#iocs — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #iocs, aggregated by home.social.
-
AsconBot
Novel multi-arch DDoS bot via ADB — ASCON-128 AEAD + key-ratchet C2
C2: 168.220.248[.]106:24032 (live)
SHA256: 96f926f634fe67a384d577612157472f7aae9db5c0651730dc9d98360b9e8766
-
Threat actors are leveraging shared infrastructure together with subdomain abuse to control and serve hundreds of malicious websites with minimal management.
This week we were investigating a cluster of crypto brand lookalike domains.Through subdomain abuse – often powered by wildcard DNS configurations – just 34 registered domains expand to over 500 scam sites.
Investigating website content across that cluster allowed us to find several additional clusters running the same playbook. Thousands of domains on them.
This initial cluster impersonated dozens of brands — Binance, Coinbase, Kraken, KuCoin, Bybit, Bitmart. Several of these sites push fake app downloads, making malware delivery and crypto wallet theft a likely component of the broader operation.
A sample of the domains associated:
cryptocoinsx[.]cfd
bmarkit[.]com
zznyusbsgo.bitmart[.]pw
4pzyy6n7log71mm0.bitmarts[.]cc
5etxkk2aeh8jfgl0.bitstamptc[.]com
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #Phishing #Scams #malware #crypto #lookalikes #subdomains #iocs -
#NPM #axios maintainer has lost control of their account. Malicious versions 1.14.1 and 0.30.4 have been published which include a RAT.
NPM has pulled the effected versions and the payload. Time to clean up and see if you were effected.
StepSecurity has an awesome write up on this issue with #iocs
Link follows this toot.
#CTI #infosec #node #cybersecurity #security #nodejs #js #malware
-
A more sane and parseable list of indicators:
Landing page
httpX://macdev.slab[.]com/public/posts/insta-іі-with-termina-і-g40n4aau?shr=6etwxr0gksp2ltctcqv7gom7Loaders
httpX://datasphere.us[.]com/debug/loader.sh?build=492f9e58358e8e2bc9e0414fa077e197
https://datasphere.us.com/debug/payload.applescript?build=492f9e58358e8e2bc9e0414fa077e197Mocked User Agent for curls
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36APIs
httpX://datasphere.us[.]com/api/debug/event # initial info gathering
httpX://datasphere.us[.]com/gate # stealer upload location
httpX://datasphere.us[.]com/gate/chunk # large file uploads
httpX://datasphere.us[.]com/api/bot/heartbeat # Persistence heartbeat APIapi key
61cb9c3bd1a2faa7d6613dd8e5d09e79fe95e85ab09ed6bcd6406badff5a083f -
Command-and-control IPv4 map, 2026-02-22 to 2026-03-07 #IOCs
https://abjuri5t.github.io/SarlackLab/43.249.172[.]0/22
23.248.208[.]0/21
178.16.52[.]0/22
23.226.58[.]0/23
156.234.56[.]0/23
158.94.208[.]0/22
43.240.239[.]0/24
103.39.16[.]0/22
185.213.60[.]0/23
23.226.48[.]0/23 -
Command-and-control IPv4 map, 2026-02-10 to 2026-02-23 #IOCs
https://abjuri5t.github.io/SarlackLab/148.178.64[.]0/19
148.178.32[.]0/19
178.16.52[.]0/22
207.56.192[.]0/19
91.92.240[.]0/22
158.94.208[.]0/22
102.117.128[.]0/18
45.114.106[.]0/24
156.234.94[.]0/24
106.52.0[.]0/14 -
Command-and-control domain tree, 2026-02-03 to 2026-02-16 #IOCs
https://abjuri5t.github.io/SarlackLab/*.bj[.]baidubce[.]com
*.tcp[.]cpolar[.]top
*.dianqi1[.]jiayongdianqi[.]xyz
*.dianqi2[.]jiayongdianqi[.]xyz
*.getupi[.]in[.]net -
Pour la chasse et vérification dans les logs réseau notamment pour la période juin ➡️ décembre 2025
👇
https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/
⬇️🔍 IOC — Validin (Exploring Notepad++ network indicators)
Ces IOC proviennent du rapport d’analyse de l’infrastructure C2 associé à l’attaque Notepad++ (indiqués dans l’article Validin).
95.179.213[.]0 (confirmé le même que Rapid7)
api[.]skycloudcenter[.]com
61.4.102[.]97
api[.]wiresguard[.]com
59.110.7[.]32
124.222.137[.]114
45.32.144[.]255
160.250.93[.]48
cloudtrafficservice[.]com
api[.]cloudtrafficservice[.]com
103.159.133[.]178
👇
https://securelist.com/notepad-supply-chain-attack/118708/🔍 IOC — Securelist (Notepad supply chain attack)
Cet article donne plusieurs catégories d’indicateurs (machines de mise à jour malicieuses, C2, fichiers, etc.).
