{"type":"bundle","id":"bundle--ea22eee3-864f-42d6-ac7d-62f094e122d4","objects":[{"type":"identity","spec_version":"2.1","id":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","created":"2026-09-16T10:04:28.277Z","modified":"2026-09-16T10:04:28.277Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--5a93f35b-6ee4-4bd6-b882-04fffa315e04","created":"2026-09-13T01:10:01.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 072558bc1a539e9936584647df51fb1797c982b0","description":"Seen in \"Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations\" (oss-security). Context: mes writes: https://github.com/unrealircd/unrealircd/commit/072558bc1a539e9936584647df51fb1797c982b0. It's a great example of the shape of many LLM-reported (I'","pattern":"[file:hashes.'SHA-1' = '072558bc1a539e9936584647df51fb1797c982b0']","pattern_type":"stix","valid_from":"2026-09-13T01:10:01.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"oss-security","url":"https://seclists.org/oss-sec/2026/q3/729"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--968f8a57-a3ab-486c-b4ba-371affce9f39","created":"2026-09-11T09:59:29.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 513a907b69edffc3cb77a494da395178d21ef9bd","description":"Seen in \"Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access\" (GBHackers). Context: mtp Second-stage payload download URL 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA-1 hash of /tmp/.z payload 2026-09-06 2026-09-08 64.207.","pattern":"[file:hashes.'SHA-1' = '513a907b69edffc3cb77a494da395178d21ef9bd']","pattern_type":"stix","valid_from":"2026-09-11T09:59:29.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-exploit-jfrog-artifactory-flaws/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e58e4d63-d9c0-4651-879a-571fcbe49869","created":"2026-09-11T08:17:33.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 513a907b69edffc3cb77a494da395178d21ef9bd","description":"Seen in \"JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control\" (Cyber Security News). Context: mtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a494da395178d21ef9bd Account 0xterror , svc_[a-zA-Z0-9]{8} , Nxploited_[a-zA-Z0-","pattern":"[file:hashes.'SHA-1' = '513a907b69edffc3cb77a494da395178d21ef9bd']","pattern_type":"stix","valid_from":"2026-09-11T08:17:33.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1a26e63-0170-4221-8599-4d4eaf35ac13","created":"2026-09-10T19:04:00.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 513a907b69edffc3cb77a494da395178d21ef9bd","description":"Seen in \"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329\" (Wiz Blog). Context: 026-42018/CVE-2026-42016 exploitation 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA1 of /tmp/.z payload 2026-09-06 2026-09-08 64.207.232[.]","pattern":"[file:hashes.'SHA-1' = '513a907b69edffc3cb77a494da395178d21ef9bd']","pattern_type":"stix","valid_from":"2026-09-10T19:04:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Wiz Blog","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--61b24667-6af7-45ce-9993-5b1064810fbb","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 59508d071661ea70fa5fcbe6f9e2fb72506e57df","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: a4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df MacSync sample SHA-1 hash Code-signing identifier com.utils","pattern":"[file:hashes.'SHA-1' = '59508d071661ea70fa5fcbe6f9e2fb72506e57df']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--016cec92-a6b8-4423-89a4-ffc0e9c57f95","created":"2026-09-10T09:53:52.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: d182eb7cba0ffa42d770d7b0d3499e49f24163a2","description":"Seen in \"Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware\" (Cyber Security News). Context: ils.Launcher Ad-hoc-signed MacSync stager identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code directory hash associated with the sample Staged archi","pattern":"[file:hashes.'SHA-1' = 'd182eb7cba0ffa42d770d7b0d3499e49f24163a2']","pattern_type":"stix","valid_from":"2026-09-10T09:53:52.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/fake-claude-and-chatgpt-installers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8b1c0932-15d6-45ef-8b43-421ba058d143","created":"2026-09-10T07:01:43.