Live threat research and hand-picked analysis curated by the NivX intel team — searchable across 408 reports.
Unified threat intelligence, malware analysis and IOC hunting — powered by 7 integrated OSINT feeds and refreshed daily from the front lines.
Track named threat actors and campaigns from continuously refreshed OSINT pulses and analyst-curated intel.
Hybrid Analysis + VirusTotal detonation ratios, malware family attribution and sandbox verdicts.
URLScan live page previews, domain impersonation checks and Shodan attack-surface signals.
444+ indicators aggregated daily from AlienVault OTX with severity scoring and analyst notes.
Named actors from active pulses
Grouped by IOC frequency
Where your intel comes from
71.56.79.90IP AddressCINS Army bad-actor IP71.208.248.116IP AddressCINS Army bad-actor IP71.204.181.207IP AddressCINS Army bad-actor IP71.200.237.182IP AddressCINS Army bad-actor IP71.19.209.232IP AddressCINS Army bad-actor IP71.190.171.180IP AddressCINS Army bad-actor IP71.187.64.177IP AddressCINS Army bad-actor IP71.172.229.56IP AddressCINS Army bad-actor IPJump straight to the industry's leading OSINT platforms to enrich and validate IOCs — hashes, URLs, IPs and domains.
Newly discovered indicators are catalogued here and automatically flagged inside the analyzer above whenever a match is found.
| Indicator | Type | Threat | Severity | Tags | Source | |
|---|---|---|---|---|---|---|
71.56.79.90 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
71.208.248.116 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
71.204.181.207 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
71.200.237.182 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
71.19.209.232 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
71.190.171.180 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
71.187.64.177 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
71.172.229.56 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
71.168.71.163 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
71.112.157.254 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
71.10.182.202 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
70.95.19.216 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
70.80.234.50 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
70.35.207.70 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
70.32.94.153 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
70.32.81.179 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
69.79.101.95 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
69.73.213.52 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
69.58.102.210 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
69.57.120.103 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
69.244.83.73 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
69.194.46.73 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
68.9.67.28 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
68.183.17.39 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
66.9.173.52 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.236.133.99 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.244.52 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.181.129 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.174.218 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.153.27 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.150.30 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.148.147 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.147.222 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.141.16 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.132.16 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.132.10 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.227.99.60 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.227.98.101 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.227.160.79 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.225.75.29 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
60.182.2.66 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
59.153.47.106 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
52.119.82.156 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
48.217.140.226 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
46.200.156.26 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.237.99.43 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.234.50.151 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.226.75.83 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.226.17.126 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.191.101.98 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.186.193.142 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.179.157.104 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.175.118.224 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.165.85.125 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.164.7.147 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.160.177.28 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
45.137.12.125 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
42.52.242.37 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
