MB-e7f82fbead8a3685fafd387f6fe8bcd7287d31ebdbba4406d2ec1b14022fa03e |
Mirai: bot.i386 |
high |
Mirai |
1 |
10 |
|
|
|
MB-91f97671a17da7b82dbb1ce3065edfdf1afa1e3db8e612311a4034fb5d5cd204 |
Mirai: 91f97671a17da7b82dbb1ce3065edfdf1afa1e3db8e612311a4034fb5d5cd204 |
high |
Mirai |
1 |
10 |
|
|
|
TF-1932716 |
Unknown malware: Domain name that delivers a malware payload ai.lzgqin.cc.cd |
high |
Unknown malware |
3 |
10 |
|
|
|
TF-1932726 |
ACR Stealer: Domain that is used for botnet Command&control (C&C) wss.scriptlab.cc |
high |
ACR Stealer |
3 |
10 |
|
|
|
TF-1932725 |
ClearFake: Domain name that delivers a malware payload ttabqw6x.tickett.bet |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932724 |
ACR Stealer: Domain that is used for botnet Command&control (C&C) sso.activeloop.cc |
high |
ACR Stealer |
3 |
10 |
|
|
|
TF-1932723 |
AsyncRAT: Domain that is used for botnet Command&control (C&C) qaqfahai.com |
high |
AsyncRAT |
3 |
10 |
|
|
|
TF-1932722 |
ClearFake: Domain name that delivers a malware payload tickett.bet |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932721 |
IClickFix: Domain name that delivers a malware payload winter-finch-slaibteis.life |
high |
IClickFix |
2 |
10 |
|
|
|
TF-1932720 |
AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 103.48.84.225:443 |
high |
AsyncRAT |
2 |
10 |
|
|
|
TF-1932719 |
AdaptixC2: ip:port combination that is used for botnet Command&control (C&C) 139.180.213.153:8080 |
high |
AdaptixC2 |
2 |
9 |
|
|
|
TF-1932718 |
AdaptixC2: ip:port combination that is used for botnet Command&control (C&C) 139.180.213.153:80 |
high |
AdaptixC2 |
2 |
8 |
|
|
|
TF-1932717 |
ClearFake: Domain name that delivers a malware payload 2ulyzvrm.professionalsports.ir |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932715 |
ClearFake: Domain name that delivers a malware payload professionalsports.ir |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932714 |
Unknown malware: URL that delivers a malware payload https://www.armoniamiddleeast.ae/ChromeSetup.exe |
high |
Unknown malware |
3 |
10 |
|
|
|
TF-1932713 |
Unknown malware: ip:port combination that is used for botnet Command&control (C&C) 31.169.125.79:46543 |
high |
Unknown malware |
2 |
9 |
|
|
|
TF-1932712 |
ClearFake: Domain name that delivers a malware payload thehealystrategy.com |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932711 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 191.124.5.229:8443 |
high |
Cobalt Strike |
2 |
10 |
|
|
|
TF-1932710 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 47.109.48.152:443 |
high |
Cobalt Strike |
2 |
0 |
|
|
|
TF-1932709 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 210.16.168.11:9999 |
high |
Cobalt Strike |
2 |
6 |
|
|
|
TF-1932708 |
ClearFake: Domain name that delivers a malware payload teknoartia.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-95864 |
Themify Builder <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via 'css[fonts]' Parameter |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-89426 |
Knit Pay <= 9.6.1.0 - Authenticated (Subscriber+) Privilege Escalation via Gravity Forms Role Field |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-94573 |
Repeater Fields for Elementor Forms <= 2.2.7 - Unauthenticated Stored Cross-Site Scripting via Repeater Field Value |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-19804 |
s2Member <= 260814 - Unauthenticated Remote Code Execution via 'first_name' Parameter in PayPal Proxy Return |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-84280 |
Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-89406 |
Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-93901 |
Optima Express IDX <= 8.7.5 - Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role Assignment |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-95866 |
User Profile Builder <= 4.0.2 - Unauthenticated Stored Cross-Site Scripting via Avatar Field |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-96568 |
Restaurant Menu and Food Ordering <= 2.4.14 - Unauthenticated Stored Cross-Site Scripting via 'phone_number' Parameter |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-13456 |
WP Maps <= 4.9.8 - Authenticated (Subscriber+) Local File Inclusion via 'page' Parameter |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-93654 |
Premium Packages <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-92713 |
Modula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-96752 |
Zero Spam for WordPress <= 5.7.10 - Unauthenticated Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration |
high |
cve |
0 |
0 |
|
|
|
TF-1932707 |
ClearFake: Domain name that delivers a malware payload 2ah1xj15.bet-303.fun |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932706 |
ClearFake: Domain name that delivers a malware payload tc-autoparts.com |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932705 |
ClearFake: Domain name that delivers a malware payload taraf303.com |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1932704 |
Remus: URL that is used for botnet Command&control (C&C) http://vgfeden.shop:7728/webhooks |
high |
Remus |
2 |
10 |
|
|
|
TF-1932703 |
Remus: URL that is used for botnet Command&control (C&C) http://jxewele.shop:4262/contacts |
high |
Remus |
2 |
10 |
|
|
|
TF-1932702 |
Remus: URL that is used for botnet Command&control (C&C) http://novxlse.click:9820/addresses |
high |
Remus |
2 |
10 |
|
|
|
OTX-6ab61e2ec525754334a6ed2d |
Major vulnerability found in ancient TACACS+ networking protocol |
info |
Salt Typhoon, Fire Ant |
2 |
8 |
|
|
|
TF-1932701 |
AdaptixC2: ip:port combination that is used for botnet Command&control (C&C) 139.180.213.153:443 |
high |
AdaptixC2 |
2 |
10 |
|
|
|
TF-1932700 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 156.254.20.48:3622 |
high |
Cobalt Strike |
2 |
6 |
|
|
|
TF-1932699 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 156.254.20.48:888 |
high |
Cobalt Strike |
2 |
7 |
|
|
|
TF-1932698 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 1.12.59.176:8006 |
high |
Cobalt Strike |
2 |
5 |
|
|
|
TF-1932697 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 23.27.143.19:22 |
high |
Cobalt Strike |
2 |
5 |
|
|
|
TF-1932696 |
Quasar RAT: ip:port combination that is used for botnet Command&control (C&C) 85.137.56.145:4782 |
high |
Quasar RAT |
2 |
3 |
|
|
|
TF-1932695 |
Remus: URL that is used for botnet Command&control (C&C) http://urbandm.click:4812/sessions |
high |
Remus |
2 |
8 |
|
|
|
TF-1932694 |
php.shin_webshell: Domain that is used for botnet Command&control (C&C) xegyfelo.workers.dev |
medium |
php.shin_webshell |
2 |
8 |
|
|
|
MB-dea10c923a8be49062bb4a58c23bd55a19bf603da1661f8df50b5d7150a0a03d |
Mirai: aarch64 |
high |
Mirai |
1 |
10 |
|
|
|