," which was registered in June 2026. In an interesting tw | CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks The Hacker News | · Jul 15, 2026 |
| domain | woofbeginner.com | nd script hosts the current build still reaches, among them woofbeginner[.]com and c.vipersfutbol[.]com, are the ones to block first. An | 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet The Hacker News | · Jul 15, 2026 |
| domain | ws01.xeox.com | iginally listed as malicious indicators, agent01.xeox.com , ws01.xeox.com , and 80.80.250.0/24 , are legitimate XEOX vendor infrastru | Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 The Hacker News | · Jul 15, 2026 |
| sha256 | a41a523ef9517aab37ed6eea0ec881821bdcb7aefcb5c5f603adc7907f868c86 | cbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60 dist/intro.js: a41a523ef9517aab37ed6eea0ec881821bdcb7aefcb5c5f603adc7907f868c86 Linux payload: fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9 | Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install The Hacker News | · Jul 15, 2026 |
| sha256 | a742de963f14a92d24ebcbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60 | added files and their decompressed payloads: dist/setup.js: a742de963f14a92d24ebcbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60 dist/intro.js: a41a523ef9517aab37ed6eea0ec881821bdcb7aefcb5 | Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install The Hacker News | · Jul 15, 2026 |
| sha256 | b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903 | 47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd Windows payload: b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903 macOS payload: c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b5 | Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install The Hacker News | · Jul 15, 2026 |
| sha256 | c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd | 25cedf741de0917c2096bbc9d24649eea7853d054903 macOS payload: c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd Network endpoints StepSecurity observed at runtime. The two | Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install The Hacker News | · Jul 15, 2026 |
| sha256 | fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd | 6eea0ec881821bdcb7aefcb5c5f603adc7907f868c86 Linux payload: fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd Windows payload: b7ca95d1b23c8e67416a25cedf741de0917c2096bb | Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install The Hacker News | · Jul 15, 2026 |
| domain | moonsand.store | by the malware Then the malware communicates with the C2 ( moonsand[.]store ) over HTTPS, sending a Base64-encoded JSON request conta | OkoBot framework infection chain Kaspersky Securelist | · Jul 14, 2026 |
| domain | files.pythonhosted.org | During installation, the PyPI frontend redirects users to “files.pythonhosted.org”, where the actual files are stored. Download URLs are deri | The serpent’s tongue: Luring the Python out of its den Cisco Talos | · Jul 14, 2026 |
| domain | cohezo.com | d to the same campaign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the Developer Team ID t | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | cohezo.io | nterfaces tied to the same campaign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the Devel | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | cordinex.io | aign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the Developer Team ID to Apple after confi | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | crashreporter.app | ce indicator on its own. The downloaded disk image contains CrashReporter.app, which carries the bundle identifier com.apple.crashreporte | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | endpoint-api-v1.com | command the dropper runs next, pulling a shell script from endpoint-api-v1[.]com. The script isn’t written to disk in readable form: it ar | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | werkbit.app | e ad-hoc-signed payload it installs.” When the victim opens Werkbit.app, it queries the GitHub API and fetches a file called sys.ca | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | werkbit.io | Gatekeeper on first launch without any warning. The domain werkbit[.]io, which serves the installer, was registered in late June | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| ipv4 | 179.43.166.242 | eporting component. The Info.plist contains the C2 address, 179.43.166.242, hardcoded as an App Transport Security exception, visible | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| url | http://endpoint-api-v1[ | t downloads the payload disk image over cleartext HTTP from hxxp://endpoint-api-v1[.]com/d/f1b24e/download , retrying up to three times, and sa | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| domain | werkbit.io | irming its use in the campaign. The installer was hosted on werkbit[.]io, a domain registered in late June, close to the build dat | New macOS malware steals passwords by posing as Apple's crash-reporting tool Help Net Security | · Jul 14, 2026 |
| domain | 7zip.com | with a trojanized 7-Zip installer hosted on a domain named "7zip[.]com," covertly recruiting compromised devices as proxy nodes. | Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes The Hacker News | · Jul 12, 2026 |
| domain | 7-zip.org | tly referenced domain names (e.g., "7zip[.]com" instead of "7-zip[.]org") to use them to their advantage. Further analysis of the | Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes The Hacker News | · Jul 12, 2026 |
| domain | iplogger.com | to their advantage. Further analysis of the IPLogger URL ("iplogger[.]com/mnWD") embedded within the samples tied to the 7-Zip camp | Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes The Hacker News | · Jul 12, 2026 |
| domain | gov.pk | is the Complaint Management System ("cms.balochistanpolice.gov[.]pk"), which is used for registering, tracking, and resolving | Hackers Weaponize Balochistan Police Portal in Multi The Hacker News | · Jul 11, 2026 |
| md5 | 257bbbbe0a2598872278c87d801d06fd | news.com/article/greece-marfin-bank-deaths-firebomb-arrests-257bbbbe0a2598872278c87d801d06fd A highly concerning development out of Greece this week reg | Friday Squid Blogging: "Squidbleed" Vulnerability Schneier on Security | · Jul 10, 2026 |
| domain | injective.network | est to an external server ("testnet.archival.chain.grpc-web.injective[.]network") in a single beacon. StepSecurity noted the malicious re | Injective Labs GitHub Compromise Pushes Wallet-Key The Hacker News | · Jul 10, 2026 |
| domain | hunt.io | spilled the group's phishing tools and logs, in a campaign Hunt.io called Operation Roundish . What to do now If you run any o | Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites The Hacker News | · Jul 10, 2026 |
| domain | xxooonline.eu.cc | ucture: 137.175.93[.]126, 43.108.17[.]80, and the domain xs.xxooonline[.]eu[.]cc. What makes WP-SHELLSTORM worth attention is not how ad | Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites The Hacker News | · Jul 10, 2026 |
| ipv4 | 2.9.99.5 | s here. Treat the Joomla JCE flaw (CVE-2026-48907, fixed in 2.9.99.5) as urgent too, since it is a maximum-severity and on CISA' | Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites The Hacker News | · Jul 10, 2026 |
| domain | github.com | ted with the investigation of a single malicious Go module: github[.]com/kaleidora/dnsub-scanning-tool, which presented itself as | 222 GitHub Repositories Linked to Fake Go Package Malware Operation Security Affairs | · Jul 10, 2026 |
| domain | muckcoding.com | ed a hidden PowerShell command that downloaded content from muckcoding[.]com, saved it as api.db, decoded it using certutil, wrote the | 222 GitHub Repositories Linked to Fake Go Package Malware Operation Security Affairs | · Jul 10, 2026 |
| domain | rambler.ru | low combined a threat actor-linked email address, ischhfd83@rambler[.]ru, with force-push automation, a schedule running every min | 222 GitHub Repositories Linked to Fake Go Package Malware Operation Security Affairs | · Jul 10, 2026 |