⚠️ Malicious Updater URLs
- hxxp://45.76.155[.]202/update/update.exe
- hxxp://45.32.144[.]255/update/update.exe
- hxxp://95.179.213[.]0/update/update.exe
- hxxp://95.179.213[.]0/update/install.exe
- hxxp://95.179.213[.]0/update/AutoUpdater.exe
📡 System Info Upload / C2
- hxxp://45.76.155[.]202/list
- hxxps://self-dns.it[.]com/list
⚙️ Metasploit downloader / Cobalt Strike
- hxxps://45.77.31[.]210/users/admin
- hxxps://cdncheck.it[.]com/users/admin
- hxxps://safe-dns.it[.]com/help/Get-Start
💻 Cobalt Strike Beacon / Payload C2
- hxxps://45.77.31[.]210/api/update/v1
- hxxps://45.77.31[.]210/api/FileUpload/submit
- hxxps://cdncheck.it[.]com/api/update/v1
- hxxps://cdncheck.it[.]com/api/Metadata/submit
- hxxps://cdncheck.it[.]com/api/getInfo/v1
- hxxps://cdncheck.it[.]com/api/FileUpload/submit
- hxxps://safe-dns.it[.]com/resolve
- hxxps://safe-dns.it[.]com/dns-query
-
aww man, looking around to see if anyone has already done some reversing/modding work on a game that's piqued my interest recently has led me to this itch account using the blog feature to redirect to fake downloads.
httpX://itch[.]io/blog/1318716/hollow-knight-silksong-mod-menu-software-for-pc-control-
Initial landing page: gitcompiler[.]com, appears to call out and test 3 sub domains to redirect to which in turn will send to a landing page. (though 2 of the domains have busted cors rules and don't work anyway)
Interestingly I was only able to download the sample on my linux machine by using the "responsive mode" emulating a mobile device in firefox for the (purpose of User Agent spoofing). Anyrun and virustotal didn't pick anything up, but another user got some signals using the recorded future sandbox under a different download.
As much as I'd love to try and dig at it myself to practice some reversing I don't have the setup here to do anything of the sort safely
reuploaded sample: https://app.any.run/tasks/5ee02578-a655-4559-8dc9-899b40f5ea57
sample from malicious host: https://app.any.run/tasks/eb5dc590-a83a-4a38-afab-6e419ce99686
public sandbox: https://tria.ge/260117-qf18ysat4c// Primary landing page
*.gitcompiler[.]com
// Redirect mirrors, contains an AES encrypted url in /head/meta[name='token']
httpX://digitalwavesway[.]com
httpX://gametolifeservers[.]com
httpX://techflowtime[.]com
// landing page for digitalwavesway
httpX://mailer.soham-sn[.]com/
// redirects to this anon filehost for applicable UAs
httpX://download.us-east-1.fromsmash[.]co/transfer/o__j34ymsr-et/file/57f99acc7c450b6d46375299cfea313a04b5c9d2?identity=a3aa69c86700fc05b854066a0e9dc0c5-46a18736882df635ff3cb7ed43d39ba05859a992c5ec0d2b7ef47c8d99fc4de6c7884d5fcf7019eafa90291a05c7421c3ef7b7b78d70fbcdced31f8a3b50dec16c04299c9ea69377415fe2a33d26899c&Expires=1768719805&Key-Pair-Id=APKAIM76HR2FWFZRN3HA&Signature=eG9gFcmZF2zZXoRTPyWemG0syj4bEbtNOitCECgcjF-XyQzUb6i9skCN~9pKcSr0n31JPfnCbfSytbNS1MdgsbQH5kpxQQthp4bhK38Xqmbsd~Gc-VgT7M~3ml7K0H1uiPrvd8eu7oWTWEaUJJjyAn-ZbqAVRSD99AjhJ8O~yWD49~nlYowUR0fO7R-gPtNd1BtB278xB3DdW0js1M2os8T5AwIULZKOW3-oDjMhrAXCfqzwGOrH8GxNyJpA09sP8ZBWvDOb73ykYWb47~UZPBLV0T2hnWGkDW5ZHoKhZUwedrankpheTBG51DeSM81OZi3ZPOEbngtGZDvtIYQtEg__ -
Command-and-control IPv4 map, 2025-12-22 to 2026-01-04 #IOCs
https://abjuri5t.github.io/SarlackLab/156.234.96[.]0/20
103.48.132[.]0/22
156.234.152[.]0/23
156.234.208[.]0/23
156.234.145[.]0/24
103.41.6[.]0/23
156.234.216[.]0/21
156.234.252[.]0/22
104.140.144[.]0/20 -
RE: https://chaos.social/@christopherkunz/115615056111216077
potentially pivotal: key indicators of compromise (#IoCs) identified by GitLab's Vulnerability Research team concerning an active, large-scale supply chain attack on the #npm ecosystem.
#DevSecOps -
Over the past 30 days, our community shared 27,165 new #IOCs on ThreatFox 🦊 — an 18% increase from the previous month.
👏 Huge shoutout to 'juroots', our top contributor with 2,746 IOCs submitted.
💀 The most-shared malware family (or in this case framework)? Clearfake, with 2,817 IOCs reported.Find the full breakdown here: 👉 https://threatfox.abuse.ch/statistics/
#ThreatFox #CommunityPower #SharingIsCaring #CyberThreatIntel
-
Command-and-control domain tree, 2025-09-26 to 2025-10-09 #IOCs
https://abjuri5t.github.io/SarlackLab/*.at[.]ply[.]gg
*.bj[.]baidubce[.]com
*.ap-guangzhou[.]tencentscf[.]com
*.su[.]baidubce[.]com
*.dianqi1[.]jiayongdianqi[.]xyz
*.dianqi2[.]jiayongdianqi[.]xyz -
CVE-2025-61882: Cadena pre-auth RCE en Oracle E-Business Suite https://www.hackplayers.com/2025/10/cve-2025-61882-cadena-pre-auth-rce-oracle.html #vulnerabilidades #amenazas #0day #iocs
-
Over the last 30 days, the community shared 26,575 #IOCs on ThreatFox 🦊. That's a 83% jump on the previous month. 🚀 And topping the charts: XtremeRAT, with 6,640 IOCs 💀
Find more ThreatFox statistics here:
👉 https://threatfox.abuse.ch/statistics