Skip to content
Latest
AI-Assisted Exploits Make OT Reachability the Real ControlWhite-Label Router Backdoors Show Why Edge Provenance MattersPaperCut Zero-Day Exploitation Shows Why Print Servers Need Edge-Asset DisciplineAI Infrastructure Is Becoming a Control Plane Attack SurfaceQScan and QTRouter Show Why Proxy Infrastructure Is an Espionage Force MultipliervCenter Exploitation Shows Patching Alone Is Not Incident ResponseEdge Infrastructure Convergence Shows Why Perimeter Devices Need Their Own Patch SLAsSigned ClickOnce Lures Show Why Hiring Workflows Need Endpoint GuardrailsShieldBreak Shows Why Endpoint Protection Needs Compensating ControlsAI-Enabled Malware Still Behaves Like MalwarePrivate APNs Are Becoming OT Attack PathsvCenter Exploitation Shows Why Control Planes Need ContainmentApollo Breach Shows Why Helpdesk Vishing Is a Cloud-Control ProblemBTR.sys Shows Why Trusted Security Drivers Need Behavioral Monitoring

Threat Intelligence · Historical Research

IOC Archive

Historical article-derived observables that no longer fall inside the current reporting-recency window for their type. Provider-supported values enter only after the applicable enabled services complete the required boundary check without qualifying positive evidence. They remain available for research, pivots, and attribution review. Archived does not mean clean, benign, remediated, resolved, or safe. This archive is not a blocklist.

Reporting-window dates come from Bulwark Black report publication dates, not provider sightings. IP/CIDR observations use 14 days, domains and URLs 30 days, file identifiers 730 days, and other context 90 days. Types without an applicable exact provider check archive by recency alone. Current verified-feed admission is evaluated separately on each IOC Passport and in the machine-readable feeds.

458 archived unique observations

58 archived observations on this page

Showing 401–458 of 458

Mutex Names

Mutex: Global\3a886eb8-fe40-4d0a-b78b-9e0bcb683fb7

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Bitcoin Addresses

3712793d3847dd0962361aa528fa124c

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-6218

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2021-44515

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2024-37079

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-22224

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-22225

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-22226

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-41244

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Ethereum Addresses

0xd67f158b2bcc819eee7029f3477f0270ec1d37b4

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Monero Addresses

87YLCx7zEFghgMEeZvJCZ3gHyS3fUsbAnXSTH8nh8EP7SeptPH8Pnh18snravwhE3dfRt5x67aWo8e6tSJ2cv4mpRNkSdqL

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Monero Addresses

88H9UmU6QyYiGeZdR6hXZJXtJF9Z8zLHDQbC1NV1PDdjCynBq3QKzB1fo1NRhgMX4cBx68Rva5msyKW3PGXfPhCA4itHmiv

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2024-7587

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2023-38831

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2026-24061

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Bitcoin Addresses

15bdc66aca9fb7290165d460e6a993a9

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2026-23760

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2026-24423

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2026-25067

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2024-28986

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2024-28987

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2024-28988

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-26399

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-40536

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-40537

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-40551

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-40552

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-40553

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2025-40554

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Bitcoin Addresses

31d58c226fc5a0aa976e13ca9ecebcc8

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Bitcoin Addresses

3k7m1n9p4q2r6s8t0v5w2x4y6z8u9

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Email Addresses

cloud-init@mail[.]io

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Email Addresses

cloud-noc@mail[.]io

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2020-16040

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2023-48788

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2024-2169

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2017-12542

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2017-5689

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

JARM

07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Bitcoin Addresses

364d4fdf430477222fe854b3cd5b6d40

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2022-0185

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2022-3052

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2023-22518

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2024-1709

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Bitcoin Addresses

34603862c5086a9063e42d79fb094e8d8

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Bitcoin Addresses

3d6238e465d07a71cadfe89877df6ac

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2023-33246

Last reported · Reporting window ended · Context-only recency placement · 2 source reports

IOC Passport →

CVE

CVE-2023-38646

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2023-50164

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2023-51467

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2021-43890

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2024-21412

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CIDR

175[.]45[.]176[.]0/22

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CIDR

210[.]214[.]0[.]0/16

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CIDR

210[.]52[.]109[.]0/24

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CIDR

77[.]94[.]35[.]0/24

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

CVE

CVE-2023-37582

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Bitcoin Addresses

30851d4a2b31e9699084a06e765e21b0

Last reported · Reporting window ended · Context-only recency placement · 1 source report

Source report →

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.