| sha256 | 51cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807 | tion blob recovered from the dead-drop material has SHA-256 51cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807 .” The decrypted URL resolves to a GitHub release: a passwo | 222 GitHub Repositories Linked to Fake Go Package Malware Operation Security Affairs | · Jul 10, 2026 |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | Winning 54% of the time Cisco Talos | · Jul 9, 2026 |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | Winning 54% of the time Cisco Talos | · Jul 9, 2026 |
| md5 | 9b512ba139304c247ddd3d2c4b9179fd | 9e8aa423684827b4375a35684c71c600f2dd9101f235e8ec633488 MD5: 9b512ba139304c247ddd3d2c4b9179fd Talos Rep: https://talosintelligence.com/talos_file_reputat | Winning 54% of the time Cisco Talos | · Jul 9, 2026 |
| md5 | cc4d231df34e57f59eb970353c7d9de2 | a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://talosintelligence.com/talos_file_reputat | Winning 54% of the time Cisco Talos | · Jul 9, 2026 |
| sha256 | 621c6d42409e8aa423684827b4375a35684c71c600f2dd9101f235e8ec633488 | D001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: 621c6d42409e8aa423684827b4375a35684c71c600f2dd9101f235e8ec633488 MD5: 9b512ba139304c247ddd3d2c4b9179fd Talos Rep: https://ta | Winning 54% of the time Cisco Talos | · Jul 9, 2026 |
| sha256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | fd.exe Detection Name: W32.HEUR:Attribute.28iy.1201 SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta | Winning 54% of the time Cisco Talos | · Jul 9, 2026 |
| sha256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta | Winning 54% of the time Cisco Talos | · Jul 9, 2026 |
| sha256 | afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 | -QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://ta | Winning 54% of the time Cisco Talos | · Jul 9, 2026 |
| domain | camorreado.click | md.exe > curl.exe to download a malicious MSI (v7.msi) from camorreado[.]click and execute it. The MSI is a multi-stage loader that down | ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories The Hacker News | · Jul 9, 2026 |
| domain | govtop.one | urgency and trick users into clicking on a malicious link ("govtop[.]one/incometax") embedded within PDF attachments. The bogus la | Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT The Hacker News | · Jul 9, 2026 |
| domain | kkxqbh.top | o take screenshots and exfiltrate data to a remote server ("kkxqbh[.]top"). Exactly who is behind the activity is unclear, but inf | Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT The Hacker News | · Jul 9, 2026 |
| domain | ouewop.com | RAT belonging to the AsyncRAT malware family connecting to ouewop[.]com on port 6351 It's worth noting that DCRat is one of the s | Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT The Hacker News | · Jul 9, 2026 |
| domain | 7zip.com | 2026: a fake version of the 7-Zip archive utility hosted at 7zip[.]com instead of the real site, 7-zip[.]org. The researchers un | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | 7-zip.org | hive utility hosted at 7zip[.]com instead of the real site, 7-zip[.]org. The researchers uncovered a years-long operation they’re | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | iplogger.com | itimate visitor-tracking service. The specific URL, hxxps://iplogger[.]com/mnWD, appeared across multiple distinct payloads spanning | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | proxyreviews.org | t appear to be independent proxy review websites, including proxyreviews[.]org, to drive traffic to its own storefronts. The review site | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | smartproxy.com | real Smartproxy company. Decodo, which owns the legitimate smartproxy[.]com, publicly called out the domain squatter. The fake was go | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | smartproxy.org | illustrates how convincing the impersonation is. The domain smartproxy[.]org presents itself as a budget proxy service offering access | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| url | https://iplogger[ | r, a legitimate visitor-tracking service. The specific URL, hxxps://iplogger[.]com/mnWD, appeared across multiple distinct payloads spann | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| domain | accenture.com | 121123_AtriasTalentAcademy”, hosted on a partially redacted accenture.com domain. The real danger isn’t the headline number: SSH and | A Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breach Security Affairs | · Jul 8, 2026 |
