{"type":"bundle","id":"bundle--fc386e49-437f-4ddb-b2a8-dba7aafbf304","objects":[{"type":"identity","spec_version":"2.1","id":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","created":"2026-09-16T18:44:51.103Z","modified":"2026-09-16T18:44:51.103Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--5c18f059-f085-436d-b43a-ed67249c2e94","created":"2026-09-16T14:54:18.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b5ea87c2ddac3aa141bc6794b8993d1e43bd064eaae591719612becea0d106d7","description":"Seen in \"GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds\" (Cyber Security News). Context: okonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa141bc6794b8993d1e43bd064eaae591719612becea0d106d7 Decrypted relay URL used for tracking, filtering, and redir","pattern":"[file:hashes.'SHA-256' = 'b5ea87c2ddac3aa141bc6794b8993d1e43bd064eaae591719612becea0d106d7']","pattern_type":"stix","valid_from":"2026-09-16T14:54:18.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/ghostcode-phishing-kit/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7cc32787-8abd-412a-8ef5-94e28ab792b4","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 3ab56c9fb6b7c404c1e5b36788959c877ea819fb124c3847fa0498e9915ef9a7","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: dac7c2bcc0904f066e0de VectraRAT-related sample hash SHA-256 3ab56c9fb6b7c404c1e5b36788959c877ea819fb124c3847fa0498e9915ef9a7 VectraRAT-related sample hash SHA-256 7b82f08120e0d9b16cd5b","pattern":"[file:hashes.'SHA-256' = '3ab56c9fb6b7c404c1e5b36788959c877ea819fb124c3847fa0498e9915ef9a7']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5f3af3f0-3f94-4b6d-9e20-657381a2493e","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7b82f08120e0d9b16cd5b9ec59d24fb68e35735c82311a233d370e7f264af650","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: c3847fa0498e9915ef9a7 VectraRAT-related sample hash SHA-256 7b82f08120e0d9b16cd5b9ec59d24fb68e35735c82311a233d370e7f264af650 VectraRAT-related sample hash SHA-256 b738c03fef5e3d26419e4","pattern":"[file:hashes.'SHA-256' = '7b82f08120e0d9b16cd5b9ec59d24fb68e35735c82311a233d370e7f264af650']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e9d2bc07-037f-41bf-a0e1-780b54989c08","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8745e872ff8aa41b0e03737f76bf35b6c934106c987dff98afe34120e47caf91","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: 9ba4113f47bf2c9244dc5 VectraRAT-related sample hash SHA-256 8745e872ff8aa41b0e03737f76bf35b6c934106c987dff98afe34120e47caf91 VectraRAT-related sample hash SHA-256 bba58f99e14e3512c04a5","pattern":"[file:hashes.'SHA-256' = '8745e872ff8aa41b0e03737f76bf35b6c934106c987dff98afe34120e47caf91']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b4ab1b5-2f5e-44cb-854a-934b64fe1466","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b738c03fef5e3d26419e4aab1818a0a7ad206c67fb3eeedcdfb3ef1ee07eb620","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: 11a233d370e7f264af650 VectraRAT-related sample hash SHA-256 b738c03fef5e3d26419e4aab1818a0a7ad206c67fb3eeedcdfb3ef1ee07eb620 VectraRAT-related sample hash IP address 86.109.75.168 Prim","pattern":"[file:hashes.'SHA-256' = 'b738c03fef5e3d26419e4aab1818a0a7ad206c67fb3eeedcdfb3ef1ee07eb620']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c2020c8-d2b1-41cd-9925-238660df0dd7","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b926cfcd3f4b07fe6001c39f46e40225ff8000411198d13782538d770c54ae5e","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: d37b3377ae7b9acdcd0c9 VectraRAT-related sample hash SHA-256 b926cfcd3f4b07fe6001c39f46e40225ff8000411198d13782538d770c54ae5e VectraRAT-related sample hash SHA-256 bff3583d04f0d5603ced9","pattern":"[file:hashes.'SHA-256' = 'b926cfcd3f4b07fe6001c39f46e40225ff8000411198d13782538d770c54ae5e']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1105fcb0-f914-4b69-814b-4c8c1aaa7fc1","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: bba58f99e14e3512c04a5a74a079d7851abf935dd258cff4c80874ce7cfc82e3","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: dff98afe34120e47caf91 VectraRAT-related sample hash SHA-256 bba58f99e14e3512c04a5a74a079d7851abf935dd258cff4c80874ce7cfc82e3 VectraRAT-related sample hash SHA-256 d8f15ba122cd6da01f83f","pattern":"[file:hashes.'SHA-256' = 'bba58f99e14e3512c04a5a74a079d7851abf935dd258cff4c80874ce7cfc82e3']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2cac7463-618e-4493-bacb-a6902015a95f","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: bff3583d04f0d5603ced9831eb7c45c1923bd90e2f7d5e5d2b32942d38cf6dc5","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: 8d13782538d770c54ae5e VectraRAT-related sample hash SHA-256 bff3583d04f0d5603ced9831eb7c45c1923bd90e2f7d5e5d2b32942d38cf6dc5 VectraRAT-related sample hash SHA-256 c708d413720848f8788f4","pattern":"[file:hashes.'SHA-256' = 'bff3583d04f0d5603ced9831eb7c45c1923bd90e2f7d5e5d2b32942d38cf6dc5']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32673d65-922e-4b59-8e97-24fc1a7b4a43","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c708d413720848f8788f43a4f47ddce016fca9af10c9ba4113f47bf2c9244dc5","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: d5e5d2b32942d38cf6dc5 VectraRAT-related sample hash SHA-256 c708d413720848f8788f43a4f47ddce016fca9af10c9ba4113f47bf2c9244dc5 VectraRAT-related sample hash SHA-256 8745e872ff8aa41b0e037","pattern":"[file:hashes.'SHA-256' = 'c708d413720848f8788f43a4f47ddce016fca9af10c9ba4113f47bf2c9244dc5']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--abb68e6b-a6e7-461c-996c-04f94d3afd48","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d8f15ba122cd6da01f83fe05294df80a6eadbce0f66dac7c2bcc0904f066e0de","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: 8cff4c80874ce7cfc82e3 VectraRAT-related sample hash SHA-256 d8f15ba122cd6da01f83fe05294df80a6eadbce0f66dac7c2bcc0904f066e0de VectraRAT-related sample hash SHA-256 3ab56c9fb6b7c404c1e5b","pattern":"[file:hashes.'SHA-256' = 'd8f15ba122cd6da01f83fe05294df80a6eadbce0f66dac7c2bcc0904f066e0de']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6a5b3aa3-b037-4d52-80f0-b19f288233b2","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ddbd636f6dfd475dc0c75bf9f6f873fa35b9062dee9d37b3377ae7b9acdcd0c9","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: 25804fc4bc13f708d08ae VectraRAT-related sample hash SHA-256 ddbd636f6dfd475dc0c75bf9f6f873fa35b9062dee9d37b3377ae7b9acdcd0c9 VectraRAT-related sample hash SHA-256 b926cfcd3f4b07fe6001c","pattern":"[file:hashes.'SHA-256' = 'ddbd636f6dfd475dc0c75bf9f6f873fa35b9062dee9d37b3377ae7b9acdcd0c9']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--447dd1f4-2e66-4ebd-be18-06f5f99895ef","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: dede8bfb55c2e6479d89b1e73e0712791cf16a7179325804fc4bc13f708d08ae","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: bd35eb7c35ae6b844a0f0 VectraRAT-related sample hash SHA-256 dede8bfb55c2e6479d89b1e73e0712791cf16a7179325804fc4bc13f708d08ae VectraRAT-related sample hash SHA-256 ddbd636f6dfd475dc0c75","pattern":"[file:hashes.'SHA-256' = 'dede8bfb55c2e6479d89b1e73e0712791cf16a7179325804fc4bc13f708d08ae']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ceb9cc54-478e-4c5c-aed7-26f7d5f2767c","created":"2026-09-16T14:36:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e2db5db12564d2a9da7ef3a57aa23d95782f5eaddc8bd35eb7c35ae6b844a0f0","description":"Seen in \"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs\" (Cyber Security News). Context: s of Compromise (IoCs):- Type Indicator Description SHA-256 e2db5db12564d2a9da7ef3a57aa23d95782f5eaddc8bd35eb7c35ae6b844a0f0 VectraRAT-related sample hash SHA-256 dede8bfb55c2e6479d89b","pattern":"[file:hashes.'SHA-256' = 'e2db5db12564d2a9da7ef3a57aa23d95782f5eaddc8bd35eb7c35ae6b844a0f0']","pattern_type":"stix","valid_from":"2026-09-16T14:36:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ce6ad329-d916-49b5-8e70-7089fd77aa80","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: f004486cd41efb Source-listed Noodle RAT sample hash SHA-256 33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f Source-listed Noodle RAT sample hash MD5 eff8675fac22c49107","pattern":"[file:hashes.'SHA-256' = '33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--919caec5-59ff-4034-8c47-0eba6971240b","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4f4d405d32d76a170ca2899c70b48ef6ffaaef792e024b6f8aab98d4ae55eae4","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: b0a7f025f08250 Source-listed Noodle RAT sample hash SHA-256 4f4d405d32d76a170ca2899c70b48ef6ffaaef792e024b6f8aab98d4ae55eae4 Source-listed Noodle RAT sample hash MD5 f1a04ffaa889c11b99","pattern":"[file:hashes.'SHA-256' = '4f4d405d32d76a170ca2899c70b48ef6ffaaef792e024b6f8aab98d4ae55eae4']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fafa9237-ec4b-42c2-8ee2-e8719a584503","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 51aed28d3468de5e75addc467ba14389356afe896098e4e478efcd7bf79a65b9","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: ba01a242f59327 Source-listed Noodle RAT sample hash SHA-256 51aed28d3468de5e75addc467ba14389356afe896098e4e478efcd7bf79a65b9 Source-listed Noodle RAT sample hash IPv4 Address 47.83.128","pattern":"[file:hashes.'SHA-256' = '51aed28d3468de5e75addc467ba14389356afe896098e4e478efcd7bf79a65b9']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca0ff7c4-1106-436c-abf1-f74e9194f56d","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 668dcf124501c1767d4ebc19f29cb44d6474cbff28947d63a695628f467b6345","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: 3beccc6fb927e2 Source-listed Noodle RAT sample hash SHA-256 668dcf124501c1767d4ebc19f29cb44d6474cbff28947d63a695628f467b6345 Source-listed Noodle RAT sample hash SHA-1 7436b37fae21f048","pattern":"[file:hashes.'SHA-256' = '668dcf124501c1767d4ebc19f29cb44d6474cbff28947d63a695628f467b6345']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e356c206-ce08-452a-a265-738f0ba618bd","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: 2e52938460410b Source-listed Noodle RAT sample hash SHA-256 7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0 Source-listed Noodle RAT sample hash SHA-256 7b63ddaf3b217f","pattern":"[file:hashes.'SHA-256' = '7aa50ba59b38494cc524dbd31519bd3a218133aed64d9037eef02d697b8e99d0']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c3d0b784-2217-4005-aa75-c72c2b06a16b","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: f02d697b8e99d0 Source-listed Noodle RAT sample hash SHA-256 7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3 Source-listed Noodle RAT sample hash Note: IP addresses and","pattern":"[file:hashes.'SHA-256' = '7b63ddaf3b217f9e7b08575ee6f80fff1d2d9e12522d862ccc192ef3d08a0dd3']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8177c92a-3d5b-497a-8f67-9e1a6b376b90","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 93b19bc56952ae1e82f1f41db49f455316736e2b8d161e64b115a150d8dcf204","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: 853571d89209df Source-listed Noodle RAT sample hash SHA-256 93b19bc56952ae1e82f1f41db49f455316736e2b8d161e64b115a150d8dcf204 Source-listed Noodle RAT sample hash MD5 3c230061e5a16cc559","pattern":"[file:hashes.'SHA-256' = '93b19bc56952ae1e82f1f41db49f455316736e2b8d161e64b115a150d8dcf204']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--db3df113-9a56-471d-bf04-997a5f559e5d","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a7632f145e45c8d932f6f1a8ccbbf65e7ae97b0d339c45dfb548e29186db1144","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: