Indicators of compromise
1,885 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | duckdns.org | d for data exfiltration troubleshooting Domain m-doxa-apodo.duckdns[.]org Mexican campaign infrastructure domain Domain m-doxa-geo. | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| domain | duckdns.org | cate SHA-256 Fingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f6377 | Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America GBHackers | · 7d ago |
| domain | netlas.io | Cut software and an Active Directory server. They also used Netlas.io to compile lists of potential targets. After validating the | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| domain | attcdn.com | om Domain TA412 delivery and download domain September 2026 attcdn[.]com Domain TA412 delivery and download domain September 2026 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| domain | msbenefit.com | .]com Domain TA412 delivery and download domain August 2026 msbenefit[.]com Domain TA412 delivery and download domain September 2026 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| domain | secboxes.com | 26c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA412 delivery and download domain August 2026 msb | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| domain | workers.dev | d URL August 2026 extension-management-portal.centerfjdr658.workers[.]dev Hostname GemStone browser extension C&C August 2026 exten | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| domain | bloom.io | s. Teams loads a resource hosted on an external domain, cdn.bloom[.]io, which ultimately results in the phishing page being rend | Cybercriminals are building phishing pages that exist only inside victims’ browsers Help Net Security | · 7d ago |
| domain | add-passkey.com | lpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkey[.]com† SSO and identity provider integratedsso[.]com†, oktasess | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | companyname.maliciousdomain.com | uman trust. The actor creates domains following the pattern companyname[.]maliciousdomain[.]com to impersonate organization-specific authentication por | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | contoso.add-passkey.com | can persuade users to proceed with authentication. Example: contoso[.]add-passkey[.]com . The me Domain examples, defanged Passkey passkeyhelpd | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | integratedsso.com | trar involvement in the activity. For example, company-name.integratedsso[.]com and company-name.secure-passkey[.]com illustrate how the | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | keysyncos.com | sso[.]com†, oktasession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | myconnectkey.com | om, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetu | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | oktasession.com | skey[.]com† SSO and identity provider integratedsso[.]com†, oktasession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[ | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | oskeyconnect.com | , oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetupac[.]com, portalset | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | oskeyregister.com | ization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | oskeysetup.com | setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | oskeysync.com | ession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | passkeyhelpdesk.com | dd-passkey[.]com . The me Domain examples, defanged Passkey passkeyhelpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passke | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | portalsetuphub.com | nnect[.]com Setup and verification validationsetupac[.]com, portalsetuphub[.]com Step 3-4 : User identity compromise From one sign-in to b | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | secure-passkey.com | example, company-name.integratedsso[.]com and company-name.secure-passkey[.]com illustrate how the same company name can appear under dif | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | setupmypasskey.com | anged Passkey passkeyhelpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkey[.]com† SSO and identity provider integrated | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | syncmykey.com | om, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verific | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | validationsetupac.com | connectkey[.]com, oskeyconnect[.]com Setup and verification validationsetupac[.]com, portalsetuphub[.]com Step 3-4 : User identity compromise | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 7d ago |
| domain | cmd.jar | same directory. The threat actors used the JAR file (named “cmd[.]jar”) to query the compromised systems’ internal databases to | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 8d ago |
| domain | home.jsp | 25a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6f6daa90c6879911cd89 | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 8d ago |