| domain | calvexagroup.com | LLC . The “contact” link on the website for Calvexa Group — calvexagroup[.]com — forwards visitors to irisc2[.]com. G2Exchange shows tha | Felons, Fraudsters Flog Offensive Cybersecurity Startup Krebs on Security | · Jul 8, 2026 |
| domain | g2exchange.com | , and operational value.” The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based i | Felons, Fraudsters Flog Offensive Cybersecurity Startup Krebs on Security | · Jul 8, 2026 |
| domain | irisc2.com | /industry experience.” The website linked in that profile — irisc2[.]com — says the company is hiring for a number of open positio | Felons, Fraudsters Flog Offensive Cybersecurity Startup Krebs on Security | · Jul 8, 2026 |
| domain | bancaporinternetbbmx.online | the phishing landing page One such redirect destination, "'bancaporinternetbbmx[.]online," contains a page-load Telegram notification script that | SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users The Hacker News | · Jul 8, 2026 |
| domain | fakeupdate.net | mediately launches Microsoft Edge in kiosk mode pointing to fakeupdate[.]net, a well-known pentesting/red team site that renders a fak | SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users The Hacker News | · Jul 8, 2026 |
| domain | bleacherreport.com | German streaming guide service, and one that resembles the BleacherReport[.]com certificate. JustWatch itself has not been compromised, n | New Malicious Campaign Delivers Vidar Stealer and Monero Crypto Miner Infosecurity Magazine | · Jul 8, 2026 |
| domain | accenture.com | tration from a private Azure DevOps repository hosted on an accenture.com -associated production URL. When contacted, an Accenture me | Accenture acknowledges security incident following 35GB data theft claim Help Net Security | · Jul 8, 2026 |
| domain | shapedplugin.com | r's Easy Digital Downloads (EDD) infrastructure via account.shapedplugin[.]com. The free versions of the plugins on WordPress.org are no | ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack The Hacker News | · Jul 7, 2026 |
| sha256 | 0352f3e338261d98895df4c7b7a76b296485b2290c72bce56603351d167d0601 | 6f3a8e913f526ec57eeec50e1306f7b34b037915b7a1cf2968cc46acc58 0352f3e338261d98895df4c7b7a76b296485b2290c72bce56603351d167d0601 52b871429833e1dee348263844efb531f6a3fcd321f88dc8a876caaee91 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 03926e3da998f32ad898b640bd15cf145768f9e849e6f18d81350234254c424e | ea5339c73cb4a777a3e9f98bf3cb08da6622c9dd3b4cc9b083cb03d10a2 03926e3da998f32ad898b640bd15cf145768f9e849e6f18d81350234254c424e 16971f9706d70ac4925651c7c8719b9d77aff63e4c0a618129efc32c2c4 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 08701ed7975bf4f5688c2724d27ab497764200ad6f4dc53d3cc03b170378ced0 | 878e28284539419612616d964ab9224cbe27e57f42293d91d02d684e3db 08701ed7975bf4f5688c2724d27ab497764200ad6f4dc53d3cc03b170378ced0 604b53f87d6c070bf387e80c70a6df8d272fa3fc143148d41f13e59d52a | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 0a8555a71868749be8c905ed53296ce335af50a9262772b5e154ad3f9c35c2e4 | 49fa81a699a667cafdbd6d1f6e781edd686c947eb8ae27134f6dc2c43d7 0a8555a71868749be8c905ed53296ce335af50a9262772b5e154ad3f9c35c2e4 5dbfa033676b5caacfae902734ce462cd871181eefbe299250ca8ac7e13 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 0a8cae96e25e85c612b0736fe886f9b124ad70ec425bc2ec1a8a4135b25436ba | 3f87d6c070bf387e80c70a6df8d272fa3fc143148d41f13e59d52ab1f13 0a8cae96e25e85c612b0736fe886f9b124ad70ec425bc2ec1a8a4135b25436ba 8459ff264a2c81c68a34c4ee6bc109d141ad28b96037d34ff112322a4c8 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 0af4c52a1d13e4132a1843ce7727abcf0ddd4d1ca6a4b17cdf599ec3f355c241 | c61baa67ae2838a36c2e6ff0476a8f2117b96a7027b830c8cb46ce78efc 0af4c52a1d13e4132a1843ce7727abcf0ddd4d1ca6a4b17cdf599ec3f355c241 