f1b0de9c0bb44b Source-listed Noodle RAT sample hash SHA-256 a7632f145e45c8d932f6f1a8ccbbf65e7ae97b0d339c45dfb548e29186db1144 Source-listed Noodle RAT sample hash SHA-256 abf83c4d6bbf50","pattern":"[file:hashes.'SHA-256' = 'a7632f145e45c8d932f6f1a8ccbbf65e7ae97b0d339c45dfb548e29186db1144']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--92239805-b33c-4aed-8618-42ce712162c7","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: abf83c4d6bbf508504398ac56031c566ed662c3cc7e7b490494d9ee72eece870","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: 48e29186db1144 Source-listed Noodle RAT sample hash SHA-256 abf83c4d6bbf508504398ac56031c566ed662c3cc7e7b490494d9ee72eece870 Source-listed Noodle RAT sample hash MD5 26f33ae36ad0558239","pattern":"[file:hashes.'SHA-256' = 'abf83c4d6bbf508504398ac56031c566ed662c3cc7e7b490494d9ee72eece870']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3f626148-060e-4209-87f5-7782563a6fd0","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: bd113d6b2cfba5ab2780c313c01d87896c64f91376903efc62ba01a242f59327","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: 14b44f623c650a Source-listed Noodle RAT sample hash SHA-256 bd113d6b2cfba5ab2780c313c01d87896c64f91376903efc62ba01a242f59327 Source-listed Noodle RAT sample hash SHA-256 51aed28d3468de","pattern":"[file:hashes.'SHA-256' = 'bd113d6b2cfba5ab2780c313c01d87896c64f91376903efc62ba01a242f59327']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--380a3fbc-b36b-4a77-82ae-1d72bd2f9f38","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: df603ed55cbf6f9d74068b956ab966a7b785eb102e1045f343d96255eb2cdc24","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: 728bf5d5c6ee71 Source-listed Noodle RAT sample hash SHA-256 df603ed55cbf6f9d74068b956ab966a7b785eb102e1045f343d96255eb2cdc24 Source-listed Noodle RAT sample hash SHA-1 d6b243db1dbca54d","pattern":"[file:hashes.'SHA-256' = 'df603ed55cbf6f9d74068b956ab966a7b785eb102e1045f343d96255eb2cdc24']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2e90ffe4-8cb4-4142-8ccc-b02d6eb3b5a5","created":"2026-09-16T14:03:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f25237d11c4d0aa0224d20b7a4f7815dc4971102d2584e991195d1dbc7b8d82d","description":"Seen in \"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems\" (Cyber Security News). Context: adf827e0d0189d Source-listed Noodle RAT sample hash SHA-256 f25237d11c4d0aa0224d20b7a4f7815dc4971102d2584e991195d1dbc7b8d82d Source-listed Noodle RAT sample hash MD5 63af61806ff5060c77","pattern":"[file:hashes.'SHA-256' = 'f25237d11c4d0aa0224d20b7a4f7815dc4971102d2584e991195d1dbc7b8d82d']","pattern_type":"stix","valid_from":"2026-09-16T14:03:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cross-platform-noodle-rat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4b180611-c112-4db8-992f-fd11c88bc681","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0c0e4935f8df04e86056798d417bf3f485c640fa0322756c0a860af2a6bd0f1d","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: 252ca5e7b7c7fe237 Related sample: Tax_436454367.img SHA-256 0c0e4935f8df04e86056798d417bf3f485c640fa0322756c0a860af2a6bd0f1d Related 2023 Chinese-language sample SHA-256 38ec1f5e23f65b","pattern":"[file:hashes.'SHA-256' = '0c0e4935f8df04e86056798d417bf3f485c640fa0322756c0a860af2a6bd0f1d']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6f59f5cb-0e8d-445b-8d03-204391b8df71","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 268a90d07cf02b16c091ef6cc52e3dbe17638bb722221807bc833c4c1299a8a9","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: b679a73c2 Related sample: ClientAny.exe / skkr3.exe SHA-256 268a90d07cf02b16c091ef6cc52e3dbe17638bb722221807bc833c4c1299a8a9 Related sample: Tax_Notice_16695 (1).img SHA-256 f23708ae47","pattern":"[file:hashes.'SHA-256' = '268a90d07cf02b16c091ef6cc52e3dbe17638bb722221807bc833c4c1299a8a9']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ff329cee-76c8-4c29-8f71-3a439fa689a6","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 2ff898c1a4bb0dd48687bbbc8cca646a896dc9ed24780a49523dfbf9fb94a4ec","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: e5a207315f7bf6ef74a966cbb5 libcurl.dll proxy loader SHA-256 2ff898c1a4bb0dd48687bbbc8cca646a896dc9ed24780a49523dfbf9fb94a4ec LIBCURL.DAT encrypted payload SHA-256 947221d0f1e2c9c090284","pattern":"[file:hashes.'SHA-256' = '2ff898c1a4bb0dd48687bbbc8cca646a896dc9ed24780a49523dfbf9fb94a4ec']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--59e79320-5585-4247-a463-1ea7b284caa1","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 38ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04c","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: 860af2a6bd0f1d Related 2023 Chinese-language sample SHA-256 38ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04c Related sample: Tax_Notice_23665.img SHA-256 a4098fe9ed421a","pattern":"[file:hashes.'SHA-256' = '38ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04c']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1bd0c164-a533-4316-bdfe-8fc6cdaaff40","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 72a321802d738e8bc6a0ab9d9d24b380be944fffbfc85094b889690b679a73c2","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: 321927fea66d Builder certificate SHA-256 thumbprint SHA-256 72a321802d738e8bc6a0ab9d9d24b380be944fffbfc85094b889690b679a73c2 Related sample: ClientAny.exe / skkr3.exe SHA-256 268a90d07","pattern":"[file:hashes.'SHA-256' = '72a321802d738e8bc6a0ab9d9d24b380be944fffbfc85094b889690b679a73c2']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a08717e8-70d5-406d-9492-7bb2735245d0","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8c1ba078598e09294d72293a42dcd878e183b6e5a207315f7bf6ef74a966cbb5","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: 8eb192583f950c Tax_Notice_45594.exe signed launcher SHA-256 8c1ba078598e09294d72293a42dcd878e183b6e5a207315f7bf6ef74a966cbb5 libcurl.dll proxy loader SHA-256 2ff898c1a4bb0dd48687bbbc8c","pattern":"[file:hashes.'SHA-256' = '8c1ba078598e09294d72293a42dcd878e183b6e5a207315f7bf6ef74a966cbb5']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f551ba4a-9b4c-4f39-a711-c8d527077bd3","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 947221d0f1e2c9c09028491997406dd9f0cb5b65258556c86d201ec1ca538f5f","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: 80a49523dfbf9fb94a4ec LIBCURL.DAT encrypted payload SHA-256 947221d0f1e2c9c09028491997406dd9f0cb5b65258556c86d201ec1ca538f5f stage2.dll VenomRAT .NET DLL Install directory %APPDATA%\\Mi","pattern":"[file:hashes.'SHA-256' = '947221d0f1e2c9c09028491997406dd9f0cb5b65258556c86d201ec1ca538f5f']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c8029748-6414-46b1-b90c-a18213e9d5b5","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a4098fe9ed421a6244c9fd4d3d1a632ff5f2ee4ffa204dff0587548932936d38","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: 7e44e6a998e04c Related sample: Tax_Notice_23665.img SHA-256 a4098fe9ed421a6244c9fd4d3d1a632ff5f2ee4ffa204dff0587548932936d38 Related sample: Tax_Notice_99674.img Sister lure domain dgd","pattern":"[file:hashes.'SHA-256' = 'a4098fe9ed421a6244c9fd4d3d1a632ff5f2ee4ffa204dff0587548932936d38']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--40a20bc3-607a-4e5d-99a6-834503d6aa2e","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d768222934f6014bf17c3d0a1ef4c35e02aa6fe1e89564e252ca5e7b7c7fe237","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: e4b10e65d0b08e3 Related sample: ITDENF2026-4281.img SHA-256 d768222934f6014bf17c3d0a1ef4c35e02aa6fe1e89564e252ca5e7b7c7fe237 Related sample: Tax_436454367.img SHA-256 0c0e4935f8df04e86","pattern":"[file:hashes.'SHA-256' = 'd768222934f6014bf17c3d0a1ef4c35e02aa6fe1e89564e252ca5e7b7c7fe237']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ffaabfe5-5696-4186-aaf0-91df9ed76157","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f23708ae470904490cb25d370185ca89c0d37e33fa5a3c652e4b10e65d0b08e3","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: 4c1299a8a9 Related sample: Tax_Notice_16695 (1).img SHA-256 f23708ae470904490cb25d370185ca89c0d37e33fa5a3c652e4b10e65d0b08e3 Related sample: ITDENF2026-4281.img SHA-256 d768222934f6014","pattern":"[file:hashes.'SHA-256' = 'f23708ae470904490cb25d370185ca89c0d37e33fa5a3c652e4b10e65d0b08e3']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--087390dc-eb34-4b75-bce9-a158c4c63e31","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f72bf7c1fd132262715820d839e4874c97d927b10072fb4709a1321927fea66d","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: ociated with the modified v6.0.3 builder SHA-256 thumbprint f72bf7c1fd132262715820d839e4874c97d927b10072fb4709a1321927fea66d Builder certificate SHA-256 thumbprint SHA-256 72a321802d73","pattern":"[file:hashes.'SHA-256' = 'f72bf7c1fd132262715820d839e4874c97d927b10072fb4709a1321927fea66d']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2840af19-d8ac-4616-9b3d-680cbad117dc","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f945b3f2f29d62099683cbbf069ed5bc952d089c16a85fb314ac8fe0f0c10d2b","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: {seq}} Unrendered variable in the From display name SHA-256 f945b3f2f29d62099683cbbf069ed5bc952d089c16a85fb314ac8fe0f0c10d2b Tax_Notice_45594.img ISO container SHA-256 fe0ddd8686324e0a","pattern":"[file:hashes.'SHA-256' = 'f945b3f2f29d62099683cbbf069ed5bc952d089c16a85fb314ac8fe0f0c10d2b']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52be985c-a59a-4272-b781-c9a3a25a432a","created":"2026-09-16T12:23:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: fe0ddd8686324e0a8b07ed5ffdb4f56397c70b1b5a19d2916c8eb192583f950c","description":"Seen in \"PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks\" (Cyber Security News). Context: 14ac8fe0f0c10d2b Tax_Notice_45594.img ISO container SHA-256 fe0ddd8686324e0a8b07ed5ffdb4f56397c70b1b5a19d2916c8eb192583f950c Tax_Notice_45594.exe signed launcher SHA-256 8c1ba078598e09","pattern":"[file:hashes.'SHA-256' = 'fe0ddd8686324e0a8b07ed5ffdb4f56397c70b1b5a19d2916c8eb192583f950c']","pattern_type":"stix","valid_from":"2026-09-16T12:23:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/papermill-hackers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--921add79-54e4-47d5-9983-81f33ab12f9b","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: fection persistent on the infected macOS host SHA-256 hash: 4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9 File size: 568,368 bytes File location: /Users/[username]/L","pattern":"[file:hashes.'SHA-256' = '4504006d1911057be42435d4625f03d83c4d0b7b6898d14beb9cdeba6cf667b9']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--09689605-4966-4133-a5b3-72cced46ca9e","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: a Z-shell (Zsh) script from hxxps[:]//ferncore13[.]com/curl/608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688 . That Zsh script contains Base64-encoded text for a GZIP-c","pattern":"[file:hashes.'SHA-256' = '608e70d1338612686917ee5cd300ff7ed8e318dfd787a50257f92142e99bd688']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--463bb8fe-687b-4569-a2ce-7c186dc1dfd3","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: fection persistent on the infected macOS host SHA-256 hash: 6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620 File size: 438,576 bytes File location: /Users/[username]/L","pattern":"[file:hashes.'SHA-256' = '6bfcdb4920383375b7e519918df7eb4db751b974b5571a15ce66b82478012620']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e133df0-9c57-4651-82bb-f4b994969cb1","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: a command run from the macOS Terminal window SHA-256 hash: 71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c File size: 1,991 bytes File type: Zsh script text executabl","pattern":"[file:hashes.'SHA-256' = '71781ad8adefb499aee9bcbe1a166e69ccc37a47066682f617d65c76d8cde88c']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d74dd566-4b00-4d8e-9abc-28b5013d51cb","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: cted from the initially downloaded Zsh script SHA-256 hash: 7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a File size: 1,213 bytes File type: Zsh script text executabl","pattern":"[file:hashes.'SHA-256' = '7ea6ff8b12c59aaae1ab6f4f5a57045dad5a8127954f3ffd3d1c154d40d7ca3a']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1eb625db-5054-4dcd-82b4-b30292fd53ff","created":"2026-09-16T10:00:06.