41.142.161.43 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
38.226.149.28 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
38.210.184.90 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
38.210.175.22 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
37.66.50.52 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
36.96.128.31 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
34.151.65.143 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
31.76.77.236 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
27.42.170.210 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
24.199.99.184 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
24.199.127.42 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
24.199.121.62 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
24.199.107.54 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
24.199.104.162 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
24.144.92.89 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
23.182.128.85 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
14.1.104.239 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
31.40.207.85 | IP Address | Emerging Threats compromised-ips entry | high | — | taloset-communityblocklist | Emerging Threats compromised-ips |
27.79.6.221 | IP Address | Emerging Threats compromised-ips entry | high | — | taloset-communityblocklist | Emerging Threats compromised-ips |
27.79.5.204 | IP Address | Emerging Threats compromised-ips entry | high | — | taloset-communityblocklist | Emerging Threats compromised-ips |
67b52da711f9e363cdf97e64727184ed | MD5 Hash | Hidden prompt turns Microsoft Copilot into an AI worm | high | — | malwarebytes | Malwarebytes · hidden-microsoft-copilot-ai-worm |
5f4c1cf2e72346e3447bdf8f93e196e1 | MD5 Hash | Hidden prompt turns Microsoft Copilot into an AI worm | high | — | malwarebytes | Malwarebytes · hidden-microsoft-copilot-ai-worm |
002c504de55e6b5f1e0b44bcb1516f8b | MD5 Hash | Hidden prompt turns Microsoft Copilot into an AI worm | high | — | malwarebytes | Malwarebytes · hidden-microsoft-copilot-ai-worm |
728c6e46bbd831c39ff8cb11af0c8258 | MD5 Hash | Hims & Hers sued over alleged health data privacy failures | high | — | malwarebytes | Malwarebytes · hims-hers-sued-over-alleged-health-data-privacy-failures |
5ba9369634af2fd5c4fb80bad09afc30 | MD5 Hash | Hims & Hers sued over alleged health data privacy failures | high | — | malwarebytes | Malwarebytes · hims-hers-sued-over-alleged-health-data-privacy-failures |
e7408cd8952cc28f8be750b071c37713 | MD5 Hash | Hims & Hers sued over alleged health data privacy failures | high | — | malwarebytes | Malwarebytes · hims-hers-sued-over-alleged-health-data-privacy-failures |
f753c48da9d704df5ae27c2345e450ce | MD5 Hash | Malwarebytes for Windows, now available on the Microsoft Store | high | — | malwarebytes | Malwarebytes · malwarebytes-for-windows-now-available-on-the-microsoft-stor |
c9fe95cf252225ab5f492a00c4e79f6a | MD5 Hash | Malwarebytes for Windows, now available on the Microsoft Store | high | — | malwarebytes | Malwarebytes · malwarebytes-for-windows-now-available-on-the-microsoft-stor |
0780b0e3b034d3ac19b40332ad373ce5 | MD5 Hash | Malwarebytes for Windows, now available on the Microsoft Store | high | — | malwarebytes | Malwarebytes · malwarebytes-for-windows-now-available-on-the-microsoft-stor |
560661c9e326c2572caa5fc577ea0f50 | MD5 Hash | Fake Flash Player installs AtlasRAT | high | — | malwarebytes | Malwarebytes · fake-flash-player-installs-atlasrat |
c0c06675fc5ae2bf42c9c98fb4d30306 | MD5 Hash | Fake Flash Player installs AtlasRAT | high | — | malwarebytes | Malwarebytes · fake-flash-player-installs-atlasrat |
25dcd887e363c85b043654a9b256cb22 | MD5 Hash | Fake Flash Player installs AtlasRAT | high | — | malwarebytes | Malwarebytes · fake-flash-player-installs-atlasrat |
f70d520f6d9e682f83d35dd2646edd51 | MD5 Hash | Fake Fortnite rewards are stealing players' accounts | high | — | malwarebytes | Malwarebytes · fake-fortnite-rewards-are-stealing-players-accounts |
8bea73b7139e89ee423859c1ff49badd | MD5 Hash | Fake Fortnite rewards are stealing players' accounts | high | — | malwarebytes | Malwarebytes · fake-fortnite-rewards-are-stealing-players-accounts |
492e1e89a5c737b492e62ebb583c8ab6 | MD5 Hash | Fake Fortnite rewards are stealing players' accounts | high | — | malwarebytes | Malwarebytes · fake-fortnite-rewards-are-stealing-players-accounts |
61d235ef96970d3e5d2ee96366fd0554 | MD5 Hash | A week in security (July 27 - August 2) | high | — | malwarebytes | Malwarebytes · a-week-in-security-july-27-august-2 |
2.27.160.39 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
2.27.160.151 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
2.26.230.9 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
74a8f72186de5ce2431af79646dc2544 | MD5 Hash | A week in security (July 27 - August 2) | high | — | malwarebytes | Malwarebytes · a-week-in-security-july-27-august-2 |
5c2e0ded6bcb15782cb8618643aeac1f | MD5 Hash | A week in security (July 27 - August 2) | high | — | malwarebytes | Malwarebytes · a-week-in-security-july-27-august-2 |
b8473eb63f9e5be46795e767e7639ab2 | MD5 Hash | Californians can tell data brokers to DROP their information | high | — | malwarebytes | Malwarebytes · californians-can-tell-data-brokers-to-drop-their-information |