| domain | java.io | and line and executes it using /bin/sh -c <command>. import java.io.BufferedReader; import java.io.InputStreamReader; public cl | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 8d ago |
| domain | license.tmp | “package_info.pl” to execute an attacker-crafted malicious “license[.]tmp” file with root privileges. The malicious file consisted | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 8d ago |
| domain | bsc.rpc.blxrbdn.com | e-loaded by the Chrome component BNB Smart Chain RPC domain bsc[.]rpc[.]blxrbdn[.]com RPC endpoint queried by ZigCryptoStealer BNB Smart Ch | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | bsc-testnet-rpc.publicnode.com | Cs):- Type Indicator Description BNB Smart Chain RPC domain bsc-testnet-rpc[.]publicnode[.]com RPC service queried by the initial ClearFake browser sc | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | fd.gstats-api-contact.cc | ed by ZigCryptoStealer to obtain C2 configuration C2 domain fd[.]gstats-api-contact[.]cc Historical ZigCryptoStealer contract value C2 domain pk | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | github.com | address for the verification.google branch TLS SNI and Host github[.]com Hostname presented by the verification.google Amatera bui | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | hub.log | werShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by the PowerShell installer SHA-256 | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | jewel.js | proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload for the verification.google | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | kffd3.vexlatech.cc | r[.]cc Historical ZigCryptoStealer contract value C2 domain kffd3[.]vexlatech[.]cc Historical ZigCryptoStealer contract value C2 domain st | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | kffd3.vogueatelier.cc | r[.]cc Historical ZigCryptoStealer contract value C2 domain kffd3[.]vogueatelier[.]cc Historical ZigCryptoStealer contract value C2 domain kf | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | kr.cedar2glanz.ru | nt for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload for the verific | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | lb.propertyfind.cc | t[.]cc Historical ZigCryptoStealer contract value C2 domain lb[.]propertyfind[.]cc ZigCryptoStealer C2 domain returned during analysis Dri | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | leaguejazire.com | 1fEb11A5 macOS-specific second-stage contract WebDAV domain leaguejazire[.]com Randomized subdomains used for Windows WebDAV delivery Do | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | paternal-angrily.com | ion file for the remote-access client Remote-access gateway paternal-angrily[.]com:443 Configured remote-access HTTP gateway IPv4 address 21 | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | phys.stunned-amniotic.com | verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by the PowerShell insta | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | pkg.vogueatelier.cc | t[.]cc Historical ZigCryptoStealer contract value C2 domain pkg[.]vogueatelier[.]cc Historical ZigCryptoStealer contract value C2 domain kf | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | riyazinikokar.xyz | ndomized subdomains used for Windows WebDAV delivery Domain riyazinikokar[.]xyz macOS ClickFix request infrastructure File name pf.ch Web | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | static.quorashift.cc | h[.]cc Historical ZigCryptoStealer contract value C2 domain static[.]quorashift[.]cc Historical ZigCryptoStealer contract value C2 domain lb | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | telegra.ph | bserved at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch to | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | update.dubbedmuch.cc | ed Go-based reverse TCP proxy executable WebSocket C2 wss://update[.]dubbedmuch[.]cc/ Hard-coded C2 endpoint for the reverse TCP proxy Power | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | clck.ru | t file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp , where it confirms that it has an internet connec | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | discord.com | end the information it steals to the following URL: https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | flow.lavasoft.com | le-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwa | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | ngrok.io | to secure tunneling services provided by ngrok at 7.tcp.eu.ngrok[.]io:12684 . Three more copies of NJRAT ( license.exe , rockst | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | telemetry.servers.getgo.com | 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0. | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | xsph.ru | and then deletes itself. The RAT then connects to a0700877.xsph[.]ru ( 141.8.197[.]42 ). This domain has been on blocklists fo | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | leaguejazire.com | opens a WebDAV UNC path hosted on a randomized subdomain of leaguejazire[.]com , then launches the pf.ch loader through rundll32.exe usi | Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware GBHackers | · 8d ago |