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9","description":"Seen in \"Atomic macOS (AMOS) Stealer Activity\" (Palo Alto Unit 42). Context: y long lines (323) Installer for AMOS stealer SHA-256 hash: a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9 File size: 330,768 bytes File location: /tmp/helper File ty","pattern":"[file:hashes.'SHA-256' = 'a598fcdcd49247312861ff90c16cb4a5d49fede6072e30e7416dd276668fa2a9']","pattern_type":"stix","valid_from":"2026-09-16T10:00:06.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--78caff32-dd35-4995-a2b0-3775a986139b","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: s of compromise (IoCs):- Type Indicator Description SHA-256 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8a","pattern":"[file:hashes.'SHA-256' = '106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d882f4fb-05fe-4799-94ec-add4081e77e2","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: 70e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127","pattern":"[file:hashes.'SHA-256' = '170dffb37e05f525f735bc9ad84b3908a488f7ce43fcb07739a10e4331e15a2c']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--50f09ab1-8299-4d90-82c8-c6ff681a4a70","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: 81bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa4","pattern":"[file:hashes.'SHA-256' = '223be3f8648bf6998c4a58b972522e5fda8d9d0a57b4e163811930de66c3f7ca']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d754332c-e25b-49b0-9bd2-c4963c70906d","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: fcb07739a10e4331e15a2c Related Wave C loader sample SHA-256 42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9 PowerShell extension-installer implementation Domain connec","pattern":"[file:hashes.'SHA-256' = '42a3e2bb135fb46b11b127f45a266b3a4d9dff4aa1cf75433f93fe69ba51a9b9']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e27c9c27-b4f7-46ba-9eaa-db5e5ad8b26d","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: aa75b2635cbdc0fa42 KREMLIN JavaScript loader sample SHA-256 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c","pattern":"[file:hashes.'SHA-256' = '5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--123a331d-5c54-4a93-8deb-f63b58427c31","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: 3811930de66c3f7ca Malicious AVSync extension sample SHA-256 ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2","pattern":"[file:hashes.'SHA-256' = 'ba80216c960977fa45e317f00dcf31e96acab29904a737cbc0bf86e929c3be5f']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--22f0d76e-7c39-4581-9740-2d4d3674215a","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: 89910e5be44f552 First-stage popup JavaScript sample SHA-256 c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 KREMLIN x64 extension installer binary SHA-256 223be3f8648b","pattern":"[file:hashes.'SHA-256' = 'c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--089fc2c8-bada-4a7f-bb85-d4cef551cecc","created":"2026-09-16T08:12:32.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0","description":"Seen in \"KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension\" (Cyber Security News). Context: a737cbc0bf86e929c3be5f Related Wave A loader sample SHA-256 cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0 Related Wave B loader sample SHA-256 170dffb37e05f525f735bc","pattern":"[file:hashes.'SHA-256' = 'cb15cbf3f01a92e609e4c2bc26155e667e96c5d04770e83abba66ee07bcecea0']","pattern_type":"stix","valid_from":"2026-09-16T08:12:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/kremlin-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8f8b0273-9b65-4c1a-892a-d8d75f6df2c9","created":"2026-09-16T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca","description":"Seen in \"Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware\" (Sansec (Magento / e-commerce security)). Context: tps://conversations-widget.brevo.com/brevo-conversations.js 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e3","pattern":"[file:hashes.'SHA-256' = '26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca']","pattern_type":"stix","valid_from":"2026-09-16T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/brevo-supply-chain-attack"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3bb5f3e2-05ef-43ef-99f5-766e734daed2","created":"2026-09-16T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7","description":"Seen in \"Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware\" (Sansec (Magento / e-commerce security)). Context: sponse, identical across every host and every observed scan 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7 {\"s\":0,\"r\":\"https:\\/\\/www.google.com\"} # Do not block sendi","pattern":"[file:hashes.'SHA-256' = '4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7']","pattern_type":"stix","valid_from":"2026-09-16T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/brevo-supply-chain-attack"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6ae42c54-d324-4a47-9aaf-f10004f90e45","created":"2026-09-16T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308","description":"Seen in \"Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware\" (Sansec (Magento / e-commerce security)). Context: 71db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980","pattern":"[file:hashes.'SHA-256' = '58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308']","pattern_type":"stix","valid_from":"2026-09-16T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/brevo-supply-chain-attack"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5ccf6203-d713-48a3-bdf9-4f0b376825b8","created":"2026-09-16T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5","description":"Seen in \"Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware\" (Sansec (Magento / e-commerce security)). Context: 7a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 injected -> cdn4 # The appended line (final line of each fi","pattern":"[file:hashes.'SHA-256' = '9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5']","pattern_type":"stix","valid_from":"2026-09-16T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/brevo-supply-chain-attack"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca55d061-793a-40d0-9b28-95dc749c99e0","created":"2026-09-16T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782","description":"Seen in \"Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware\" (Sansec (Magento / e-commerce security)). Context: 588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 injected -> cdn11 https://conversations-widget.brevo.com/br","pattern":"[file:hashes.'SHA-256' = 'f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782']","pattern_type":"stix","valid_from":"2026-09-16T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/brevo-supply-chain-attack"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7717d9e1-face-415e-b040-0f926dc6eac7","created":"2026-09-16T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09","description":"Seen in \"Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware\" (Sansec (Magento / e-commerce security)). Context: e 15 September 2026) https://cdn.brevo.com/js/sdk-loader.js fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795f","pattern":"[file:hashes.'SHA-256' = 'fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09']","pattern_type":"stix","valid_from":"2026-09-16T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/brevo-supply-chain-attack"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--238328cf-c54b-4429-992e-f7e5f0309847","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: cb92 SIC MP3/HTA payload and Talos clipper artifact SHA-256 06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b; d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975","pattern":"[file:hashes.'SHA-256' = '06a3d3bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4ea5c6a5-6124-4926-96a4-fac0d3ab216b","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: b7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c287","pattern":"[file:hashes.'SHA-256' = '131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--31209bde-c7aa-4f6d-a205-a6586f23a922","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 3c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505; 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd","pattern":"[file:hashes.'SHA-256' = '18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a1a2015c-5e1a-43fb-bb74-0e09ee35fd10","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 9ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e51a7505; 249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938; 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e8","pattern":"[file:hashes.'SHA-256' = '249088420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--439a47e2-8aa8-4e63-bf23-734bb6d84b76","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 2365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7; 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 SIC MP3/HTA payload and Talos clipper artifact SHA-256 06a3","pattern":"[file:hashes.'SHA-256' = '279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dfc68783-cb67-425c-b64c-d1c986bc9848","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5; 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24 InstallFix MP3/HTA, InstallFix /cl and recovered InstallFix","pattern":"[file:hashes.'SHA-256' = '3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92541a24']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dabeb738-1d80-4a47-808d-bfc1ba9b799c","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 83129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad; 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5; 3276414afb3c7ce7aa19db5401051ce4ad6968a7cc6bf8384cd6470c92","pattern":"[file:hashes.'SHA-256' = '480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c891795dc2f5']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c1df9019-7996-41ce-bee8-44c9c9a373b9","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ake Ledger, Trezor and Exodus application artifacts SHA-256 5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad; 480c65e5bb793da2d5ddfdcf00dd37bd4c7176ea0fb58d4e6bd5c89179","pattern":"[file:hashes.'SHA-256' = '5e8ad983129f6771d186f60379dca30d208374cac45bac75d5459aaf0fabc8ad']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0b690546-5793-4c2e-a321-9231b2b740e0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: