Indicators of compromise
4,251 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | D001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta | Catan and Mouse Cisco Talos | · Jul 2, 2026 |
| sha256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta | Catan and Mouse Cisco Talos | · Jul 2, 2026 |
| sha256 | afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 | mple.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://ta | Catan and Mouse Cisco Talos | · Jul 2, 2026 |
| sha256 | c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe | exe Detection Name: PUA.Win.Tool.Kmsactivator::1201 SHA256: c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe MD5: bf9672ec85283fdf002d83662f0b08b7 Talos Rep: https://ta | Catan and Mouse Cisco Talos | · Jul 2, 2026 |
| domain | google.com | orization code request to direct the browser to a "accounts.google[.]com/o/oauth2/v2/auth/identifier" URL containing a "client_id" | ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API The Hacker News | · Jul 2, 2026 |
| domain | proton.me | ss: 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy; contact e78393397[@]proton[.]me; ransom table named README_RANSOM Sysdig calls JADEPUFFER | AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack The Hacker News | · Jul 2, 2026 |
| url | http://45.131.66[ | ion) Command-and-control: 45.131.66[.]106, with a beacon to hxxp://45.131.66[.]106:4444/beacon every 30 minutes Claimed staging server: 6 | AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack The Hacker News | · Jul 2, 2026 |
| domain | mora1987.work | malware then establishes a connection to a remote server ("mora1987.work[.]gd"), allowing the threat actor to covertly control infec | SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT The Hacker News | · Jul 1, 2026 |
| domain | work.gd | then establishes a connection to a remote server ("mora1987.work[.]gd"), allowing the threat actor to covertly control infected | SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT The Hacker News | · Jul 1, 2026 |
| domain | rentry.co | or serverless workers. These include - Telegra.ph Teletype Rentry.co Write.as Dropbox GoFile DEV Community (dev.to) Mastodon Les | Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse The Hacker News | · Jul 1, 2026 |
| domain | socket.io | connects to attacker-controlled infrastructure, launches a socket.io backdoor, and eventually deploys a Python infostealer. The | Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer The Hacker News | · Jul 1, 2026 |
| domain | duckdns.org | C2 domains lean on free dynamic DNS services, specifically duckdns.org, which is where the name comes from. Once a device checks i | RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow Security Affairs | · Jul 1, 2026 |
| ipv4 | 192.0.2.1 | worth 35 points makes an asynchronous connection attempt to 192.0.2.1, an IP address reserved for testing that should never respo | RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow Security Affairs | · Jul 1, 2026 |
| domain | pamconj.com | gagement, we identified a management panel at “dashboard-bl.pamconj[.]com” serving a React single-page application (SPA) with a 1.7 | ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos | · Jul 1, 2026 |
| domain | sharepoint.com | he vendor's genuine SharePoint tenant: “https[:]//mononapfp.sharepoint[.]com/:f:/document/INV-IgCx1X50pgUjR7iAjZL2fuQaAW4GfKVs6wHT3BYv | ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos | · Jul 1, 2026 |
| domain | workers.dev | flare Workers accounts including “clear90489058903-document.workers[.]dev”. Linking ARToken to EvilTokens The connection between AR | ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos | · Jul 1, 2026 |
| domain | babybon.cfd | e payload servers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one of these does no | Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API The Hacker News | · Jul 1, 2026 |
| domain | comicstar.lat | also listed three payload servers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one of | Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API The Hacker News | · Jul 1, 2026 |
| domain | merkantalolol.asia | ers seen during the research: comicstar[.]lat babybon[.]cfd merkantalolol[.]asia A connection to one of these does not prove infection. It | Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API The Hacker News | · Jul 1, 2026 |
| domain | atlasregister.net | ty of the domains registered between June and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]ne | Cyber Recorded Future | · Jul 1, 2026 |
