{"type":"bundle","id":"bundle--b833fb76-299a-4956-86c7-bae93def50a6","objects":[{"type":"identity","spec_version":"2.1","id":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","created":"2026-09-16T08:58:52.499Z","modified":"2026-09-16T08:58:52.499Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--90a7aadf-8c8c-4d0c-ab2d-8f0be50bff68","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 5c92d3b8734b4f498752f735a1ca0987","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: n installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]","pattern":"[file:hashes.MD5 = '5c92d3b8734b4f498752f735a1ca0987']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0adca47a-843e-40d0-b4f0-337998c5601e","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d278edd3-0449-4f92-9d8d-4e7576b48df0","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d763f5b7-245a-4c48-90f5-cdec0274432e","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 9a47c4d379998ade2f8f99e23a630c06","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '9a47c4d379998ade2f8f99e23a630c06']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--811342b6-6a01-4641-9cad-8b7d21bca439","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c2efb2dcacba6d3ccc175b6ce1b7ed0a","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'c2efb2dcacba6d3ccc175b6ce1b7ed0a']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ceeb2d32-3eea-4d5e-9d1e-545c6c6e9db9","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: f3e82419a43220a7a222fc01b7607adc","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: 8fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'f3e82419a43220a7a222fc01b7607adc']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e4fbe35-e737-4d39-9d7a-00480319ec99","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 0e39e8d7b641bcda4376ebbfeff7b12e","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: cluded in the malicious ISO File name / MD5 %TEMP%\\find.vbs 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays the fake “license not found” message E","pattern":"[file:hashes.MD5 = '0e39e8d7b641bcda4376ebbfeff7b12e']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2828272a-9d38-4c07-baf8-9ee6b0d440e8","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 15eca4a3f7350423cf4db0b4c30d1968","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3","pattern":"[file:hashes.MD5 = '15eca4a3f7350423cf4db0b4c30d1968']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4d4da648-4133-4a3a-b417-140db669914c","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 1ec9eff863dc4418d1498bc3d904899d","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: haos ransomware File name / MD5 %TEMP%\\YandexPackLoader.exe 1ec9eff863dc4418d1498bc3d904899d Browser installer included in the malicious ISO File name /","pattern":"[file:hashes.MD5 = '1ec9eff863dc4418d1498bc3d904899d']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2abb8609-caef-42af-a966-57a9f338fa47","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2a0834560ed3770fc33d7a42f8229722","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: %\\rockstargamescrashfixer.exe , %TEMP%\\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651","pattern":"[file:hashes.MD5 = '2a0834560ed3770fc33d7a42f8229722']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--470de786-6be2-480c-8f90-99e83162d42e","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2a385fe7bed9899d77d05cb8e302d557","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associated launchers IP addresses 35.157.1","pattern":"[file:hashes.MD5 = '2a385fe7bed9899d77d05cb8e302d557']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dd18eb52-38be-4740-87bd-5aa3f02e36e9","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 57b9c56ef97a7ada98257b23577bf5e3","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: TEMP%\\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3","pattern":"[file:hashes.MD5 = '57b9c56ef97a7ada98257b23577bf5e3']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b1582567-4f63-4791-a5db-9a31d011f899","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 60a0f58001ea7be538cd42b651924cc7","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee","pattern":"[file:hashes.MD5 = '60a0f58001ea7be538cd42b651924cc7']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f90e20fb-5d74-4a1e-ae47-3976ac408c8f","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 6b49f24d5d5b49127476bc385565f8b0","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: ecutable File name / MD5 %TEMP%\\checkinternetconnection.bat 6b49f24d5d5b49127476bc385565f8b0 Batch file used to confirm internet connectivity File names","pattern":"[file:hashes.MD5 = '6b49f24d5d5b49127476bc385565f8b0']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4839a51b-5385-4131-8389-5cb4de7b5f42","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 8da3fe3664d81226b0fb2a50a0537d4f","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: at , C:\\Users\\Default\\Local Settings\\[RANDOM FILE NAME].exe 8da3fe3664d81226b0fb2a50a0537d4f DCRAT installer components and binary Hosts-file entries 0.","pattern":"[file:hashes.MD5 = '8da3fe3664d81226b0fb2a50a0537d4f']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e3ecf156-670a-479c-8363-cd7702e2a284","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a15e280a3fd65dfaa243bbe2dbf45e97","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: ype Indicator Description File name / MD5 Gta6installer.exe a15e280a3fd65dfaa243bbe2dbf45e97 Initial fake installation executable File name / MD5 %TEMP%","pattern":"[file:hashes.MD5 = 'a15e280a3fd65dfaa243bbe2dbf45e97']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a5937829-e5de-4e4f-b6b0-8c11952a4451","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: b9648ec8cc806e7661aabcfc91dc836c","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: %TEMP%\\gta6.exe , %USERPROFILE%\\AppData\\Roaming\\svchost.exe b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries File name read_it.txt Note droppe","pattern":"[file:hashes.MD5 = 'b9648ec8cc806e7661aabcfc91dc836c']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--212f905d-b64a-42ac-833c-7d2df4933e0d","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: dfdf5e5b78d2ec764c0e5641cf9a0d26","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: -control infrastructure File name / MD5 %TEMP%\\adminapp.exe dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]","pattern":"[file:hashes.MD5 = 'dfdf5e5b78d2ec764c0e5641cf9a0d26']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4645724c-5669-48d7-9d06-5f8bf4d164cc","created":"2026-09-10T14:23:36.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: ea991bc9334b36a6b958f564ee716776","description":"Seen in \"Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware\" (Cyber Security News). Context: 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associate","pattern":"[file:hashes.MD5 = 'ea991bc9334b36a6b958f564ee716776']","pattern_type":"stix","valid_from":"2026-09-10T14:23:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-gta-6-downloads/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e01d6ba7-5d74-42dc-84d8-f114e00349c9","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 15eca4a3f7350423cf4db0b4c30d1968","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3","pattern":"[file:hashes.MD5 = '15eca4a3f7350423cf4db0b4c30d1968']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3ec2cef5-bae7-4e7e-8b75-ef779a081c8a","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2a0834560ed3770fc33d7a42f8229722","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: ckstargamescrashfixer.exe %TEMP%\\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651","pattern":"[file:hashes.MD5 = '2a0834560ed3770fc33d7a42f8229722']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--27c51782-9eb6-451b-84d0-77bc11234b89","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2a385fe7bed9899d77d05cb8e302d557","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers Note: IP addresses","pattern":"[file:hashes.MD5 = '2a385fe7bed9899d77d05cb8e302d557']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bb93cc0a-e5de-42fc-b97a-6d1dd71cc12a","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 57b9c56ef97a7ada98257b23577bf5e3","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3","pattern":"[file:hashes.MD5 = '57b9c56ef97a7ada98257b23577bf5e3']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a51e1948-8805-4c20-b27d-9e1b3522db98","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 60a0f58001ea7be538cd42b651924cc7","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee","pattern":"[file:hashes.MD5 = '60a0f58001ea7be538cd42b651924cc7']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d1bbd2d-a541-4d15-815f-189c6bc638c9","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 6b49f24d5d5b49127476bc385565f8b0","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: llation executable %TEMP%\\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEM","pattern":"[file:hashes.MD5 = '6b49f24d5d5b49127476bc385565f8b0']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49373cb6-eff2-4dc0-88c8-13da25524762","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a15e280a3fd65dfaa243bbe2dbf45e97","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: -clean media. IOCs Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\\checkinternetconnect","pattern":"[file:hashes.MD5 = 'a15e280a3fd65dfaa243bbe2dbf45e97']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c5e5c5a9-986f-4da7-a917-6e7e92ec83fb","created":"2026-09-10T11:43:44.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: ea991bc9334b36a6b958f564ee716776","description":"Seen in \"Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers\" (GBHackers). Context: 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associ","pattern":"[file:hashes.MD5 = 'ea991bc9334b36a6b958f564ee716776']","pattern_type":"stix","valid_from":"2026-09-10T11:43:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/fake-gta-6-installer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--242d30ac-373e-47a2-8c37-6e50f910866e","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 9678f71ea4cccbc3d511dc8d7f24b113","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: 25f44db68a MacSync sample hash reported by SEQRITE MD5 hash 9678f71ea4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6","pattern":"[file:hashes.MD5 = '9678f71ea4cccbc3d511dc8d7f24b113']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--85f2379f-1cef-44e8-8593-9b5737fae022","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: de62a2f47d1c7dec2997f931a050a615","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: h used for stolen-data uploads HTTP request header api-key: de62a2f47d1c7dec2997f931a050a615 API key observed in MacSync network requests HTTP User-Agen","pattern":"[file:hashes.MD5 = 'de62a2f47d1c7dec2997f931a050a615']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0b6e08e6-a490-4f62-bbcd-1348ae18c0c3","created":"2026-09-10T07:01:43.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 9678f71ea4cccbc3d511dc8d7f24b113","description":"Seen in \"Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.\" (GBHackers). Context: b68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5f","pattern":"[file:hashes.MD5 = '9678f71ea4cccbc3d511dc8d7f24b113']","pattern_type":"stix","valid_from":"2026-09-10T07:01:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/clickfix-lures-target-macos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bbe97052-27a8-4066-8c38-a9ed4ac41776","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 528cd4e69ecfa5191adbcf6ef28667bf","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: Infrastructure used to execute campaign activity File hash 528cd4e69ecfa5191adbcf6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d","pattern":"[file:hashes.MD5 = '528cd4e69ecfa5191adbcf6ef28667bf']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d353d6c-5bd9-420d-9bd6-f8f6562e9acb","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 974decb9ff4c8f9ccb0937c96d513347","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: sa_collect_small.exe — Rust LSA bootkey collector File hash 974decb9ff4c8f9ccb0937c96d513347 certipy.exe — Active Directory Certificate Services abuse t","pattern":"[file:hashes.MD5 = '974decb9ff4c8f9ccb0937c96d513347']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6e7146be-21cf-4403-bbda-1acf37cd28b5","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a6437ac3d6798090a218520985d36a3f","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: 687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d6798090a218520985d36a3f collect_custom.exe — Rust custom collection tool File hash","pattern":"[file:hashes.MD5 = 'a6437ac3d6798090a218520985d36a3f']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ddbcb30-c59a-4c2f-9814-e1903175011d","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: ce870a91e8d27e8f663f0687abc60b04","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: f6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d27e8f663f0687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d67","pattern":"[file:hashes.MD5 = 'ce870a91e8d27e8f663f0687abc60b04']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8b7063d8-7158-4d2b-b90f-4c839e7a1743","created":"2026-09-10T05:20:30.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: fc92dfafa7aa741c5f2b9cbcf75d1d19","description":"Seen in \"Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers\" (GBHackers). Context: collect_custom.exe — Rust custom collection tool File hash fc92dfafa7aa741c5f2b9cbcf75d1d19 lsa_collect_small.exe — Rust LSA bootkey collector File has","pattern":"[file:hashes.MD5 = 'fc92dfafa7aa741c5f2b9cbcf75d1d19']","pattern_type":"stix","valid_from":"2026-09-10T05:20:30.