ZeroHour

Indicators of compromise

1,885 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainduckdns.orgd for data exfiltration troubleshooting Domain m-doxa-apodo.duckdns[.]org Mexican campaign infrastructure domain Domain m-doxa-geo.Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 7d ago
domainduckdns.orgcate SHA-256 Fingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f6377Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers
· 7d ago
domainnetlas.ioCut software and an Active Directory server. They also used Netlas.io to compile lists of potential targets. After validating theHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
domainattcdn.comom Domain TA412 delivery and download domain September 2026 attcdn[.]com Domain TA412 delivery and download domain September 2026China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
domainmsbenefit.com.]com Domain TA412 delivery and download domain August 2026 msbenefit[.]com Domain TA412 delivery and download domain September 2026China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
domainsecboxes.com26c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA412 delivery and download domain August 2026 msbChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
domainworkers.devd URL August 2026 extension-management-portal.centerfjdr658.workers[.]dev Hostname GemStone browser extension C&C August 2026 extenChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
domainbloom.ios. Teams loads a resource hosted on an external domain, cdn.bloom[.]io, which ultimately results in the phishing page being rendCybercriminals are building phishing pages that exist only inside victims’ browsers
Help Net Security
· 7d ago
domainadd-passkey.comlpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkey[.]com† SSO and identity provider integratedsso[.]com†, oktasessPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domaincompanyname.maliciousdomain.comuman trust. The actor creates domains following the pattern companyname[.]maliciousdomain[.]com to impersonate organization-specific authentication porPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domaincontoso.add-passkey.comcan persuade users to proceed with authentication. Example: contoso[.]add-passkey[.]com . The me Domain examples, defanged Passkey passkeyhelpdPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainintegratedsso.comtrar involvement in the activity. For example, company-name.integratedsso[.]com and company-name.secure-passkey[.]com illustrate how thePasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainkeysyncos.comsso[.]com†, oktasession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com,Passkey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainmyconnectkey.comom, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetuPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainoktasession.comskey[.]com† SSO and identity provider integratedsso[.]com†, oktasession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[Passkey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainoskeyconnect.com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetupac[.]com, portalsetPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainoskeyregister.comization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]comPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainoskeysetup.comsetup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]comPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainoskeysync.comession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com,Passkey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainpasskeyhelpdesk.comdd-passkey[.]com . The me Domain examples, defanged Passkey passkeyhelpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkePasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainportalsetuphub.comnnect[.]com Setup and verification validationsetupac[.]com, portalsetuphub[.]com Step 3-4 : User identity compromise From one sign-in to bPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainsecure-passkey.comexample, company-name.integratedsso[.]com and company-name.secure-passkey[.]com illustrate how the same company name can appear under difPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainsetupmypasskey.comanged Passkey passkeyhelpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkey[.]com† SSO and identity provider integratedPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainsyncmykey.comom, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verificPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domainvalidationsetupac.comconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetupac[.]com, portalsetuphub[.]com Step 3-4 : User identity compromisePasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 7d ago
domaincmd.jarsame directory. The threat actors used the JAR file (named “cmd[.]jar”) to query the compromised systems’ internal databases toActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 8d ago
domainhome.jsp25a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6f6daa90c6879911cd89Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 8d ago
