# PitScaler campaign-domain edge-blocklist (CVE-2026-88771/88772 and the 2 Oct SAML-issue chain) # Generated 2026-10-03 18:32 UTC from https://pitscaler.com/iocs.csv # Block inbound AND outbound: the actor downloads payloads from these names (inbound to the appliance) # and the Sliver implant beacons out to them (outbound from the appliance). # Wildcard semantics: a line "*.pylrk.cc." means the name and every subdomain of it (NCSC-NL guidance: block all subdomains). # Read the caveats: https://pitscaler.com/iocs.csv # These are Cloudflare-fronted names: block the DNS name, never the resolved proxy IPs. # Blocking these is defence in depth, not incident response. A clean log proves nothing. # # Wildcard: the C2 domain of the 2 Oct FreeBSD Sliver implant (embedded C2 string, Expel-corroborated MAR); # covers delivery subdomain f.pylrk.cc and rotation. Registered 2 Oct 06:56 UTC. *.pylrk.cc. # Wildcard: same campaign, subdomain-rotation coverage (spelled *.pylrk.cc in NCSC-NL guidance). pylrk.cc. # Delivery host of the FreeBSD Sliver implant (/HaKi2ufpiQ8AeVTZ/host), explicit single-name line for # resolvers/devices that do not support wildcards. f.pylrk.cc.