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-hundreds-of-ai-agents/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ee874811-03e3-4545-889e-68e6afed8719","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 0e39e8d7b641bcda4376ebbfeff7b12e","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: 18d1498bc3d904899d Yandex web browser %TEMP%\\find.vbs MD5 : 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays a \"license not found\" message","pattern":"[file:hashes.MD5 = '0e39e8d7b641bcda4376ebbfeff7b12e']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed0c1d62-f3c3-49b7-a7d3-98bcd5747814","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 15eca4a3f7350423cf4db0b4c30d1968","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3","pattern":"[file:hashes.MD5 = '15eca4a3f7350423cf4db0b4c30d1968']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e976789f-e4d7-496b-ac15-8c9612b47832","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 1ec9eff863dc4418d1498bc3d904899d","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: ansomware-encrypted files %TEMP%\\YandexPackLoader.exe MD5 : 1ec9eff863dc4418d1498bc3d904899d Yandex web browser %TEMP%\\find.vbs MD5 : 0e39e8d7b641bcda43","pattern":"[file:hashes.MD5 = '1ec9eff863dc4418d1498bc3d904899d']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a73d5bb5-b0d8-49de-ad8d-7321eae0b9fc","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2a0834560ed3770fc33d7a42f8229722","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: ckstargamescrashfixer.exe %TEMP%\\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651","pattern":"[file:hashes.MD5 = '2a0834560ed3770fc33d7a42f8229722']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--acb88709-ed8d-4745-a5a3-fbee8ccea909","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2a385fe7bed9899d77d05cb8e302d557","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers 35.157.111[.]131 3","pattern":"[file:hashes.MD5 = '2a385fe7bed9899d77d05cb8e302d557']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a3ba6df0-3edd-4201-9f7d-ad8eea0bb7fb","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 57b9c56ef97a7ada98257b23577bf5e3","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3","pattern":"[file:hashes.MD5 = '57b9c56ef97a7ada98257b23577bf5e3']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--82c306de-e1e3-4104-ae68-07c0063a8983","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 60a0f58001ea7be538cd42b651924cc7","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee","pattern":"[file:hashes.MD5 = '60a0f58001ea7be538cd42b651924cc7']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0879a654-b10f-4b17-8192-93a21a7c859c","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 6b49f24d5d5b49127476bc385565f8b0","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: llation executable %TEMP%\\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEM","pattern":"[file:hashes.MD5 = '6b49f24d5d5b49127476bc385565f8b0']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--233157d5-95b5-45c4-b7d5-355b1f3dd73a","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 8da3fe3664d81226b0fb2a50a0537d4f","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: :\\Users\\Default\\Local Settings\\[RANDOM FILE NAME].exe MD5 : 8da3fe3664d81226b0fb2a50a0537d4f Copy of DCRAT and associated installation files 0.0.0.0 app","pattern":"[file:hashes.MD5 = '8da3fe3664d81226b0fb2a50a0537d4f']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b49170f1-0a30-40fa-a32c-64f7a7c27525","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a15e280a3fd65dfaa243bbe2dbf45e97","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: Compromise (IOCs) Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\\checkinternetconnect","pattern":"[file:hashes.MD5 = 'a15e280a3fd65dfaa243bbe2dbf45e97']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e2129d11-4078-4dda-a1c2-573398c633c8","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: b9648ec8cc806e7661aabcfc91dc836c","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: MP%\\gta6.exe %USERPROFILE%\\AppData\\Roaming\\svchost.exe MD5: b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries read_it.txt Ransomware note left","pattern":"[file:hashes.MD5 = 'b9648ec8cc806e7661aabcfc91dc836c']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d33a5eef-bc59-4620-a211-6f4438e21a19","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: dfdf5e5b78d2ec764c0e5641cf9a0d26","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: IP address that DCRAT connects to %TEMP%\\adminapp.exe MD5 : dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary https://discord[.]com/","pattern":"[file:hashes.MD5 = 'dfdf5e5b78d2ec764c0e5641cf9a0d26']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--312120ff-c6c7-4aad-9087-f170a7a1198d","created":"2026-09-09T14:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: ea991bc9334b36a6b958f564ee716776","description":"Seen in \"Grand Theft Auto VI hype leads to malware\" (Huntress). Context: 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associ","pattern":"[file:hashes.MD5 = 'ea991bc9334b36a6b958f564ee716776']","pattern_type":"stix","valid_from":"2026-09-09T14:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/fake-gta6-download-malware-analysis"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--25874575-49bd-4ae6-a33e-45bab4e41d0a","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 528cd4e69ecfa5191adbcf6ef28667bf","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: ute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0","pattern":"[file:hashes.MD5 = '528cd4e69ecfa5191adbcf6ef28667bf']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dbf69d34-47d7-4fd2-b348-ed1952d241d6","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 974decb9ff4c8f9ccb0937c96d513347","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: f75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9ff4c8f9ccb0937c96d513347 (certipy.exe) ADCS Abuse Tool Administrator17 Adversary cre","pattern":"[file:hashes.MD5 = '974decb9ff4c8f9ccb0937c96d513347']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1818cbcf-87b9-43d2-904c-ac3e9d525ee7","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a6437ac3d6798090a218520985d36a3f","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: 27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c","pattern":"[file:hashes.MD5 = 'a6437ac3d6798090a218520985d36a3f']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eb089a9b-5391-4589-a11b-1b44ece7a2e4","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: ce870a91e8d27e8f663f0687abc60b04","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: fa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a2185","pattern":"[file:hashes.MD5 = 'ce870a91e8d27e8f663f0687abc60b04']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b54317f3-7f51-423d-bf8b-e5935709ff86","created":"2026-09-09T00:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: fc92dfafa7aa741c5f2b9cbcf75d1d19","description":"Seen in \"Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF\" (GreyNoise). Context: a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c5f2b9cbcf75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9","pattern":"[file:hashes.MD5 = 'fc92dfafa7aa741c5f2b9cbcf75d1d19']","pattern_type":"stix","valid_from":"2026-09-09T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GreyNoise","url":"https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d5f52454-038f-43c2-9fd0-1f38e45ee194","created":"2026-09-07T10:19:45.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 581e2e2265d0c1509b3799c5a9039374","description":"Seen in \"JSCeal Hides Crypto Malware in V8 Bytecode\" (Security Affairs). Context: encrypted payload we observed was generated on 2025-11-11 ( 581e2e2265d0c1509b3799c5a9039374 ). The AES key is not stored in the malware bundle itself.","pattern":"[file:hashes.MD5 = '581e2e2265d0c1509b3799c5a9039374']","pattern_type":"stix","valid_from":"2026-09-07T10:19:45.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198573/malware/jsceal-hides-crypto-malware-in-v8-bytecode.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1cc0615b-91a4-4adc-97b6-7de8b42c0dc4","created":"2026-09-06T11:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 5568cd69c754b392121f1dbb8f900fda","description":"Seen in \"Critical N-able N-central Vulnerability and Active Exploitation\" (Huntress). Context: r IPv4 (Tzulo VPN) 23.234.97[.]68 Intruder IPv4 (Tzulo VPN) 5568cd69c754b392121f1dbb8f900fda Malicious Cloudflare tunnel account tag Update: 8/6/26 @ 5:","pattern":"[file:hashes.MD5 = '5568cd69c754b392121f1dbb8f900fda']","pattern_type":"stix","valid_from":"2026-09-06T11:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/n-able-vulnerability-exploitation"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13c0fd23-e4b2-49d8-82e1-29b93d0bd8e9","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: fced27f6d57702565353ecc11722533b","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: /cache/ss_<10hex>/sync_<10hex>.php web shell X-Cache-Token: fced27f6d57702565353ecc11722533b header the web shell requires, 404 without it 457cfa2fb7p5.","pattern":"[file:hashes.MD5 = 'fced27f6d57702565353ecc11722533b']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0211e501-9135-47ee-aaf4-706b40bd951c","created":"2026-09-04T14:51:13.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c8c68e629bba773a10ac80012d10bf19","description":"Seen in \"New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic\" (The Hacker News). Context: tore File - ~/cache/haproxy-1000.cache File - /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 File - /var/lib/snapd/g580 File - /tmp/jasper-log SHA-256 -","pattern":"[file:hashes.MD5 = 'c8c68e629bba773a10ac80012d10bf19']","pattern_type":"stix","valid_from":"2026-09-04T14:51:13.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eb4ebc4c-453d-437f-abbc-e2ece83316d6","created":"2026-09-04T12:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c8c68e629bba773a10ac80012d10bf19","description":"Seen in \"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors\" (Rapid7 Blog). Context: and saves them to an encrypted log file under /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 . Figure 2: hardcoded master passwords in userauth_passwd()","pattern":"[file:hashes.MD5 = 'c8c68e629bba773a10ac80012d10bf19']","pattern_type":"stix","valid_from":"2026-09-04T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Rapid7 Blog","url":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05569920-de9a-4a56-899d-f8910c972bde","created":"2026-09-04T12:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: ecd427ea8330a4ff73618483e00b9b41","description":"Seen in \"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors\" (Rapid7 Blog). Context: main – img.darklights.store – authenticating with api_token/ecd427ea8330a4ff73618483e00b9b41 and setting the User-token header to the victim ID to fetch","pattern":"[file:hashes.MD5 = 'ecd427ea8330a4ff73618483e00b9b41']","pattern_type":"stix","valid_from":"2026-09-04T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Rapid7 Blog","url":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--10a9ed9e-a315-456e-abb4-835155c922eb","created":"2026-09-04T10:00:05.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7916c33688385525078bee504c90f359","description":"Seen in \"Angry Birds: Toy Ghouls’ new toys\" (Kaspersky Securelist). Context: upport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.toml Registry keys: HKLM\\Software\\synapse\\Config\\S","pattern":"[file:hashes.MD5 = '7916c33688385525078bee504c90f359']","pattern_type":"stix","valid_from":"2026-09-04T10:00:05.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c22017ec-1542-4987-913d-a1a254935c28","created":"2026-09-04T10:00:05.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: bfadbeee63a4f0bf19ec9deb8fa58f58","description":"Seen in \"Angry Birds: Toy Ghouls’ new toys\" (Kaspersky Securelist). Context: t.Zapchast.abwo File names and MD5 hashes: cplsupport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.tom","pattern":"[file:hashes.MD5 = 'bfadbeee63a4f0bf19ec9deb8fa58f58']","pattern_type":"stix","valid_from":"2026-09-04T10:00:05.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--edab915b-0ba5-4776-b52a-d564b39dba1d","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4a4c8dcc-0cd1-44bf-8239-6f6b21e4d308","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--57de1fd3-3cab-4299-90e0-1cc9106437c7","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 41444d7018601b599beac0c60ed1bf83","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: dceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 MD5: 41444d7018601b599beac0c60ed1bf83 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '41444d7018601b599beac0c60ed1bf83']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed608634-813f-4b6d-a0ef-e56fbbedd537","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 61e046145ee5cf45aeb033cd71e8b07c","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 MD5: 61e046145ee5cf45aeb033cd71e8b07c Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '61e046145ee5cf45aeb033cd71e8b07c']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eee6c2b9-aba8-4cd4-9e75-98ba09554e66","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7bdbd180c081fa63ca94f9c22c457376","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '7bdbd180c081fa63ca94f9c22c457376']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99391b6b-b467-48a5-858d-53fc2979811f","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 9a47c4d379998ade2f8f99e23a630c06","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '9a47c4d379998ade2f8f99e23a630c06']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--feb84149-1532-40ca-8a1b-82e8c6671350","created":"2026-09-03T02:02:56.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2ec37a7cc8daf20b10e1ad6221061ca5","description":"Seen in \"Honeypot-Omaha and batch.py &#x5b;Guest Diary&#x5d;, (Wed, Sep 2nd)\" (SANS Internet Storm Center). Context: the malicious actor’s secure shell client hash fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5 showing an established session. Attempt number 6 shows a fa","pattern":"[file:hashes.MD5 = '2ec37a7cc8daf20b10e1ad6221061ca5']","pattern_type":"stix","valid_from":"2026-09-03T02:02:56.000Z","labels":["auto-extracted","tooling"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33306"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6b2221a7-4a41-4bfc-b3f0-4300ddeea748","created":"2026-08-18T04:46:34.