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 59508d071661ea70fa5fcbe6f9e2fb72506e57df","description":"Seen in \"Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.\" (GBHackers). Context: cbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df Native Mach-O Stager Binary Code Signing ID com.utils.Launc","pattern":"[file:hashes.'SHA-1' = '59508d071661ea70fa5fcbe6f9e2fb72506e57df']","pattern_type":"stix","valid_from":"2026-09-10T07:01:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/clickfix-lures-target-macos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cbe1c043-a7c9-4c54-879c-8d8bf9b78328","created":"2026-09-10T07:01:43.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: d182eb7cba0ffa42d770d7b0d3499e49f24163a2","description":"Seen in \"Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.\" (GBHackers). Context: om.utils.Launcher Ad-hoc signature bundle identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code Directory Hash Note: IP addresses and domains are inte","pattern":"[file:hashes.'SHA-1' = 'd182eb7cba0ffa42d770d7b0d3499e49f24163a2']","pattern_type":"stix","valid_from":"2026-09-10T07:01:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/clickfix-lures-target-macos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ccd5263b-fba6-42db-bc1d-2be6ee67f09c","created":"2026-09-05T12:12:45.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 286dd3ff41526b582ef48830de239dffbaa61f90","description":"Seen in \"Re: Vulnerability fixes in util-linux-2.42.3\" (oss-security). Context: Sep 05 Hi, https://github.com/util-linux/util-linux/commit/286dd3ff41526b582ef48830de239dffbaa61f90 Regards, Salvatore","pattern":"[file:hashes.'SHA-1' = '286dd3ff41526b582ef48830de239dffbaa61f90']","pattern_type":"stix","valid_from":"2026-09-05T12:12:45.000Z","labels":["auto-extracted","vulnerability"],"confidence":30,"external_references":[{"source_name":"oss-security","url":"https://seclists.org/oss-sec/2026/q3/655"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ad197199-b1a7-4aad-936a-e12a2d30fa81","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 03defdda9397e7536cf39951246483a0339ccd35","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-2","pattern":"[file:hashes.'SHA-1' = '03defdda9397e7536cf39951246483a0339ccd35']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6dbd93a8-a390-4425-a310-af79c5438658","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-0","pattern":"[file:hashes.'SHA-1' = '0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--da258b1d-881f-4453-887b-1083b53dabaf","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-1","pattern":"[file:hashes.'SHA-1' = '25ba920cb440b4a1c127c8eb0fb23ee783c9e01a']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--98b3dc24-633a-4a27-b525-8eea534bba7b","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: ac3f20ddc2567af0b050c672ecd59dddab1fe55e","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: 947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-2","pattern":"[file:hashes.'SHA-1' = 'ac3f20ddc2567af0b050c672ecd59dddab1fe55e']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cdfdbd5d-dcf0-4740-a5ce-8e7ccee8a834","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 177837d0fa5bfd274abe79d80a01cfe2374b4cd9","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: ing file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbca","pattern":"[file:hashes.'SHA-1' = '177837d0fa5bfd274abe79d80a01cfe2374b4cd9']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c50ac7c-9a7a-4e4a-bd2d-d6eaa8391944","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 89a7861acb7983ad712ae9206131c96454a1b3d8","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: ing file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a794bac4bf650b6ba537137504162520b67266449be979679","pattern":"[file:hashes.'SHA-1' = '89a7861acb7983ad712ae9206131c96454a1b3d8']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e11179ff-9587-44c4-9980-8bcb92a82269","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: d2c161ce52240b61d632607a2262890327d82502","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: ing file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd9","pattern":"[file:hashes.'SHA-1' = 'd2c161ce52240b61d632607a2262890327d82502']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2fd34eed-9b66-46a2-a5b8-5bb2c855efc7","created":"2026-08-17T12:57:39.