Skip to content
Latest
Aeternum Shows Why Blockchain-Based C2 Is a Practical Defense ProblemDeadLock Ransomware Shows Why Recovery Infrastructure Is Part of the Attack SurfaceUNC6671 Shows Why Helpdesk Vishing Is a Cloud Data-Theft ProblemVeloCloud Orchestrator RCE Shows Why SD-WAN Controllers Need Incident ResponseMSI Router Command-Injection Cluster Shows Why Edge Devices Need Exposure ControlJuly CVE Data Shows Why Patch Priority Needs Threat ContextExfilSquad Shows Why CRM and Portal Data Need Extortion-Ready ControlsBdThemes Compromise Shows Why WordPress Plugin Risk Extends Beyond Code UpdatesCloudflare workerd Bugs Show Why Agent Sandboxes Need Real Defense-in-DepthLangflow RCE Shows Why AI Workflow Tools Need Cloud-Grade IsolationBINDCLOAK Shows Why C2 Detection Needs Message-Level VisibilityPasskey Attacks Show Why Passwordless Still Needs Endpoint DefenseDPRK npm Compromises Show Why Dependency Trust Is Now Identity RiskN-able N-central Exploitation Shows Why MSP Tools Are Control-Plane Risk

Indicator of Compromise

Hunt[.]io

Domain Seen in 2 reports Watch this →

A domain observed in malicious infrastructure. Block or monitor it in DNS and web proxies. Shown defanged for safe viewing; use Copy live value for the functional form.

Included in the Domains feed (live, machine-readable).

Related indicators

Indicators that appear alongside this one in the same reporting, often shared infrastructure or the same campaign.

0f8c905aa25c86f85454acb7e77bf5c50220c2a82e5b69a33741e55c8a85f2fc103[.]97[.]0[.]57118[.]107[.]222[.]232131[.]0[.]0[.]0202[.]181[.]27[.]1152A4CB412EFA93FED7C3B3B3E49D6247B11A95CE9FDDF71D9FE9DB8E5F0068E0D43[.]246[.]208[.]2075633BC0033FDE3AAD929D6CBD47C554E264180360B017AAE04687C2D6D83F753576C70E12BE8B2E8E7C35A5FEB082E90621989ADCE8E64400126918D37F13E4958338A93FEE4E008EA28E459C4D1598313D1524763AB13894AB63BF2BEC4302A9FF4B6D3B7DBB023BAD65D2538ADE745D46B763E5A12116C9C83AA2F6F5D96AAa182e35da64e6d71cb55f125c4d4225196523f14a9447ae174f4aa54f760b7d7cc985c1a970f31e151d3ff66fac247f99ba1b509b65b7ede835ebba36294d52d7780065523340ee09bb8b209ef2dc495e53dfd53cdn[.]jsdelivr[.]net CVE-2017-7269 CVE-2021-3156 CVE-2021-4034 CVE-2021-44515 CVE-2026-31431 CVE-2026-43284 CVE-2026-43500 CVE-2026-43503d252ee7b348b7e43e432d8fb154465838f5cd5fb564905323460e6f0a0c7d1e2d5dbb3783b4_7d5dbb3783b4_e1926048963fDBBB8A11A239DA11CBAF99F847A2D032F34D3B522E13B0FD4EF7B2649DA7123Bdnsrd[.]comec7e9ab43a0cc65d29f0b84a93ba88c43d01fed3dec5c968525dc73c03cbfda2FF662B60F6A142F99292FBDD65DD1CCD79DC9628686DDF5935C92F7FB1B62A81hxxps://malpedia[.]caad[.]fkie[.]fraunhofer[.]de/details/win[.]shadowpad&quotjava[.]iomail4[.]pl malpedia[.]caad[.]fkie[.]fraunhofer[.]de redhatupdating432[.]dnsrd[.]com

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.