Threat Intelligence

Curated intelligence from the front lines

Live threat research and hand-picked analysis curated by the NivX intel team — searchable across 408 reports.

NivX Counter Adversary Operations

Know your adversary. Stop the breach.

Unified threat intelligence, malware analysis and IOC hunting — powered by 7 integrated OSINT feeds and refreshed daily from the front lines.

104,492
IOCs tracked
33,133 hashes · 3,148 domains · 53,491 IPs
0
Named adversaries
4
Malware families
js.clearfake
01:37 PM
OTX last sync
50 pulses · 482 updated

Adversary Intelligence

Track named threat actors and campaigns from continuously refreshed OSINT pulses and analyst-curated intel.

Malware Analysis

Hybrid Analysis + VirusTotal detonation ratios, malware family attribution and sandbox verdicts.

Digital Risk Protection

URLScan live page previews, domain impersonation checks and Shodan attack-surface signals.

Curated IOC Database

444+ indicators aggregated daily from AlienVault OTX with severity scoring and analyst notes.

Top adversaries

Named actors from active pulses

No named adversary attribution in current IOCs

Top malware families

Grouped by IOC frequency

js.clearfake601
Generic.AsyncRAT.Marte.B501
AsyncRAT428
apk.triada351

Intelligence sources

Where your intel comes from

AbuseIPDB Blacklist26485
CINS Army25653
Malwarebytes17455
URLhaus14003
Hybrid Analysis11327
AlienVault OTX5712
ThreatFox1861
Emerging Threats compromised-ips1089

Recent IOCs on your radar

Last 8
high71.56.79.90IP Address
high71.208.248.116IP Address
high71.204.181.207IP Address
high71.200.237.182IP Address
high71.19.209.232IP Address
high71.190.171.180IP Address
high71.187.64.177IP Address
high71.172.229.56IP Address

Top active campaigns

1AbuseIPDB confidence 10026485 IOCs
2CINS Army bad-actor IP25653 IOCs
3malware_download14003 IOCs
4Hybrid Analysis submission8480 IOCs
5Emerging Threats compromised-ips entry1089 IOCs
6ClearFake601 IOCs
Threat Intel · IOC Database

Our curated indicator database

Newly discovered indicators are catalogued here and automatically flagged inside the analyzer above whenever a match is found.

