158[.]220[.]87[.]79Live check · abuse.ch · CISA KEV · NVD
IOC and CVE lookup
Paste any indicator — an IP, domain, URL, file hash or CVE. For IP/domain/URL/hash you get abuse.ch ThreatFox reputation (with the malware family behind it); for a CVE, CISA KEV exploitation status, FIRST EPSS probability and NVD detail.
Indicator reputation (abuse.ch ThreatFox) or CVE triage (CISA KEV · FIRST EPSS · NVD). No key required.
Feed indicators
crates[.]iousbank[.]comhunt[.]ioany[.]rungca-emailauth[.]orgwordpress[.]orghelper-beeps[.]solidityweb3devtoolsx[.]solidityLive malicious infrastructure · abuse.ch
Active threat infrastructure tracked worldwide right now — C2 servers, malicious domains and payload hashes. The lookup above runs against exactly this list.
Most active malware families
Threat types
Latest C2 indicators
Defanged — not clickable. Paste into the lookup above to investigate.
Sources: abuse.ch ThreatFox (keyless active-indicator export), CISA KEV, FIRST EPSS, NIST NVD, geo via ipwho.is. «Not listed» does not mean «safe».