projecthoneypot.org |
DOMAIN |
IP Blocklists |
— |
16 |
56 |
|
2026-08-06 |
Abuse.ch |
DOMAIN |
IP Blocklists |
— |
22 |
39 |
|
2026-08-06 |
http://iplists.firehol.org/ |
URL |
IP Blocklists |
auto-tagged, medium-severity, url |
15 |
35 |
|
2026-08-06 |
http://www.projecthoneypot.org/ |
URL |
IP Blocklists |
— |
16 |
28 |
|
2026-08-06 |
http://www.projecthoneypot.org/?rf=192670) |
URL |
IP Blocklists |
— |
16 |
28 |
|
2026-08-06 |
http://osint.bambenekconsulting.com/feeds/ |
URL |
IP Blocklists |
— |
14 |
25 |
|
2026-08-06 |
http://osint.bambenekconsulting.com/feeds/) |
URL |
IP Blocklists |
— |
14 |
25 |
|
2026-08-06 |
http://urandom.us.to/ |
URL |
IP Blocklists |
— |
12 |
23 |
|
2026-08-06 |
urandom.us.to |
DOMAIN |
IP Blocklists |
— |
12 |
23 |
|
2026-08-06 |
http://www.stopforumspam.com/ |
URL |
IP Blocklists |
— |
8 |
18 |
|
2026-08-06 |
http://www.stopforumspam.com) |
URL |
IP Blocklists |
— |
8 |
18 |
|
2026-08-06 |
StopForumSpam.com |
DOMAIN |
IP Blocklists |
— |
8 |
18 |
|
2026-08-06 |
win32k.sys |
DOMAIN |
Vulnerabilities |
— |
6 |
16 |
|
2026-08-06 |
EmergingThreats.net |
DOMAIN |
IP Blocklists |
— |
8 |
16 |
|
2026-08-06 |
proxylists.net |
DOMAIN |
IP Blocklists |
— |
4 |
16 |
|
2026-08-06 |
http://free-proxy-list.net/ |
URL |
IP Blocklists |
— |
8 |
15 |
|
2026-08-06 |
Info.plist |
DOMAIN |
ATT&CK |
— |
5 |
13 |
|
2026-08-06 |
DShield.org |
DOMAIN |
IP Blocklists |
— |
7 |
13 |
|
2026-08-06 |
http.sys |
DOMAIN |
Vulnerabilities |
— |
4 |
12 |
|
2026-08-06 |
gmail.com |
DOMAIN |
Cryptocurrency |
— |
9 |
12 |
|
2026-08-06 |
http://www.emergingthreats.net/ |
URL |
IP Blocklists |
— |
6 |
12 |
|
2026-08-06 |
readme.txt |
DOMAIN |
Ransomware Actors |
— |
2 |
11 |
|
2026-08-06 |
history.txt |
DOMAIN |
ATT&CK |
— |
7 |
11 |
|
2026-08-06 |
https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/ |
URL |
ATT&CK |
— |
6 |
11 |
|
2026-08-06 |
TEMP.Hex |
DOMAIN |
ATT&CK |
— |
6 |
11 |
|
2026-08-06 |
Kernel.org |
DOMAIN |
ATT&CK |
— |
7 |
11 |
|
2026-08-06 |
https://feeds.dshield.org/block.txt |
URL |
IP Blocklists |
— |
6 |
11 |
|
2026-08-06 |
https://cleantalk.org/ |
URL |
IP Blocklists |
— |
7 |
11 |
|
2026-08-06 |
https://cleantalk.org/) |
URL |
IP Blocklists |
— |
7 |
11 |
|
2026-08-06 |
admin.cgi |
DOMAIN |
Vulnerabilities |
— |
6 |
10 |
|
2026-08-06 |
bug.cgi |
DOMAIN |
Vulnerabilities |
— |
6 |
10 |
|
2026-08-06 |
Personal.xlsb |
DOMAIN |
ATT&CK |
— |
3 |
10 |
|
2026-08-06 |
Normal.dotm |
DOMAIN |
ATT&CK |
— |
3 |
10 |
|
2026-08-06 |
w32.tidserv |
DOMAIN |
ATT&CK |
— |
3 |
10 |
|
2026-08-06 |
SSH.COM |
DOMAIN |
ATT&CK |
— |
3 |
10 |
|
2026-08-06 |
https://attack.mitre.org/techniques/T1106)s |
URL |
ATT&CK |
— |
3 |
10 |
|
2026-08-06 |
Robots.txt |
DOMAIN |
ATT&CK |
— |
3 |
10 |
|
2026-08-06 |
Freedesktop.org |
DOMAIN |
ATT&CK |
— |
3 |
10 |
|
2026-08-06 |
PubPrn.vbs |
DOMAIN |
ATT&CK |
— |
3 |
10 |
|
2026-08-06 |
osx.dok |
DOMAIN |
ATT&CK |
— |
3 |
10 |
|
2026-08-06 |
https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdf |
URL |
ATT&CK |
— |
6 |
10 |
|
2026-08-06 |
https://attack.mitre.org/groups/G0034 |
URL |
ATT&CK |
— |
6 |
10 |
|
2026-08-06 |
TEMP.Zagros |
DOMAIN |
ATT&CK |
— |
6 |
10 |
|
2026-08-06 |
https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf |
URL |
ATT&CK |
— |
6 |
10 |
|
2026-08-06 |
https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/microsoft-threat-actor-naming?view=o365-worldwide |
URL |
ATT&CK |
— |
6 |
10 |
|
2026-08-06 |
Rc.common |
DOMAIN |
ATT&CK |
— |
3 |
10 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2017/12/attackers-deploy-new-ics-attack-framework-triton.html |
URL |
ATT&CK |
— |
6 |
10 |
|
2026-08-06 |
live.cn |
DOMAIN |
Sanctions |
— |
7 |
10 |
|
2026-08-06 |
mail.ru |
DOMAIN |
Sanctions |
— |
7 |
10 |
|
2026-08-06 |