| domain | atlasregister.org | gistered between June and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com | Cyber Recorded Future | · Jul 1, 2026 |
| domain | beninmaritime.bj | e and October 2025: atlasregister[.]net atlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org g | Cyber Recorded Future | · Jul 1, 2026 |
| domain | beninmaritime.co | ng the Benin Maritime Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not included in Lloyd’s original | Cyber Recorded Future | · Jul 1, 2026 |
| domain | beninmaritime.in | are operated by the same threat actors: beninmaritime[.]co beninmaritime[.]in beninmaritime[.]org registry[.]zmgov[.]org In October 202 | Cyber Recorded Future | · Jul 1, 2026 |
| domain | beninmaritime.net | e Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not included in Lloyd’s original investigation. Resear | Cyber Recorded Future | · Jul 1, 2026 |
| domain | beninmaritime.org | flags and impersonating the Benin Maritime Administration ( beninmaritime[.]org, beninmaritime[.]co, beninmaritime[.]net ), not included | Cyber Recorded Future | · Jul 1, 2026 |
| domain | bma.gov.bj | files shared by three of the Oceaniek-attributed websites ( bma[.]gov[.]bj, beninmaritime[.]net , and beninmaritime[.]bj) and four | Cyber Recorded Future | · Jul 1, 2026 |
| domain | cadredevie.gouv.bj | s part of the Ministère du Cadre de Vie et des Transports ( cadredevie[.]gouv[.]bj ). The three inauthentic Benin Maritime Administration | Cyber Recorded Future | · Jul 1, 2026 |
| domain | epnicaragua.com | atlasregister[.]org beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net | Cyber Recorded Future | · Jul 1, 2026 |
| domain | epnicaragua.org | rg beninmaritime[.]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]o | Cyber Recorded Future | · Jul 1, 2026 |
| domain | gouv.bj | real email address listed for Benin on GISIS ( gmahissou[@]gouv[.]bj is spoofed as gmahissou[@]guve[.]bj ). Figure 2 : Screens | Cyber Recorded Future | · Jul 1, 2026 |
| domain | gove.bj | ]bj beninmaritime[.]net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links t | Cyber Recorded Future | · Jul 1, 2026 |
| domain | guve.bj | on GISIS ( gmahissou[@]gouv[.]bj is spoofed as gmahissou[@]guve[.]bj ). Figure 2 : Screenshot from the Benin Maritime Administ | Cyber Recorded Future | · Jul 1, 2026 |
| domain | hellasnaval.net | Cluster Alpha domains, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticac | Cyber Recorded Future | · Jul 1, 2026 |
| domain | imsag.org | a website impersonating a Guyanese maritime administration, imsag[.]org . The CENM websites claim that they provide IMO-mandated | Cyber Recorded Future | · Jul 1, 2026 |
| domain | isithin.com | p IP range as Cluster Alpha domains, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medll | Cyber Recorded Future | · Jul 1, 2026 |
| domain | malawi.marinegov.org | ral subdomains impersonating Malawi ship registry websites, malawi[.]marinegov[.]org and malawi[.]shipregistry[.]marinegov[.]org . By defaul | Cyber Recorded Future | · Jul 1, 2026 |
| domain | malawi.shipregistry.marinegov.org | Malawi ship registry websites, malawi[.]marinegov[.]org and malawi[.]shipregistry[.]marinegov[.]org . By default, the latter displays a page showing ship | Cyber Recorded Future | · Jul 1, 2026 |
| domain | marinegov.net | er of fraudulent ship registries centered around the domain marinegov[.]net. This activity also aligns with prior reporting from inde | Cyber Recorded Future | · Jul 1, 2026 |
| domain | marinegov.org | ins, 159[.]198[.]0[.]0/16 : isithin[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com naut | Cyber Recorded Future | · Jul 1, 2026 |
| domain | medlloyd.online | link to another domain hosted on different infrastructure, medlloyd[.]online . This domain is co-hosted on 159[.]198[.]36[.]123 with t | Cyber Recorded Future | · Jul 1, 2026 |
| domain | medlloyd.online.beninmaritime.net | ubdomain on the Cluster Alpha website beninmaritime[.]net , medlloyd[.]online[.]beninmaritime[.]net , indicates a link to another domain hosted on differ | Cyber Recorded Future | · Jul 1, 2026 |
| domain | medlloyd.org | n[.]com hellasnaval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry mari | Cyber Recorded Future | · Jul 1, 2026 |
| domain | nauticacentro.com | aval[.]net marinegov[.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry marinegov[.]org has seve | Cyber Recorded Future | · Jul 1, 2026 |
| domain | nauticacentro.mx | [.]org medlloyd[.]online medlloyd[.]org nauticacentro[.]com nauticacentro[.]mx Ship Registry marinegov[.]org has several subdomains impe | Cyber Recorded Future | · Jul 1, 2026 |
