{"type":"bundle","id":"bundle--7c62ff81-8d78-4f8b-8eac-4ebc7c9181dc","objects":[{"type":"identity","spec_version":"2.1","id":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","created":"2026-09-16T09:04:16.709Z","modified":"2026-09-16T09:04:16.709Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--6335ffc6-2fbc-4ac1-aee1-19808d6b415c","created":"2026-09-13T01:10:01.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 072558bc1a539e9936584647df51fb1797c982b0","description":"Seen in \"Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations\" (oss-security). Context: mes writes: https://github.com/unrealircd/unrealircd/commit/072558bc1a539e9936584647df51fb1797c982b0. It's a great example of the shape of many LLM-reported (I'","pattern":"[file:hashes.'SHA-1' = '072558bc1a539e9936584647df51fb1797c982b0']","pattern_type":"stix","valid_from":"2026-09-13T01:10:01.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"oss-security","url":"https://seclists.org/oss-sec/2026/q3/729"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--62ee1fa1-6baf-477b-b257-d85cd9df1f54","created":"2026-09-11T09:59:29.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 513a907b69edffc3cb77a494da395178d21ef9bd","description":"Seen in \"Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access\" (GBHackers). Context: mtp Second-stage payload download URL 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA-1 hash of /tmp/.z payload 2026-09-06 2026-09-08 64.207.","pattern":"[file:hashes.'SHA-1' = '513a907b69edffc3cb77a494da395178d21ef9bd']","pattern_type":"stix","valid_from":"2026-09-11T09:59:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-jfrog-artifactory-flaws/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9be0808e-232b-4eb0-844f-934d5072c5c5","created":"2026-09-11T08:17:33.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 513a907b69edffc3cb77a494da395178d21ef9bd","description":"Seen in \"JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control\" (Cyber Security News). Context: mtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a494da395178d21ef9bd Account 0xterror , svc_[a-zA-Z0-9]{8} , Nxploited_[a-zA-Z0-","pattern":"[file:hashes.'SHA-1' = '513a907b69edffc3cb77a494da395178d21ef9bd']","pattern_type":"stix","valid_from":"2026-09-11T08:17:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c48023ec-6473-4793-98f8-381942b994a7","created":"2026-09-10T19:04:00.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 513a907b69edffc3cb77a494da395178d21ef9bd","description":"Seen in \"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329\" (Wiz Blog). Context: 026-42018/CVE-2026-42016 exploitation 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA1 of /tmp/.z payload 2026-09-06 2026-09-08 64.207.232[.]","pattern":"[file:hashes.'SHA-1' = '513a907b69edffc3cb77a494da395178d21ef9bd']","pattern_type":"stix","valid_from":"2026-09-10T19:04:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Wiz Blog","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e389dd83-6ca3-4b19-baf3-3113eeaac22e","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 59508d071661ea70fa5fcbe6f9e2fb72506e57df","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: a4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df MacSync sample SHA-1 hash Code-signing identifier com.utils","pattern":"[file:hashes.'SHA-1' = '59508d071661ea70fa5fcbe6f9e2fb72506e57df']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ba865af5-0902-40cb-bec0-c011212a8dd2","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: d182eb7cba0ffa42d770d7b0d3499e49f24163a2","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: ils.Launcher Ad-hoc-signed MacSync stager identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code directory hash associated with the sample Staged archi","pattern":"[file:hashes.'SHA-1' = 'd182eb7cba0ffa42d770d7b0d3499e49f24163a2']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6f7dd45d-5d06-461e-bb2b-e7859214101b","created":"2026-09-10T07:01:43.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 59508d071661ea70fa5fcbe6f9e2fb72506e57df","description":"Seen in \"Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.\" (GBHackers). Context: cbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df Native Mach-O Stager Binary Code Signing ID com.utils.Launc","pattern":"[file:hashes.'SHA-1' = '59508d071661ea70fa5fcbe6f9e2fb72506e57df']","pattern_type":"stix","valid_from":"2026-09-10T07:01:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/clickfix-lures-target-macos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05faa73e-44dd-44db-951a-8a9c89eb43e5","created":"2026-09-10T07:01:43.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: d182eb7cba0ffa42d770d7b0d3499e49f24163a2","description":"Seen in \"Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.