Skip to content
Latest
Malware Crypting Services Show Why Behavioral Detection MattersPrivate Wireless Utility Networks Are Becoming OT Attack PathsKong Mesh Vulnerabilities Show Why Service Mesh Security Needs Control-Plane DisciplineGunra Ransomware Shows Why VPN Compromise Is an Incident, Not a Patch TicketCI Fortify Shows Why OT Isolation Must Be Engineered Before the IncidentLazarus Dream Job Campaign Turns Fake Recruiting Into a Windows Zero-Day IntrusionDeno Runtime Abuse Shows Why Developer Tooling Needs Security GovernanceAeternum Shows Why Blockchain-Based C2 Is a Practical Defense ProblemDeadLock Ransomware Shows Why Recovery Infrastructure Is Part of the Attack SurfaceUNC6671 Shows Why Helpdesk Vishing Is a Cloud Data-Theft ProblemVeloCloud Orchestrator RCE Shows Why SD-WAN Controllers Need Incident ResponseMSI Router Command-Injection Cluster Shows Why Edge Devices Need Exposure ControlJuly CVE Data Shows Why Patch Priority Needs Threat ContextExfilSquad Shows Why CRM and Portal Data Need Extortion-Ready Controls

Indicator of Compromise

claude[.]ai

Domain Seen in 7 reports Watch this →

A domain observed in malicious infrastructure. Block or monitor it in DNS and web proxies. Shown defanged for safe viewing; use Copy live value for the functional form.

Included in the Domains feed (live, machine-readable).

Related indicators

Indicators that appear alongside this one in the same reporting, often shared infrastructure or the same campaign.

0434437a073a3f3a49e84d5ecb20c99dd551bacc32bf100fbb8cf67a5064218113[.]227[.]180[.]415de71073f44c657c23f5f97caa11f1b12e654d4d17684bfc628cc1e5b6bcdd5193[.]143[.]1[.]1041bd605ef84b6767df74bd6290f1468eed5a88264df23fcf70b6a75d5bdcf7d762050468744e44554fac17fb83f1515c95f2f2236716e2b5267a81c2b94205e6a213[.]165[.]51[.]1152abe0ef88ba92db79d82cde4c0ed1f382bb347517a54ea82084c841d0f95551834[.]34[.]57[.]14134[.]34[.]81[.]12935[.]192[.]41[.]2014264a88035aa0b63e9aef96daa78a58114d60a344ea10168a8ef5ef36bf8edbd433a13cc70396f80dc29d1150c050339d78964fdc91bcdc3f40c67a77add1476449f528f5ceae8c3f8336d0d8e3e3ec9031d1ad67c31ee7311b67e01d5fdf22545[.]59[.]160[.]19945[.]93[.]20[.]19545[.]93[.]20[.]614e90d386c1c7d3d1fd4176975795a2f432d95685690778e09313b4a1dbab9997576692df4bf1c7d8927d3a183f5219a81c3bff3dd22971691f8af6889f80c5a07f2315b89fb9a47e1516def136844d617bfcdce19000a1b0436706692dbe166cadrinal[.]comaefd15e3c395edd16ede7685c6e97ca0350a702ee7c8585274b457166e86b1faarchicad3d[.]comatlassian[.]netbarankinyserialxud[.]onlinebest-tinted[.]combest-tinted[.]com/github-download[.]htmlbotshield[.]vubotshield[.]vu/kFcjldbotshield[.]vu/KKRkm9brw[.]soc40b9913e79c5dd09751b1afb03aaa98658bab61bacf27a299abd84fd44fe707 CVE-2026-21509 CVE-2026-21513 d295720bc0c1111ce1c3d8b1bc1b36ba840f103b3ca7e95a5a8bf03e2cc44fe5dropbox[.]comed1745cc49b929e499966d87e163219fe0f24069fe88dfacbd69c0ebab85a640egest[.]filen[.]iofa767391b99865f8533efc1fe6dfa6175215718679fb00ca85fc13c3bd4ae4b7fe4e5fb28d2c2b3a640112b6b125ce8c4afa8be28342e3bfda097ad9dd2ef9ee

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.