| domain | adoube.vu | email, which took them to a fake CAPTCHA lure (at https[://]adoube[.]vu/2a8ed9baefcd ). This phishing landing page displayed a fa | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | hosthiifran.screenconnect.com | was downloaded from the attacker-controlled infrastructure, hosthiifran[.]screenconnect[.]com . When the target opened their Downloads folder and exe | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | instance-uxh86b-relay.screenconnect.com | Client ( 9c1aea531ba4c511 ) configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com . The attacker used a legitimate ScreenConnect Trial Re | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | relay.goldenmelon.us | client ( d751818fd46e5ca9 ), configured to communicate with relay[.]goldenmelon[.]us . That client (again) used the native Windows command s | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | relay.illuminantgroup.net | lluminantgroup[.]net and was configured to communicate with relay[.]illuminantgroup[.]net . Both ScreenConnect clients were registered as Windows | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | scx.illuminantgroup.net | nConnect Client ( c19e38a20f1ba492 ), which downloaded from scx[.]illuminantgroup[.]net and was configured to communicate with relay[.]illumina | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | selectstructure.com.au | ed the malicious link in the message, which brought them to selectstructure[.]com[.]au/freedom/adobedocument.html . This domain uses the same | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | victory.mkc1.digitaloceanspaces.com | eader update ( AdbRdBkUpsStUp.msi ) and was downloaded from victory[.]mkc1[.]digitaloceanspaces[.]com . Once it was executed, the installer again led to th | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | wir.consultingics.com | d ScreenConnect client payload ( patch.msi ) from hxxps[://]wir[.]consultingics[.]com/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest&c=GO | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | google.com | compromise (IoCs):- Type Indicator Description Domain docs.google[.]com Google-hosted documents and Sheets were used for lure hos | Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks Cyber Security News | · 8d ago |
| domain | obfuscator.io | or the fraudulent Google Docs lure document Tool or service Obfuscator[.]io JavaScript obfuscation service whose output patterns were | Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks Cyber Security News | · 8d ago |
| domain | paste.sh | and payload retrieval through the Visualization API Domain paste[.]sh Hosted first-stage JavaScript loader scripts used in the | Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks Cyber Security News | · 8d ago |
| domain | simpleswap.io | cy trading site targeted by the initial lure version Domain SimpleSwap[.]io Cryptocurrency trading site targeted by the later Tamperm | Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks Cyber Security News | · 8d ago |
| domain | swapzone.io | RL promoted for the Tampermonkey-based loader script Domain SwapZone[.]io Cryptocurrency trading site targeted by the initial lure | Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks Cyber Security News | · 8d ago |
| domain | amazingshield.xyz | , redundant agent. This Python script is downloaded from aa.amazingshield[.]xyz . The installer downloads a legitimate Python distributio | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | atthelake.info | rring SEO Domain Search Keyword Victim IP Windows_10 Chrome atthelake[.]info hwidspoofer 5.xxx.xx.xxx Windows_10 Chrome atthelake[.]in | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | crowdstri.com | hostname and processor architecture. The Python agent used crowdstri[.]com as its C2 domain. This appears to be a deliberate typosqu | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | crowdstrike.com | its C2 domain. This appears to be a deliberate typosquat of crowdstrike[.]com , designed to blend into logs and evade quick security re | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | extentrack.com | t extracts and runs eld2.tmp which contacts the affiliate’s extentrack[.]com install tracker. eld2.tmp drops and loads Adblock.dll , w | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | mqsearch.com | : Search hijacking : Changes the default search provider to mqsearch[.]com , a domain that masquerades as a search engine Extension | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | noiseship.cfd | h affiliate ID CID=2855 . Second intrusion set : Browsed to noiseship[.]cfd , a domain registered just 39 days earlier, and downloade | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | pcsdkflyer.ca | ling, as well as file execution. The C2 server address, reg.pcsdkflyer[.]ca , is decoded from a 39-byte configuration blob using Base | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | stryper.info | rst part of Insomnia RAT is a Node.js agent downloaded from stryper[.]info/aa.js . While the prior variant targeted Windows, Linux a | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | voyagemist.space | This temporary file transmits an initial tracking beacon to voyagemist[.]space . This is another gating mechanism: depending on the stru | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | bloom.io | Teams, which then loads an external resource hosted on cdn.bloom[.]io. It is this resource that is converted by the browser int | New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser SecurityWeek | · 8d ago |