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 3612f843a42db38f48f59d2a3597e19c","description":"Seen in \"Home & Small Office Wireless Routers Exploited to Attack Gaming Servers\" (Palo Alto Unit 42). Context: d75ee30 ” , uri =“/ ctrlt / DeviceUpgrade_1 ” , response =“ 3612f843a42db38f48f59d2a3597e19c ” , algorithm =“ MD5 ” , qop =“ auth ” , nc = 00000001 , cn","pattern":"[file:hashes.MD5 = '3612f843a42db38f48f59d2a3597e19c']","pattern_type":"stix","valid_from":"2026-08-18T04:46:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/home-small-office-wireless-routers-exploited-to-attack-gaming-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c09579b0-c8de-4b49-bdda-0c45ff0a06db","created":"2026-08-18T04:46:34.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 88645cefb1f9ede0e336e3569d75ee30","description":"Seen in \"Home & Small Office Wireless Routers Exploited to Attack Gaming Servers\" (Palo Alto Unit 42). Context: “ dslf - config ” , realm =“ HuaweiHomeGateway ” , nonce =“ 88645cefb1f9ede0e336e3569d75ee30 ” , uri =“/ ctrlt / DeviceUpgrade_1 ” , response =“ 3612f84","pattern":"[file:hashes.MD5 = '88645cefb1f9ede0e336e3569d75ee30']","pattern_type":"stix","valid_from":"2026-08-18T04:46:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/home-small-office-wireless-routers-exploited-to-attack-gaming-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1de2bb44-8e47-4ab7-a62c-84cced9c895a","created":"2026-08-18T04:46:34.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: f1c099d65bf94e009f5e65238caac468","description":"Seen in \"Home & Small Office Wireless Routers Exploited to Attack Gaming Servers\" (Palo Alto Unit 42). Context: 18b34633f303949a0bb07282dedcd8e9dc Updated JenX Sample MD5: f1c099d65bf94e009f5e65238caac468 SHA256: 676813ee73d382c08765a75204be8bab6bea730ff0073de1076","pattern":"[file:hashes.MD5 = 'f1c099d65bf94e009f5e65238caac468']","pattern_type":"stix","valid_from":"2026-08-18T04:46:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/home-small-office-wireless-routers-exploited-to-attack-gaming-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3d4dac28-af79-4927-ac94-d3e5380563a6","created":"2026-08-18T04:46:34.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: fb93601f8d4e0228276edff1c6fe635d","description":"Seen in \"Home & Small Office Wireless Routers Exploited to Attack Gaming Servers\" (Palo Alto Unit 42). Context: tinuity. Indicators of Compromise Original JenX sample MD5: fb93601f8d4e0228276edff1c6fe635d SHA256: 04463cd1a961f7cd1b77fe6c9e9f5e18b34633f303949a0bb07","pattern":"[file:hashes.MD5 = 'fb93601f8d4e0228276edff1c6fe635d']","pattern_type":"stix","valid_from":"2026-08-18T04:46:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/home-small-office-wireless-routers-exploited-to-attack-gaming-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--98188b83-de5f-440b-ace6-7261947dc9e8","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 79ad2084b057847ce2ec2e48fda64073","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: 80154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2 MD5 79ad2084b057847ce2ec2e48fda64073 Compile Date 2017-12-22 11:54:03 UTC One of the first modif","pattern":"[file:hashes.MD5 = '79ad2084b057847ce2ec2e48fda64073']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e154f070-47f8-47a0-aec8-4b4fd745a3c9","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: dd1876848203d9e10abceec07282ff37","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: d using AES-128 and the following static key (hex-encoded): DD1876848203D9E10ABCEEC07282FF37 Conclusion The Patchwork group continues to plague victims","pattern":"[file:hashes.MD5 = 'dd1876848203d9e10abceec07282ff37']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e927ef83-ba26-43b3-8d28-535e7accdc4e","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: e3e7e71a0b28b5e96cc492e636722f73","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: cation with the C2 (note the additional forward slashes): //e3e7e71a0b28b5e96cc492e636722f73//4sVKAOvu3D//ABDYot0NxyG.php In the event data is uploaded","pattern":"[file:hashes.MD5 = 'e3e7e71a0b28b5e96cc492e636722f73']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--93a31a08-d8b9-4140-b9ce-c53efe33f366","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 6fa5bcedaf124cdaccfa5548eed7f4b0","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 4d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-14 07:20:11 UTC File Type PE32 executa","pattern":"[file:hashes.MD5 = '6fa5bcedaf124cdaccfa5548eed7f4b0']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f16ab27-3046-4478-b172-9ec4563bfc5d","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7c65565dcf5b40bd8358472d032bc8fb","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 32e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-25 00:54:18 UTC File Type PE32 executa","pattern":"[file:hashes.MD5 = '7c65565dcf5b40bd8358472d032bc8fb']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35c5bee6-5b1a-41e8-8a06-da4972e5d140","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a5164c686c405734b7362bc6b02488cb","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: f9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-28 01:54:40 UTC File Type PE32 executa","pattern":"[file:hashes.MD5 = 'a5164c686c405734b7362bc6b02488cb']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1a4807a6-cd68-47a2-b381-2a4fb9d1982d","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: d5679158937ce288837efe62bc1d9693","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: a473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-02 07:57:38 UTC File Type PE32 executa","pattern":"[file:hashes.MD5 = 'd5679158937ce288837efe62bc1d9693']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--adf11ae0-301c-4b43-9849-d123b0076795","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7cc0b212d1b8ceb808c250495d83bae4","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: remainder of the analysis, the following file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0","pattern":"[file:hashes.MD5 = '7cc0b212d1b8ceb808c250495d83bae4']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--449eb76f-0295-400f-ad31-11e193a10fbd","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 8d42c01180be7588a2a68ad96dd0cf85","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: remainder of the analysis, the following file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a79","pattern":"[file:hashes.MD5 = '8d42c01180be7588a2a68ad96dd0cf85']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f7b695aa-a244-481e-a52a-07750d12ef25","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a1bdb1889d960e424920e57366662a59","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: remainder of the analysis, the following file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef42","pattern":"[file:hashes.MD5 = 'a1bdb1889d960e424920e57366662a59']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--95817fd4-a5b1-48d2-b460-2a1df2dfe614","created":"2026-08-17T12:57:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 76429f8515768f9f5def697e71071f51","description":"Seen in \"New Malware 'Rover' Targets Indian Ambassador to Afghanistan\" (Palo Alto Unit 42). Context: l 80386, for MS Windows Architecture : 32 Bits binary MD5 : 76429f8515768f9f5def697e71071f51 SHA1 : d04ce934561934f758d77dfa944bd6743dd82cff SHA256: 775","pattern":"[file:hashes.MD5 = '76429f8515768f9f5def697e71071f51']","pattern_type":"stix","valid_from":"2026-08-17T12:57:39.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/new-malware-rover-targets-indian-ambassador-to-afghanistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd310225-90df-4a6c-a180-90a7320d2c2a","created":"2026-08-17T12:57:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: b5aa366f452feb9f4dff3c72157ca1f9","description":"Seen in \"New Malware 'Rover' Targets Indian Ambassador to Afghanistan\" (Palo Alto Unit 42). Context: LuO7bIWjRO5gjPNq:JarSKu6yzoF8rpAqXYv3XOgQLfnpLuOu imphash : b5aa366f452feb9f4dff3c72157ca1f9 Date : 0x5637227B [Mon Nov 2 08:44:43 2015 UTC] Language :","pattern":"[file:hashes.MD5 = 'b5aa366f452feb9f4dff3c72157ca1f9']","pattern_type":"stix","valid_from":"2026-08-17T12:57:39.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/new-malware-rover-targets-indian-ambassador-to-afghanistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f196748f-fd87-43f0-9208-986928b31796","created":"2026-08-17T12:54:22.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 41ee612602833345fc5bd2b98103811c","description":"Seen in \"Analysis of Smoke Loader in New Tsunami Campaign\" (Palo Alto Unit 42). Context: hash value of the string, MD5(\"Test_PC0B0D040612345678\") = 41EE612602833345FC5BD2B98103811C It then appends the volume serial to the hash value and get","pattern":"[file:hashes.MD5 = '41ee612602833345fc5bd2b98103811c']","pattern_type":"stix","valid_from":"2026-08-17T12:54:22.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/analysis-of-smoke-loader-in-new-tsunami-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d231e800-bd85-4903-97a6-c6e4b3d578b5","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 05d43d417a8f50e7b23246643fc7e03d","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: After decryption, the following payload was identified: MD5 05d43d417a8f50e7b23246643fc7e03d SHA1 67c05b3937d94136eda4a60a2d5fb685abc776a1 SHA256 3fee06","pattern":"[file:hashes.MD5 = '05d43d417a8f50e7b23246643fc7e03d']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1b2dbdc3-baa5-478a-b58d-a4dbea1ae8eb","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 0f1d3ed85fee2acc23a8a26e0dc12e0f","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: tion is provided after it is decrypted by the malware): MD5 0f1d3ed85fee2acc23a8a26e0dc12e0f SHA1 3d161de48d3f4da0aefff685253404c8b0111563 SHA256 fb94a5","pattern":"[file:hashes.MD5 = '0f1d3ed85fee2acc23a8a26e0dc12e0f']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2ea25382-e4cd-42ac-a0f6-4550d6635874","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a2fe5dcb08ae8b72e8bc98ddc0b918e7","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: oject(20180108)\\Final1stspy\\LoadDll\\Release\\LoadDll.pdb MD5 a2fe5dcb08ae8b72e8bc98ddc0b918e7 SHA1 741dbdb20d1beeb8ff809291996c8b78585cb812 SHA256 0669c7","pattern":"[file:hashes.MD5 = 'a2fe5dcb08ae8b72e8bc98ddc0b918e7']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f8fb502-4134-4789-b981-9439b4162816","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: e02024f38dfb6290ce0d693539a285a9","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: was identified. This file had the following properties: MD5 e02024f38dfb6290ce0d693539a285a9 SHA1 d13fc918433c705b49db74c91f56ae6c0cb5cf8d SHA256 66a0c2","pattern":"[file:hashes.MD5 = 'e02024f38dfb6290ce0d693539a285a9']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7ebc7167-eb1f-4c98-8337-8602dce65bb4","created":"2026-08-17T12:22:32.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 3e4015366126dcdbdcc8b5c508a6d25c","description":"Seen in \"The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia\" (Palo Alto Unit 42). Context: s For the analysis below, the following sample is used: MD5 3e4015366126dcdbdcc8b5c508a6d25c SHA1 f459f9cfbd10b136cafb19cbc233a4c8342ad984 SHA256 aef92b","pattern":"[file:hashes.MD5 = '3e4015366126dcdbdcc8b5c508a6d25c']","pattern_type":"stix","valid_from":"2026-08-17T12:22:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-the-fractured-block-campaign-carrotbat-malware-used-to-deliver-malware-targeting-southeast-asia/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--74211f6a-c858-41ce-85b1-e8d668860218","created":"2026-08-17T12:22:32.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a943e196b83c4acd9c5ce13e4c43b4f4","description":"Seen in \"The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia\" (Palo Alto Unit 42). Context: l The downloaded CAB file has the following properties: MD5 a943e196b83c4acd9c5ce13e4c43b4f4 SHA1 e66e416f300c7efb90c383a7630c9cfe901ff9fd SHA256 cfe436","pattern":"[file:hashes.MD5 = 'a943e196b83c4acd9c5ce13e4c43b4f4']","pattern_type":"stix","valid_from":"2026-08-17T12:22:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-the-fractured-block-campaign-carrotbat-malware-used-to-deliver-malware-targeting-southeast-asia/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f5bc4da-3ea1-443a-ad68-82f5e71d831e","created":"2026-08-17T12:21:44.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 0304674e9876530dfbea5a9b4fec7b98","description":"Seen in \"Cardinal RAT Sins Again, Targets Israeli Fin\" (Palo Alto Unit 42). Context: Server: affiliatecollective[.]club C2 Port: 443 Hash Value: 0304674e9876530dfbea5a9b4fec7b98 Additional C2 Servers: 0 GUID: '\\xd6\\x04hr\\x9a\\xedLN\\xae\\xe","pattern":"[file:hashes.MD5 = '0304674e9876530dfbea5a9b4fec7b98']","pattern_type":"stix","valid_from":"2026-08-17T12:21:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cardinal-rat-sins-again-targets-israeli-fin-tech-firms/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--072aa965-f2fc-42b7-b359-97d3b8ce69a6","created":"2026-08-17T11:46:22.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 723df0296951abd2aeed01361cec6b0d","description":"Seen in \"Exploring the Latest Mispadu Stealer Variant\" (Palo Alto Unit 42). Context: 5a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes File Type PE32+ executable (GUI) x86-6","pattern":"[file:hashes.MD5 = '723df0296951abd2aeed01361cec6b0d']","pattern_type":"stix","valid_from":"2026-08-17T11:46:22.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mispadu-infostealer-variant/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e6a26f7f-99df-47b1-a392-669469270ff0","created":"2026-08-06T18:00:01.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"Why metaphor may dictate your security strategy\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-08-06T18:00:01.