\" (GBHackers). Context: om.utils.Launcher Ad-hoc signature bundle identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code Directory Hash Note: IP addresses and domains are inte","pattern":"[file:hashes.'SHA-1' = 'd182eb7cba0ffa42d770d7b0d3499e49f24163a2']","pattern_type":"stix","valid_from":"2026-09-10T07:01:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/clickfix-lures-target-macos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5c243120-e5a3-4697-9dba-a111a895d5fd","created":"2026-09-05T12:12:45.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 286dd3ff41526b582ef48830de239dffbaa61f90","description":"Seen in \"Re: Vulnerability fixes in util-linux-2.42.3\" (oss-security). Context: Sep 05 Hi, https://github.com/util-linux/util-linux/commit/286dd3ff41526b582ef48830de239dffbaa61f90 Regards, Salvatore","pattern":"[file:hashes.'SHA-1' = '286dd3ff41526b582ef48830de239dffbaa61f90']","pattern_type":"stix","valid_from":"2026-09-05T12:12:45.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"oss-security","url":"https://seclists.org/oss-sec/2026/q3/655"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c94bcf5f-3809-4cf1-a86b-70335cdd21d3","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 03defdda9397e7536cf39951246483a0339ccd35","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-2","pattern":"[file:hashes.'SHA-1' = '03defdda9397e7536cf39951246483a0339ccd35']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4d3c46a0-195b-45f2-80e5-387ca0baed93","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-0","pattern":"[file:hashes.'SHA-1' = '0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c8e165cf-4f17-4a5b-939a-5b2f90db9063","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-1","pattern":"[file:hashes.'SHA-1' = '25ba920cb440b4a1c127c8eb0fb23ee783c9e01a']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--274527b3-4767-410a-926c-98e20db546c0","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: ac3f20ddc2567af0b050c672ecd59dddab1fe55e","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-2","pattern":"[file:hashes.'SHA-1' = 'ac3f20ddc2567af0b050c672ecd59dddab1fe55e']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b34ca64-9747-4128-acbf-13637c4b3f18","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 177837d0fa5bfd274abe79d80a01cfe2374b4cd9","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: ing file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbca","pattern":"[file:hashes.'SHA-1' = '177837d0fa5bfd274abe79d80a01cfe2374b4cd9']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d9f8c9d-61b3-4c27-9365-df9d8d164197","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 89a7861acb7983ad712ae9206131c96454a1b3d8","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: ing file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a794bac4bf650b6ba537137504162520b67266449be979679","pattern":"[file:hashes.'SHA-1' = '89a7861acb7983ad712ae9206131c96454a1b3d8']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c925f3f7-da97-4eef-9780-dd31a62deac4","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: d2c161ce52240b61d632607a2262890327d82502","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: ing file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd9","pattern":"[file:hashes.'SHA-1' = 'd2c161ce52240b61d632607a2262890327d82502']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--107a2ea2-fc0e-4e8d-a76b-a7a571c68d1c","created":"2026-08-17T12:57:39.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: d04ce934561934f758d77dfa944bd6743dd82cff","description":"Seen in \"New Malware 'Rover' Targets Indian Ambassador to Afghanistan\" (Palo Alto Unit 42). Context: 2 Bits binary MD5 : 76429f8515768f9f5def697e71071f51 SHA1 : d04ce934561934f758d77dfa944bd6743dd82cff SHA256: 7757517ae6b4d513a57826f9ab65bd070d99d25ac526cfae3e9","pattern":"[file:hashes.'SHA-1' = 'd04ce934561934f758d77dfa944bd6743dd82cff']","pattern_type":"stix","valid_from":"2026-08-17T12:57:39.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/new-malware-rover-targets-indian-ambassador-to-afghanistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f3f04d43-67c3-416c-8dc1-e8157e0b0372","created":"2026-08-17T12:54:22.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 41ee612602833345fc5bd2b98103811c12345678","description":"Seen in \"Analysis of Smoke Loader in New Tsunami Campaign\" (Palo Alto Unit 42). Context: ique ID. \"41EE612602833345FC5BD2B98103811C\" + \"12345678\" = \"41EE612602833345FC5BD2B98103811C12345678\" Next, Smoke Loader generates two strings based on the firs","pattern":"[file:hashes.'SHA-1' = '41ee612602833345fc5bd2b98103811c12345678']","pattern_type":"stix","valid_from":"2026-08-17T12:54:22.