Skip to content
Latest
Dropcatch Domains Show Why Reputation Is Not TrustCaptiveCrunch Shows Why Travel Wi-Fi Is an Identity Attack SurfaceHoneyMyte’s CoolClient Rootkit Shows Why Kernel Visibility MattersJWR Phishing Framework Shows Why MFA Codes Are Now Live TargetsEvooo1Bot Shows Why Exposed Linux and Edge Devices Are Still High-Value TargetsMalware Crypting Services Show Why Behavioral Detection MattersPrivate Wireless Utility Networks Are Becoming OT Attack PathsKong Mesh Vulnerabilities Show Why Service Mesh Security Needs Control-Plane DisciplineGunra Ransomware Shows Why VPN Compromise Is an Incident, Not a Patch TicketCI Fortify Shows Why OT Isolation Must Be Engineered Before the IncidentLazarus Dream Job Campaign Turns Fake Recruiting Into a Windows Zero-Day IntrusionDeno Runtime Abuse Shows Why Developer Tooling Needs Security GovernanceAeternum Shows Why Blockchain-Based C2 Is a Practical Defense ProblemDeadLock Ransomware Shows Why Recovery Infrastructure Is Part of the Attack Surface

Indicator of Compromise

sharepoint[.]com

Domain Seen in 2 reports Watch this →

A domain observed in malicious infrastructure. Block or monitor it in DNS and web proxies. Shown defanged for safe viewing; use Copy live value for the functional form.

Included in the Domains feed (live, machine-readable).

Related indicators

Indicators that appear alongside this one in the same reporting, often shared infrastructure or the same campaign.

06b4aebbc3cd62e0aadd1852102645f9a00cc7eea492c0939675efba7566a6de11b71429869f29122236a44a292fde3f0269cde8eb76a52c89139f79f4b97e631204knos[.]ru1204networks[.]ru2ba527fb8e31cb209df8d1890a63cda9cd4433aa0b841ed8b86fa801aff4ccbd2ed5660c7b768b4c2a7899d00773af60cd4396f24a2f7d643ccc1bf74a40397044cac5bf0bab56b0840bd1c7b95f9c7f5078ff417705eeaaf5ea5a2167a81dd548aa2393ef590bab4ff2fd1e7d95af36e5b6911348d7674347626c9aaafa255e7e646dfe7b7f330cb21db07b94f611eb39f604fab36e347fb884f797ba462402abobe[.]ithr[.]orgaka[.]msamgreetings[.]techamgreetings[.]tech-department[.]usamydeks[.]ithr[.]orgapi[.]storeb79633917e51da2a4401473d08719f493d61fd64a1b10fe482c12d984d791ccbcabotcorpsupport-my[.]sharepoint[.]comcbre[.]techcbre[.]tech-department[.]usclear90489058903-document[.]workers[.]devCVE-2021-43890 CVE-2025-20333 CVE-2025-20362 CVE-2026-20182 dashboard-bl[.]pamconj[.]comffb45dc14ea908b21e01e87ec18725dff560c093884005c2b71277e2de354866formeld[.]techformeld[.]tech-department[.]usgertefin[.]comhxxps://aka[.]ms/threatintelbloghxxps://mononapfp[.]sharepoint[.]com/:f:/document/INV-IgCx1X50pgUjR7iAjZL2fuQaAW4GfKVs6wHT3BYv9sgwW7g”hxxps://mononapfpcom[.]sharepoint[.]com/:f:/g/IgAdH_aaBPMcQbtINZzC1TsLARj3dHj63MnKjvnY-QJrKEchxxps://scheta[.]site/api[.]store/Setup[.]msixhxxps://scheta[.]site/api[.]store/ZoomInstaller[.]msixhxxps://thecyberwire[.]com/podcasts/microsoft-threat-intelligencehubergroup[.]techhubergroup[.]tech-department[.]usinfo-zoomapp[.]comithr[.]orgkellyhrservices-my[.]sharepoint[.]com

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.