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b065108-18b5-4f0c-ab21-eb67dbd34ab0","created":"2026-08-06T18:00:01.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"Why metaphor may dictate your security strategy\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-08-06T18:00:01.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--eeef3417-6339-4ae5-b9f6-b6c40cae5ec9","created":"2026-08-06T18:00:01.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7bdbd180c081fa63ca94f9c22c457376","description":"Seen in \"Why metaphor may dictate your security strategy\" (Cisco Talos). Context: 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '7bdbd180c081fa63ca94f9c22c457376']","pattern_type":"stix","valid_from":"2026-08-06T18:00:01.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1b0e1f83-393e-4fe8-977a-11b85c8d463b","created":"2026-08-06T18:00:01.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c2efb2dcacba6d3ccc175b6ce1b7ed0a","description":"Seen in \"Why metaphor may dictate your security strategy\" (Cisco Talos). Context: e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'c2efb2dcacba6d3ccc175b6ce1b7ed0a']","pattern_type":"stix","valid_from":"2026-08-06T18:00:01.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1dc7c27-aabd-446a-87e6-de77d63f0618","created":"2026-07-31T09:44:07.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 082d49ef9f14e6811d68c7e0e82e5069","description":"Seen in \"OctLurk and SilkLurk: new Backdoors in Central Asia\" (Kaspersky Securelist). Context: IntSvc , which loads the loader DLL named oleasapi.dll (MD5 082d49ef9f14e6811d68c7e0e82e5069 ). The ServiceMain parameter in the service’s registry entr","pattern":"[file:hashes.MD5 = '082d49ef9f14e6811d68c7e0e82e5069']","pattern_type":"stix","valid_from":"2026-07-31T09:44:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d804a89e-333f-4993-a055-29298a60d72a","created":"2026-07-31T09:44:07.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2a571f6cee42a17d873f4c942649813f","description":"Seen in \"OctLurk and SilkLurk: new Backdoors in Central Asia\" (Kaspersky Securelist). Context: ogger located at C:\\Users\\Public\\Pictures\\AnyDesk.exe (MD5: 2a571f6cee42a17d873f4c942649813f ). They then created a scheduled task named AnyDesk to run","pattern":"[file:hashes.MD5 = '2a571f6cee42a17d873f4c942649813f']","pattern_type":"stix","valid_from":"2026-07-31T09:44:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f26ddb0b-3eef-4022-82f7-7cbd923a86ff","created":"2026-07-31T09:44:07.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 32a5985543433a4f60da2fafd873b927","description":"Seen in \"OctLurk and SilkLurk: new Backdoors in Central Asia\" (Kaspersky Securelist). Context: tsdump Attackers ran a malicious file named Adobe.exe (MD5 32a5985543433a4f60da2fafd873b927 ), which is a portable‑executable version of Impacket’s sec","pattern":"[file:hashes.MD5 = '32a5985543433a4f60da2fafd873b927']","pattern_type":"stix","valid_from":"2026-07-31T09:44:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--70038264-bd1f-41e5-ae38-11ac542e224c","created":"2026-07-31T09:44:07.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 37dc84e4bcad92fa28f1e7778d088283","description":"Seen in \"OctLurk and SilkLurk: new Backdoors in Central Asia\" (Kaspersky Securelist). Context: rd Decryptor tool C:\\users\\[username]\\libraries\\64.exe (MD5 37dc84e4bcad92fa28f1e7778d088283 ) is used to extract passwords from browsers. The tool offe","pattern":"[file:hashes.MD5 = '37dc84e4bcad92fa28f1e7778d088283']","pattern_type":"stix","valid_from":"2026-07-31T09:44:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ee6c4e2b-490d-43c8-87f3-01f9d5db8347","created":"2026-07-31T09:44:07.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 45cf5916fab4272a1313c26e67aa9220","description":"Seen in \"OctLurk and SilkLurk: new Backdoors in Central Asia\" (Kaspersky Securelist). Context: executing the script located at C:\\windows\\temp\\in.bat (MD5 45cf5916fab4272a1313c26e67aa9220, 4e6d5c4770d5a822d7fcce6a74f7ad73). After querying the task","pattern":"[file:hashes.MD5 = '45cf5916fab4272a1313c26e67aa9220']","pattern_type":"stix","valid_from":"2026-07-31T09:44:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e06925d9-e767-486b-9191-b9100de35101","created":"2026-07-31T09:44:07.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 4e6d5c4770d5a822d7fcce6a74f7ad73","description":"Seen in \"OctLurk and SilkLurk: new Backdoors in Central Asia\" (Kaspersky Securelist). Context: \\windows\\temp\\in.bat (MD5 45cf5916fab4272a1313c26e67aa9220, 4e6d5c4770d5a822d7fcce6a74f7ad73). After querying the task’s status, the attacker triggers i","pattern":"[file:hashes.MD5 = '4e6d5c4770d5a822d7fcce6a74f7ad73']","pattern_type":"stix","valid_from":"2026-07-31T09:44:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6f8ec6a2-0666-477f-b4fb-d4f95f7878fc","created":"2026-07-31T09:44:07.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 5e26df131ff0a679a0a2699b723b46e3","description":"Seen in \"OctLurk and SilkLurk: new Backdoors in Central Asia\" (Kaspersky Securelist). Context: ther C:\\Users\\[username]\\1.bat or C:\\ProgramData\\1.bat (MD5 5e26df131ff0a679a0a2699b723b46e3). The task’s status is first queried, then it is executed,","pattern":"[file:hashes.MD5 = '5e26df131ff0a679a0a2699b723b46e3']","pattern_type":"stix","valid_from":"2026-07-31T09:44:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b90e2c58-8ec3-43e5-b35f-127c92ea99b4","created":"2026-07-31T09:44:07.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 6ecf84fb18f6747ed08d7598364d853a","description":"Seen in \"OctLurk and SilkLurk: new Backdoors in Central Asia\" (Kaspersky Securelist). Context: tch script located at C:\\Users\\<username>\\Videos\\1.bat (MD5 6ecf84fb18f6747ed08d7598364d853a ). Prior to executing the task, the actor queries its statu","pattern":"[file:hashes.MD5 = '6ecf84fb18f6747ed08d7598364d853a']","pattern_type":"stix","valid_from":"2026-07-31T09:44:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32a63af2-e2d6-486f-9cf8-e09cb684c5f2","created":"2026-07-31T09:44:07.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: b874123a80fc4f40e06872b9cb54ebc6","description":"Seen in \"OctLurk and SilkLurk: new Backdoors in Central Asia\" (Kaspersky Securelist). Context: the batch script C:\\Users\\[username]\\Desktop\\auto.bat (MD5 b874123a80fc4f40e06872b9cb54ebc6 ). The script created a service named Cusrxsrv , which load","pattern":"[file:hashes.MD5 = 'b874123a80fc4f40e06872b9cb54ebc6']","pattern_type":"stix","valid_from":"2026-07-31T09:44:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7f072343-0804-43c0-824e-bc36d191b3d1","created":"2026-07-31T09:44:07.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: cf903e4a1629aa0582fd0363b5786676","description":"Seen in \"OctLurk and SilkLurk: new Backdoors in Central Asia\" (Kaspersky Securelist). Context: services. The executable is dropped to %TEMP%\\fc.exe (MD5: cf903e4a1629aa0582fd0363b5786676) and writes its output to %TEMP%\\result.txt . Using Fscan,","pattern":"[file:hashes.MD5 = 'cf903e4a1629aa0582fd0363b5786676']","pattern_type":"stix","valid_from":"2026-07-31T09:44:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--42f82583-530e-48ef-ab2d-c3a81e96727a","created":"2026-07-30T18:52:40.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"You were onto something with “It’s the Climb,” Miley\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-07-30T18:52:40.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d51c5217-5748-44bd-95a2-8d2f9faff0c3","created":"2026-07-30T18:52:40.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"You were onto something with “It’s the Climb,” Miley\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-07-30T18:52:40.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--70bb343a-0079-43a4-92c1-562ca4811a1a","created":"2026-07-30T18:52:40.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7bdbd180c081fa63ca94f9c22c457376","description":"Seen in \"You were onto something with “It’s the Climb,” Miley\" (Cisco Talos). Context: 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '7bdbd180c081fa63ca94f9c22c457376']","pattern_type":"stix","valid_from":"2026-07-30T18:52:40.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--df8ef0ba-af50-4410-818a-ec047fe150b3","created":"2026-07-30T18:52:40.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c2efb2dcacba6d3ccc175b6ce1b7ed0a","description":"Seen in \"You were onto something with “It’s the Climb,” Miley\" (Cisco Talos). Context: e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'c2efb2dcacba6d3ccc175b6ce1b7ed0a']","pattern_type":"stix","valid_from":"2026-07-30T18:52:40.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7396b566-e242-49af-b107-9fc8f3fc34b2","created":"2026-07-30T18:52:40.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: ded73d04bb3e3525226de64c38a332e3","description":"Seen in \"You were onto something with “It’s the Climb,” Miley\" (Cisco Talos). Context: 6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 MD5: ded73d04bb3e3525226de64c38a332e3 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'ded73d04bb3e3525226de64c38a332e3']","pattern_type":"stix","valid_from":"2026-07-30T18:52:40.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b8c5940d-ad6d-402a-b074-bd89f6d6b7fd","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 18f61c6d686cffd131c9fd3f3437064b","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: AD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9","pattern":"[file:hashes.MD5 = '18f61c6d686cffd131c9fd3f3437064b']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65ec6eae-2e19-4cc5-a8e7-375a9d78f002","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 25480dad40152ef3d0c6d38eecc9bd9b","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F34","pattern":"[file:hashes.MD5 = '25480dad40152ef3d0c6d38eecc9bd9b']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--94a2e48b-ec48-4333-9ca4-3365c2eb7c63","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 34a7f28e0bb69b0d49bacc88bdf20ac1","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe 34A7F28E0BB69B0D49BACC88BDF20AC1 run.exe, run2.exe, genie.exe 5D62C1349B8981C396C9A23F4F8F05","pattern":"[file:hashes.MD5 = '34a7f28e0bb69b0d49bacc88bdf20ac1']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--51429f14-109d-4167-a422-3163941f47fa","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 34b8828635f88078735799a3c1ac8e28","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: 4F8F053C genie_encrypt.exe A8842616C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB3","pattern":"[file:hashes.MD5 = '34b8828635f88078735799a3c1ac8e28']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--efd9f479-8397-450a-80e1-540744178c60","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 3a4479b51890373bfc4a011ef41fe376","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F069660166D61FD74F911 GenieLocker for Linux and","pattern":"[file:hashes.MD5 = '3a4479b51890373bfc4a011ef41fe376']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4df1fb10-943e-4d00-b56d-459353839a9a","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 58c0dda52b8f069660166d61fd74f911","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: 7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F069660166D61FD74F911 GenieLocker for Linux and ESXi 9201E35E2993612612919A3C7130","pattern":"[file:hashes.MD5 = '58c0dda52b8f069660166d61fd74f911']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7648de7b-35cf-4f5c-ba70-c6e5454e0d42","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 5d62c1349b8981c396c9a23f4f8f053c","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: Trojan for Windows The Windows version of GenieLocker (MD5: 5d62c1349b8981c396c9a23f4f8f053c) is primarily written in C, but compiled with the C++ libra","pattern":"[file:hashes.MD5 = '5d62c1349b8981c396c9a23f4f8f053c']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--06aeda84-03fa-4bbe-a1fb-9aaa6e87a3b0","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 780c8f4c6f077da4da96582987920362","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: 0C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe","pattern":"[file:hashes.MD5 = '780c8f4c6f077da4da96582987920362']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e9d0df9-2e61-49cc-9108-d414c5ddf1f1","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7dad78584795aa5c160520cc6accf260","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969","pattern":"[file:hashes.MD5 = '7dad78584795aa5c160520cc6accf260']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c42cd959-e669-4fc4-b2d1-3c7af94aed00","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 824ca1e906cc073ee5b0f3519df69a8f","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: 50DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6A","pattern":"[file:hashes.MD5 = '824ca1e906cc073ee5b0f3519df69a8f']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--116549bf-bc52-4233-aeba-891aebb1c5ed","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 9201e35e2993612612919a3c71302cab","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: ounterpart, the Linux and ESXi version of GenieLocker (MD5: 9201e35e2993612612919a3c71302cab) is simpler: there is no secret argument, anti‑debugging te","pattern":"[file:hashes.MD5 = '9201e35e2993612612919a3c71302cab']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce43a1af-4d82-48cc-8df4-e25643867288","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 9969a8221312dba70dd5cbddf83a146c","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: F260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09","pattern":"[file:hashes.MD5 = '9969a8221312dba70dd5cbddf83a146c']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--07c5d893-2c6e-4bb0-9ae2-5f95cb8f1d63","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 9cd514ff2809ce0b993e3b8649e82a94","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: C3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EEC","pattern":"[file:hashes.MD5 = '9cd514ff2809ce0b993e3b8649e82a94']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9470fb27-97bb-4572-b8d6-ee12b7dfd38b","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a50eaaf514f4f84e61ca2455a8789753","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: ntact: intelreports@kaspersky.com . GenieLocker for Windows A50EAAF514F4F84E61CA2455A8789753 kftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0","pattern":"[file:hashes.MD5 = 'a50eaaf514f4f84e61ca2455a8789753']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3a520324-bc89-4c35-8a01-9ba862380c7d","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a8842616c9057d5cf6e1fe1fa8c3c160","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: enie.exe 5D62C1349B8981C396C9A23F4F8F053C genie_encrypt.exe A8842616C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0","pattern":"[file:hashes.MD5 = 'a8842616c9057d5cf6e1fe1fa8c3c160']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35e344a3-cd7d-4214-afba-1bf57891de51","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: b893eafed0659f70d4ac250f09073723","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: 221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373B","pattern":"[file:hashes.MD5 = 'b893eafed0659f70d4ac250f09073723']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8ad743a2-27e6-47c7-b3a8-292734dc4bf1","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c68b6862725777651085650db34947fc","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: 8635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906C","pattern":"[file:hashes.MD5 = 'c68b6862725777651085650db34947fc']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4efbeced-0dd3-46e4-9d2f-2c7072b02994","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: d3e06eb34d8eee7ef92cac3ad0a20ff5","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: 16C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF280","pattern":"[file:hashes.MD5 = 'd3e06eb34d8eee7ef92cac3ad0a20ff5']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0aefc2eb-e2af-43bc-acff-c3f71ca354ca","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: d661cf666b9acbab7cfeae1127a261a9","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: 6E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F0696","pattern":"[file:hashes.MD5 = 'd661cf666b9acbab7cfeae1127a261a9']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9ae28b4a-7e15-4e21-9b26-e65fcc180ffc","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: d87d0b01d95acc936b7dc47b8f41937a","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: B50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe 34A7F28E0BB69B0D49BACC88BDF20AC1","pattern":"[file:hashes.MD5 = 'd87d0b01d95acc936b7dc47b8f41937a']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--690d46c1-b1c8-4ede-a281-4debedeb7dec","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: de3cfbb50f66079bfee20a6f64e59433","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: 6F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F","pattern":"[file:hashes.MD5 = 'de3cfbb50f66079bfee20a6f64e59433']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80bc2d7f-3176-4710-8f2f-3a838ff9c72f","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: f08f476f26b01d142ca73923de65fc0c","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: 50EAAF514F4F84E61CA2455A8789753 kftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64","pattern":"[file:hashes.MD5 = 'f08f476f26b01d142ca73923de65fc0c']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--78edcfc8-457b-4e4d-a4a2-55d1555f9118","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: f7b9e36e94163a9a303160945f99267a","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: 064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127","pattern":"[file:hashes.MD5 = 'f7b9e36e94163a9a303160945f99267a']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d204ea6-c5ff-432b-9a60-f455d923b6bc","created":"2026-07-30T08:00:57.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: fd46a80c2f45577263328984edf7f4dc","description":"Seen in \"New GenieLocker ransomware for Windows, ESXi, and Linux\" (Kaspersky Securelist). Context: ftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987","pattern":"[file:hashes.MD5 = 'fd46a80c2f45577263328984edf7f4dc']","pattern_type":"stix","valid_from":"2026-07-30T08:00:57.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b4ad2a4c-dd14-4544-a0cf-c73151dd4776","created":"2026-07-28T09:18:10.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 42f847597109da2a220391bb09d00676","description":"Seen in \"Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools\" (Kaspersky Securelist). Context: e WebSocket tunneling tool 5FA15EF96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CC6F498 BridgeHead WebSocket tunne","pattern":"[file:hashes.MD5 = '42f847597109da2a220391bb09d00676']","pattern_type":"stix","valid_from":"2026-07-28T09:18:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/mirage-kitten-new-tools/120811/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ed9d96ee-d94a-4627-8ef9-86e1308b3632","created":"2026-07-28T09:18:10.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 5fa15ef96808ea82f0a6176f0bb4b386","description":"Seen in \"Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools\" (Kaspersky Securelist). Context: DBED163679 – sspicli.dll ArcBridge WebSocket tunneling tool 5FA15EF96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33C","pattern":"[file:hashes.MD5 = '5fa15ef96808ea82f0a6176f0bb4b386']","pattern_type":"stix","valid_from":"2026-07-28T09:18:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/mirage-kitten-new-tools/120811/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29c9c891-e077-4426-9c8f-ce83da6784e3","created":"2026-07-28T09:18:10.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 6038d42af0affd1fb263f470c0956f6b","description":"Seen in \"Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools\" (Kaspersky Securelist). Context: 606599C7272CFB33CC6F498 BridgeHead WebSocket tunneling tool 6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7","pattern":"[file:hashes.MD5 = '6038d42af0affd1fb263f470c0956f6b']","pattern_type":"stix","valid_from":"2026-07-28T09:18:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/mirage-kitten-new-tools/120811/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0a9b2c4f-a11a-4c55-8181-9643f9e10862","created":"2026-07-28T09:18:10.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a239e655709a2518dd0b7bdbed163679","description":"Seen in \"Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools\" (Kaspersky Securelist). Context: telreports@kaspersky.com . File hashes NightLedger backdoor A239E655709A2518DD0B7BDBED163679 – sspicli.dll ArcBridge WebSocket tunneling tool 5FA15EF968","pattern":"[file:hashes.MD5 = 'a239e655709a2518dd0b7bdbed163679']","pattern_type":"stix","valid_from":"2026-07-28T09:18:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/mirage-kitten-new-tools/120811/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7b3ef228-24da-4783-a4d6-4d13f41a58dd","created":"2026-07-28T09:18:10.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: ae628efa305387b633dce82f9364875b","description":"Seen in \"Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools\" (Kaspersky Securelist). Context: tunneling tool 6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthrea","pattern":"[file:hashes.MD5 = 'ae628efa305387b633dce82f9364875b']","pattern_type":"stix","valid_from":"2026-07-28T09:18:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/mirage-kitten-new-tools/120811/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f5f3ebd-50cf-410a-9c48-40d4247faf95","created":"2026-07-28T09:18:10.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: afb1c1583606599c7272cfb33cc6f498","description":"Seen in \"Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools\" (Kaspersky Securelist). Context: F96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CC6F498 BridgeHead WebSocket tunneling tool 6038D42AF0AFFD1FB263F47","pattern":"[file:hashes.MD5 = 'afb1c1583606599c7272cfb33cc6f498']","pattern_type":"stix","valid_from":"2026-07-28T09:18:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/mirage-kitten-new-tools/120811/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--76d55491-493b-49b9-be67-b4d175236758","created":"2026-07-28T09:18:10.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c832ecd135781b11f59e3fffb3d2b6ac","description":"Seen in \"Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools\" (Kaspersky Securelist). Context: ocess of threat hunting, we detected another variant ( MD5: C832ECD135781B11F59E3FFFB3D2B6AC ) that shares the same dynamic-resolve stub pattern. This v","pattern":"[file:hashes.MD5 = 'c832ecd135781b11f59e3fffb3d2b6ac']","pattern_type":"stix","valid_from":"2026-07-28T09:18:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/mirage-kitten-new-tools/120811/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f8661dd-53bd-4a4c-860b-508c5a5bcf35","created":"2026-07-28T09:18:10.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c90f0efadbf322e5eb1c4103a38c30e6","description":"Seen in \"Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools\" (Kaspersky Securelist). Context: .dll F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll D09B14A2FE01C7363ECC56F5D046162C – IP","pattern":"[file:hashes.MD5 = 'c90f0efadbf322e5eb1c4103a38c30e6']","pattern_type":"stix","valid_from":"2026-07-28T09:18:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/mirage-kitten-new-tools/120811/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a51a4d9e-b0e0-4f62-aae6-73e50a66d82c","created":"2026-07-28T09:18:10.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: d09b14a2fe01c7363ecc56f5d046162c","description":"Seen in \"Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools\" (Kaspersky Securelist). Context: .dll C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll D09B14A2FE01C7363ECC56F5D046162C – IPHLPAPI.dll Domains and IPs smartconnect[.]azurewebsites","pattern":"[file:hashes.MD5 = 'd09b14a2fe01c7363ecc56f5d046162c']","pattern_type":"stix","valid_from":"2026-07-28T09:18:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/mirage-kitten-new-tools/120811/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5b9941a1-4c18-465a-8ab3-d50512448c1e","created":"2026-07-28T09:18:10.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: f7d36cc5904a53252d2bb3d21615134f","description":"Seen in \"Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools\" (Kaspersky Securelist). Context: 6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll C90F0EFADBF322E5EB1C4103A38C30E6 – li","pattern":"[file:hashes.MD5 = 'f7d36cc5904a53252d2bb3d21615134f']","pattern_type":"stix","valid_from":"2026-07-28T09:18:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/mirage-kitten-new-tools/120811/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--092308b9-9d9e-408d-b917-b4d35c7ac891","created":"2026-07-27T08:48:47.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c99f29ac08454855b3d538960bb2f34f","description":"Seen in \"TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments\" (The Hacker News). Context: ctive loader codenamed MIXEDKEY to decrypt the contents of \"C99F29AC08454855B3D538960BB2F34F.PCPKEY\" and execute it. Both TELESHIM and MIXEDKEY have bee","pattern":"[file:hashes.MD5 = 'c99f29ac08454855b3d538960bb2f34f']","pattern_type":"stix","valid_from":"2026-07-27T08:48:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/teleshim-abuses-telegram-for-c2-in.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--386fecbc-56d7-4d90-95fe-bcda871c9d3b","created":"2026-07-23T18:00:46.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"Don’t swing at everything\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-07-23T18:00:46.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/dont-swing-at-everything/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--28aef325-8987-4005-891d-20145c97d209","created":"2026-07-23T18:00:46.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"Don’t swing at everything\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-07-23T18:00:46.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/dont-swing-at-everything/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e15c6b46-ec9b-4070-8155-5fc750ab0b94","created":"2026-07-23T18:00:46.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 770dbe473180366d7b539ff2c188e551","description":"Seen in \"Don’t swing at everything\" (Cisco Talos). Context: fd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a MD5: 770dbe473180366d7b539ff2c188e551 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '770dbe473180366d7b539ff2c188e551']","pattern_type":"stix","valid_from":"2026-07-23T18:00:46.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/dont-swing-at-everything/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--44107549-2466-4280-a558-79f82f9b6408","created":"2026-07-23T18:00:46.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c2efb2dcacba6d3ccc175b6ce1b7ed0a","description":"Seen in \"Don’t swing at everything\" (Cisco Talos). Context: e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'c2efb2dcacba6d3ccc175b6ce1b7ed0a']","pattern_type":"stix","valid_from":"2026-07-23T18:00:46.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/dont-swing-at-everything/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--29021835-47a1-4627-a0e2-c9aece4f5d73","created":"2026-07-23T18:00:46.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: dbd8dbecaa80795c135137d69921fdba","description":"Seen in \"Don’t swing at everything\" (Cisco Talos). Context: 05ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'dbd8dbecaa80795c135137d69921fdba']","pattern_type":"stix","valid_from":"2026-07-23T18:00:46.