Skip to content
Latest
Project ORBITAL Maps the Edge-Device Relay Networks Hiding APT TrafficCISA OT Advisories Show How Trusted Monitoring and Physical-Security Systems Can Become Attack PathsGolden Chickens Shows Browser Sessions Are the New Malware PrizeCl0p’s Windchill Campaign Shows Why Engineering Data Is Extortion SurfaceOrigin Energy Breach Shows Why Customer Data Is Critical-Infrastructure Attack SurfaceJADEPUFFER Shows How Autonomous Ransomware Turns Old Exposure Into Fast ImpactIranian PLC Exploitation Shows Why OT Remote Access Is Now a Board-Level RiskFakeAgent Shows Why Trusted AI Brands Are Now Malware Delivery InfrastructureJadeProx Shows Why China-Nexus Intrusions Still Start With Basic ExposureAPT34 Shows Why Identity Infrastructure Is Iran’s Quietest Attack PathAI Malware Analysis Agents Need Human-Led Quality GatesTrickBot DNS Tunneling Shows Why DNS Is a Malware Control PlaneBitLocker Extortion Shows Why Misconfiguration Is Still Ransomware’s ShortcutProject CAV3RN Turns Outlook Calendars and DNS Into Covert C2

Indicator of Compromise

redcanary[.]com

Domain Seen in 2 reports Watch this →

A domain observed in malicious infrastructure. Block or monitor it in DNS and web proxies. Shown defanged for safe viewing; use Copy live value for the functional form.

Included in the Domains feed (live, machine-readable).

Related indicators

Indicators that appear alongside this one in the same reporting, often shared infrastructure or the same campaign.

Booking[.]com CVE-2022-30190 decoded[.]avast[.]io hxxps://decoded[.]avast[.]io/janvojtesek/raspberry-robins-roshtyak-a-little-lesson-in-trickery/hxxps://redcanary[.]com/blog/raspberry-robinhxxps://securityintelligence[.]com/posts/raspberry-robin-worm-dridex-malware/ securityintelligence[.]com CVE-2020-1472 hxxps://ico[.]org[.]uk/media2/xdrfahsw/south-staffordshire-plc-and-south-staffordshire-water-plc-monetary-penalty-notice[.]pdfhxxps://malpedia[.]caad[.]fkie[.]fraunhofer[.]de/details/win[.]clophxxps://malpedia[.]caad[.]fkie[.]fraunhofer[.]de/details/win[.]get2hxxps://malpedia[.]caad[.]fkie[.]fraunhofer[.]de/details/win[.]sdbbothxxps://www[.]ransomware[.]live/group/clopico[.]orgico[.]org[.]uk malpedia[.]caad[.]fkie[.]fraunhofer[.]de www[.]ransomware[.]live