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: d04ce934561934f758d77dfa944bd6743dd82cff","description":"Seen in \"New Malware 'Rover' Targets Indian Ambassador to Afghanistan\" (Palo Alto Unit 42). Context: 2 Bits binary MD5 : 76429f8515768f9f5def697e71071f51 SHA1 : d04ce934561934f758d77dfa944bd6743dd82cff SHA256: 7757517ae6b4d513a57826f9ab65bd070d99d25ac526cfae3e9","pattern":"[file:hashes.'SHA-1' = 'd04ce934561934f758d77dfa944bd6743dd82cff']","pattern_type":"stix","valid_from":"2026-08-17T12:57:39.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/new-malware-rover-targets-indian-ambassador-to-afghanistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f41fbf4e-6720-4f1f-85fb-329c322ccf16","created":"2026-08-17T12:54:22.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 41ee612602833345fc5bd2b98103811c12345678","description":"Seen in \"Analysis of Smoke Loader in New Tsunami Campaign\" (Palo Alto Unit 42). Context: ique ID. \"41EE612602833345FC5BD2B98103811C\" + \"12345678\" = \"41EE612602833345FC5BD2B98103811C12345678\" Next, Smoke Loader generates two strings based on the firs","pattern":"[file:hashes.'SHA-1' = '41ee612602833345fc5bd2b98103811c12345678']","pattern_type":"stix","valid_from":"2026-08-17T12:54:22.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/analysis-of-smoke-loader-in-new-tsunami-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4beee303-054c-44dc-a6ac-6136e02c7f62","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 3d161de48d3f4da0aefff685253404c8b0111563","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: by the malware): MD5 0f1d3ed85fee2acc23a8a26e0dc12e0f SHA1 3d161de48d3f4da0aefff685253404c8b0111563 SHA256 fb94a5e30de7afd1d9072ccedd90a249374f687f16170e1986d6","pattern":"[file:hashes.'SHA-1' = '3d161de48d3f4da0aefff685253404c8b0111563']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--89cc36e8-4789-405c-9831-7b10fb99fdac","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 67c05b3937d94136eda4a60a2d5fb685abc776a1","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: d was identified: MD5 05d43d417a8f50e7b23246643fc7e03d SHA1 67c05b3937d94136eda4a60a2d5fb685abc776a1 SHA256 3fee068bf90ffbeb25549eb52be0456609b1decfe91cda1967eb","pattern":"[file:hashes.'SHA-1' = '67c05b3937d94136eda4a60a2d5fb685abc776a1']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4a02f9dc-4b00-4d9c-8c40-62d75fff5ceb","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 741dbdb20d1beeb8ff809291996c8b78585cb812","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: lease\\LoadDll.pdb MD5 a2fe5dcb08ae8b72e8bc98ddc0b918e7 SHA1 741dbdb20d1beeb8ff809291996c8b78585cb812 SHA256 0669c71740134323793429d10518576b42941f9eee0def6057ed","pattern":"[file:hashes.'SHA-1' = '741dbdb20d1beeb8ff809291996c8b78585cb812']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--56c69310-fd6b-4658-a4fe-971d9a6e5dcc","created":"2026-08-17T12:23:37.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: d13fc918433c705b49db74c91f56ae6c0cb5cf8d","description":"Seen in \"NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT\" (Palo Alto Unit 42). Context: owing properties: MD5 e02024f38dfb6290ce0d693539a285a9 SHA1 d13fc918433c705b49db74c91f56ae6c0cb5cf8d SHA256 66a0c294ee8f3507d723a376065798631906128ce79bd6dfd8f0","pattern":"[file:hashes.'SHA-1' = 'd13fc918433c705b49db74c91f56ae6c0cb5cf8d']","pattern_type":"stix","valid_from":"2026-08-17T12:23:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-nokki-almost-ties-the-knot-with-dogcall-reaper-group-uses-new-malware-to-deploy-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--89596985-72e6-4571-9231-544bd8ec340a","created":"2026-08-17T12:22:32.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: e66e416f300c7efb90c383a7630c9cfe901ff9fd","description":"Seen in \"The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia\" (Palo Alto Unit 42). Context: owing properties: MD5 a943e196b83c4acd9c5ce13e4c43b4f4 SHA1 e66e416f300c7efb90c383a7630c9cfe901ff9fd SHA256 cfe436c1f0ce5eb7ac61b32cd073cc4e4b21d5016ceef77575be","pattern":"[file:hashes.'SHA-1' = 'e66e416f300c7efb90c383a7630c9cfe901ff9fd']","pattern_type":"stix","valid_from":"2026-08-17T12:22:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-the-fractured-block-campaign-carrotbat-malware-used-to-deliver-malware-targeting-southeast-asia/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--87cf982d-2d32-4f2f-89fd-e6294be51a28","created":"2026-08-17T12:22:32.