IOC Database (104492 indicators)
33464 critical64805 high2301 medium3922 low
IndicatorTypeThreatSeverityTagsSource
71.56.79.90IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
71.208.248.116IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
71.204.181.207IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
71.200.237.182IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
71.19.209.232IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
71.190.171.180IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
71.187.64.177IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
71.172.229.56IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
71.168.71.163IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
71.112.157.254IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
71.10.182.202IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
70.95.19.216IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
70.80.234.50IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
70.35.207.70IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
70.32.94.153IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
70.32.81.179IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
69.79.101.95IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
69.73.213.52IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
69.58.102.210IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
69.57.120.103IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
69.244.83.73IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
69.194.46.73IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
68.9.67.28IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
68.183.17.39IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
66.9.173.52IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.236.133.99IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.244.52IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.181.129IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.174.218IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.153.27IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.150.30IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.148.147IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.147.222IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.141.16IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.132.16IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.132.10IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.227.99.60IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.227.98.101IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.227.160.79IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.225.75.29IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
60.182.2.66IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
59.153.47.106IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
52.119.82.156IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
48.217.140.226IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
46.200.156.26IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.237.99.43IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.234.50.151IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.226.75.83IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.226.17.126IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.191.101.98IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.186.193.142IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.179.157.104IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.175.118.224IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.165.85.125IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.164.7.147IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.160.177.28IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
45.137.12.125IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
42.52.242.37IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
41.142.161.43IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
38.226.149.28IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
38.210.184.90IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
38.210.175.22IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
37.66.50.52IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
36.96.128.31IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
34.151.65.143IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
31.76.77.236IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
27.42.170.210IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
24.199.99.184IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
24.199.127.42IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
24.199.121.62IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
24.199.107.54IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
24.199.104.162IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
24.144.92.89IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
23.182.128.85IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
14.1.104.239IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
31.40.207.85IP AddressEmerging Threats compromised-ips entryhigh
taloset-communityblocklist
Emerging Threats compromised-ips
27.79.6.221IP AddressEmerging Threats compromised-ips entryhigh
taloset-communityblocklist
Emerging Threats compromised-ips
27.79.5.204IP AddressEmerging Threats compromised-ips entryhigh
taloset-communityblocklist
Emerging Threats compromised-ips
67b52da711f9e363cdf97e64727184edMD5 HashHidden prompt turns Microsoft Copilot into an AI wormhigh
malwarebytes
Malwarebytes · hidden-microsoft-copilot-ai-worm
5f4c1cf2e72346e3447bdf8f93e196e1MD5 HashHidden prompt turns Microsoft Copilot into an AI wormhigh
malwarebytes
Malwarebytes · hidden-microsoft-copilot-ai-worm
002c504de55e6b5f1e0b44bcb1516f8bMD5 HashHidden prompt turns Microsoft Copilot into an AI wormhigh
malwarebytes
Malwarebytes · hidden-microsoft-copilot-ai-worm
728c6e46bbd831c39ff8cb11af0c8258MD5 HashHims & Hers sued over alleged health data privacy failureshigh
malwarebytes
Malwarebytes · hims-hers-sued-over-alleged-health-data-privacy-failures
5ba9369634af2fd5c4fb80bad09afc30MD5 HashHims & Hers sued over alleged health data privacy failureshigh
malwarebytes
Malwarebytes · hims-hers-sued-over-alleged-health-data-privacy-failures
