ShadowMap

Dark Web Exposure for index.php

Credentials, devices and data found in dark web stealer logs & breaches
78
Exposure level: High
index.php scores 78/100 based on leaked credentials, compromised devices, and stolen financial & session data found on the dark web.
Most recent exposure 0 days ago Last 90 days -87% 6% reuse a top-10 password
Employee exposure
corporate accounts — @index.php
553,040
leaked credentials · 1,135 compromised devices
Top exposed employee accounts
index.php714
8002/index.php592
8000/index.php320
8003/index.php314
2689/index.php168
Where staff accounts were caught
https240,420
http75,982
c22,576
223.27.144.1951,104
www.facebook.com710
Customer exposure
stolen logins for index.php
11,479
leaked credentials · 688 compromised devices
Top exposed customer accounts
00057374372
p-***@mail.ru66
o***@hotmail.com66
gabrielmendoza64
davidutz12364
Most targeted services
cliquebook.net.index.php72
hypeptc.club.index.php72
clixblue.com.index.php71
community.multitheftauto.com.index.php53
comnavcare.kompas-navigasi.co.id.index.php53
564,519
Exposed Credentials
1,177
Compromised Devices
0
Credit Cards
0
Crypto Wallets
9
Auth Tokens
108,866
Stolen Cookies

Exposure over time (credentials leaked per month)

2024-012026-07

Corporate SaaS & shadow-IT exposed (employee logins to third-party services)

Google480

Most common passwords 6% reuse a top-10 password

(h***ps11,449
(h***tp8,908
12***564,176
ad***in2,341
12***781,682
****939
12***89784
****766
12***45759
****472

Stolen sessions (active cookies that can bypass MFA)

youtube.com3,817
google.com2,808
tiktok.com1,693
bing.com1,595
savefrom.net1,100
deriv.com1,000

Financial, crypto & app tokens

App / session tokens
Google9

Browsers & apps affected

Browser/Logins/Firefox_55qe6m68.default-release[35688c9b].txt20
android:smsgateway.rbsoft3
Google Chrome (Profile 15)1

Stealer malware families seen

RedLine RisePro

Related companies

Explore

Check your own exposure →

Free dark web & attack-surface check by ShadowMap

Figures are aggregate counts derived from dark web stealer logs and public breach data. Data is indicative and updated periodically.