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/dont-swing-at-everything/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d01b35d6-4028-461d-8d01-e41c3c57805f","created":"2026-07-17T09:23:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 19f8befcb035f52bf70094e6b4f5779a","description":"Seen in \"GoSerpent backdoor attacks in Southeast Asia\" (Kaspersky Securelist). Context: 483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B","pattern":"[file:hashes.MD5 = '19f8befcb035f52bf70094e6b4f5779a']","pattern_type":"stix","valid_from":"2026-07-17T09:23:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6392add7-5a63-43c1-98ac-ef34ed767ad1","created":"2026-07-17T09:23:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 64e9d1950e42bc98486dfd9919463d1c","description":"Seen in \"GoSerpent backdoor attacks in Southeast Asia\" (Kaspersky Securelist). Context: 95F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD5","pattern":"[file:hashes.MD5 = '64e9d1950e42bc98486dfd9919463d1c']","pattern_type":"stix","valid_from":"2026-07-17T09:23:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cfc7b0d4-3435-4365-8f5f-9f22062c0367","created":"2026-07-17T09:23:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7f223ee0716ce2ad56f55d3744419449","description":"Seen in \"GoSerpent backdoor attacks in Southeast Asia\" (Kaspersky Securelist). Context: 8486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4","pattern":"[file:hashes.MD5 = '7f223ee0716ce2ad56f55d3744419449']","pattern_type":"stix","valid_from":"2026-07-17T09:23:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1dd3d2a1-824b-4476-90f2-dcd11cc6947d","created":"2026-07-17T09:23:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 846ef7c1c7323849b2a778c5e4cda162","description":"Seen in \"GoSerpent backdoor attacks in Southeast Asia\" (Kaspersky Securelist). Context: E0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4","pattern":"[file:hashes.MD5 = '846ef7c1c7323849b2a778c5e4cda162']","pattern_type":"stix","valid_from":"2026-07-17T09:23:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--617c3d6b-5794-4161-b8fa-0d04269a0d81","created":"2026-07-17T09:23:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 93a1569d5d5ab2c4761fedf84f83709e","description":"Seen in \"GoSerpent backdoor attacks in Southeast Asia\" (Kaspersky Securelist). Context: B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4761FEDF84F83709E C2 IP addresses 152.32.160[.]239 8.220.194[.]108 8.220.214[","pattern":"[file:hashes.MD5 = '93a1569d5d5ab2c4761fedf84f83709e']","pattern_type":"stix","valid_from":"2026-07-17T09:23:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--14362f8f-d15d-483f-9d6e-7ae2a096bc4e","created":"2026-07-17T09:23:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: cb6c4c70a3b171fa3404b8e1a3382116","description":"Seen in \"GoSerpent backdoor attacks in Southeast Asia\" (Kaspersky Securelist). Context: 6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA356","pattern":"[file:hashes.MD5 = 'cb6c4c70a3b171fa3404b8e1a3382116']","pattern_type":"stix","valid_from":"2026-07-17T09:23:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--70579c1d-385d-404f-98ac-b3d854cb9d57","created":"2026-07-17T09:23:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: cbbb6d483737ea3566726e51752dff40","description":"Seen in \"GoSerpent backdoor attacks in Southeast Asia\" (Kaspersky Securelist). Context: A3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4","pattern":"[file:hashes.MD5 = 'cbbb6d483737ea3566726e51752dff40']","pattern_type":"stix","valid_from":"2026-07-17T09:23:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8785a7a9-a8f7-4ff7-b4a0-a0c29309ab64","created":"2026-07-17T09:23:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: d08a059e8b815e3b891505bc8777fc28","description":"Seen in \"GoSerpent backdoor attacks in Southeast Asia\" (Kaspersky Securelist). Context: F70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4761FEDF84F83709E C2 IP addresses 152.32.160","pattern":"[file:hashes.MD5 = 'd08a059e8b815e3b891505bc8777fc28']","pattern_type":"stix","valid_from":"2026-07-17T09:23:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3a42d499-2500-46ca-9320-0e286f9736fa","created":"2026-07-17T09:23:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: d6e86bf8a90e9b632add5fa495f97fbc","description":"Seen in \"GoSerpent backdoor attacks in Southeast Asia\" (Kaspersky Securelist). Context: A690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D195","pattern":"[file:hashes.MD5 = 'd6e86bf8a90e9b632add5fa495f97fbc']","pattern_type":"stix","valid_from":"2026-07-17T09:23:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2e3c1358-9399-4c3d-95b3-cd2c63c07b7d","created":"2026-07-17T09:23:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: dc506ff7bb72735444fb3703a6bee6d8","description":"Seen in \"GoSerpent backdoor attacks in Southeast Asia\" (Kaspersky Securelist). Context: mise File hashes GoSerpent EBFFD5A76AAA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6","pattern":"[file:hashes.MD5 = 'dc506ff7bb72735444fb3703a6bee6d8']","pattern_type":"stix","valid_from":"2026-07-17T09:23:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--478a03cc-0a73-4426-978c-6d83764b4c3e","created":"2026-07-17T09:23:39.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: ebffd5a76aaa690bcdb922f82e0bacc5","description":"Seen in \"GoSerpent backdoor attacks in Southeast Asia\" (Kaspersky Securelist). Context: the future. Indicators of compromise File hashes GoSerpent EBFFD5A76AAA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5","pattern":"[file:hashes.MD5 = 'ebffd5a76aaa690bcdb922f82e0bacc5']","pattern_type":"stix","valid_from":"2026-07-17T09:23:39.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c036919c-6715-4468-aa97-b23612fbdedc","created":"2026-07-16T18:00:50.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 0398df5a18f71efcfeef4571a2cef577","description":"Seen in \"Begun, the Patch Wars have\" (Cisco Talos). Context: 191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a MD5: 0398df5a18f71efcfeef4571a2cef577 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '0398df5a18f71efcfeef4571a2cef577']","pattern_type":"stix","valid_from":"2026-07-16T18:00:50.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/begun-the-patch-wars-have/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d0e3634-ed66-45a4-abb6-dfe4bc134e49","created":"2026-07-16T18:00:50.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"Begun, the Patch Wars have\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-07-16T18:00:50.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/begun-the-patch-wars-have/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cdcac9ab-9438-460a-b45d-0f593a482c83","created":"2026-07-16T18:00:50.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"Begun, the Patch Wars have\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-07-16T18:00:50.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/begun-the-patch-wars-have/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--63de933a-9b01-46a2-a2d8-d7dc73bfe021","created":"2026-07-16T18:00:50.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c2efb2dcacba6d3ccc175b6ce1b7ed0a","description":"Seen in \"Begun, the Patch Wars have\" (Cisco Talos). Context: e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'c2efb2dcacba6d3ccc175b6ce1b7ed0a']","pattern_type":"stix","valid_from":"2026-07-16T18:00:50.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/begun-the-patch-wars-have/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cfe44444-06ba-4714-b824-6aeab5e0a9e8","created":"2026-07-10T21:07:16.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 257bbbbe0a2598872278c87d801d06fd","description":"Seen in \"Friday Squid Blogging: \"Squidbleed\" Vulnerability\" (Schneier on Security). Context: news.com/article/greece-marfin-bank-deaths-firebomb-arrests-257bbbbe0a2598872278c87d801d06fd A highly concerning development out of Greece this week reg","pattern":"[file:hashes.MD5 = '257bbbbe0a2598872278c87d801d06fd']","pattern_type":"stix","valid_from":"2026-07-10T21:07:16.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Schneier on Security","url":"https://www.schneier.com/blog/archives/2026/07/friday-squid-blogging-squidbleed-vulnerability.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--143c57a5-6e36-439b-acb9-0ca0de022745","created":"2026-07-09T18:00:06.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"Winning 54% of the time\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-07-09T18:00:06.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/winning-54-of-the-time/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9516715a-4f41-42a5-aaf5-7ba89a481fdd","created":"2026-07-09T18:00:06.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"Winning 54% of the time\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-07-09T18:00:06.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/winning-54-of-the-time/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de3c69e3-c5eb-4ff6-8222-a332cefb3caa","created":"2026-07-09T18:00:06.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 9b512ba139304c247ddd3d2c4b9179fd","description":"Seen in \"Winning 54% of the time\" (Cisco Talos). Context: 9e8aa423684827b4375a35684c71c600f2dd9101f235e8ec633488 MD5: 9b512ba139304c247ddd3d2c4b9179fd Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '9b512ba139304c247ddd3d2c4b9179fd']","pattern_type":"stix","valid_from":"2026-07-09T18:00:06.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/winning-54-of-the-time/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b21709d0-e9bc-4732-b044-441a4b68d48b","created":"2026-07-09T18:00:06.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: cc4d231df34e57f59eb970353c7d9de2","description":"Seen in \"Winning 54% of the time\" (Cisco Talos). Context: a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'cc4d231df34e57f59eb970353c7d9de2']","pattern_type":"stix","valid_from":"2026-07-09T18:00:06.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/winning-54-of-the-time/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--05d95c22-fcd6-4cb3-ae38-b2455b9869b0","created":"2026-07-02T18:00:34.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"Catan and Mouse\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-07-02T18:00:34.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/catan-and-mouse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1f6f8dc7-2a3f-49f4-94cb-6096a4835b0c","created":"2026-07-02T18:00:34.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"Catan and Mouse\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-07-02T18:00:34.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/catan-and-mouse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e8f5700-3d44-4cd0-b490-b767ee498855","created":"2026-07-02T18:00:34.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 41acb30b9d662d48b7b4fc0ac3d4b79f","description":"Seen in \"Catan and Mouse\" (Cisco Talos). Context: 1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453 MD5: 41acb30b9d662d48b7b4fc0ac3d4b79f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '41acb30b9d662d48b7b4fc0ac3d4b79f']","pattern_type":"stix","valid_from":"2026-07-02T18:00:34.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/catan-and-mouse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--70daede8-4478-4ddb-84b8-7b761f5f76ef","created":"2026-07-02T18:00:34.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: bf9672ec85283fdf002d83662f0b08b7","description":"Seen in \"Catan and Mouse\" (Cisco Talos). Context: dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe MD5: bf9672ec85283fdf002d83662f0b08b7 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'bf9672ec85283fdf002d83662f0b08b7']","pattern_type":"stix","valid_from":"2026-07-02T18:00:34.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/catan-and-mouse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d493d082-fb0c-4586-be43-eef39d93b5ef","created":"2026-07-02T18:00:34.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: cc4d231df34e57f59eb970353c7d9de2","description":"Seen in \"Catan and Mouse\" (Cisco Talos). Context: a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'cc4d231df34e57f59eb970353c7d9de2']","pattern_type":"stix","valid_from":"2026-07-02T18:00:34.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/catan-and-mouse/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1628b3d7-ad1c-42d3-a2de-d14227cc03d2","created":"2026-06-26T00:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 1b67183acc18d7641917f4fe07c1b053","description":"Seen in \"RedAlpha: New Campaigns Discovered Targeting the Tibetan Community\" (Recorded Future). Context: ampaign, we were unable to acquire one of the samples (MD5: 1b67183acc18d7641917f4fe07c1b053) from common malware multiscanner repositories at the time","pattern":"[file:hashes.MD5 = '1b67183acc18d7641917f4fe07c1b053']","pattern_type":"stix","valid_from":"2026-06-26T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/redalpha-cyber-campaigns"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce599ddd-d2b8-4ebf-a281-8eb7653390e7","created":"2026-06-26T00:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: e6c0ac26b473d1e0fa9f74fdf1d01af8","description":"Seen in \"RedAlpha: New Campaigns Discovered Targeting the Tibetan Community\" (Recorded Future). Context: nce executed, the lure document loads an embedded DLL (MD5: e6c0ac26b473d1e0fa9f74fdf1d01af8) that drops the validator implant into the users “Temp” dir","pattern":"[file:hashes.MD5 = 'e6c0ac26b473d1e0fa9f74fdf1d01af8']","pattern_type":"stix","valid_from":"2026-06-26T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/redalpha-cyber-campaigns"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d5803d6c-3009-400b-b0c7-dd8b36dd307c","created":"2026-06-25T18:00:26.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"Beyond IOCs: AI\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-06-25T18:00:26.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/beyond-iocs-ai-enabled-threat-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bbaaa656-08c9-4522-9fca-1bbbe20996de","created":"2026-06-25T18:00:26.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"Beyond IOCs: AI\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-06-25T18:00:26.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/beyond-iocs-ai-enabled-threat-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--253ca084-07c9-4f26-a021-2abdbe95ae0c","created":"2026-06-25T18:00:26.