e7408cd8952cc28f8be750b071c37713MD5 HashHims & Hers sued over alleged health data privacy failureshigh
malwarebytes
Malwarebytes · hims-hers-sued-over-alleged-health-data-privacy-failures
f753c48da9d704df5ae27c2345e450ceMD5 HashMalwarebytes for Windows, now available on the Microsoft Storehigh
malwarebytes
Malwarebytes · malwarebytes-for-windows-now-available-on-the-microsoft-stor
c9fe95cf252225ab5f492a00c4e79f6aMD5 HashMalwarebytes for Windows, now available on the Microsoft Storehigh
malwarebytes
Malwarebytes · malwarebytes-for-windows-now-available-on-the-microsoft-stor
0780b0e3b034d3ac19b40332ad373ce5MD5 HashMalwarebytes for Windows, now available on the Microsoft Storehigh
malwarebytes
Malwarebytes · malwarebytes-for-windows-now-available-on-the-microsoft-stor
560661c9e326c2572caa5fc577ea0f50MD5 HashFake Flash Player installs AtlasRAThigh
malwarebytes
Malwarebytes · fake-flash-player-installs-atlasrat
c0c06675fc5ae2bf42c9c98fb4d30306MD5 HashFake Flash Player installs AtlasRAThigh
malwarebytes
Malwarebytes · fake-flash-player-installs-atlasrat
25dcd887e363c85b043654a9b256cb22MD5 HashFake Flash Player installs AtlasRAThigh
malwarebytes
Malwarebytes · fake-flash-player-installs-atlasrat
f70d520f6d9e682f83d35dd2646edd51MD5 HashFake Fortnite rewards are stealing players' accountshigh
malwarebytes
Malwarebytes · fake-fortnite-rewards-are-stealing-players-accounts
8bea73b7139e89ee423859c1ff49baddMD5 HashFake Fortnite rewards are stealing players' accountshigh
malwarebytes
Malwarebytes · fake-fortnite-rewards-are-stealing-players-accounts
492e1e89a5c737b492e62ebb583c8ab6MD5 HashFake Fortnite rewards are stealing players' accountshigh
malwarebytes
Malwarebytes · fake-fortnite-rewards-are-stealing-players-accounts
61d235ef96970d3e5d2ee96366fd0554MD5 HashA week in security (July 27 - August 2)high
malwarebytes
Malwarebytes · a-week-in-security-july-27-august-2
2.27.160.39IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
2.27.160.151IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
2.26.230.9IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
74a8f72186de5ce2431af79646dc2544MD5 HashA week in security (July 27 - August 2)high
malwarebytes
Malwarebytes · a-week-in-security-july-27-august-2
5c2e0ded6bcb15782cb8618643aeac1fMD5 HashA week in security (July 27 - August 2)high
malwarebytes
Malwarebytes · a-week-in-security-july-27-august-2
b8473eb63f9e5be46795e767e7639ab2MD5 HashCalifornians can tell data brokers to DROP their informationhigh
malwarebytes
Malwarebytes · californians-can-tell-data-brokers-to-drop-their-information
16f4e2bb8b9a9a5d64e45406583d6e42MD5 HashCalifornians can tell data brokers to DROP their informationhigh
malwarebytes
Malwarebytes · californians-can-tell-data-brokers-to-drop-their-information
ba221e4bfe7206771e49111fc2f6b153MD5 HashCalifornians can tell data brokers to DROP their informationhigh
malwarebytes
Malwarebytes · californians-can-tell-data-brokers-to-drop-their-information
http://83.219.1.198:43918/iURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://219.157.244.162:41098/iURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
e38d5a6355aa95eacce40e7771b84869MD5 HashThe AI Act kicks into action, forces companies to be clear about AI chatbotshigh
malwarebytes
Malwarebytes · the-ai-act-kicks-into-action-forces-companies-to-be-clear-ab
http://115.50.91.234:36928/bin.shURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://115.50.91.234:36928/iURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://110.37.106.148:44260/bin.shURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
b1a1155e646bb11466537fb3e730438fMD5 HashThe AI Act kicks into action, forces companies to be clear about AI chatbotshigh
malwarebytes
Malwarebytes · the-ai-act-kicks-into-action-forces-companies-to-be-clear-ab
http://60.23.206.11:46446/iURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/lterouterURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/mipsURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145.ptr.pfcloud.network/n2/mpslURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145.ptr.pfcloud.network/n2/mipsURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145.ptr.pfcloud.network/n2/lterouterURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/mpslURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
267a7fe6e940ceb99b3db15a9a0a7e6fMD5 HashThe AI Act kicks into action, forces companies to be clear about AI chatbotshigh
malwarebytes
Malwarebytes · the-ai-act-kicks-into-action-forces-companies-to-be-clear-ab
http://196.189.35.172:43014/bin.shURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://196.190.133.180:48265/iURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/x86URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/mips64URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/aarch64URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/ppcURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/armv4lURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/armv6lURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/sparcURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
de176b91d39e825ffad35b60c780668dMD5 Hash"Adult TikTok" searches lead to scamshigh
malwarebytes
Malwarebytes · adult-tiktok-searches-lead-to-scams
http://176.65.148.145/n2/sh4URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
7c57bdeb0b874877abc746fed86eb9a6MD5 Hash"Adult TikTok" searches lead to scamshigh
malwarebytes
Malwarebytes · adult-tiktok-searches-lead-to-scams
http://176.65.148.145/n2/m68kURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
ae4c967324fd61965e3e5b15e51c7f1aMD5 Hash"Adult TikTok" searches lead to scamshigh
malwarebytes
Malwarebytes · adult-tiktok-searches-lead-to-scams
http://176.65.148.145/n2/armv5lURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/armv7lURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/x86_64URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145.ptr.pfcloud.network/n2/tbkURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145/n2/tbkURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://196.189.35.172:43014/iURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://94.154.43.238/tURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://94.154.43.123//bot.spcURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://94.154.43.123//bot.mpslURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://217.60.195.187/parm7URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://94.154.43.115/bins/parm64URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://94.154.43.123//bot.arm6URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://94.154.43.123//bot.m68kURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://94.154.43.123//bot.arm5URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