bitcointrader.ai |
DOMAIN |
Phishing |
— |
6 |
10 |
|
2026-08-06 |
https://dshield.org/ |
URL |
IP Blocklists |
— |
5 |
10 |
|
2026-08-06 |
https://dshield.org/) |
URL |
IP Blocklists |
— |
5 |
10 |
|
2026-08-06 |
https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://blog.talosintelligence.com/2019/04/sodinokibi-ransomware-exploits-weblogic.html |
URL |
ATT&CK |
— |
6 |
9 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2017/09/zero-day-used-to-distribute-finspy.html |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://unit42.paloaltonetworks.com/oilrig-novel-c2-channel-steganography/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.us-cert.gov/ncas/alerts/TA17-318B |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://cloud.google.com/blog/topics/threat-intelligence/ivanti-post-exploitation-lateral-movement |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://securelist.com/luckymouse-hits-national-data-center/86083/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://unit42.paloaltonetworks.com/hamas-affiliate-ashen-lepus-uses-new-malware-suite-ashtag/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://lab52.io/blog/wirte-group-attacking-the-middle-east/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.proofpoint.com/sites/default/files/proofpoint-operation-transparent-tribe-threat-insight-en.pdf |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/ |
URL |
ATT&CK |
— |
6 |
9 |
|
2026-08-06 |
TEMP.MixMaster |
DOMAIN |
ATT&CK |
— |
6 |
9 |
|
2026-08-06 |
https://www.secureworks.com/blog/cybercriminals-increasingly-trying-to-ensnare-the-big-financial-fish |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://securelist.com/blackoasis-apt-and-new-targeted-attacks-leveraging-zero-day-exploit/82732/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://attack.mitre.org/groups/G1004) |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://securelist.com/the-silence/83009/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://go.recordedfuture.com/hubfs/reports/cta-2023-0808.pdf |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.secureworks.com/blog/revil-the-gandcrab-connection |
URL |
ATT&CK |
— |
6 |
9 |
|
2026-08-06 |
https://www.secureworks.com/research/revil-sodinokibi-ransomware |
URL |
ATT&CK |
— |
6 |
9 |
|
2026-08-06 |
https://media.defense.gov/2020/Aug/13/2002476465/-1/-1/0/CSA_DROVORUB_RUSSIAN_GRU_MALWARE_AUG_2020.PDF |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.microsoft.com/security/blog/2020/09/10/strontium-detecting-new-patters-credential-harvesting/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://researchcenter.paloaltonetworks.com/2018/06/unit42-sofacy-groups-parallel-attacks/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://securelist.com/sofacy-apt-hits-high-profile-targets-with-updated-toolset/72924/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://securelist.com/a-slice-of-2017-sofacy-activity/83930/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.microsoft.com/en-us/security/blog/2023/12/07/star-blizzard-increases-sophistication-and-evasion-in-ongoing-attacks/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://info.lookout.com/rs/051-ESQ-475/images/Lookout_Dark-Caracal_srr_20180118_us_v.1.0.pdf |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://foxitsecurity.files.wordpress.com/2016/06/fox-it_mofang_threatreport_tlp-white.pdf |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.welivesecurity.com/en/eset-research/moustachedbouncer-espionage-against-foreign-diplomats-in-belarus/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.symantec.com/blogs/threat-intelligence/orangeworm-targets-healthcare-us-europe-asia |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.volexity.com/blog/2021/08/17/north-korean-apt-inkysquid-infects-victims-using-browser-exploits/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.symantec.com/blogs/threat-intelligence/seedworm-espionage-group |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2018/03/iranian-threat-group-updates-ttps-in-spear-phishing-campaign.html |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.trendmicro.com/en_us/research/21/c/earth-vetala---muddywater-continues-to-target-organizations-in-t.html |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.clearskysec.com/wp-content/uploads/2018/11/MuddyWater-Operations-in-Lebanon-and-Oman.pdf |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2018/09/apt10-targeting-japanese-corporations-using-updated-ttps.html |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2017/04/apt10_menupass_grou.html |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://attack.mitre.org/groups/G0096 |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.forcepoint.com/sites/default/files/resources/files/forcepoint-security-labs-monsoon-analysis-report.pdf |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.volexity.com/blog/2018/06/07/patchwork-apt-group-targets-us-think-tanks/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://documents.trendmicro.com/assets/tech-brief-untangling-the-patchwork-cyberespionage-group.pdf |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://securelist.com/the-dropping-elephant-actor/75328/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://unit42.paloaltonetworks.com/updated-backconfig-malware-targeting-government-and-military-organizations/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://securelist.com/the-kimsuky-operation-a-north-korean-apt/57915/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.cybereason.com/blog/back-to-the-future-inside-the-kimsuky-kgh-spyware-suite |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://us-cert.cisa.gov/ncas/alerts/aa20-301a |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.secureworks.com/research/threat-profiles/gold-prelude |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.microsoft.com/en-us/security/blog/2022/05/09/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself/ |
URL |
ATT&CK |
— |
6 |
9 |
|
2026-08-06 |
https://blogs.technet.microsoft.com/mmpc/2016/12/14/twin-zero-day-attacks-promethium-and-neodymium-target-individuals-in-europe/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2021GTR.pdf |
URL |
ATT&CK |
— |
6 |
9 |
|
2026-08-06 |
https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/ |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
https://www.mandiant.com/resources/blog/investigating-ivanti-zero-day-exploitation |
URL |
ATT&CK |
— |
5 |
9 |
|
2026-08-06 |
TEMP.Veles |
DOMAIN |
ATT&CK |
— |
6 |
9 |
|
2026-08-06 |
google.com |
DOMAIN |
Sanctions |
— |
6 |
9 |
|
2026-08-06 |
ukr.net |
DOMAIN |
Sanctions |
— |
5 |
9 |
|
2026-08-06 |
https://threatfox.abuse.ch/faq/#tos |
URL |
Malware Attribution |
— |
5 |
9 |
|
2026-08-06 |
https://www.torproject.org/ |
URL |
IP Blocklists |
— |
5 |
9 |
|
2026-08-06 |
ransomed.vc |
DOMAIN |
Ransomware Actors |
— |
2 |
8 |
|
2026-08-06 |
http://www.botvrij.eu |
URL |
Domains/URLs |
— |
4 |
8 |
|
2026-08-06 |
ntconfig.pol |
DOMAIN |
Vulnerabilities |
— |
2 |
8 |
|
2026-08-06 |
FormHandler.cgi |
DOMAIN |
Vulnerabilities |
— |
2 |
8 |
|
2026-08-06 |
ftp.NetBSD.ORG |
DOMAIN |
Vulnerabilities |
— |
2 |
8 |
|
2026-08-06 |
ftp.sco.com |
DOMAIN |
Vulnerabilities |
— |
2 |
8 |
|
2026-08-06 |
ftp.freebsd.org |
DOMAIN |
Vulnerabilities |
— |
2 |
8 |
|
2026-08-06 |
ASP.NET |
DOMAIN |
Vulnerabilities |
— |
5 |
8 |
|
2026-08-06 |
wordpress.org |
DOMAIN |
Vulnerabilities |
— |
5 |
8 |
|
2026-08-06 |