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 41acb30b9d662d48b7b4fc0ac3d4b79f","description":"Seen in \"Beyond IOCs: AI\" (Cisco Talos). Context: 1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453 MD5: 41acb30b9d662d48b7b4fc0ac3d4b79f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '41acb30b9d662d48b7b4fc0ac3d4b79f']","pattern_type":"stix","valid_from":"2026-06-25T18:00:26.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/beyond-iocs-ai-enabled-threat-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32dd09ea-b6f9-41d0-ae58-4703abd0e2af","created":"2026-06-25T18:00:26.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: cc4d231df34e57f59eb970353c7d9de2","description":"Seen in \"Beyond IOCs: AI\" (Cisco Talos). Context: a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'cc4d231df34e57f59eb970353c7d9de2']","pattern_type":"stix","valid_from":"2026-06-25T18:00:26.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/beyond-iocs-ai-enabled-threat-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a3bb187e-dfc7-455f-8611-03fec363214e","created":"2026-06-25T18:00:26.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: dbd8dbecaa80795c135137d69921fdba","description":"Seen in \"Beyond IOCs: AI\" (Cisco Talos). Context: 05ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'dbd8dbecaa80795c135137d69921fdba']","pattern_type":"stix","valid_from":"2026-06-25T18:00:26.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/beyond-iocs-ai-enabled-threat-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0ee55707-cdd0-47d3-8232-2151c73e14e2","created":"2026-06-24T14:23:53.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 1f65544978b8ea0e745e573b8ee9684b","description":"Seen in \"StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon\" (Kaspersky Securelist). Context: er sample, discovered on a machine located in Lebanon (MD5: 1F65544978B8EA0E745E573B8EE9684B), the dropper extracts and decompresses SystemSettings.dll","pattern":"[file:hashes.MD5 = '1f65544978b8ea0e745e573b8ee9684b']","pattern_type":"stix","valid_from":"2026-06-24T14:23:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/strikeshark-campaign/120326/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1512607f-bf78-4c76-9e49-462bb4f244cf","created":"2026-06-24T14:23:53.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 24fcebdeecba65004fdb0923763d74fd","description":"Seen in \"StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon\" (Kaspersky Securelist). Context: licious dropper named 一种异常状况的截图（包括操作系统和输入法版本）.pdf.exe (MD5: 24FCEBDEECBA65004FDB0923763D74FD), which was identified in a campaign targeting a government","pattern":"[file:hashes.MD5 = '24fcebdeecba65004fdb0923763d74fd']","pattern_type":"stix","valid_from":"2026-06-24T14:23:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/strikeshark-campaign/120326/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--97829e3a-f616-4ad2-86e0-20b5443bc28f","created":"2026-06-24T14:23:53.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 9cbd560f820c95d7c38342cd558cb5c6","description":"Seen in \"StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon\" (Kaspersky Securelist). Context: DscCoreR.mui A514D1BB62D7916475946FE7C07AC0AA SyncRest.dat 9CBD560F820C95D7C38342CD558CB5C6 “PerfectDLL Hijacking” technique Once the malicious DLL is","pattern":"[file:hashes.MD5 = '9cbd560f820c95d7c38342cd558cb5c6']","pattern_type":"stix","valid_from":"2026-06-24T14:23:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/strikeshark-campaign/120326/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9781bd45-9240-4b83-9aad-93634f94f4bd","created":"2026-06-24T14:23:53.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: a514d1bb62d7916475946fe7c07ac0aa","description":"Seen in \"StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon\" (Kaspersky Securelist). Context: mSettings.dll AA3086BE652C8B20B0B29B2730D57119 DscCoreR.mui A514D1BB62D7916475946FE7C07AC0AA SyncRest.dat 9CBD560F820C95D7C38342CD558CB5C6 “PerfectDLL H","pattern":"[file:hashes.MD5 = 'a514d1bb62d7916475946fe7c07ac0aa']","pattern_type":"stix","valid_from":"2026-06-24T14:23:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/strikeshark-campaign/120326/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--238094bf-bc29-45f0-a7e4-72e45a41dd53","created":"2026-06-24T14:23:53.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: aa3086be652c8b20b0b29b2730d57119","description":"Seen in \"StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon\" (Kaspersky Securelist). Context: ngs.exe D98F568496512E4F98670C61C97CB07A SystemSettings.dll AA3086BE652C8B20B0B29B2730D57119 DscCoreR.mui A514D1BB62D7916475946FE7C07AC0AA SyncRest.dat","pattern":"[file:hashes.MD5 = 'aa3086be652c8b20b0b29b2730d57119']","pattern_type":"stix","valid_from":"2026-06-24T14:23:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/strikeshark-campaign/120326/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--90b45d86-3192-4b70-babc-746dc7328078","created":"2026-06-24T14:23:53.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: d98f568496512e4f98670c61c97cb07a","description":"Seen in \"StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon\" (Kaspersky Securelist). Context: overnment entity in Taiwan. Filename MD5 SystemSettings.exe D98F568496512E4F98670C61C97CB07A SystemSettings.dll AA3086BE652C8B20B0B29B2730D57119 DscCore","pattern":"[file:hashes.MD5 = 'd98f568496512e4f98670c61c97cb07a']","pattern_type":"stix","valid_from":"2026-06-24T14:23:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/strikeshark-campaign/120326/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0400db7-5d47-47f1-8ddf-7103bfd1d5ed","created":"2026-06-24T00:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 95b3ec0a4e539efaa1faa3d4e25d51de","description":"Seen in \"Enriching User Behavior Analytics With Threat Intelligence\" (Recorded Future). Context: machine on the network to execute a file with the MD5 hash 95b3ec0a4e539efaa1faa3d4e25d51de. A quick search in Recorded Future shows that this hash is","pattern":"[file:hashes.MD5 = '95b3ec0a4e539efaa1faa3d4e25d51de']","pattern_type":"stix","valid_from":"2026-06-24T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/blog/user-behavior-analytics"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a9a0cb1-c85d-4fac-aa78-32823f2e3b33","created":"2026-06-23T00:00:00.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 857ef30bf15ea3da9b94092da78ef0fc","description":"Seen in \"Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access\" (Recorded Future). Context: wiper used in the Middle East. It is likely that this file (857ef30bf15ea3da9b94092da78ef0fc) is the wiper in question. In 2012, APT33 deployed the dest","pattern":"[file:hashes.MD5 = '857ef30bf15ea3da9b94092da78ef0fc']","pattern_type":"stix","valid_from":"2026-06-23T00:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Recorded Future","url":"https://www.recordedfuture.com/research/iranian-cyber-response"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8dd43df-28af-47b3-99f4-b26ea9f8d546","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 02bb20455cc592a69c080abac770ce90","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 0ba93109757776a44de9d8c88baa4963 Financial Reports(C1).vbs 02bb20455cc592a69c080abac770ce90 Le formulaire de demande le plus récent .vbs 6c39900d77dcba","pattern":"[file:hashes.MD5 = '02bb20455cc592a69c080abac770ce90']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aa1b24b8-c9b1-4527-bf3b-93e044c1a44d","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 05d188f071d097f5b6bd8138749b4b14","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 708e050632a4280cabf98ac1376b7 Outstanding Balance Sheet.vbs 05d188f071d097f5b6bd8138749b4b14 Penyata bank.vbs 2c6f05f1f309d89b2236e6c8b59c88f9 Account S","pattern":"[file:hashes.MD5 = '05d188f071d097f5b6bd8138749b4b14']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e085888-659f-472c-a8d0-0fcbd791e060","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 0ba93109757776a44de9d8c88baa4963","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: s 20209b3a32769afc6a75694b8d8839dd Statement of Debt(A).vbs 0ba93109757776a44de9d8c88baa4963 Financial Reports(C1).vbs 02bb20455cc592a69c080abac770ce90","pattern":"[file:hashes.MD5 = '0ba93109757776a44de9d8c88baa4963']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a56e43fa-fefb-4b25-b511-90acef0a01cc","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 1a3cc75466ffb1971482f7abf7aabc3f","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: cf iowepv.vbs 8c6d9fc389ad3f20ccbc71d77eb39bfa btksfmsi.vbs 1a3cc75466ffb1971482f7abf7aabc3f home3.vbs 1c47c63e5ed25060d95359c57c77b107 zipats.vbs 31037","pattern":"[file:hashes.MD5 = '1a3cc75466ffb1971482f7abf7aabc3f']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32069a33-7715-4a8f-9553-5979bc360c98","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 1c47c63e5ed25060d95359c57c77b107","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: bfa btksfmsi.vbs 1a3cc75466ffb1971482f7abf7aabc3f home3.vbs 1c47c63e5ed25060d95359c57c77b107 zipats.vbs 31037a42ca048e06e69a78f55bc2eff5 1122.vbs 7f1644","pattern":"[file:hashes.MD5 = '1c47c63e5ed25060d95359c57c77b107']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d02bcbd9-215a-4a4c-a63f-bbf6d6fcbf51","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 1d94fbe9cab21278cc3f104bea334d08","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: .vbs 993f4c0cadbc769a4b0ed62a918db58d FinancialReportsS.vbs 1d94fbe9cab21278cc3f104bea334d08 Promissory_Note(b).vbs 9d9ac85765e4a818a3ccabe2cf4fef82 Deb","pattern":"[file:hashes.MD5 = '1d94fbe9cab21278cc3f104bea334d08']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--252f6710-f95a-4042-aec3-49b9a3edd7b8","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 20209b3a32769afc6a75694b8d8839dd","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 4044e4b6471c9de7b0a4ba37d9d9df9a billing statement (2).vbs 20209b3a32769afc6a75694b8d8839dd Statement of Debt(A).vbs 0ba93109757776a44de9d8c88baa4963 F","pattern":"[file:hashes.MD5 = '20209b3a32769afc6a75694b8d8839dd']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--01ba1661-fb77-4709-bca7-137b71986963","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2c6f05f1f309d89b2236e6c8b59c88f9","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: Sheet.vbs 05d188f071d097f5b6bd8138749b4b14 Penyata bank.vbs 2c6f05f1f309d89b2236e6c8b59c88f9 Account Statement（13K） (2).vbs 3b1aba44dd3d9b6339b6f56e2f42","pattern":"[file:hashes.MD5 = '2c6f05f1f309d89b2236e6c8b59c88f9']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65a566c0-14fc-4c53-b57d-aa64212f8c12","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 31037a42ca048e06e69a78f55bc2eff5","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: abc3f home3.vbs 1c47c63e5ed25060d95359c57c77b107 zipats.vbs 31037a42ca048e06e69a78f55bc2eff5 1122.vbs 7f16449cd0c4862d1eadf8a5742bf09a payload_1.vbs 79e","pattern":"[file:hashes.MD5 = '31037a42ca048e06e69a78f55bc2eff5']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3d60bc9c-20f6-4f53-b966-4ec6cc7466dd","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 3b1aba44dd3d9b6339b6f56e2f42034b","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 05f1f309d89b2236e6c8b59c88f9 Account Statement（13K） (2).vbs 3b1aba44dd3d9b6339b6f56e2f42034b Statement of Account.txt d43fdaa1f0ee09d7e5f0f94ee9df7b6c B","pattern":"[file:hashes.MD5 = '3b1aba44dd3d9b6339b6f56e2f42034b']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9eb11881-286e-4670-b1e0-ba4d1ebaa0ba","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 4044e4b6471c9de7b0a4ba37d9d9df9a","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 0593e8e0e8fac49429e9b45ebf7fa1 Outstanding Payment List.vbs 4044e4b6471c9de7b0a4ba37d9d9df9a billing statement (2).vbs 20209b3a32769afc6a75694b8d8839dd","pattern":"[file:hashes.MD5 = '4044e4b6471c9de7b0a4ba37d9d9df9a']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c282bf92-9d8c-4f4b-b197-94af2ef3ee4e","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 4f0593e8e0e8fac49429e9b45ebf7fa1","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 5002eca748205d544618e3bd2dedc223 Statement of Debt(29K).vbs 4f0593e8e0e8fac49429e9b45ebf7fa1 Outstanding Payment List.vbs 4044e4b6471c9de7b0a4ba37d9d9df","pattern":"[file:hashes.MD5 = '4f0593e8e0e8fac49429e9b45ebf7fa1']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--380c4bb2-b7a1-40da-be73-99aeaa0cf524","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 5002eca748205d544618e3bd2dedc223","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 5b6bbcc06cf08cc99e1afeda486d42fb Extrato de Conciliação.vbs 5002eca748205d544618e3bd2dedc223 Statement of Debt(29K).vbs 4f0593e8e0e8fac49429e9b45ebf7fa1","pattern":"[file:hashes.MD5 = '5002eca748205d544618e3bd2dedc223']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4e775909-ad3d-4b10-a4f0-8762fc095ec9","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 5b6bbcc06cf08cc99e1afeda486d42fb","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: ).vbs 6359e6236471cbe434d0ef4c42b7f879 Applicationform1.vbs 5b6bbcc06cf08cc99e1afeda486d42fb Extrato de Conciliação.vbs 5002eca748205d544618e3bd2dedc223","pattern":"[file:hashes.MD5 = '5b6bbcc06cf08cc99e1afeda486d42fb']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91266096-bd01-4bfe-8422-4b3e7beb7d63","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 6359e6236471cbe434d0ef4c42b7f879","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 66442f2457eca8f47385b1fb2c6fcab8 Statement of Debt(30K).vbs 6359e6236471cbe434d0ef4c42b7f879 Applicationform1.vbs 5b6bbcc06cf08cc99e1afeda486d42fb Extra","pattern":"[file:hashes.MD5 = '6359e6236471cbe434d0ef4c42b7f879']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5df717ff-ac5b-49c8-b338-a86104be3c00","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 63ac85195b73753333316a889cf5880f","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: .vbs df4fa0369eaca5cec348be293890d4af Account Statement.vbs 