c218e1aba3fcb Recovered x86 artifact and Amatera PE SHA-256 6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7; 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739","pattern":"[file:hashes.'SHA-256' = '6759c72365d0c690db613ff30635970668f5699b65c3842ecdc4f1b695ed13a7']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6cc57ef5-7363-47d8-9b70-bcc06ce51dde","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 41ef5d316a1ae8631329349287e6a411 Metadata artifacts SHA-256 93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494","pattern":"[file:hashes.'SHA-256' = '93d986f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--215d54af-39c4-4bd9-8153-14e0a3ce2aba","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 420058e50b5e7d1e615a6b9c212e1c341b43fbd8b60cde30d5bd281938; 9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96 Houston, Pressureulcerlawyer, Lalandscapelighting, Aidevmas","pattern":"[file:hashes.'SHA-256' = '9eb96fc1fda13b143a90896793754b6a61942dbf87846895bb9ea8c1e849cd96']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2e46f6b-8527-4488-a386-8b0b2745becf","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411 Metadata artifacts SHA-256 93d986f39599df747e4f65484a41d5e5","pattern":"[file:hashes.'SHA-256' = 'a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287e6a411']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--32078c6f-bfdc-4424-a031-c95ebd05b0ad","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: bdeb33411fba53eed53cf528f3b33fdf5c2a74921d5d98002cb5e2ba1b; d1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0","pattern":"[file:hashes.'SHA-256' = 'd1690bec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--31f1101d-6af4-40a2-8f4f-cc23738b7209","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 949cfc514f145262136898b009 September macOS artifact SHA-256 d4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2 AccountsHelper artifact SHA-256 f71d72711fe132f00d1a10d6f8c","pattern":"[file:hashes.'SHA-256' = 'd4150c1c97f047c6edb14767bf1efa8f9e37d63b124f38f27da4ef52d570aac2']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15ffb328-3b51-423d-8657-525c6191d9d0","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb Recovered x86 artifact and Amatera PE SHA-256 6759c72365d0c","pattern":"[file:hashes.'SHA-256' = 'd4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3c86e5d5-f46d-4636-b7ff-f90b7858e690","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e5","pattern":"[file:hashes.'SHA-256' = 'd95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0af1733f-bcf6-4db5-acb8-855cc607a768","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c","pattern":"[file:hashes.'SHA-256' = 'e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9863ec97-04b4-4d15-a67c-2cdbb7f40406","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: , InstallFix /cl and recovered InstallFix artifacts SHA-256 ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1a","pattern":"[file:hashes.'SHA-256' = 'ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fc150972-3c5b-460d-b481-e4f16d5fe8ce","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 1301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb Fake Ledger, Trezor and Exodus application artifacts SHA-25","pattern":"[file:hashes.'SHA-256' = 'ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--69f78101-8f5d-48ef-850d-c6831aa25d9f","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: ec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b","pattern":"[file:hashes.'SHA-256' = 'ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65ce152c-5b86-4b6f-b3d7-020abfb3cbba","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: Selectors for getData() , balanceOf() and setData() SHA-256 eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 September macOS artifact SHA-256 d4150c1c97f047c6edb14767bf","pattern":"[file:hashes.'SHA-256' = 'eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8ec96060-044c-4360-a48c-601611e438a6","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: 63b124f38f27da4ef52d570aac2 AccountsHelper artifact SHA-256 f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287","pattern":"[file:hashes.'SHA-256' = 'f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ca3d5853-5890-4224-bcc9-404542b0c875","created":"2026-09-15T06:56:40.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e","description":"Seen in \"Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads\" (Cyber Security News). Context: b41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f1","pattern":"[file:hashes.'SHA-256' = 'f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e']","pattern_type":"stix","valid_from":"2026-09-15T06:56:40.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-hijack-hbo-max/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91db1657-8361-4324-815e-832af5d9dfe8","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ple.com Twitch Enhanced Viewer Firefox Add-ons ID; SHA-256: 141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc Note: IP addresses and domains are intentionally defanged (","pattern":"[file:hashes.'SHA-256' = '141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc165775-5315-44e1-a7b6-ecf9a7ebb491","created":"2026-09-14T13:50:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8","description":"Seen in \"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users\" (Cyber Security News). Context: ed Viewer | JeetBot Chrome Web Store extension ID; SHA-256: e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8 Firefox extension twitchenhancedviewer@example.com Twitch E","pattern":"[file:hashes.'SHA-256' = 'e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8']","pattern_type":"stix","valid_from":"2026-09-14T13:50:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/malicious-twitch-extension/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a6e15dc7-0ad1-44a3-9a2c-0f447347455f","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: RAYRABBIT command-and-control domain using port 443 SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 Trojanized DLL loader, originally identified as 7zp.dll wit","pattern":"[file:hashes.'SHA-256' = '29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dcf6046f-90ec-4bac-b9bc-6cf7418ab52a","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: ly identified as 7zp.dll with internal name boy.dll SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e Encrypted payload blob identified as p SHA-256 D7a3c7eb94ed","pattern":"[file:hashes.'SHA-256' = '749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d12cf74f-4b5b-4c97-9e36-27da2615a5d9","created":"2026-09-14T13:01:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a","description":"Seen in \"One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users\" (Cyber Security News). Context: 98662e02422e Encrypted payload blob identified as p SHA-256 D7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor with internal name core.dll File name 7","pattern":"[file:hashes.'SHA-256' = 'd7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a']","pattern_type":"stix","valid_from":"2026-09-14T13:01:36.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/one-click-on-a-malicious-link/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12708724-4d33-4750-b648-9cb0f70624c4","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure PDF SHA-256 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a Malicious PDF lure Email SHA-256 debe871710268e7bb770b72c67","pattern":"[file:hashes.'SHA-256' = '0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60b105fa-b864-4ef5-8132-9c8a53f8e124","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 Malicious PDF lure PDF SHA-256 c521b3a189b0089a2558aa4e42bd","pattern":"[file:hashes.'SHA-256' = '0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d12a3a2-8578-455e-91bb-fdf1c1b572ff","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 4a2145348b953b1d06e2eaf0bf2c Malicious PDF lure PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure PDF SHA-256 62ef39ec29966d71c8254f68bd5e","pattern":"[file:hashes.'SHA-256' = '1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--04a9e7e3-d5d9-4227-98d2-4339238ef879","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 042d76c12dbafdcc0766861827c5 Malicious PDF lure PDF SHA-256 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 Malicious PDF lure PDF SHA-256 ea8af591fe2d605c82bb7831d2eb","pattern":"[file:hashes.'SHA-256' = '1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--189c9ce3-4252-4134-b2c2-70646fe0d196","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 64f8db457bafafb97a011da59e73 Malicious PDF lure PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Malicious PDF lure PDF SHA-256 bf92a287a3d79afb73a3f2d38877","pattern":"[file:hashes.'SHA-256' = '40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7983df97-10f4-4979-9bcb-b1d57b11a3b6","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 89eb6b87bb0 2f0bd59d565 Phishing email artifact HTA SHA-256 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 HTA downloader HTA SHA-256 85767416f8d1e73833ccaa193263d119","pattern":"[file:hashes.'SHA-256' = '4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2271dc5b-6b04-41c7-82a9-3b5085eee8e9","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 246d3d50110c6b0c248919ad796c6fd4 HTA downloader HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 HTA downloader HTA SHA-256 92a1428e125f33de012c7f52fb0827be","pattern":"[file:hashes.'SHA-256' = '4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0f78b3d4-5197-45a2-bb90-9cd9a8b88305","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: ca6e1b70fe30ba3752b881574365 Malicious PDF lure PDF SHA-256 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 Malicious PDF lure PDF SHA-256 d13ad6fc5fda54e65f1214e554a5","pattern":"[file:hashes.'SHA-256' = '47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c93c1388-c91a-4e68-baaf-f07fba274ead","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 3b5c42dd2a33b5a6520159b41c43b093 HTA downloader HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c HTA downloader HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba2","pattern":"[file:hashes.'SHA-256' = '51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--33bcc16e-e656-4928-9e6d-d1bcd3332dc5","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: f537a02949315eb768c88906b0c65add HTA downloader HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e HTA downloader HTA SHA-256 8092b9de455463296898fcaf8c9955d1","pattern":"[file:hashes.'SHA-256' = '5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b474171b-32c2-459e-9084-f7b3d7fc9142","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: c8224686669ba4b64196591414fdc64c HTA downloader HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02 HTA downloader HTA SHA-256 71dea06c2271a46fc2fd6092e2ba0c2f","pattern":"[file:hashes.'SHA-256' = '5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6eae89e6-5604-4e0f-ab59-55d9f141b435","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: badab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure PDF SHA-256 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5 Malicious PDF lure PDF SHA-256 