PULSE NAME
EbeeDec2025 Pt6
WHITE DNS requests to deliver MgBot, Arcane Werewolf, MEDUSA LOCKER, HoneyMyte IMEBEEIMFINE 2026-01-02 Modified: 2026-02-01
474
IOCs
HIGH VOLUME
Multiple APT/threat actors, Malware and Campaigns
Indicators of Compromise (41 / 474 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname email
TYPEINDICATORDESCRIPTIONCREATED
URL http://104.243.43.115:443 2026-01-02
URL http://154.89.152.204:9200 2026-01-02
URL http://203.91.76.58:9200 2026-01-02
URL http://aaaaaaaa.cyou:443 2026-01-02
URL http://arabtravellers-24.com/favicon.ico 2026-01-02
URL http://arabtravellers-24.com/r/?c3Y9bzM2NV8xX29uZSZtPU03JnVpZD1VU0VSMDUwNjIwMjVVMDUwNjA1MDgmdD0xMw==N0123N 2026-01-02
URL http://asia.aaaaaaaa.cyou:1110 2026-01-02
URL http://eu.aaaaaaaa.cyou:1110 2026-01-02
URL http://m.ms/suKcHZYV/1/010001948f5ca 2026-01-02
URL http://ssl.aaaaaaaa.cyou:9654 2026-01-02
URL http://ssl.aaaaaaaa.cyou:9655 2026-01-02
URL http://us.aaaaaaaa.cyou:1110 2026-01-02
URL http://www.cloudsecure.top:9200 2026-01-02
URL http://www.combilke.top:9200 2026-01-02
URL http://www.combilkee.top:9200 2026-01-02
URL http://xmr.aaaaaaaa.cyou:1110 2026-01-02
URL https://cdn.electropriborzavod.ru/index?data=[base64_enc_data] 2026-01-02
URL https://cloud.electropriborzavod.ru/files/d8287185e4ae695a 2026-01-02
URL https://static.my 2026-01-02
URL http://aquiverif-outoksmail2025.gamer.gd/ 2026-01-02
URL http://verification-email2025.iceiy.com/ 2026-01-02
URL http://verification-email2025.iceiy.com/_index.html 2026-01-02
URL https://soyfix.com/log/log/ 2026-01-02
URL http://getnjs.com/util.js 2026-01-02
URL http://iniciar-sesion-email2.iceiy.com/ 2026-01-02
URL http://livequranlearner.com/ 2026-01-02
URL http://malicious-panel.com/payload.exe' 2026-01-02
URL http://portal-online.net/ 2026-01-02
URL http://proceso-de-cobro-micro-personal.infy.uk/ 2026-01-02
URL https://aquiverif-outoksmail2025.gamer.gd/ 2026-01-02
URL https://aterymaganthr.zya.me/?i=1 2026-01-02
URL https://aterymaganthr.zya.me/?i=2 2026-01-02
URL https://attacker-domain.com/api/css.js.php 2026-01-02
URL https://drjagrutichavan.com/assetl/hp/pk5//ico/wd.ico 2026-01-02
URL https://innlive.in/assets/public/01/jlp/jip.hta 2026-01-02
URL https://obf-io.deobfuscate.io 2026-01-02
URL https://renovacion365out.zya.me/?i=1 2026-01-02
URL https://renovacion365out.zya.me/?i=2 2026-01-02
URL https://www.alertacomunicado365.es/ 2026-01-02
URL https://www.cc-analytics.com/app.js 2026-01-02
URL https://www.pstatics.com/i' 2026-01-02
References (1)
↗ IOC-Dec 2025.csv