| domain | niataregister.net | net epnicaragua[.]com epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links to Oceaniek Technologies Insikt | Cyber Recorded Future | · Jul 1, 2026 |
| domain | niataregister.org | m epnicaragua[.]org gove[.]bj guve[.]bj niataregister[.]net niataregister[.]org Links to Oceaniek Technologies Insikt Group identified PD | Cyber Recorded Future | · Jul 1, 2026 |
| domain | oceaniektechnologies.com | l as document authors and creators. Oceaniek Technologies ( oceaniektechnologies[.]com ) is an Indian web development company listed throughout | Cyber Recorded Future | · Jul 1, 2026 |
| domain | palaureg.com | ata for similar PDFs distributed on PISR’s official website palaureg[.]com , which likely indicates that the operators behind epnica | Cyber Recorded Future | · Jul 1, 2026 |
| domain | pamconj.com | los published the operation’s domains and addresses, led by pamconj[.]com, for defenders to hunt on. | The ARToken phishing panel targets Microsoft 365 accounts Help Net Security | · Jul 1, 2026 |
| domain | pdf.beninmaritime.co | beninmaritime[.]org registry[.]zmgov[.]org In October 2025, pdf[.]beninmaritime[.]co displayed a “Certificate PDF Generator” ( Figure 3 ). F | Cyber Recorded Future | · Jul 1, 2026 |
| domain | registry.zmgov.org | : beninmaritime[.]co beninmaritime[.]in beninmaritime[.]org registry[.]zmgov[.]org In October 2025, pdf[.]beninmaritime[.]co displayed a “ | Cyber Recorded Future | · Jul 1, 2026 |
| domain | thesecure.biz | int about spam from “thesecure.biz,” is itself an artefact: thesecure.biz is the encrypted Jabber server Europol later said the arres | XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn't Security Affairs | · Jun 30, 2026 |
| domain | duckdns.org | he control addresses lean on free dynamic-DNS services like duckdns.org, which is where the "Duck" in the name comes from. This fit | RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS The Hacker News | · Jun 30, 2026 |
| domain | internal.corp.com | /page?ref=youtube.com bank.example.com/search?q=youtube.com internal.corp.com/redirect?from=youtube.com "The concern is not a single susp | Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability The Hacker News | · Jun 30, 2026 |
| domain | ipinfo.io | s wiped from the file system. It further sends a request to ipinfo[.]io to obtain the host's public IP address and location, allo | Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints The Hacker News | · Jun 30, 2026 |
| domain | perplexity-ai.online | bkiofojicogddingbdmcmkpbplcd) and used a look-alike domain, perplexity-ai[.]online, to pass for the real service at perplexity.ai. Microsoft | Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input The Hacker News | · Jun 30, 2026 |
| domain | dev-tunnels.com | ablishing encrypted communications with a remote server ("a.dev-tunnels[.]com"), and retrieving and executing additional JavaScript pay | Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer The Hacker News | · Jun 30, 2026 |
| domain | booking.com | Cyber threat actors are targeting employees of Booking.com partner accommodations in Japan, using phishing emails that | Hackers Leverage Blockchain to Hit Japan's Hotels Through Booking.com Infosecurity Magazine | · Jun 30, 2026 |
| domain | domain.com | Lateral movement flag using specified domain credentials (“domain.com\user:pass”) or a single space (” “) to leverage the current | The Gentlemen RaaS: rapid growth and a new ransomware variant Kaspersky Securelist | · Jun 30, 2026 |
| domain | sysinternals.com | shell . exe - Command "Invoke-WebRequest -Uri 'https://live.sysinternals[.]com/PsExec.exe' -OutFile 'C:\Temp\psexec.exe'" The ransomware | The Gentlemen RaaS: rapid growth and a new ransomware variant Kaspersky Securelist | · Jun 30, 2026 |
| domain | accounts.google.com | to direct the browser to the following URL: 1 https [ : ] //accounts[.]google[.]com/o/oauth2/v2/auth/identifier?response_type=code&client_i | How the ToddyCat APT group gains access to Gmail accounts Kaspersky Securelist | · Jun 30, 2026 |
| domain | cabsecnow.com | ation. Additionally, the hosting IP for the PlugX C2 domain cabsecnow[.]com was switched from 167.88.180[.]32 to 103.85.24[.]149 on A | Back Despite Disruption: RedDelta Resumes Operations Recorded Future | · Jun 30, 2026 |
| domain | ipsoftwarelabs.com | ng universities. This IP address currently hosts the domain ipsoftwarelabs[.]com, which was previously noted within reporting on activity | Back Despite Disruption: RedDelta Resumes Operations Recorded Future | · Jun 30, 2026 |
