s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

Threats

233213 threats catalogued · filter, sort and triage below.

All Threats · 233213 TOTAL
Reset
ID ↕ Title ↕ Severity ↕ Category ↕ RefsRemediations Published ↕ Source updated ↕ APEX Update Time ↕
MB-e7f82fbead8a3685fafd387f6fe8bcd7287d31ebdbba4406d2ec1b14022fa03e Mirai: bot.i386 high Mirai 1 10
MB-91f97671a17da7b82dbb1ce3065edfdf1afa1e3db8e612311a4034fb5d5cd204 Mirai: 91f97671a17da7b82dbb1ce3065edfdf1afa1e3db8e612311a4034fb5d5cd204 high Mirai 1 10
TF-1932716 Unknown malware: Domain name that delivers a malware payload ai.lzgqin.cc.cd high Unknown malware 3 10
TF-1932726 ACR Stealer: Domain that is used for botnet Command&control (C&C) wss.scriptlab.cc high ACR Stealer 3 10
TF-1932725 ClearFake: Domain name that delivers a malware payload ttabqw6x.tickett.bet high ClearFake 2 10
TF-1932724 ACR Stealer: Domain that is used for botnet Command&control (C&C) sso.activeloop.cc high ACR Stealer 3 10
TF-1932723 AsyncRAT: Domain that is used for botnet Command&control (C&C) qaqfahai.com high AsyncRAT 3 10
TF-1932722 ClearFake: Domain name that delivers a malware payload tickett.bet high ClearFake 2 10
TF-1932721 IClickFix: Domain name that delivers a malware payload winter-finch-slaibteis.life high IClickFix 2 10
TF-1932720 AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 103.48.84.225:443 high AsyncRAT 2 10
TF-1932719 AdaptixC2: ip:port combination that is used for botnet Command&control (C&C) 139.180.213.153:8080 high AdaptixC2 2 9
TF-1932718 AdaptixC2: ip:port combination that is used for botnet Command&control (C&C) 139.180.213.153:80 high AdaptixC2 2 8
TF-1932717 ClearFake: Domain name that delivers a malware payload 2ulyzvrm.professionalsports.ir high ClearFake 2 10
TF-1932715 ClearFake: Domain name that delivers a malware payload professionalsports.ir high ClearFake 2 10
TF-1932714 Unknown malware: URL that delivers a malware payload https://www.armoniamiddleeast.ae/ChromeSetup.exe high Unknown malware 3 10
TF-1932713 Unknown malware: ip:port combination that is used for botnet Command&control (C&C) 31.169.125.79:46543 high Unknown malware 2 9
TF-1932712 ClearFake: Domain name that delivers a malware payload thehealystrategy.com high ClearFake 2 10
TF-1932711 Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 191.124.5.229:8443 high Cobalt Strike 2 10
TF-1932710 Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 47.109.48.152:443 high Cobalt Strike 2 0
TF-1932709 Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 210.16.168.11:9999 high Cobalt Strike 2 6
TF-1932708 ClearFake: Domain name that delivers a malware payload teknoartia.com high ClearFake 2 10
CVE-2026-95864 Themify Builder <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via 'css[fonts]' Parameter high cve 0 0
CVE-2026-89426 Knit Pay <= 9.6.1.0 - Authenticated (Subscriber+) Privilege Escalation via Gravity Forms Role Field high cve 0 0
CVE-2026-94573 Repeater Fields for Elementor Forms <= 2.2.7 - Unauthenticated Stored Cross-Site Scripting via Repeater Field Value high cve 0 0
CVE-2026-19804 s2Member <= 260814 - Unauthenticated Remote Code Execution via 'first_name' Parameter in PayPal Proxy Return high cve 0 0
CVE-2026-84280 Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter high cve 0 0
CVE-2026-89406 Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters high cve 0 0
CVE-2026-93901 Optima Express IDX <= 8.7.5 - Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role Assignment high cve 0 0
CVE-2026-95866 User Profile Builder <= 4.0.2 - Unauthenticated Stored Cross-Site Scripting via Avatar Field high cve 0 0
CVE-2026-96568 Restaurant Menu and Food Ordering <= 2.4.14 - Unauthenticated Stored Cross-Site Scripting via 'phone_number' Parameter high cve 0 0
CVE-2026-13456 WP Maps <= 4.9.8 - Authenticated (Subscriber+) Local File Inclusion via 'page' Parameter high cve 0 0
CVE-2026-93654 Premium Packages <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter high cve 0 0
CVE-2026-92713 Modula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter high cve 0 0
CVE-2026-96752 Zero Spam for WordPress <= 5.7.10 - Unauthenticated Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration high cve 0 0
TF-1932707 ClearFake: Domain name that delivers a malware payload 2ah1xj15.bet-303.fun high ClearFake 2 10
TF-1932706 ClearFake: Domain name that delivers a malware payload tc-autoparts.com high ClearFake 2 10
TF-1932705 ClearFake: Domain name that delivers a malware payload taraf303.com high ClearFake 2 10
TF-1932704 Remus: URL that is used for botnet Command&control (C&C) http://vgfeden.shop:7728/webhooks high Remus 2 10
TF-1932703 Remus: URL that is used for botnet Command&control (C&C) http://jxewele.shop:4262/contacts high Remus 2 10
TF-1932702 Remus: URL that is used for botnet Command&control (C&C) http://novxlse.click:9820/addresses high Remus 2 10
OTX-6ab61e2ec525754334a6ed2d Major vulnerability found in ancient TACACS+ networking protocol info Salt Typhoon, Fire Ant 2 8
TF-1932701 AdaptixC2: ip:port combination that is used for botnet Command&control (C&C) 139.180.213.153:443 high AdaptixC2 2 10
TF-1932700 Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 156.254.20.48:3622 high Cobalt Strike 2 6
TF-1932699 Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 156.254.20.48:888 high Cobalt Strike 2 7
TF-1932698 Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 1.12.59.176:8006 high Cobalt Strike 2 5
TF-1932697 Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 23.27.143.19:22 high Cobalt Strike 2 5
TF-1932696 Quasar RAT: ip:port combination that is used for botnet Command&control (C&C) 85.137.56.145:4782 high Quasar RAT 2 3
TF-1932695 Remus: URL that is used for botnet Command&control (C&C) http://urbandm.click:4812/sessions high Remus 2 8
TF-1932694 php.shin_webshell: Domain that is used for botnet Command&control (C&C) xegyfelo.workers.dev medium php.shin_webshell 2 8
MB-dea10c923a8be49062bb4a58c23bd55a19bf603da1661f8df50b5d7150a0a03d Mirai: aarch64 high Mirai 1 10
Showing 1301–1350 of 233213 threats (page 27 of 4665).