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/analysis-of-smoke-loader-in-new-tsunami-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a5e72292-ca12-42eb-853f-99f20c1fc75c","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 3d161de48d3f4da0aefff685253404c8b0111563","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: by the malware): MD5 0f1d3ed85fee2acc23a8a26e0dc12e0f SHA1 3d161de48d3f4da0aefff685253404c8b0111563 SHA256 fb94a5e30de7afd1d9072ccedd90a249374f687f16170e1986d6","pattern":"[file:hashes.'SHA-1' = '3d161de48d3f4da0aefff685253404c8b0111563']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ea9c3ea2-ebd8-4eaa-8039-e8ed45590a86","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 67c05b3937d94136eda4a60a2d5fb685abc776a1","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: d was identified: MD5 05d43d417a8f50e7b23246643fc7e03d SHA1 67c05b3937d94136eda4a60a2d5fb685abc776a1 SHA256 3fee068bf90ffbeb25549eb52be0456609b1decfe91cda1967eb","pattern":"[file:hashes.'SHA-1' = '67c05b3937d94136eda4a60a2d5fb685abc776a1']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8648fb55-3669-4ffc-847c-febb8503e52d","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 741dbdb20d1beeb8ff809291996c8b78585cb812","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: lease\\LoadDll.pdb MD5 a2fe5dcb08ae8b72e8bc98ddc0b918e7 SHA1 741dbdb20d1beeb8ff809291996c8b78585cb812 SHA256 0669c71740134323793429d10518576b42941f9eee0def6057ed","pattern":"[file:hashes.'SHA-1' = '741dbdb20d1beeb8ff809291996c8b78585cb812']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c8071327-2ec9-4ed9-94ce-69228717ffef","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: d13fc918433c705b49db74c91f56ae6c0cb5cf8d","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: owing properties: MD5 e02024f38dfb6290ce0d693539a285a9 SHA1 d13fc918433c705b49db74c91f56ae6c0cb5cf8d SHA256 66a0c294ee8f3507d723a376065798631906128ce79bd6dfd8f0","pattern":"[file:hashes.'SHA-1' = 'd13fc918433c705b49db74c91f56ae6c0cb5cf8d']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a041e90e-205b-482a-a57a-825bd1e1d807","created":"2026-08-17T12:22:32.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: e66e416f300c7efb90c383a7630c9cfe901ff9fd","description":"Seen in \"The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia\" (Palo Alto Unit 42). Context: owing properties: MD5 a943e196b83c4acd9c5ce13e4c43b4f4 SHA1 e66e416f300c7efb90c383a7630c9cfe901ff9fd SHA256 cfe436c1f0ce5eb7ac61b32cd073cc4e4b21d5016ceef77575be","pattern":"[file:hashes.'SHA-1' = 'e66e416f300c7efb90c383a7630c9cfe901ff9fd']","pattern_type":"stix","valid_from":"2026-08-17T12:22:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-the-fractured-block-campaign-carrotbat-malware-used-to-deliver-malware-targeting-southeast-asia/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60350dc3-4b0d-4c9d-a132-494e3f5934e6","created":"2026-08-17T12:22:32.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: f459f9cfbd10b136cafb19cbc233a4c8342ad984","description":"Seen in \"The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia\" (Palo Alto Unit 42). Context: g sample is used: MD5 3e4015366126dcdbdcc8b5c508a6d25c SHA1 f459f9cfbd10b136cafb19cbc233a4c8342ad984 SHA256 aef92be267a05cbff83aec0f23d33dfe0c4cdc71f9a424f5a2e5","pattern":"[file:hashes.'SHA-1' = 'f459f9cfbd10b136cafb19cbc233a4c8342ad984']","pattern_type":"stix","valid_from":"2026-08-17T12:22:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-the-fractured-block-campaign-carrotbat-malware-used-to-deliver-malware-targeting-southeast-asia/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1de32f83-f46f-49c9-a6ee-ae713d4c887f","created":"2026-08-17T11:46:22.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad","description":"Seen in \"Exploring the Latest Mispadu Stealer Variant\" (Palo Alto Unit 42). Context: c3c689899dc4e75fdbdd0ab076ac457de7fb83645fb735a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes F","pattern":"[file:hashes.'SHA-1' = 'ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad']","pattern_type":"stix","valid_from":"2026-08-17T11:46:22.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mispadu-infostealer-variant/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3ca030f2-05be-4ecf-a22a-ef618e661cfd","created":"2026-08-17T10:57:32.000Z","modified":"2026-09-16T09:04:16.709Z","created_by_ref":"identity--3139b037-1bbc-487e-9749-080dd0df5aac","name":"sha1: 82cb695f463b93b9cc089253cd6b5e32dce46c35","description":"Seen in \"Fake CVE-2023\" (Palo Alto Unit 42). Context: 0477 - main . zip Type = zip Physical Size = 2360 Comment = 82cb695f463b93b9cc089253cd6b5e32dce46c35 Date Time Attr Size Compressed Name ------------------- ---","pattern":"[file:hashes.'SHA-1' = '82cb695f463b93b9cc089253cd6b5e32dce46c35']","pattern_type":"stix","valid_from":"2026-08-17T10:57:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/"}]}]}