| domain | quochoice.com | http://103.85.24[.]158/hk097.dat , before ultimately using quochoice[.]com for command and control. This domain is currently hosted | Back Despite Disruption: RedDelta Resumes Operations Recorded Future | · Jun 30, 2026 |
| domain | systeminfor.com | amples. When loaded into memory, the PlugX payload uses www.systeminfor[.]com for command and control — the same domain used across the | Back Despite Disruption: RedDelta Resumes Operations Recorded Future | · Jun 30, 2026 |
| domain | couldinstallup.com | keys, a scheduled task named SolidPDFPcl2Bmp, the C2 domain couldinstallup[.]com, and the Zoho user agents that turn up on non-browser pro | Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks The Hacker News | · Jun 29, 2026 |
| domain | faq-whatsapp-center.com | Center using lookalike domains (e.g., "whats-zwp[.]vip" or "faq-whatsapp-center[.]com") Generic template phishing and credential collection tha | 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers The Hacker News | · Jun 29, 2026 |
| domain | whats-zwp.vip | sApp's Security Help Center using lookalike domains (e.g., "whats-zwp[.]vip" or "faq-whatsapp-center[.]com") Generic template phishin | 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers The Hacker News | · Jun 29, 2026 |
| domain | mitarchive.info | Koi Security has linked the credential exfiltration domain mitarchive.info to DarkSpectre , a Chinese operation previously connected t | StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years Security Affairs | · Jun 29, 2026 |
| domain | trycloudflare.com | are Tunnel hosted on the domain amsterdam-sheet-veteran-aka.trycloudflare[.]com. For its part, GammaLoad makes use of DNS-over-HTTPS ( Do | Hackers Leveraging Cloudflare Tunnels, DNS Fast The Hacker News | · Jun 29, 2026 |
| domain | mitarchive.info | face on a known one. Its credential payload exfiltrates to mitarchive.info, a domain Koi Security ties to DarkSpectre , the Chinese op | Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts The Hacker News | · Jun 29, 2026 |
| domain | weedhack.to | Central to the campaign is an enterprise-grade dashboard ("weedhack[.]to") that enables customers to view stolen credentials and s | Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content The Hacker News | · Jun 29, 2026 |
| domain | allcryptotalk.net | is IP address also hosted a defunct crypto news site called allcryptotalk[.]net, which has not posted new content since June 2015, and th | Shifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite Recorded Future | · Jun 29, 2026 |
| domain | contraloria.gob.pe | network of the Comptroller General of the Republic of Peru (contraloria[.]gob[.]pe). As of April 25, 2022, the BlackByte ransomware operat | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | digimin.gob.pe | Peru that affected the General Directorate of Intelligence (digimin[.]gob[.]pe) and Ministry of Economics and Finance (mef[.]gob[.]pe) | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | fazenda.rj.gov.br | e Secretary of State for Finance of Rio De Janeiro, Brazil (fazenda[.]rj[.]gov[.]br). Neither of these incidents were widely reported in | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | fodesaf.go.cr | o[.]cr), the Development Fund and Family Allowances Bureau (fodesaf[.]go[.]cr), and the Interuniversity Headquarters of Alajuela, Cos | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | hacienda.go.cr | ral Costa Rican entities including the Ministry of Finance (hacienda[.]go[.]cr), the Ministry of Labor and Social Security (mtss[.]go[ | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | marine-chain.io | other site, www[.]shipowner[.]io. April 2018 screenshots of marine-chain[.]io and shipowner[.]io provided by forum participants. Domain | Shifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite Recorded Future | · Jun 29, 2026 |
| domain | mef.gob.pe | (digimin[.]gob[.]pe) and Ministry of Economics and Finance (mef[.]gob[.]pe). Figure 3: Announcements of attacks on Costa Rican and | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | mtss.go.cr | enda[.]go[.]cr), the Ministry of Labor and Social Security (mtss[.]go[.]cr), the Development Fund and Family Allowances Bureau (fo | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | quito.gob.ec | romised data related to the Municipality of Quito, Ecuador (quito[.]gob[.]ec). This marked the first time that ALPHV targeted a gove | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | saludparatodos.ssm.gob.mx | to the Secretary of Health of the State of Morelos, Mexico (saludparatodos[.]ssm[.]gob[.]mx), a breach that was initially disclosed on or around | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | shipowner.io | owner[.]io. April 2018 screenshots of marine-chain[.]io and shipowner[.]io provided by forum participants. Domain registration histo | Shifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite Recorded Future | · Jun 29, 2026 |