| domain | socket.ayakliborsa.net | pool endpoint used by botnet-deployed XMRig Domain and port socket.ayakliborsa.net:8081 Live operator-controlled hostname resolving to 188.245 | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| domain | hunt.io | oop from believed-write to confirmed shell access (Source : Hunt.io). The flaw can allow a remote, unauthenticated attacker to | Massive Redis Cryptojacking Campaign Hijacks Thousands of Linux Servers GBHackers | · 8d ago |
| domain | moneroocean.stream | ocal mining pool/proxy used by the operator’s own host pool.moneroocean[.]stream:443 Domain:port Mining pool used by botnet-deployed XMRig | Massive Redis Cryptojacking Campaign Hijacks Thousands of Linux Servers GBHackers | · 8d ago |
| domain | asp.net | Mode [7]. Deploy an EDR solution. Rotate SharePoint Server ASP.NET machine keys [8] and restart IIS using iisreset.exe . It is | 2026-004: Critical Vulnerability in SharePoint Exploited CERT-EU Advisories | · 9d ago |
| domain | oast.site | s writable, and exfiltrates the data through requests to an oast.site subdomain, which is typically seen in security tests that u | Adobe fixes critical Magento zero-day exploited to backdoor servers BleepingComputer | · 9d ago |
| domain | itemrange.com | ystarting.com Historical Ethereum resolver C2 domain Domain itemrange.com Most recently recorded Ethereum resolver C2 domain URL http | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| domain | publisherresolution.com | sed address from April 2026, designated monitor-only Domain publisherresolution.com First C2 domain written to the Ethereum resolver contract D | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| domain | resumeacceptable.com | C2 domain written to the Ethereum resolver contract Domain resumeacceptable.com Historical Ethereum resolver C2 domain Domain simultaneousl | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| domain | simultaneouslypower.com | cceptable.com Historical Ethereum resolver C2 domain Domain simultaneouslypower.com Historical Ethereum resolver C2 domain Domain wiselystartin | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| domain | wiselystarting.com | uslypower.com Historical Ethereum resolver C2 domain Domain wiselystarting.com Historical Ethereum resolver C2 domain Domain itemrange.com | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| domain | gerenciadorcaixa.digital | letely separate banking-phishing cluster A related domain — gerenciadorcaixa.digital, cloning Caixa Econômica Federal’s corporate banking portal | HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures ANY.RUN | · 9d ago |
| domain | bsc.rpc.blxrbdn.com | ad. The payload makes a separate JSON-RPC eth_call through "bsc[.]rpc[.]blxrbdn[.]com" to BNB Smart Chain contract 0x7CC3cFC1Ac007B8c6566fD | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | bsc-testnet-rpc.publicnode.com | ontract 0x886d310Ac23e05EA705e24E513D19f53793832A9 through "bsc-testnet-rpc[.]publicnode[.]com". BNB Smart Chain is a public, Ethereum-compatible bloc | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | fd.gstats-api-contact.cc | ly: Effective period in UTC Contract value June 30 – July 5 fd[.]gstats-api-contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.] | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | github.com | connects to it directly on TCP port 443, while presenting "github[.]com" as the TLS server name and HTTP Host value. Unlike the " | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | kffd3.vexlatech.cc | ier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 static[.]quorashift[.]cc July 26 – 30 lb[. | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | kffd3.vogueatelier.cc | contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 static | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | lb.propertyfind.cc | ring) function. During our analysis, the contract returned "lb[.]propertyfind[.]cc", which ZigCryptoStealer then used as its C2 domain. Th | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | leaguejazire.com | d command opens a WebDAV path on a randomized subdomain of "leaguejazire[.]com", places the victim identifier in the path, and executes | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | pkg.vogueatelier.cc | ue June 30 – July 5 fd[.]gstats-api-contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| domain | riyazinikokar.xyz | acOS user-agent string. The request goes to a subdomain of "riyazinikokar[.]xyz". Since the subject of our initial research was a custome | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.