16f4e2bb8b9a9a5d64e45406583d6e42 | MD5 Hash | Californians can tell data brokers to DROP their information | high | — | malwarebytes | Malwarebytes · californians-can-tell-data-brokers-to-drop-their-information |
ba221e4bfe7206771e49111fc2f6b153 | MD5 Hash | Californians can tell data brokers to DROP their information | high | — | malwarebytes | Malwarebytes · californians-can-tell-data-brokers-to-drop-their-information |
http://83.219.1.198:43918/i | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://219.157.244.162:41098/i | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
e38d5a6355aa95eacce40e7771b84869 | MD5 Hash | The AI Act kicks into action, forces companies to be clear about AI chatbots | high | — | malwarebytes | Malwarebytes · the-ai-act-kicks-into-action-forces-companies-to-be-clear-ab |
http://115.50.91.234:36928/bin.sh | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://115.50.91.234:36928/i | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://110.37.106.148:44260/bin.sh | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
b1a1155e646bb11466537fb3e730438f | MD5 Hash | The AI Act kicks into action, forces companies to be clear about AI chatbots | high | — | malwarebytes | Malwarebytes · the-ai-act-kicks-into-action-forces-companies-to-be-clear-ab |
http://60.23.206.11:46446/i | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/lterouter | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/mips | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145.ptr.pfcloud.network/n2/mpsl | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145.ptr.pfcloud.network/n2/mips | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145.ptr.pfcloud.network/n2/lterouter | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/mpsl | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
267a7fe6e940ceb99b3db15a9a0a7e6f | MD5 Hash | The AI Act kicks into action, forces companies to be clear about AI chatbots | high | — | malwarebytes | Malwarebytes · the-ai-act-kicks-into-action-forces-companies-to-be-clear-ab |
http://196.189.35.172:43014/bin.sh | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://196.190.133.180:48265/i | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/x86 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/mips64 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/aarch64 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/ppc | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/armv4l | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/armv6l | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/sparc | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
de176b91d39e825ffad35b60c780668d | MD5 Hash | "Adult TikTok" searches lead to scams | high | — | malwarebytes | Malwarebytes · adult-tiktok-searches-lead-to-scams |
http://176.65.148.145/n2/sh4 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
7c57bdeb0b874877abc746fed86eb9a6 | MD5 Hash | "Adult TikTok" searches lead to scams | high | — | malwarebytes | Malwarebytes · adult-tiktok-searches-lead-to-scams |
http://176.65.148.145/n2/m68k | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
ae4c967324fd61965e3e5b15e51c7f1a | MD5 Hash | "Adult TikTok" searches lead to scams | high | — | malwarebytes | Malwarebytes · adult-tiktok-searches-lead-to-scams |
http://176.65.148.145/n2/armv5l | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/armv7l | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/x86_64 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145.ptr.pfcloud.network/n2/tbk | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145/n2/tbk | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://196.189.35.172:43014/i | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://94.154.43.238/t | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://94.154.43.123//bot.spc | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://94.154.43.123//bot.mpsl | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://217.60.195.187/parm7 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://94.154.43.115/bins/parm64 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://94.154.43.123//bot.arm6 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://94.154.43.123//bot.m68k | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://94.154.43.123//bot.arm5 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
768d82415a5ffdfb6752d109314f6bcb | MD5 Hash | WhatsApp account takeover scam asks you to "vote for my friend" | high | — | malwarebytes | Malwarebytes · whatsapp-account-takeover-scam-asks-you-to-vote-for-my-frien |
http://94.154.43.115/bins/parc | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
11d67d2c35c1929d7a5cc0d4e4746256 | MD5 Hash | WhatsApp account takeover scam asks you to "vote for my friend" | high | — | malwarebytes | Malwarebytes · whatsapp-account-takeover-scam-asks-you-to-vote-for-my-frien |
104.252.127.62 | IP Address | Emerging Threats compromised-ips entry | high | — | taloset-communityblocklist | Emerging Threats compromised-ips |
http://193.233.82.82/t | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.149.168.ptr.pfcloud.network/bins/kaizen.mpsl | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