1f1a89bef73e4866a198a08e750f","pattern":"[file:hashes.'SHA-256' = '62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c34e651a-99aa-40bf-a846-badb09bfae5f","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 02b1b25b78e5f3707e81bad5054cf4e8 HTA downloader HTA SHA-256 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093 HTA downloader HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88","pattern":"[file:hashes.'SHA-256' = '6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4941dcea-044b-421c-9d35-f1641191618e","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: compromise (IoCs):- Type Indicator Description PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 Malicious PDF lure PDF SHA-256 40d253480f752805e58c21266e40","pattern":"[file:hashes.'SHA-256' = '6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d035288c-0d01-4d15-9d13-d94007385f00","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: aff294f5250c2eed406765032cb68756 HTA downloader HTA SHA-256 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4 HTA downloader HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002f","pattern":"[file:hashes.'SHA-256' = '6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f41e9d44-4182-4c28-a858-66b99fd0ce92","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: ff91c829d87f566bee453d715280 Malicious PDF lure PDF SHA-256 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859 Malicious PDF lure PDF SHA-256 d910e08a11a4f6f764e7495f4602","pattern":"[file:hashes.'SHA-256' = '711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bec28ce9-f008-49e2-ad56-a49176b61e39","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 7170018382cbc362343db63717d0ff02 HTA downloader HTA SHA-256 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secures","pattern":"[file:hashes.'SHA-256' = '71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe7f46c3-d3c8-4222-9fe6-c6eb60f83c28","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 5d7407ba AutoIt loader component Casbaneiro payload SHA-256 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8 Casbaneiro payload Cryptocurrency address 0xb4c12078448fdef","pattern":"[file:hashes.'SHA-256' = '7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f319d3a6-f036-4952-ba6e-a1d0258241e8","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 2abf7f72ef093292c86c1e9e7c2be456 HTA downloader HTA SHA-256 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8 HTA downloader HTA SHA-256 6547736c31dabb5bef2a290b32a72bf6","pattern":"[file:hashes.'SHA-256' = '7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--429ff043-b92b-430f-bf14-f5744cec3b06","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 976b299ee27c5fc3d42f2673170ab95e HTA downloader HTA SHA-256 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33 HTA downloader HTA SHA-256 99fcabf7c996d6ec077ccd745a158a3a","pattern":"[file:hashes.'SHA-256' = '8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--689c3c1f-a540-4a95-937e-1171103bc616","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 50c8155ed113f3f62337d756e6915044 HTA downloader HTA SHA-256 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f HTA downloader HTA SHA-256 f1aa14ebfd2da477edba94b34f09f775","pattern":"[file:hashes.'SHA-256' = '85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f0af46de-586a-472d-b168-0c67c642766d","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 395403d6a3df9d8da179f3cd5faf81b1 HTA downloader HTA SHA-256 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b HTA downloader HTA SHA-256 bd724bbb27f9a71fd44f1c334b003541","pattern":"[file:hashes.'SHA-256' = '875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--69345226-1322-4b3e-af46-a549a184fd45","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: adb8c5ff4e32e6a41fdf508455c5b697 HTA downloader HTA SHA-256 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c HTA downloader HTA SHA-256 e57409c5e1f8287900c1c3b3e8c099ce","pattern":"[file:hashes.'SHA-256' = '92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d85076e8-40ce-4a85-9028-899a6a906903","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 9f4a7d6ac2e0385472298f384fc8 Malicious PDF lure PDF SHA-256 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280 Malicious PDF lure PDF SHA-256 711c0aa8cde078aa349fb329e3e4","pattern":"[file:hashes.'SHA-256' = '943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dba9a034-d9ab-4f06-a3df-3dbd318d9468","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: c00dae6812c03bba019edf9c059ece33 HTA downloader HTA SHA-256 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1 HTA downloader HTA SHA-256 875e8d4137e1016b4be869e36e00a941","pattern":"[file:hashes.'SHA-256' = '99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e527536e-7121-4567-87ae-870a7950147f","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 761071655fa585b64eed3bd78fc28e01 HTA downloader HTA SHA-256 a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456 HTA downloader HTA SHA-256 7e04e86c07213fed7bebccd9953818b1","pattern":"[file:hashes.'SHA-256' = 'a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2c597400-bb7c-4498-8653-fde7e6a79a10","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 4e89902fd5592a2fb881ebb0e4bd2f8b HTA downloader HTA SHA-256 bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01 HTA downloader HTA SHA-256 a42daeca71a6bdc79fd66b8b6ee41356","pattern":"[file:hashes.'SHA-256' = 'bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3109f98b-cb2d-494c-bcfa-b09f578dd83c","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 96feea0d355732af5bea459db1dd Malicious PDF lure PDF SHA-256 bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8 Malicious PDF lure PDF SHA-256 943d63ace373ee50d074daf84d35","pattern":"[file:hashes.'SHA-256' = 'bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bfa3a8ab-4bc8-4745-866a-716d48b9bc04","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 485688b5958d82fcb072a837e27e246b HTA downloader HTA SHA-256 c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756 HTA downloader HTA SHA-256 6e6bd2f7566ffa52d52fa9d5f048bbb9","pattern":"[file:hashes.'SHA-256' = 'c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a06b85b-3bb7-480a-8538-dd3e16022592","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: fae0b57d708aebd77d99667616d5 Malicious PDF lure PDF SHA-256 c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure PDF SHA-256 0849a6b87fbef25089ad0be746f8","pattern":"[file:hashes.'SHA-256' = 'c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7915e63b-8e85-48a2-84a8-752838263a34","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 7b3ce6db57566ed7bd0e92d03d85 Malicious PDF lure PDF SHA-256 d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c Malicious PDF lure PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca","pattern":"[file:hashes.'SHA-256' = 'd04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a106304e-c273-45a3-b547-720ec9d16d01","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 1a2f0f8eac289e6b653a5d126f95 Malicious PDF lure PDF SHA-256 d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85 Malicious PDF lure PDF SHA-256 d04f68079ca90c65223a907f23fa","pattern":"[file:hashes.'SHA-256' = 'd13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6dc9e949-7968-458d-a871-3b3ca0ef0603","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 66a5e651ad8a64893c76a725c859 Malicious PDF lure PDF SHA-256 d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365 Malicious PDF lure PDF SHA-256 47d321c1a232e5cdd1e39a06dadb","pattern":"[file:hashes.'SHA-256' = 'd910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--21833049-e8d5-4f02-b3ad-60f00bfa4250","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 3d7e90e38a0e38083181f8c3312adc9c HTA downloader HTA SHA-256 e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add HTA downloader HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207","pattern":"[file:hashes.'SHA-256' = 'e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fed79130-bdeb-47bc-b572-0c5a857dae9a","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: b82816a8353e9a8a574bfde5f491 Malicious PDF lure PDF SHA-256 ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15","pattern":"[file:hashes.'SHA-256' = 'ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6ba7a264-1e9d-4d1f-9cd1-5f268807b5c8","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 8857308b3a1185e6f4ebc4164db8584f HTA downloader HTA SHA-256 f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b HTA downloader HTA SHA-256 c477bdfae91e3df9be29e9eeba785467","pattern":"[file:hashes.'SHA-256' = 'f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60ac0a7a-a7e4-4d07-a8b5-f26979793dbd","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: b07b25cc7d910 AutoIt loader component AutoIt script SHA-256 f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba AutoIt loader component Casbaneiro payload SHA-256 7de63753","pattern":"[file:hashes.'SHA-256' = 'f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--84087906-4b4a-4128-87ba-51b1736e2ee5","created":"2026-09-14T08:42:16.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910","description":"Seen in \"Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites\" (Cyber Security News). Context: 99[.]188[.]28 Campaign infrastructure AutoIt script SHA-256 fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910 AutoIt loader component AutoIt script SHA-256 f76d09cbd455c","pattern":"[file:hashes.'SHA-256' = 'fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910']","pattern_type":"stix","valid_from":"2026-09-14T08:42:16.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c0289a6a-b633-4af7-8e2e-0e95bd3934de","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: involving 7-Zip binaries. IOCs Indicator Value SHA-256 hash 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 Associated file 7zp.dll File description Trojanized DLL loa","pattern":"[file:hashes.'SHA-256' = '29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2958dbc2-4a2d-4fc0-983d-b1b5c600d847","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: on Trojanized DLL loader Internal name boy.dll SHA-256 hash 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e Associated file p File description Encrypted PE loader shel","pattern":"[file:hashes.'SHA-256' = '749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49de309f-c09a-4dc2-8447-20f665450d1f","created":"2026-09-14T08:09:26.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a","description":"Seen in \"China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor\" (GBHackers). Context: File description Encrypted PE loader shellcode SHA-256 hash d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a Associated malware GRAYRABBIT backdoor Internal name core.d","pattern":"[file:hashes.'SHA-256' = 'd7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a']","pattern_type":"stix","valid_from":"2026-09-14T08:09:26.