63ac85195b73753333316a889cf5880f Statement of Account(O).vbs 74fd9f91fc93b6288b4fc253ea5b3e2","pattern":"[file:hashes.MD5 = '63ac85195b73753333316a889cf5880f']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d974ba3e-aa1e-47ce-9524-ec11da8871d3","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 66442f2457eca8f47385b1fb2c6fcab8","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: (4).vbs 68c16c46f8afb9e00bbaba0207fb0a46 Debt Note (2).vbs 66442f2457eca8f47385b1fb2c6fcab8 Statement of Debt(30K).vbs 6359e6236471cbe434d0ef4c42b7f879","pattern":"[file:hashes.MD5 = '66442f2457eca8f47385b1fb2c6fcab8']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0f069480-8c5f-444b-8969-5c97f81c24d0","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 66705384a7ad81d14c34fc6c054a0ecf","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 58e5c0 dfjieya.vbs 8c3322009b8982663c0cbecd9492e7eb 0lf.vbs 66705384a7ad81d14c34fc6c054a0ecf iowepv.vbs 8c6d9fc389ad3f20ccbc71d77eb39bfa btksfmsi.vbs 1a","pattern":"[file:hashes.MD5 = '66705384a7ad81d14c34fc6c054a0ecf']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--177dba01-4e68-4ab4-a33f-3766cf3171e8","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 68c16c46f8afb9e00bbaba0207fb0a46","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 7403cbcc5a9c32384d431856dc48fcc9 Statement of debt (4).vbs 68c16c46f8afb9e00bbaba0207fb0a46 Debt Note (2).vbs 66442f2457eca8f47385b1fb2c6fcab8 Statemen","pattern":"[file:hashes.MD5 = '68c16c46f8afb9e00bbaba0207fb0a46']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8de428cd-8543-4c43-baaf-0bbb2599d459","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 6c39900d77dcba158e1d27c7619cb06d","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 080abac770ce90 Le formulaire de demande le plus récent .vbs 6c39900d77dcba158e1d27c7619cb06d Outstanding Balance Sheet(A).vbs dad708e050632a4280cabf98ac","pattern":"[file:hashes.MD5 = '6c39900d77dcba158e1d27c7619cb06d']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--376308cb-f03a-4c08-a11f-42024e6a6b33","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 6fb6a55424adfb61e31f06aef33273e5","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: (b).vbs 9d9ac85765e4a818a3ccabe2cf4fef82 Debt Statement.vbs 6fb6a55424adfb61e31f06aef33273e5 dfjieya.vbs f90ed4b2d0b67114aa89ddfed658e5c0 dfjieya.vbs 8c","pattern":"[file:hashes.MD5 = '6fb6a55424adfb61e31f06aef33273e5']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0839b0b1-18fd-48bc-8dd5-489ed7fc7ae3","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7403cbcc5a9c32384d431856dc48fcc9","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 81c1bc8cfd588e8998968e2621456e Outstanding Payment List.vbs 7403cbcc5a9c32384d431856dc48fcc9 Statement of debt (4).vbs 68c16c46f8afb9e00bbaba0207fb0a46","pattern":"[file:hashes.MD5 = '7403cbcc5a9c32384d431856dc48fcc9']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e19e54cd-dcfe-4df6-a908-da3fdca2971f","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 74fd9f91fc93b6288b4fc253ea5b3e20","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 3ac85195b73753333316a889cf5880f Statement of Account(O).vbs 74fd9f91fc93b6288b4fc253ea5b3e20 Sila semak bil anda.vbs d06333c360b51456f427e616c3c5f8bd Si","pattern":"[file:hashes.MD5 = '74fd9f91fc93b6288b4fc253ea5b3e20']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0a077e91-9422-461a-8b4a-852e4881f685","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7849061c536a3efb05a56d504694e7e7","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 09a payload_1.vbs 79ecd61b09b0f2d54b34586c916c4ec9 sac8.vbs 7849061c536a3efb05a56d504694e7e7 6oy.vbs ddaffe9849f7f3c79f8804adb9a6b3d5 kof.vbs d01cad98dd","pattern":"[file:hashes.MD5 = '7849061c536a3efb05a56d504694e7e7']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13db0ec9-3ec9-4615-8b58-efda34fd8eff","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 79ecd61b09b0f2d54b34586c916c4ec9","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: ff5 1122.vbs 7f16449cd0c4862d1eadf8a5742bf09a payload_1.vbs 79ecd61b09b0f2d54b34586c916c4ec9 sac8.vbs 7849061c536a3efb05a56d504694e7e7 6oy.vbs ddaffe984","pattern":"[file:hashes.MD5 = '79ecd61b09b0f2d54b34586c916c4ec9']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f763e05-670b-4e56-afc6-fa03ffe0e4cd","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7f16449cd0c4862d1eadf8a5742bf09a","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 77b107 zipats.vbs 31037a42ca048e06e69a78f55bc2eff5 1122.vbs 7f16449cd0c4862d1eadf8a5742bf09a payload_1.vbs 79ecd61b09b0f2d54b34586c916c4ec9 sac8.vbs 784","pattern":"[file:hashes.MD5 = '7f16449cd0c4862d1eadf8a5742bf09a']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--78712692-d3a9-42a2-af09-694266cf397e","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 7f81c1bc8cfd588e8998968e2621456e","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: s 993f4c0cadbc769a4b0ed62a918db58d Financial Reports(s).vbs 7f81c1bc8cfd588e8998968e2621456e Outstanding Payment List.vbs 7403cbcc5a9c32384d431856dc48fc","pattern":"[file:hashes.MD5 = '7f81c1bc8cfd588e8998968e2621456e']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--04d3de64-5371-4b04-a039-da29e4c5da66","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 8c3322009b8982663c0cbecd9492e7eb","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: e5 dfjieya.vbs f90ed4b2d0b67114aa89ddfed658e5c0 dfjieya.vbs 8c3322009b8982663c0cbecd9492e7eb 0lf.vbs 66705384a7ad81d14c34fc6c054a0ecf iowepv.vbs 8c6d9fc","pattern":"[file:hashes.MD5 = '8c3322009b8982663c0cbecd9492e7eb']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b362b873-6deb-4418-b9a4-4351ba50193d","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 8c6d9fc389ad3f20ccbc71d77eb39bfa","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 492e7eb 0lf.vbs 66705384a7ad81d14c34fc6c054a0ecf iowepv.vbs 8c6d9fc389ad3f20ccbc71d77eb39bfa btksfmsi.vbs 1a3cc75466ffb1971482f7abf7aabc3f home3.vbs 1c4","pattern":"[file:hashes.MD5 = '8c6d9fc389ad3f20ccbc71d77eb39bfa']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91251511-f407-45ff-8ea0-d60246b33899","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 993f4c0cadbc769a4b0ed62a918db58d","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: f13c7b8ba391b2f597874e54d310648 Electronic statement(A).vbs 993f4c0cadbc769a4b0ed62a918db58d Financial Reports(s).vbs 7f81c1bc8cfd588e8998968e2621456e O","pattern":"[file:hashes.MD5 = '993f4c0cadbc769a4b0ed62a918db58d']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f3ed3d64-6125-4965-a027-313c5d6bd8f9","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 9d9ac85765e4a818a3ccabe2cf4fef82","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: vbs 1d94fbe9cab21278cc3f104bea334d08 Promissory_Note(b).vbs 9d9ac85765e4a818a3ccabe2cf4fef82 Debt Statement.vbs 6fb6a55424adfb61e31f06aef33273e5 dfjieya","pattern":"[file:hashes.MD5 = '9d9ac85765e4a818a3ccabe2cf4fef82']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bff19631-25c1-43ee-93cf-5daf9a9270c8","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 9f13c7b8ba391b2f597874e54d310648","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: .vbs b7cd06c71465038b658a6dc1f273a507 Debt confirmation.vbs 9f13c7b8ba391b2f597874e54d310648 Electronic statement(A).vbs 993f4c0cadbc769a4b0ed62a918db58","pattern":"[file:hashes.MD5 = '9f13c7b8ba391b2f597874e54d310648']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--51f9446e-d0eb-40f7-be60-c45d9674434b","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: b7cd06c71465038b658a6dc1f273a507","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: ript c7f38cbb99c8b74fa0465293feeba700 Financial Reports.vbs b7cd06c71465038b658a6dc1f273a507 Debt confirmation.vbs 9f13c7b8ba391b2f597874e54d310648 Elec","pattern":"[file:hashes.MD5 = 'b7cd06c71465038b658a6dc1f273a507']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--19ce6c8c-6028-42a4-b58e-15055eb48823","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: c7f38cbb99c8b74fa0465293feeba700","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: r legitimacy has been independently verified. IOCs VBScript c7f38cbb99c8b74fa0465293feeba700 Financial Reports.vbs b7cd06c71465038b658a6dc1f273a507 Debt","pattern":"[file:hashes.MD5 = 'c7f38cbb99c8b74fa0465293feeba700']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e8ee956e-2c2e-4502-9170-103447982345","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: d01cad98dd0d01b75e04e784953c5e2b","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 504694e7e7 6oy.vbs ddaffe9849f7f3c79f8804adb9a6b3d5 kof.vbs d01cad98dd0d01b75e04e784953c5e2b sleestak_payload_1.vbs Domains temu.baskwms[.]top invoice.m","pattern":"[file:hashes.MD5 = 'd01cad98dd0d01b75e04e784953c5e2b']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a0c99a1a-89e7-4794-97b4-125d6daf3ff1","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: d06333c360b51456f427e616c3c5f8bd","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: bs 74fd9f91fc93b6288b4fc253ea5b3e20 Sila semak bil anda.vbs d06333c360b51456f427e616c3c5f8bd Sila semak bil anda.vbs 993f4c0cadbc769a4b0ed62a918db58d Fi","pattern":"[file:hashes.MD5 = 'd06333c360b51456f427e616c3c5f8bd']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b72047e4-542f-46c4-8971-999efaabc183","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: d43fdaa1f0ee09d7e5f0f94ee9df7b6c","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: s 3b1aba44dd3d9b6339b6f56e2f42034b Statement of Account.txt d43fdaa1f0ee09d7e5f0f94ee9df7b6c Bitte füllen Sie das Formular für Umsatzsteuer-Nullsatz-Ver","pattern":"[file:hashes.MD5 = 'd43fdaa1f0ee09d7e5f0f94ee9df7b6c']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--aeefbeaf-a15b-44e4-8d4e-3e419437cdad","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: dad708e050632a4280cabf98ac1376b7","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: 0d77dcba158e1d27c7619cb06d Outstanding Balance Sheet(A).vbs dad708e050632a4280cabf98ac1376b7 Outstanding Balance Sheet.vbs 05d188f071d097f5b6bd8138749b4","pattern":"[file:hashes.MD5 = 'dad708e050632a4280cabf98ac1376b7']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f3e06f12-9024-406a-a752-4184f64a0dc4","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: ddaffe9849f7f3c79f8804adb9a6b3d5","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: c916c4ec9 sac8.vbs 7849061c536a3efb05a56d504694e7e7 6oy.vbs ddaffe9849f7f3c79f8804adb9a6b3d5 kof.vbs d01cad98dd0d01b75e04e784953c5e2b sleestak_payload_1","pattern":"[file:hashes.MD5 = 'ddaffe9849f7f3c79f8804adb9a6b3d5']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--33360007-8297-4b41-890d-29b59f35d3ed","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: df4fa0369eaca5cec348be293890d4af","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: Sie das Formular für Umsatzsteuer-Nullsatz-Verkäufe aus.vbs df4fa0369eaca5cec348be293890d4af Account Statement.vbs 63ac85195b73753333316a889cf5880f Stat","pattern":"[file:hashes.MD5 = 'df4fa0369eaca5cec348be293890d4af']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--37a2251f-3592-444a-96ce-f6efad8f3364","created":"2026-06-22T10:00:38.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: f90ed4b2d0b67114aa89ddfed658e5c0","description":"Seen in \"An unknown actor distributes malicious VBS scripts via WhatsApp\" (Kaspersky Securelist). Context: Statement.vbs 6fb6a55424adfb61e31f06aef33273e5 dfjieya.vbs f90ed4b2d0b67114aa89ddfed658e5c0 dfjieya.vbs 8c3322009b8982663c0cbecd9492e7eb 0lf.vbs 667053","pattern":"[file:hashes.MD5 = 'f90ed4b2d0b67114aa89ddfed658e5c0']","pattern_type":"stix","valid_from":"2026-06-22T10:00:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Kaspersky Securelist","url":"https://securelist.com/whatsapp-vbs-rmm-campaign/120290/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7760a95d-c6ce-4945-8956-4f5d3d407f3f","created":"2026-06-18T18:00:24.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 2915b3f8b703eb744fc54c81f4a9c67f","description":"Seen in \"Close Encounters of the Human Kind\" (Cisco Talos). Context: d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']","pattern_type":"stix","valid_from":"2026-06-18T18:00:24.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/close-encounters-of-the-human-kind/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--56403742-0439-4371-bdfc-cd5158bd951f","created":"2026-06-18T18:00:24.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: 38de5b216c33833af710e88f7f64fc98","description":"Seen in \"Close Encounters of the Human Kind\" (Cisco Talos). Context: bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']","pattern_type":"stix","valid_from":"2026-06-18T18:00:24.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/close-encounters-of-the-human-kind/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7d9cde2f-5efe-47cb-89f8-910a6b9e9194","created":"2026-06-18T18:00:24.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: bf9672ec85283fdf002d83662f0b08b7","description":"Seen in \"Close Encounters of the Human Kind\" (Cisco Talos). Context: dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe MD5: bf9672ec85283fdf002d83662f0b08b7 Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'bf9672ec85283fdf002d83662f0b08b7']","pattern_type":"stix","valid_from":"2026-06-18T18:00:24.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/close-encounters-of-the-human-kind/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b148ff8b-bcbd-4100-9e98-bb67cb5bb3e1","created":"2026-06-18T18:00:24.000Z","modified":"2026-09-16T08:58:52.499Z","created_by_ref":"identity--d7a81621-f396-4d91-8a68-4c4a2a48f8ce","name":"md5: dbd8dbecaa80795c135137d69921fdba","description":"Seen in \"Close Encounters of the Human Kind\" (Cisco Talos). Context: 05ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://talosintelligence.com/talos_file_reputat","pattern":"[file:hashes.MD5 = 'dbd8dbecaa80795c135137d69921fdba']","pattern_type":"stix","valid_from":"2026-06-18T18:00:24.000Z","labels":["auto-extracted","ransomware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/close-encounters-of-the-human-kind/"}]}]}