domainjava.ioand line and executes it using /bin/sh -c <command>. import java.io.BufferedReader; import java.io.InputStreamReader; public clActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 8d ago
domainlicense.tmp“package_info.pl” to execute an attacker-crafted malicious “license[.]tmp” file with root privileges. The malicious file consistedActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 8d ago
domainbsc.rpc.blxrbdn.come-loaded by the Chrome component BNB Smart Chain RPC domain bsc[.]rpc[.]blxrbdn[.]com RPC endpoint queried by ZigCryptoStealer BNB Smart ChClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainbsc-testnet-rpc.publicnode.comCs):- Type Indicator Description BNB Smart Chain RPC domain bsc-testnet-rpc[.]publicnode[.]com RPC service queried by the initial ClearFake browser scClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainfd.gstats-api-contact.cced by ZigCryptoStealer to obtain C2 configuration C2 domain fd[.]gstats-api-contact[.]cc Historical ZigCryptoStealer contract value C2 domain pkClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domaingithub.comaddress for the verification.google branch TLS SNI and Host github[.]com Hostname presented by the verification.google Amatera buiClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainhub.logwerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by the PowerShell installer SHA-256ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainjewel.jsproxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload for the verification.googleClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainkffd3.vexlatech.ccr[.]cc Historical ZigCryptoStealer contract value C2 domain kffd3[.]vexlatech[.]cc Historical ZigCryptoStealer contract value C2 domain stClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainkffd3.vogueatelier.ccr[.]cc Historical ZigCryptoStealer contract value C2 domain kffd3[.]vogueatelier[.]cc Historical ZigCryptoStealer contract value C2 domain kfClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainkr.cedar2glanz.runt for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload for the verificClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainlb.propertyfind.cct[.]cc Historical ZigCryptoStealer contract value C2 domain lb[.]propertyfind[.]cc ZigCryptoStealer C2 domain returned during analysis DriClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainleaguejazire.com1fEb11A5 macOS-specific second-stage contract WebDAV domain leaguejazire[.]com Randomized subdomains used for Windows WebDAV delivery DoClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainpaternal-angrily.comion file for the remote-access client Remote-access gateway paternal-angrily[.]com:443 Configured remote-access HTTP gateway IPv4 address 21ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainphys.stunned-amniotic.comverification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by the PowerShell instaClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainpkg.vogueatelier.cct[.]cc Historical ZigCryptoStealer contract value C2 domain pkg[.]vogueatelier[.]cc Historical ZigCryptoStealer contract value C2 domain kfClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainriyazinikokar.xyzndomized subdomains used for Windows WebDAV delivery Domain riyazinikokar[.]xyz macOS ClickFix request infrastructure File name pf.ch WebClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainstatic.quorashift.cch[.]cc Historical ZigCryptoStealer contract value C2 domain static[.]quorashift[.]cc Historical ZigCryptoStealer contract value C2 domain lbClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domaintelegra.phbserved at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch toClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainupdate.dubbedmuch.cced Go-based reverse TCP proxy executable WebSocket C2 wss://update[.]dubbedmuch[.]cc/ Hard-coded C2 endpoint for the reverse TCP proxy PowerClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainclck.rut file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp , where it confirms that it has an internet connecGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domaindiscord.comend the information it steals to the following URL: https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-YGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domainflow.lavasoft.comle-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwaGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domainngrok.ioto secure tunneling services provided by ngrok at 7.tcp.eu.ngrok[.]io:12684 . Three more copies of NJRAT ( license.exe , rockstGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domaintelemetry.servers.getgo.com0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0.Grand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domainxsph.ruand then deletes itself. The RAT then connects to a0700877.xsph[.]ru ( 141.8.197[.]42 ). This domain has been on blocklists foGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domainleaguejazire.comopens a WebDAV UNC path hosted on a randomized subdomain of leaguejazire[.]com , then launches the pf.ch loader through rundll32.exe usiHackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware
GBHackers
· 8d ago
domainadoube.vuemail, which took them to a fake CAPTCHA lure (at https[://]adoube[.]vu/2a8ed9baefcd ). This phishing landing page displayed a faPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainhosthiifran.screenconnect.comwas downloaded from the attacker-controlled infrastructure, hosthiifran[.]screenconnect[.]com . When the target opened their Downloads folder and exePhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domaininstance-uxh86b-relay.screenconnect.comClient ( 9c1aea531ba4c511 ) configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com . The attacker used a legitimate ScreenConnect Trial RePhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainrelay.goldenmelon.usclient ( d751818fd46e5ca9 ), configured to communicate with relay[.]goldenmelon[.]us . That client (again) used the native Windows command sPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainrelay.illuminantgroup.netlluminantgroup[.]net and was configured to communicate with relay[.]illuminantgroup[.]net . Both ScreenConnect clients were registered as WindowsPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainscx.illuminantgroup.netnConnect Client ( c19e38a20f1ba492 ), which downloaded from scx[.]illuminantgroup[.]net and was configured to communicate with relay[.]illuminaPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainselectstructure.com.aued the malicious link in the message, which brought them to selectstructure[.]com[.]au/freedom/adobedocument.html . This domain uses the samePhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainvictory.mkc1.digitaloceanspaces.comeader update ( AdbRdBkUpsStUp.msi ) and was downloaded from victory[.]mkc1[.]digitaloceanspaces[.]com . Once it was executed, the installer again led to thPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainwir.consultingics.comd ScreenConnect client payload ( patch.msi ) from hxxps[://]wir[.]consultingics[.]com/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest&c=GOPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domaingoogle.comcompromise (IoCs):- Type Indicator Description Domain docs.google[.]com Google-hosted documents and Sheets were used for lure hosHackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cyber Security News
· 8d ago
domainobfuscator.ioor the fraudulent Google Docs lure document Tool or service Obfuscator[.]io JavaScript obfuscation service whose output patterns wereHackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cyber Security News
· 8d ago
domainpaste.shand payload retrieval through the Visualization API Domain paste[.]sh Hosted first-stage JavaScript loader scripts used in theHackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cyber Security News
· 8d ago
domainsimpleswap.iocy trading site targeted by the initial lure version Domain SimpleSwap[.]io Cryptocurrency trading site targeted by the later TampermHackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cyber Security News
· 8d ago
domainswapzone.ioRL promoted for the Tampermonkey-based loader script Domain SwapZone[.]io Cryptocurrency trading site targeted by the initial lureHackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cyber Security News
· 8d ago
domainamazingshield.xyz, redundant agent. This Python script is downloaded from aa.amazingshield[.]xyz . The installer downloads a legitimate Python distributioUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainatthelake.inforring SEO Domain Search Keyword Victim IP Windows_10 Chrome atthelake[.]info hwidspoofer 5.xxx.xx.xxx Windows_10 Chrome atthelake[.]inUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domaincrowdstri.comhostname and processor architecture. The Python agent used crowdstri[.]com as its C2 domain. This appears to be a deliberate typosquUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domaincrowdstrike.comits C2 domain. This appears to be a deliberate typosquat of crowdstrike[.]com , designed to blend into logs and evade quick security reUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainextentrack.comt extracts and runs eld2.tmp which contacts the affiliate’s extentrack[.]com install tracker. eld2.tmp drops and loads Adblock.dll , wUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainmqsearch.com: Search hijacking : Changes the default search provider to mqsearch[.]com , a domain that masquerades as a search engine ExtensionUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainnoiseship.cfdh affiliate ID CID=2855 . Second intrusion set : Browsed to noiseship[.]cfd , a domain registered just 39 days earlier, and downloadeUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainpcsdkflyer.caling, as well as file execution. The C2 server address, reg.pcsdkflyer[.]ca , is decoded from a 39-byte configuration blob using BaseUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainstryper.inforst part of Insomnia RAT is a Node.js agent downloaded from stryper[.]info/aa.js . While the prior variant targeted Windows, Linux aUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainvoyagemist.spaceThis temporary file transmits an initial tracking beacon to voyagemist[.]space . This is another gating mechanism: depending on the struUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainbloom.ioTeams, which then loads an external resource hosted on cdn.bloom[.]io. It is this resource that is converted by the browser intNew Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
