Skip to content
Latest
DragonForce TURN and MQTT Backdoors Show Why Ransomware Defense Needs Egress VisibilityTA419 Shows AI Policy Is Now an Espionage Phishing TargetAI Is Turning Vulnerability Triage Into a Threat-Intel Problem2CLoader Shows Why Malware Loader Alerts Need Identity ResponseZimbra CVE-2026-73570 Shows Mail Servers Need Full Incident ReviewRMM Phishing Turns Trusted Admin Tools Into Persistent AccessApache MINA SSHD Auth Bypasses Show Why Embedded SSH Needs InventoryCustom GPT ClickFix Shows Why AI Trust Needs Browser-to-Shell ControlsNetScaler Zero-Days Show Why Edge Devices Need Incident Response, Not Just PatchingNeedyMantis Shows Why Post-Compromise Malware Needs Full Intrusion ReviewPython MaaS Infostealer Builder Shows Why Credential Theft Needs Behavior ControlsTEST DO NOT PUBLISHMacSync Shows Why macOS Stealers Need Full Endpoint ResponseNetScaler KEV RCEs Show Why Edge Devices Need Emergency Playbooks

IOC Passport

aka[.]ms

DomainArticle-derived observationCurrent reporting windowReported in 2 articlesWatch this →

A domain extracted from published reporting. It may be infrastructure, a cited service, or a candidate indicator; check current feed admission before blocking. Shown defanged for safe viewing; use Copy live value for the functional form.

This value remains inside its 30-day domain/URL reporting window. Current reporting status is separate from verified-feed admission. Archive-cleared or archived does not mean clean, inactive, benign, remediated, resolved, or safe, and this lifecycle does not change current verified-feed admission.

Current verified-feed status

Checking live guard…

Article reporting and current malicious-feed admission are evaluated separately.

First reported
Last reported
Article count
2
Admission policy
bulwark-exact-malicious-v2
Research lifecycle
Current

Article reporting history

These dates are report publication dates, not provider sightings or proof of malicious activity.

Related indicators

Observables that appear alongside this one in the same reporting. Co-occurrence can suggest shared infrastructure, but it does not establish common ownership, campaign identity, or actor attribution.

06b4aebbc3cd62e0aadd1852102645f9a00cc7eea492c0939675efba7566a6de0x25bdA7Feb3553995AD68a9A8Ed8c731b73a71586117[.]107[.]25[.]243:707111b71429869f29122236a44a292fde3f0269cde8eb76a52c89139f79f4b97e631204knos[.]ru1204networks[.]ru192[.]255[.]193[.]111:9004193[.]42[.]40[.]135:44322ef852f6ebc39ee71235b90648b4b200b385c47d25c79545986493f8c70db692ba527fb8e31cb209df8d1890a63cda9cd4433aa0b841ed8b86fa801aff4ccbd2ed5660c7b768b4c2a7899d00773af60cd4396f24a2f7d643ccc1bf74a4039703[.]209[.]137[.]175:44344cac5bf0bab56b0840bd1c7b95f9c7f5078ff417705eeaaf5ea5a2167a81dd545[.]32[.]30[.]235:808045[.]32[.]30[.]235:808148aa2393ef590bab4ff2fd1e7d95af36e5b6911348d7674347626c9aaafa255e518fe65dd349180191d9b258ab24876aaed6613cd657d0b626d1fc24e03a22b665a7576c389326b6cdf9c993d0be6e5d50fed9655d1cdf2a3a50f2c21c8ec4356ab7de2509038edf580aef6229c1c3db17f4da8f2d7d940818faf617d19382447e646dfe7b7f330cb21db07b94f611eb39f604fab36e347fb884f797ba462402abobe[.]ithr[.]orgaea991f694911e321b0ab97534f2ad0291c392c0a43dabff664c563618bd036damgreetings[.]techamgreetings[.]tech-department[.]usamydeks[.]ithr[.]orgapi[.]storeb594a42b8f1c6f090327bb9a3361c2d3515537fb7ac8da6b9061b9a3f330e159b79633917e51da2a4401473d08719f493d61fd64a1b10fe482c12d984d791ccbbf28f38122bf20d5fac969cc414daa6a890cdea872d389ca93d2092b6b7773cfbypass[.]eu[.]orgcabotcorpsupport-my[.]sharepoint[.]comcbre[.]techcbre[.]tech-department[.]usCVE-2021-43890CVE-2026-73570dee5af1c0f76b45d28bafd6e60c07bb8e391d98addf81ef8f13d073acdb3c48adnslog[.]pp[.]uaffb45dc14ea908b21e01e87ec18725dff560c093884005c2b71277e2de354866formeld[.]techformeld[.]tech-department[.]us

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.