| domain | siua.ac.cr | d the Interuniversity Headquarters of Alajuela, Costa Rica (siua[.]ac[.]cr). Previous Conti posts also made vague references to co | Latin American Governments Targeted By Ransomware Recorded Future | · Jun 29, 2026 |
| domain | www.marine-chain.io | le users and owners. Users on other forums pointed out that www[.]marine-chain[.]io was a near mirror image of another site, www[.]shipowne | Shifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite Recorded Future | · Jun 29, 2026 |
| domain | www.shipowner.io | ]marine-chain[.]io was a near mirror image of another site, www[.]shipowner[.]io. April 2018 screenshots of marine-chain[.]io and shipow | Shifting Patterns in Internet Use Reveal Adaptable and Innovative North Korean Ruling Elite Recorded Future | · Jun 29, 2026 |
| sha256 | 81e81f0bbbdb831eda215033b7a7dbf2eed3812f4e58118f181a8e99e613179e | be found in Appendix A. Figure 3: Configuration from sample 81e81f0bbbdb831eda215033b7a7dbf2eed3812f4e58118f181a8e99e613179e. (Source: Recorded Future) The builder is also responsible | New Ransomware-as-a-Service Tool ‘Thanos’ Shows Connections to ‘Hakbit’ Recorded Future | · Jun 29, 2026 |
| domain | clo4shara.xyz | eving the main payload at runtime from an external domain ("clo4shara[.]xyz/11z77u3.php"). This architecture offers added flexibility | Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks The Hacker News | · Jun 26, 2026 |
| domain | com-apps.cc | ported C2 domains named "restrictes[.]com/11z77u3.php" and "com-apps[.]cc/11z77u3.php" (instead of "clo4shara[.]xyz/11z77u3.php"), | Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks The Hacker News | · Jun 26, 2026 |
| domain | restrictes.com | ection point to two previously unreported C2 domains named "restrictes[.]com/11z77u3.php" and "com-apps[.]cc/11z77u3.php" (instead of | Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks The Hacker News | · Jun 26, 2026 |
| domain | web-telegram.ug | designed to achieve persistence and poll a remote server ("web-telegram[.]ug") every 30 seconds to process instructions issued by the | Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks The Hacker News | · Jun 26, 2026 |
| domain | ackques.com | on port 80, as well as issuing POST requests to the <index.ackques[.]com> C2 server with the specific User-Agent, pictured below: | RedAlpha: New Campaigns Discovered Targeting the Tibetan Community Recorded Future | · Jun 26, 2026 |
| domain | acques.com | ation about the victim system while POST requests to “index.acques[.]com/index.html” primarily uploaded zlib compressed files from | RedAlpha: New Campaigns Discovered Targeting the Tibetan Community Recorded Future | · Jun 26, 2026 |
| domain | cheacker.store | a protected business document. The March 16 registration of cheacker[.]store suggests the domain was created for a short-lived phishin | Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials Help Net Security | · Jun 26, 2026 |
| domain | hktechy.com | creating a separate thread with an open socket to the < www.hktechy[.]com> server on port 80, as well as issuing POST requests to t | RedAlpha: New Campaigns Discovered Targeting the Tibetan Community Recorded Future | · Jun 26, 2026 |
| domain | internetdocss.com | s; however, malware from both campaigns made use of the doc.internetdocss[.]com C2 domain, thus tying both campaigns together. A maliciou | RedAlpha: New Campaigns Discovered Targeting the Tibetan Community Recorded Future | · Jun 26, 2026 |
| domain | ukr.net | t had sent malicious emails to roughly one million users of Ukr.net, a widely used Ukrainian email service, and compromised mor | Pro-Russian hackers pose as Ukraine's cyber agency to target government, businesses The Record | · Jun 26, 2026 |
| domain | user.cheacker.store | ond-stage script from attacker-controlled infrastructure at user[.]cheacker[.]store,” the researchers explained. The second-stage phishing | Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials Help Net Security | · Jun 26, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.