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/grayrabbit-backdoor/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1a4bcc10-8f22-4499-8b4b-6ab2a936293c","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 06e0afd01bbc6c9d5dc16c3165089b233dc071e1f251abd06235d1b9166cdac5","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: de3cdf Resource icon shared across ARKTunnel samples SHA256 06e0afd01bbc6c9d5dc16c3165089b233dc071e1f251abd06235d1b9166cdac5 Resource icon shared across ARKTunnel samples SHA256 2c6e11","pattern":"[file:hashes.'SHA-256' = '06e0afd01bbc6c9d5dc16c3165089b233dc071e1f251abd06235d1b9166cdac5']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4f060352-6af5-46bc-ac9c-1fcda4a98cd2","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 25558ea78c4aa0fdd0f45fafcaa546d3115dc5806809d144a5801a40e48fd4c5","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 9ed15ce1a6961 eld0.exe , Insomnia RAT initial loader SHA256 25558ea78c4aa0fdd0f45fafcaa546d3115dc5806809d144a5801a40e48fd4c5 eld0.tmp unpacked loader stage SHA256 9b0d9cbc0fd4a7bae8b78","pattern":"[file:hashes.'SHA-256' = '25558ea78c4aa0fdd0f45fafcaa546d3115dc5806809d144a5801a40e48fd4c5']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0350ff84-5019-4d6b-b09a-da1c3bc4a15b","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 2c6e11027b011042c9a118fc20728f8f4ebb6be8795cc84cc9a45622c297d354","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 6cdac5 Resource icon shared across ARKTunnel samples SHA256 2c6e11027b011042c9a118fc20728f8f4ebb6be8795cc84cc9a45622c297d354 eld2.exe , Docro Hijacker branch installer SHA256 553ce594c","pattern":"[file:hashes.'SHA-256' = '2c6e11027b011042c9a118fc20728f8f4ebb6be8795cc84cc9a45622c297d354']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3098fb2b-5b5e-40c5-abd7-deaf6661f298","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 3052bd320a34e12ee694811ed0578797477dfd480c664491e509ed15ce1a6961","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: efff1f2d73 windirstat.tmp unpacked OfferLoader stage SHA256 3052bd320a34e12ee694811ed0578797477dfd480c664491e509ed15ce1a6961 eld0.exe , Insomnia RAT initial loader SHA256 25558ea78c4aa","pattern":"[file:hashes.'SHA-256' = '3052bd320a34e12ee694811ed0578797477dfd480c664491e509ed15ce1a6961']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fa3ed68e-c94d-4860-9c4e-a8f840858d5e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 553ce594c9c6afdd4794fddc28c194e3bc3c1b052310e5099c58ac15bab72104","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 2c297d354 eld2.exe , Docro Hijacker branch installer SHA256 553ce594c9c6afdd4794fddc28c194e3bc3c1b052310e5099c58ac15bab72104 eld2.tmp , unpacked Docro Hijacker stage SHA256 fdcc95b7791","pattern":"[file:hashes.'SHA-256' = '553ce594c9c6afdd4794fddc28c194e3bc3c1b052310e5099c58ac15bab72104']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cbb9cad7-1451-4698-abe6-ab18b5ee59e9","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: de Python component of the Insomnia RAT dual payload SHA256 62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e aa.js , Node.js component of the Insomnia RAT dual payload","pattern":"[file:hashes.'SHA-256' = '62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80d62d4d-5706-4ecd-916e-af0023f346bf","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: rs of Compromise (IoCs):- Type Indicator Description SHA256 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c Trojanized windirstat.exe OfferLoader installer delivered t","pattern":"[file:hashes.'SHA-256' = '7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2c7259da-70c0-4628-9be9-a3a25851f411","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 9d144a5801a40e48fd4c5 eld0.tmp unpacked loader stage SHA256 9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69 a.dll , PowerShell downloader for Insomnia RAT stages SHA25","pattern":"[file:hashes.'SHA-256' = '9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--af9ef0ae-a9ed-4fac-8fba-40a21a053b40","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: , Node.js component of the Insomnia RAT dual payload SHA256 aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1 eld1.exe , ARKTunnel steganography dropper SHA256 e05bc22af","pattern":"[file:hashes.'SHA-256' = 'aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d19ba093-76d8-4806-8fd5-da12afe7c602","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: Trex.zip , archive extracted from the bitmap payload SHA256 b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c wscl.exe , ARKTunnel WebSocket tunneling RAT SHA256 d8d783f","pattern":"[file:hashes.'SHA-256' = 'b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--21681115-42d2-4c74-b308-16ffb2b9ff0e","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: .dll , PowerShell downloader for Insomnia RAT stages SHA256 ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e t.ps1 , Insomnia RAT PowerShell loader SHA256 cf184d04ca31f","pattern":"[file:hashes.'SHA-256' = 'ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ecf88efc-863e-4c04-82e0-8e2718a553ec","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 0b4d636eb576e t.ps1 , Insomnia RAT PowerShell loader SHA256 cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de Python component of the Insomnia RAT dual payload SHA256 62","pattern":"[file:hashes.'SHA-256' = 'cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6281d3b4-674e-48b9-81c4-43ca467cacc6","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: c87989c wscl.exe , ARKTunnel WebSocket tunneling RAT SHA256 d8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf Resource icon shared across ARKTunnel samples SHA256 06e0af","pattern":"[file:hashes.'SHA-256' = 'd8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e738fe33-5c05-4270-9fec-f71120c88b62","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: 90b4560f1 eld1.exe , ARKTunnel steganography dropper SHA256 e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d procorTrex.zip , archive extracted from the bitmap payload","pattern":"[file:hashes.'SHA-256' = 'e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0164e9ab-e0dd-4fd9-8f23-7ecd5b545345","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: fferLoader installer delivered through SEO poisoning SHA256 fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 windirstat.tmp unpacked OfferLoader stage SHA256 3052bd320a","pattern":"[file:hashes.'SHA-256' = 'fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4fd5d506-1d08-41ea-a05a-b2c1a80df17a","created":"2026-09-14T08:01:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007","description":"Seen in \"Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker\" (Cyber Security News). Context: c15bab72104 eld2.tmp , unpacked Docro Hijacker stage SHA256 fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007 Adblock.dll , Chrome Secure Preferences bypass DLL File nam","pattern":"[file:hashes.'SHA-256' = 'fdcc95b7791c0d6590dcf1a412dc9fcc92ad2095818d1b78368b31efad012007']","pattern_type":"stix","valid_from":"2026-09-14T08:01:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-abuse-youtube-gaming/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8355ad4-ae5a-4913-8f24-e7a2288471e7","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: 76409f69d445a93910964f8db457bafafb97a011da59e73 PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2ea","pattern":"[file:hashes.'SHA-256' = '40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--33b209ad-676c-4f36-a4d3-74ff26dc7c74","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: o financial websites. IOCs Indicator type Value PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355","pattern":"[file:hashes.'SHA-256' = '6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e5afceef-9a4f-4ef7-bfe1-59b8ad493ad1","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: c21266e40afe99afc96feea0d355732af5bea459db1dd Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc6","pattern":"[file:hashes.'SHA-256' = 'debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d82ed24a-5020-4b50-bad5-74470db5e2e8","created":"2026-09-14T05:56:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390","description":"Seen in \"Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users\" (GBHackers). Context: 0b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Dom","pattern":"[file:hashes.'SHA-256' = 'eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390']","pattern_type":"stix","valid_from":"2026-09-14T05:56:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/casbaneiro-banking-trojan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0721011-70b9-4eae-bb1a-220b4b5efc6c","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: 122ea3cbcb99c8a525b0b30ab985bc8e375c7a 3200000_02C37000.exe 15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda Note: IP addresses and domains are intentionally defanged (","pattern":"[file:hashes.'SHA-256' = '15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671adda']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0c52d61a-8632-42c8-9d67-4706cbfbcf57","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: d5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c 3200000.exe 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a 3200000_02C37000.exe 15700817e517fefcabc0291e350daf3e10d52f","pattern":"[file:hashes.'SHA-256' = '22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e375c7a']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--438aa598-989a-40cc-b544-582c5e48b0f5","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: 1fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6 kojuyn.ini 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c 3200000.exe 22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b","pattern":"[file:hashes.'SHA-256' = '4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a0c']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--905296c2-af7a-45c2-b6ac-69d2adb44990","created":"2026-09-14T05:24:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6","description":"Seen in \"AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process\" (GBHackers). Context: Cs Filename SHA-256 Right-click to open Invoice Details.bat ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6 kojuyn.ini 4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c74","pattern":"[file:hashes.'SHA-256' = 'ae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3450a6']","pattern_type":"stix","valid_from":"2026-09-14T05:24:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/asyncrat-in-hides-windows-process/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7a38f1a1-0f46-4011-a18b-d0214089118d","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: tection For this analysis, we examine the following script: 106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42 . The obfuscation is fairly basic: function names are repla","pattern":"[file:hashes.'SHA-256' = '106eac79396a3ff77b8f375c391260ce422be2ae4d55d3aa75b2635cbdc0fa42']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b447c36-4d5b-4276-ba4f-325ca04b2263","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: ful pivot for finding additional first-stage samples (e.g., 5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552 ). The sandbox-detection heuristic consists of two checks.","pattern":"[file:hashes.'SHA-256' = '5ece7fd3766b0b7f8aadefa562313cea6c3c94f9398658dd389910e5be44f552']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--58219a19-4a53-4bd9-a14a-b226975db304","created":"2026-09-14T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268","description":"Seen in \"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions\" (Elastic Security Labs). Context: ugging. For this analysis, we examine the following binary: c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268 . KREMLIN string decryption algorithm As noted at the begin","pattern":"[file:hashes.'SHA-256' = 'c8c38634dd44d7c6162c66174a6ee23ee404265125166e8d757681bdd66a4268']","pattern_type":"stix","valid_from":"2026-09-14T00:00:00.