d4861088161fc72b9922abf933b4ea664a807105ec1eab4a173253aa60b | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 13acadb3541e75af50e02d5be56c2238b93d8f154ce5514be1558e6ee59a1432 | 8dea8ed9aec4466e67a9d0aecf9e7026ff16a792d1d6f306e8b67d3f34c 13acadb3541e75af50e02d5be56c2238b93d8f154ce5514be1558e6ee59a1432 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 1660536f448b8b9f086ce9ea3ce4e9deefc59a76711ea53ee6d8f08fc8c1bb99 | 636eec376ad6c3ece2202b1722219955638e09b6f96d4cfc0598d3b1890 1660536f448b8b9f086ce9ea3ce4e9deefc59a76711ea53ee6d8f08fc8c1bb99 65feba2c971c214e71303ad2e0fbf62b45ebcaa784cbf3d0dab62786cb4 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 16971f9706d70ac4925651c7c8719b9d77aff63e4c0a618129efc32c2c46b989 | e3da998f32ad898b640bd15cf145768f9e849e6f18d81350234254c424e 16971f9706d70ac4925651c7c8719b9d77aff63e4c0a618129efc32c2c46b989 6917c0f9eafefe42e33e791b75a7e503ff8b081bc10a98449e4076787df | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 1b5649b479fd625de5c8120873644b5eb669cc89cd504582c18e0ae350fd8823 | ttp[:]//95.182.100[.]231:2222/ Malware indicators LEASHTEST 1b5649b479fd625de5c8120873644b5eb669cc89cd504582c18e0ae350fd8823 LONGLEASH 755fcee1337a252203002ecfdf673a08cfadeda8d738bef2d | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 20fcba222f74dd68aaeb1f0ad30cdf702a828ee164a182b30d05d600c35b72d9 | 033676b5caacfae902734ce462cd871181eefbe299250ca8ac7e139719e 20fcba222f74dd68aaeb1f0ad30cdf702a828ee164a182b30d05d600c35b72d9 912adea5339c73cb4a777a3e9f98bf3cb08da6622c9dd3b4cc9b083cb03 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 29686c933cec1e274467e2dae264625ae6f754824bb7f550bc9c3131f625562c | a37a9943a267a8b2100fba2678353d6ec88844505ccbba659e586c7a105 29686c933cec1e274467e2dae264625ae6f754824bb7f550bc9c3131f625562c d973ad5a80c3d7468a9c392db4166857ed32b5d61cd6755766ba8922156 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 29c7fccc6ef8cbfe4da9a169c7c74bacaea1fb515a1fddef91ab1b1522f76e4c | 1f273eeb576d39235d0a5c6f18f2574b132a1022598edfa38065783ab98 29c7fccc6ef8cbfe4da9a169c7c74bacaea1fb515a1fddef91ab1b1522f76e4c 425bf771c8c9f740b1ae9803dcb4fd45af4d6a6f171fcc72fc7d511095c | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 2e0e43776e2e1a37d882a1b2ebb7d337ee88950177e43831dae645a367824feb | e8ae98579bfb940290f60e59a502b3065345aaf765456387989c0488b20 2e0e43776e2e1a37d882a1b2ebb7d337ee88950177e43831dae645a367824feb b5969636eec376ad6c3ece2202b1722219955638e09b6f96d4cfc0598d3 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 2ebc1b6cf543e2cb3f22d9a5b54b6676bb71dde98df7532f8791297734e44fdd | dfae488d9dfe260b32460a1d947fb5af58ceaf2fb0139bc08b4bb79a966 2ebc1b6cf543e2cb3f22d9a5b54b6676bb71dde98df7532f8791297734e44fdd 6dbd507ca7cecea861f9cf704b3c5c37f5bd5392886a8c2562088892b77 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 3169a6dbcce684e2c5a2f166996b58ffa673df6e58b8edf2bdf3e66271c8c69e | e9acd50f96d566e8d139f6490abf2bbf7a9293b876eeb4598fd2c37c515 3169a6dbcce684e2c5a2f166996b58ffa673df6e58b8edf2bdf3e66271c8c69e d871d76171504597bbda387689e12e7a5e354c360ff135f4df231cec68c | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 323c3a91be60ebc3e06e942bad04899a15911cea23269e43d07829164b2ce5d4 | 90571645c4641dcff2c07a4c3ab9acad06aa9607350a385729d8d6139f1 323c3a91be60ebc3e06e942bad04899a15911cea23269e43d07829164b2ce5d4 880425fee707e9f42e0b8d60119ed639b1ad506ea29877d126bdebce379 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 324d95024fc8da5c92b5a1f4825aed5a2a91c9ca8fb6aa52abb332a4c9cf4257 | 29d9d0d4e45fc2b784a7fcfcf31dd48fd3bde30f8d956383d1 JARLEASH 324d95024fc8da5c92b5a1f4825aed5a2a91c9ca8fb6aa52abb332a4c9cf4257 bafba443170e54ef7fd431ce7f1b5e202719f3fd022e4ef70788904f574 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
| sha256 | 33c10b77e1da9f0679023d55fb3057879d15609db9c1d46ee5c3ff1240a3d052 | b231c23d41234e55b1f7ed89f86234f785adbbe820959655d7b019d7df9 33c10b77e1da9f0679023d55fb3057879d15609db9c1d46ee5c3ff1240a3d052 5faea1650cac0f3ffd2dc1fb220182095a46e34158967d37c2a942e85e2 | UAT-7810 continues building ORB networks using new malware Cisco Talos | · Jul 7, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.