635be9dafc3e1406a137ac7b7be0138d | MD5 Hash | WhatsApp account takeover scam asks you to "vote for my friend" | high | — | malwarebytes | Malwarebytes · whatsapp-account-takeover-scam-asks-you-to-vote-for-my-frien |
http://72.255.3.147:51931/Mozi.m | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70.ptr.pfcloud.network/389b2e | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70/f19d21 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70/df904c | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145.ptr.pfcloud.network/n2/armv5l | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
7c7057211b26d3ce3ac8bfaa2321e47e | MD5 Hash | Online backlash ends in Google rolling back Google Earth AI tool after a day | high | — | malwarebytes | Malwarebytes · online-backlash-ends-in-google-rolling-back-google-earth-ai- |
http://45.135.194.70/5f5213 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70/316f75 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
b57f741b98538817945f405a9d09c956 | MD5 Hash | Online backlash ends in Google rolling back Google Earth AI tool after a day | high | — | malwarebytes | Malwarebytes · online-backlash-ends-in-google-rolling-back-google-earth-ai- |
http://45.135.194.70/003f95 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70/99f292 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70/389b2e | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70/a8f148 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://176.65.148.145.ptr.pfcloud.network/n2/x86 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
aa3dca1fc1dc41180012ad3ba932e374 | MD5 Hash | Online backlash ends in Google rolling back Google Earth AI tool after a day | high | — | malwarebytes | Malwarebytes · online-backlash-ends-in-google-rolling-back-google-earth-ai- |
http://94.154.43.123/bins.sh | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70.ptr.pfcloud.network/a14f31 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70.ptr.pfcloud.network/a00b40 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70.ptr.pfcloud.network/ca6491 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70.ptr.pfcloud.network/e623fb | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
713577d029bfdb6865521b77d8424ea3 | MD5 Hash | Travelers targeted when logging into hotel Wi-Fi networks | high | — | malwarebytes | Malwarebytes · travelers-targeted-when-logging-into-hotel-wi-fi-networks |
http://45.135.194.70.ptr.pfcloud.network/fbeb13 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70.ptr.pfcloud.network/792865 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70.ptr.pfcloud.network/eab403 | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://45.135.194.70.ptr.pfcloud.network/3f20ca | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
057ef5955730e4ed8d03a42fa7f744c2 | MD5 Hash | Travelers targeted when logging into hotel Wi-Fi networks | high | — | malwarebytes | Malwarebytes · travelers-targeted-when-logging-into-hotel-wi-fi-networks |
http://45.135.194.70.ptr.pfcloud.network/968d9d | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://123.8.9.216:53523/bin.sh | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://59.96.137.157:36091/i | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://27.215.121.130:42924/i | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://123.8.9.216:53523/i | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://175.165.132.16:50966/i | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://222.137.144.217:41848/bin.sh | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
56e9e7ca636e69bbaf93e533c6ff9023 | MD5 Hash | Travelers targeted when logging into hotel Wi-Fi networks | high | — | malwarebytes | Malwarebytes · travelers-targeted-when-logging-into-hotel-wi-fi-networks |
http://182.124.127.129:37266/i | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
http://119.186.204.22:51908/bin.sh | URL | malware_download | high | — | urlhausabuse.chmalicious-urlthreat:malware_download | URLhaus |
68.220.57.96 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
68.183.69.247 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
68.183.40.92 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
68.183.223.149 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
68.183.15.228 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.255.65 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.255.240 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.244.64 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.223.50 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.219.143 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.206.213 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
64.23.206.186 | IP Address | CINS Army bad-actor IP | high | — | cins-armysentinel-ipsattacker-ip | CINS Army |
Sign in as admin to add or delete indicators.
Fresh reports and adversary research — updated continuously by the NivX intel team.
DFIR, malware analysis, SOC playbooks and breaking security news curated live by NivX analysts — refreshed every 30 minutes. Click any card to jump straight to the full report.
Made with Emergent