SecurityWeek
· 8d ago
domainsocket.ayakliborsa.netpool endpoint used by botnet-deployed XMRig Domain and port socket.ayakliborsa.net:8081 Live operator-controlled hostname resolving to 188.245Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
domainhunt.iooop from believed-write to confirmed shell access (Source : Hunt.io). The flaw can allow a remote, unauthenticated attacker toMassive Redis Cryptojacking Campaign Hijacks Thousands of Linux Servers
GBHackers
· 8d ago
domainmoneroocean.streamocal mining pool/proxy used by the operator’s own host pool.moneroocean[.]stream:443 Domain:port Mining pool used by botnet-deployed XMRigMassive Redis Cryptojacking Campaign Hijacks Thousands of Linux Servers
GBHackers
· 8d ago
domainasp.netMode [7]. Deploy an EDR solution. Rotate SharePoint Server ASP.NET machine keys [8] and restart IIS using iisreset.exe . It is2026-004: Critical Vulnerability in SharePoint Exploited
CERT-EU Advisories
· 9d ago
domainoast.sites writable, and exfiltrates the data through requests to an oast.site subdomain, which is typically seen in security tests that uAdobe fixes critical Magento zero-day exploited to backdoor servers
BleepingComputer
· 9d ago
domainitemrange.comystarting.com Historical Ethereum resolver C2 domain Domain itemrange.com Most recently recorded Ethereum resolver C2 domain URL httpHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
domainpublisherresolution.comsed address from April 2026, designated monitor-only Domain publisherresolution.com First C2 domain written to the Ethereum resolver contract DHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
domainresumeacceptable.comC2 domain written to the Ethereum resolver contract Domain resumeacceptable.com Historical Ethereum resolver C2 domain Domain simultaneouslHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
domainsimultaneouslypower.comcceptable.com Historical Ethereum resolver C2 domain Domain simultaneouslypower.com Historical Ethereum resolver C2 domain Domain wiselystartinHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
domainwiselystarting.comuslypower.com Historical Ethereum resolver C2 domain Domain wiselystarting.com Historical Ethereum resolver C2 domain Domain itemrange.comHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
domaingerenciadorcaixa.digitalletely separate banking-phishing cluster A related domain — gerenciadorcaixa.digital, cloning Caixa Econômica Federal’s corporate banking portalHVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures
ANY.RUN
· 9d ago
domainbsc.rpc.blxrbdn.comad. The payload makes a separate JSON-RPC eth_call through "bsc[.]rpc[.]blxrbdn[.]com" to BNB Smart Chain contract 0x7CC3cFC1Ac007B8c6566fDClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainbsc-testnet-rpc.publicnode.comontract 0x886d310Ac23e05EA705e24E513D19f53793832A9 through "bsc-testnet-rpc[.]publicnode[.]com". BNB Smart Chain is a public, Ethereum-compatible blocClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainfd.gstats-api-contact.ccly: Effective period in UTC Contract value June 30 – July 5 fd[.]gstats-api-contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domaingithub.comconnects to it directly on TCP port 443, while presenting "github[.]com" as the TLS server name and HTTP Host value. Unlike the "ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainkffd3.vexlatech.ccier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 static[.]quorashift[.]cc July 26 – 30 lb[.ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainkffd3.vogueatelier.cccontact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffd3[.]vexlatech[.]cc July 18 – 26 staticClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainlb.propertyfind.ccring) function. During our analysis, the contract returned "lb[.]propertyfind[.]cc", which ZigCryptoStealer then used as its C2 domain. ThClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainleaguejazire.comd command opens a WebDAV path on a randomized subdomain of "leaguejazire[.]com", places the victim identifier in the path, and executesClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainpkg.vogueatelier.ccue June 30 – July 5 fd[.]gstats-api-contact[.]cc July 5 – 9 pkg[.]vogueatelier[.]cc July 9 – 12 kffd3[.]vogueatelier[.]cc July 12 – 18 kffdClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago
domainriyazinikokar.xyzacOS user-agent string. The request goes to a subdomain of "riyazinikokar[.]xyz". Since the subject of our initial research was a customeClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Cisco Talos
· 9d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.