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Elastic Security Labs","url":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c2d6ab1b-4f58-4107-a3dd-bc5091aea043","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: 256 UTA0560 msgbox.exe GRIMWEDGE loader, a Win32 executable 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3 SHA-256 JungleBamboo a001 LONGTALE malicious Chrome extensi","pattern":"[file:hashes.'SHA-256' = '5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f70475a0-18df-4637-9cff-21cf5f97ccd5","created":"2026-09-12T08:04:47.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc","description":"Seen in \"China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks\" (GBHackers). Context: mber 2 phishing URL serving the shared Chrome exploit chain 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc SHA-256 UTA0560 msgbox.exe GRIMWEDGE loader, a Win32 execut","pattern":"[file:hashes.'SHA-256' = '69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc']","pattern_type":"stix","valid_from":"2026-09-12T08:04:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2a49184c-6320-403c-aaa6-fdd639b6cf63","created":"2026-09-11T14:17:53.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4","description":"Seen in \"New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks\" (Cyber Security News). Context: 056e3a9218 Loader or closely related loader variant SHA-256 13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4 KATARU ARM32 payload SHA-256 6fbae3505ae0d638b820165c572d54","pattern":"[file:hashes.'SHA-256' = '13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4']","pattern_type":"stix","valid_from":"2026-09-11T14:17:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-kataru-iot-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0f926bfa-d117-4559-880f-a110e684094c","created":"2026-09-11T14:17:53.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f","description":"Seen in \"New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks\" (Cyber Security News). Context: ec254d98b876e59692b5fa22abc1d4 KATARU ARM32 payload SHA-256 6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f KATARU ARM32 sample SHA-256 9d87e6615c810907443ebd5e915f3b3","pattern":"[file:hashes.'SHA-256' = '6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f']","pattern_type":"stix","valid_from":"2026-09-11T14:17:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-kataru-iot-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c58d6700-5762-46a1-8c72-9308614ab6b1","created":"2026-09-11T14:17:53.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5","description":"Seen in \"New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks\" (Cyber Security News). Context: 99c3b5c6b6c684637138a7f8ec9cebc KATARU ARM32 sample SHA-256 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5 KATARU AMD64 sample IP address 160[.]191.242.92 Observed Te","pattern":"[file:hashes.'SHA-256' = '9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5']","pattern_type":"stix","valid_from":"2026-09-11T14:17:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-kataru-iot-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--639fc1dc-1f91-4705-8de3-35f8921fefb3","created":"2026-09-11T14:17:53.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc","description":"Seen in \"New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks\" (Cyber Security News). Context: 92dda71e82dc47e8efe13f30617f35f KATARU ARM32 sample SHA-256 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc KATARU ARM32 sample SHA-256 9d7cd4948a1fcbaeadc425752fce9a9","pattern":"[file:hashes.'SHA-256' = '9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc']","pattern_type":"stix","valid_from":"2026-09-11T14:17:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-kataru-iot-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--957ea49a-88c4-4c6e-95f4-05430fa30356","created":"2026-09-11T14:17:53.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218","description":"Seen in \"New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks\" (Cyber Security News). Context: and executed after Telnet credential brute forcing SHA-256 cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218 Loader or closely related loader variant SHA-256 13382c16e2","pattern":"[file:hashes.'SHA-256' = 'cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218']","pattern_type":"stix","valid_from":"2026-09-11T14:17:53.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/new-kataru-iot-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b226375e-5bec-4bc3-b1e8-752d4eb3b904","created":"2026-09-11T12:24:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c","description":"Seen in \"Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign\" (GBHackers). Context: look ordinary. IOCs SHA-256 File Name File Type Description 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c windirstat.exe PE32 executable; Inno Setup 6.7.1 installer","pattern":"[file:hashes.'SHA-256' = '7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c']","pattern_type":"stix","valid_from":"2026-09-11T12:24:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/10000-malware-loaders/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f5af19d4-a4fc-41dd-b918-13780de77d68","created":"2026-09-11T12:24:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73","description":"Seen in \"Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign\" (GBHackers). Context: at installer distributed through an SEO-poisoning campaign. fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 windirstat.tmp PE32 executable; unpacked Inno Setup stage U","pattern":"[file:hashes.'SHA-256' = 'fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73']","pattern_type":"stix","valid_from":"2026-09-11T12:24:51.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/10000-malware-loaders/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bc4cb6e9-a705-42b9-8e26-bf43445a8c0c","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 382be8e1ddbebf3cdf4733cf989ba291f9013 SloppyRAT DLL SHA-256 00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec SloppyRAT DLL SHA-256 93273ea09bd9df881a594db8cfe1b1bbc54f4","pattern":"[file:hashes.'SHA-256' = '00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--00cd80fb-e4d1-46bd-84f9-52860ed6f5ed","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: ebdbecb3322453bdc41b2113427f9f92d32d2 SloppyRAT DLL SHA-256 1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd SloppyRAT DLL SHA-256 eaa52d2d6d4daf29157e8e813247fb2e92797","pattern":"[file:hashes.'SHA-256' = '1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9b541807-1aa8-415f-8a63-191032a6d67a","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 5e0ee093541d99a9dba5f69a264f7f3054b19 SloppyRAT DLL SHA-256 2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2 SloppyRAT DLL SHA-256 1439990ff65364a0f608a322aa3a493bc1683","pattern":"[file:hashes.'SHA-256' = '2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4ac3e086-360e-483e-ae60-75943c563cb6","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: a5bcbf9a287d4653de7b76051bde73a94d064 SloppyRAT DLL SHA-256 3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19 SloppyRAT DLL SHA-256 2f3d95de716f330fad2330d8787ebdbecb332","pattern":"[file:hashes.'SHA-256' = '3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--598a0b3e-7c3f-4afc-82ef-816e2a1cb472","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 60f6d09ddb5be36cc1766a41d77c5b89d3a56 SloppyRAT DLL SHA-256 466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8 SloppyRAT DLL SHA-256 f534a957edec74d69081665309311b791b6d1","pattern":"[file:hashes.'SHA-256' = '466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3cc20ac9-6c61-45d6-9c12-5440ce696cf8","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: d1d8b6e9847aa6b8613493e5bc233ece3d189 SloppyRAT DLL SHA-256 4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56 SloppyRAT DLL SHA-256 466f9b8dce77b3a026fe4f833aa4949784fb8","pattern":"[file:hashes.'SHA-256' = '4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0d5af322-5cbb-4beb-8244-b575d74c8a58","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: e3b763bd4a4b0cdf59eeff981d8e307fcf316 SloppyRAT DLL SHA-256 518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064 SloppyRAT DLL SHA-256 3a8994928f512fffcb32e117ac45e0ee09354","pattern":"[file:hashes.'SHA-256' = '518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9b240c52-7847-4794-af0e-6091f9466d36","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 7374e2234f2a497b19d26637018a1839e6dfd SloppyRAT DLL SHA-256 607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9 SloppyRAT DLL SHA-256 7bb025b426ae6ccbc170fbca58634b8dd77a6","pattern":"[file:hashes.'SHA-256' = '607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4fb47b01-33ca-46a4-b7e0-f11a7ba59d80","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SloppyRAT DLL SHA-256 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SloppyRAT DLL SHA-256 bdcf8fe230e23692b658b62b6547374e2234f","pattern":"[file:hashes.'SHA-256' = '680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3d64315e-44a9-4680-acd6-a8a6936e1818","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 34b8dd77a61447e48dabe9c2e2fb0d339d8b7 SloppyRAT DLL SHA-256 6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013 SloppyRAT DLL SHA-256 00c116e498799dc831c8aeb602349296c4b93","pattern":"[file:hashes.'SHA-256' = '6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1cc79862-cc96-412e-a828-d3efebb6d1e3","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: f37a47f4c8aad08e6d5cbb7c19a62c6b765f9 SloppyRAT DLL SHA-256 7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7 SloppyRAT DLL SHA-256 6d50bb50d4e7d6ac36ca6d2761f382be8e1dd","pattern":"[file:hashes.'SHA-256' = '7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e4bd160-b67c-4e88-ab6b-74e98b095649","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 0a091743cf567396201eff7731f5475768f9a SloppyRAT DLL SHA-256 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 SloppyRAT DLL SHA-256 ff142fc192daa2a83bc565e5b38ebbe05561f","pattern":"[file:hashes.'SHA-256' = '8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1a5b4568-f896-4911-a97f-c8aa9fd2695e","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 49296c4b9325535d674fe2b6e2e091878dcec SloppyRAT DLL SHA-256 93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490 SloppyRAT DLL SHA-256 971f25f84be88c4fd304d555b5e3da12f6b36","pattern":"[file:hashes.'SHA-256' = '93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b1aa6c80-6512-4244-82a6-828eefe0e1d8","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 1b1bbc54f40f623f44427278ae96fb9b46490 SloppyRAT DLL SHA-256 971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d SloppyRAT DLL SHA-256 a13fcbb0870f2fabb7e0a8c757ee3b763bd4a","pattern":"[file:hashes.'SHA-256' = '971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--390729c7-a3c9-4103-8fc6-ca55cce06576","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: s of compromise (IoCs):- Type Indicator Description SHA-256 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a SloppyRAT DLL SHA-256 