768d82415a5ffdfb6752d109314f6bcbMD5 HashWhatsApp account takeover scam asks you to "vote for my friend"high
malwarebytes
Malwarebytes · whatsapp-account-takeover-scam-asks-you-to-vote-for-my-frien
http://94.154.43.115/bins/parcURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
11d67d2c35c1929d7a5cc0d4e4746256MD5 HashWhatsApp account takeover scam asks you to "vote for my friend"high
malwarebytes
Malwarebytes · whatsapp-account-takeover-scam-asks-you-to-vote-for-my-frien
104.252.127.62IP AddressEmerging Threats compromised-ips entryhigh
taloset-communityblocklist
Emerging Threats compromised-ips
http://193.233.82.82/tURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.149.168.ptr.pfcloud.network/bins/kaizen.mpslURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
635be9dafc3e1406a137ac7b7be0138dMD5 HashWhatsApp account takeover scam asks you to "vote for my friend"high
malwarebytes
Malwarebytes · whatsapp-account-takeover-scam-asks-you-to-vote-for-my-frien
http://72.255.3.147:51931/Mozi.mURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70.ptr.pfcloud.network/389b2eURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70/f19d21URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70/df904cURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145.ptr.pfcloud.network/n2/armv5lURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
7c7057211b26d3ce3ac8bfaa2321e47eMD5 HashOnline backlash ends in Google rolling back Google Earth AI tool after a dayhigh
malwarebytes
Malwarebytes · online-backlash-ends-in-google-rolling-back-google-earth-ai-
http://45.135.194.70/5f5213URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70/316f75URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
b57f741b98538817945f405a9d09c956MD5 HashOnline backlash ends in Google rolling back Google Earth AI tool after a dayhigh
malwarebytes
Malwarebytes · online-backlash-ends-in-google-rolling-back-google-earth-ai-
http://45.135.194.70/003f95URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70/99f292URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70/389b2eURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70/a8f148URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://176.65.148.145.ptr.pfcloud.network/n2/x86URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
aa3dca1fc1dc41180012ad3ba932e374MD5 HashOnline backlash ends in Google rolling back Google Earth AI tool after a dayhigh
malwarebytes
Malwarebytes · online-backlash-ends-in-google-rolling-back-google-earth-ai-
http://94.154.43.123/bins.shURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70.ptr.pfcloud.network/a14f31URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70.ptr.pfcloud.network/a00b40URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70.ptr.pfcloud.network/ca6491URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70.ptr.pfcloud.network/e623fbURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
713577d029bfdb6865521b77d8424ea3MD5 HashTravelers targeted when logging into hotel Wi-Fi networkshigh
malwarebytes
Malwarebytes · travelers-targeted-when-logging-into-hotel-wi-fi-networks
http://45.135.194.70.ptr.pfcloud.network/fbeb13URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70.ptr.pfcloud.network/792865URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70.ptr.pfcloud.network/eab403URLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://45.135.194.70.ptr.pfcloud.network/3f20caURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
057ef5955730e4ed8d03a42fa7f744c2MD5 HashTravelers targeted when logging into hotel Wi-Fi networkshigh
malwarebytes
Malwarebytes · travelers-targeted-when-logging-into-hotel-wi-fi-networks
http://45.135.194.70.ptr.pfcloud.network/968d9dURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://123.8.9.216:53523/bin.shURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://59.96.137.157:36091/iURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://27.215.121.130:42924/iURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://123.8.9.216:53523/iURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://175.165.132.16:50966/iURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://222.137.144.217:41848/bin.shURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
56e9e7ca636e69bbaf93e533c6ff9023MD5 HashTravelers targeted when logging into hotel Wi-Fi networkshigh
malwarebytes
Malwarebytes · travelers-targeted-when-logging-into-hotel-wi-fi-networks
http://182.124.127.129:37266/iURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
http://119.186.204.22:51908/bin.shURLmalware_downloadhigh
urlhausabuse.chmalicious-urlthreat:malware_download
URLhaus
68.220.57.96IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
68.183.69.247IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
68.183.40.92IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
68.183.223.149IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
68.183.15.228IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.255.65IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.255.240IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.244.64IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.223.50IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.219.143IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.206.213IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army
64.23.206.186IP AddressCINS Army bad-actor IPhigh
cins-armysentinel-ipsattacker-ip
CINS Army

Sign in as admin to add or delete indicators.

Live · Timely Threat Intel

Latest published intelligence

Fresh reports and adversary research — updated continuously by the NivX intel team.

View full source
Community Signals

Threat intel blog & writeups

DFIR, malware analysis, SOC playbooks and breaking security news curated live by NivX analysts — refreshed every 30 minutes. Click any card to jump straight to the full report.

Made with Emergent