LIVE_FEED
--:--:--[HIGH]shop-***-deals.comMagecart skimmer (Group 7)// US-EAST--:--:--[HIGH]wp-***-blog.netDrive-by iframe → exploit kit// EU-WEST--:--:--[MEDIUM]cdn-***-helper.ioObfuscated cryptominer (CoinIMP)// AP-SOUTH--:--:--[HIGH]auth-***-login.coCredential phishing kit (16shop)// EU-CENTRAL--:--:--[MEDIUM]media-***-files.orgMalicious redirect chain → ClickFix// US-WEST--:--:--[HIGH]support-***-desk.comFakeUpdates / SocGholish payload// US-EAST--:--:--[LOW]track-***-pixel.appUnauthorized 3rd-party tracker// EU-NORTH--:--:--[MEDIUM]img-***-host.ruDrive-by download (TLD reputation)// EU-EAST--:--:--[HIGH]api-***-stats.xyzC2 beacon (Cobalt Strike profile)// AP-EAST--:--:--[LOW]promo-***-coupon.shopAffiliate cloaking + cookie stuff// US-CENTRAL--:--:--[HIGH]shop-***-deals.comMagecart skimmer (Group 7)// US-EAST--:--:--[HIGH]wp-***-blog.netDrive-by iframe → exploit kit// EU-WEST--:--:--[MEDIUM]cdn-***-helper.ioObfuscated cryptominer (CoinIMP)// AP-SOUTH--:--:--[HIGH]auth-***-login.coCredential phishing kit (16shop)// EU-CENTRAL--:--:--[MEDIUM]media-***-files.orgMalicious redirect chain → ClickFix// US-WEST--:--:--[HIGH]support-***-desk.comFakeUpdates / SocGholish payload// US-EAST--:--:--[LOW]track-***-pixel.appUnauthorized 3rd-party tracker// EU-NORTH--:--:--[MEDIUM]img-***-host.ruDrive-by download (TLD reputation)// EU-EAST--:--:--[HIGH]api-***-stats.xyzC2 beacon (Cobalt Strike profile)// AP-EAST--:--:--[LOW]promo-***-coupon.shopAffiliate cloaking + cookie stuff// US-CENTRAL
sample_alert

What an alert actually looks like.

Every detection ships as a forensic bundle, not a one-liner. Click between the tabs below to see the email body, the evidence we attach, the parsed IOCs, and the raw network transcript.

Fromalerts@domainexploitsdetector.io
Tosecurity@yourcompany.com
Subject[HIGH] Drive-by iframe injection on shop.yourcompany.com
Date2026-05-11 14:02:47 UTC
Severity9.1 / 10 (HIGH)

Hello — we detected a confirmed malicious injection on a page you monitor.

Target: https://shop.yourcompany.com/checkout
Detection time: 14:01:09 UTC (delay: 98s after injection)
Classification: Drive-by iframe → SocGholish payload

The page loaded a hidden iframe pointing at cdn-helper-stats[.]xyz/loader.js which executed a known SocGholish dropper. The injection appears to originate from a compromised version of the "quick-cart" WordPress plugin.

Full evidence bundle (screenshot, HAR, replay URL, IOC list) is attached and viewable in your dashboard. Recommended action: roll back plugin to v3.1.4 and rotate any admin credentials touched in the last 72h.

— Domain Exploits Detector // automated alert