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: f459f9cfbd10b136cafb19cbc233a4c8342ad984","description":"Seen in \"The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia\" (Palo Alto Unit 42). Context: g sample is used: MD5 3e4015366126dcdbdcc8b5c508a6d25c SHA1 f459f9cfbd10b136cafb19cbc233a4c8342ad984 SHA256 aef92be267a05cbff83aec0f23d33dfe0c4cdc71f9a424f5a2e5","pattern":"[file:hashes.'SHA-1' = 'f459f9cfbd10b136cafb19cbc233a4c8342ad984']","pattern_type":"stix","valid_from":"2026-08-17T12:22:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-the-fractured-block-campaign-carrotbat-malware-used-to-deliver-malware-targeting-southeast-asia/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--59e4dd9d-0958-4ac8-be3c-4f40a5f7acd9","created":"2026-08-17T11:46:22.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad","description":"Seen in \"Exploring the Latest Mispadu Stealer Variant\" (Palo Alto Unit 42). Context: c3c689899dc4e75fdbdd0ab076ac457de7fb83645fb735a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes F","pattern":"[file:hashes.'SHA-1' = 'ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad']","pattern_type":"stix","valid_from":"2026-08-17T11:46:22.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mispadu-infostealer-variant/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fa2e325b-0e98-42dc-a486-44be1319d4e4","created":"2026-08-17T10:57:32.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 82cb695f463b93b9cc089253cd6b5e32dce46c35","description":"Seen in \"Fake CVE-2023\" (Palo Alto Unit 42). Context: 0477 - main . zip Type = zip Physical Size = 2360 Comment = 82cb695f463b93b9cc089253cd6b5e32dce46c35 Date Time Attr Size Compressed Name ------------------- ---","pattern":"[file:hashes.'SHA-1' = '82cb695f463b93b9cc089253cd6b5e32dce46c35']","pattern_type":"stix","valid_from":"2026-08-17T10:57:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--111ccf46-7d86-473d-b198-7b82be077b4d","created":"2026-07-28T13:10:44.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 3b4f44d8e3d9d5de35127b42dd449babe2d19fe5","description":"Seen in \"Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root\" (The Hacker News). Context: he main branches of both LuCI and uhttpd, using LuCI commit 3b4f44d8e3d9d5de35127b42dd449babe2d19fe5 from May 27 and uhttpd commit 7b1bec45826bd78c8afc993435bdc","pattern":"[file:hashes.'SHA-1' = '3b4f44d8e3d9d5de35127b42dd449babe2d19fe5']","pattern_type":"stix","valid_from":"2026-07-28T13:10:44.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9facf0ff-ff01-405f-9402-8c82884d76a4","created":"2026-07-28T13:10:44.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 7b1bec45826bd78c8afc993435bdc0f1df2fe399","description":"Seen in \"Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root\" (The Hacker News). Context: 9d5de35127b42dd449babe2d19fe5 from May 27 and uhttpd commit 7b1bec45826bd78c8afc993435bdc0f1df2fe399 from June 13. It described three as pre-authentication path","pattern":"[file:hashes.'SHA-1' = '7b1bec45826bd78c8afc993435bdc0f1df2fe399']","pattern_type":"stix","valid_from":"2026-07-28T13:10:44.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--733cb9b3-8912-412e-90bf-0d47696e7f64","created":"2026-07-17T17:12:23.000Z","modified":"2026-09-16T10:04:28.277Z","created_by_ref":"identity--1a5e0af0-f805-403e-a6d4-bd3a9786c4f1","name":"sha1: 31c69b3e12936abca770d430066f379ec1d997ec","description":"Seen in \"New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens\" (The Hacker News). Context: 235, the domain cdnorigin[.]net, and one agent sample, SHA1 31c69b3e12936abca770d430066f379ec1d997ec. The Hacker News covered a different operator working the s","pattern":"[file:hashes.'SHA-1' = '31c69b3e12936abca770d430066f379ec1d997ec']","pattern_type":"stix","valid_from":"2026-07-17T17:12:23.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html"}]}]}