8774533134d9d1514106c4090a0c5bccab455","pattern":"[file:hashes.'SHA-256' = '9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a89f4c55-cde4-4f39-b4ec-54d3e16ee2b6","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 3da12f6b368e4b9ba0943961ff21ba6fa4d4d SloppyRAT DLL SHA-256 a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316 SloppyRAT DLL SHA-256 518cd57a303ff7ac2b5c4c8439aa5bcbf9a28","pattern":"[file:hashes.'SHA-256' = 'a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--26fd18b8-423d-48e4-914e-fe08fad0ae5c","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SloppyRAT DLL SHA-256 bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd SloppyRAT DLL SHA-256 607212cfe73c5c84b2dd95b2c0ff37a47f4c8","pattern":"[file:hashes.'SHA-256' = 'bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--20923a60-a065-41fa-8f3d-63e05adf9204","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 60b937c7beaf9ab51b03191dfcaba40b7b189 SloppyRAT DLL SHA-256 c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189 SloppyRAT DLL SHA-256 4ecb2d06510dfee1b67f5d9a68c60f6d09ddb","pattern":"[file:hashes.'SHA-256' = 'c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--74d0ca31-eeac-4ed0-bd3c-af64e4853879","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 7fb2e92797324230ee42c79f7861b2f5c341d SloppyRAT DLL SHA-256 cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189 SloppyRAT DLL SHA-256 c0ef62a2d5ca11c2eedad3561d5d1d8b6e984","pattern":"[file:hashes.'SHA-256' = 'cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0380168f-3c73-4422-ac1a-6ba6bb820cb6","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: a493bc1683cb5fc30cffc44948da29623fffd SloppyRAT DLL SHA-256 eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d SloppyRAT DLL SHA-256 cb9930d0cde5bf8e8a7ad08fe2c60b937c7be","pattern":"[file:hashes.'SHA-256' = 'eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d771ce6a-2b3f-4763-849d-48165b3d8aa3","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: 4949784fb854bea4137e52609e857d439dec8 SloppyRAT DLL SHA-256 f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickF","pattern":"[file:hashes.'SHA-256' = 'f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0623e62f-5634-4a13-a590-2800ad44f2a1","created":"2026-09-11T09:12:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (Cyber Security News). Context: c5bccab4550facdcfe03f4e02b9764343a990 SloppyRAT DLL SHA-256 ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SloppyRAT DLL SHA-256 680c3a9f5fdddfcc34856c7a67d21bbdd2b47","pattern":"[file:hashes.'SHA-256' = 'ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5']","pattern_type":"stix","valid_from":"2026-09-11T09:12:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-deploy-new-sloppyrat/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f2b24baf-a332-41f8-ad58-8fd9d75f4f5d","created":"2026-09-11T09:07:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4","description":"Seen in \"New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks\" (GBHackers). Context: nd execute an ARM payload named vlxx.arm, with SHA-256 hash 13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4. Staging markers including condi72 and condixx link the del","pattern":"[file:hashes.'SHA-256' = '13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4']","pattern_type":"stix","valid_from":"2026-09-11T09:07:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/iot-malware-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--383b9eea-dbdc-4f15-b47e-06e44e09a9e3","created":"2026-09-11T09:07:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f","description":"Seen in \"New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks\" (GBHackers). Context: 634b8031ec254d98b876e59692b5fa22abc1d4 SHA-256 Hash (ARM32) 6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f SHA-256 Hash (ARM32) 9d87e6615c810907443ebd5e915f3b35099c3b","pattern":"[file:hashes.'SHA-256' = '6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f']","pattern_type":"stix","valid_from":"2026-09-11T09:07:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/iot-malware-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7628994a-6283-49eb-8a22-82e622be88b9","created":"2026-09-11T09:07:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5","description":"Seen in \"New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks\" (GBHackers). Context: 5f3b35099c3b5c6b6c684637138a7f8ec9cebc SHA-256 Hash (AMD64) 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5 IPv4 Address 160[.]191.242.92 Telnet credential brute-force","pattern":"[file:hashes.'SHA-256' = '9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5']","pattern_type":"stix","valid_from":"2026-09-11T09:07:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/iot-malware-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--73bf6a5b-3330-4636-8873-b53dc8af265b","created":"2026-09-11T09:07:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc","description":"Seen in \"New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks\" (GBHackers). Context: 2d548ce92dda71e82dc47e8efe13f30617f35f SHA-256 Hash (ARM32) 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc SHA-256 Hash (AMD64) 9d7cd4948a1fcbaeadc425752fce9a933bd6fc","pattern":"[file:hashes.'SHA-256' = '9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc']","pattern_type":"stix","valid_from":"2026-09-11T09:07:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/iot-malware-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b94d9cb5-b294-421d-abc0-3a46ecc9a8e0","created":"2026-09-11T09:07:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218","description":"Seen in \"New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks\" (GBHackers). Context: imperfect. IOCs Indicator Type Value SHA-256 Hash (Loader) cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218 SHA-256 Hash (ARM32) 13382c16e2401b07451577b46e634b8031ec25","pattern":"[file:hashes.'SHA-256' = 'cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218']","pattern_type":"stix","valid_from":"2026-09-11T09:07:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/iot-malware-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f67775c-4aa0-496a-9d29-7feefb53d009","created":"2026-09-11T07:14:09.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63","description":"Seen in \"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor\" (The Hacker News). Context: dy running. Gen published the following indicators. SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 malicious DLL loader, written to disk as 7z.dll SHA-256 749","pattern":"[file:hashes.'SHA-256' = '29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63']","pattern_type":"stix","valid_from":"2026-09-11T07:14:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--37bbf446-3b5a-4afe-982a-5f51dc8f2b6d","created":"2026-09-11T07:14:09.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e","description":"Seen in \"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor\" (The Hacker News). Context: a63 malicious DLL loader, written to disk as 7z.dll SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e encrypted payload file, named p SHA-256 d7a3c7eb94edc0e020f","pattern":"[file:hashes.'SHA-256' = '749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e']","pattern_type":"stix","valid_from":"2026-09-11T07:14:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34cae475-3e9a-4fc1-8f47-fa7a052087c4","created":"2026-09-11T07:14:09.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a","description":"Seen in \"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor\" (The Hacker News). Context: 74d675a98662e02422e encrypted payload file, named p SHA-256 d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll Domain mail.uai","pattern":"[file:hashes.'SHA-256' = 'd7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a']","pattern_type":"stix","valid_from":"2026-09-11T07:14:09.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b0c9e50-989c-4181-9faf-2d72e7a6040d","created":"2026-09-11T07:11:14.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b","description":"Seen in \"UK Council Attack Linked to Mass Exploitation of SonicWall Flaw\" (Security Affairs). Context: ts. The SHA-256 of the Impacket binary the operator used is 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b , and the delivery IP was 95.181.173[.]36. The operator ran","pattern":"[file:hashes.'SHA-256' = '690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b']","pattern_type":"stix","valid_from":"2026-09-11T07:11:14.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f805b7b8-ba44-41aa-be03-bdb7424c4c28","created":"2026-09-11T06:17:07.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (GBHackers). Context: be05561f3a19c7fc2d08e38c97e1986bbc5 SHA256 of SloppyRAT DLL 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SHA256 of SloppyRAT DLL bdcf8fe230e23692b658b62b6547374e223","pattern":"[file:hashes.'SHA-256' = '680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21']","pattern_type":"stix","valid_from":"2026-09-11T06:17:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-new-sloppyrat-via-clickfix-to-enable-ransomware-lateral-movement/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c64c05ee-2d14-48c2-8b5c-447e2e7edf28","created":"2026-09-11T06:17:07.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (GBHackers). Context: 091743cf567396201eff7731f5475768f9a SHA256 of SloppyRAT DLL 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 SHA256 of SloppyRAT DLL ff142fc192daa2a83bc565e5b38ebbe0556","pattern":"[file:hashes.'SHA-256' = '8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990']","pattern_type":"stix","valid_from":"2026-09-11T06:17:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-new-sloppyrat-via-clickfix-to-enable-ransomware-lateral-movement/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3b2ad8e9-e3dc-4cde-8c2d-9d54057921d5","created":"2026-09-11T06:17:07.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (GBHackers). Context: vent. Indicators Of Compromise (IOCs) Indicator Description 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a SHA256 of SloppyRAT DLL 8774533134d9d1514106c4090a0c5bccab4","pattern":"[file:hashes.'SHA-256' = '9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a']","pattern_type":"stix","valid_from":"2026-09-11T06:17:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-new-sloppyrat-via-clickfix-to-enable-ransomware-lateral-movement/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f1070526-26b3-4764-b528-4c617feb5429","created":"2026-09-11T06:17:07.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (GBHackers). Context: bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SHA256 of SloppyRAT DLL bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd SHA256 of SloppyRAT DLL Note: IP addresses and domains are","pattern":"[file:hashes.'SHA-256' = 'bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd']","pattern_type":"stix","valid_from":"2026-09-11T06:17:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-new-sloppyrat-via-clickfix-to-enable-ransomware-lateral-movement/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6adc4bc0-845e-438b-a13e-ac890119a77a","created":"2026-09-11T06:17:07.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5","description":"Seen in \"Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement\" (GBHackers). Context: bccab4550facdcfe03f4e02b9764343a990 SHA256 of SloppyRAT DLL ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SHA256 of SloppyRAT DLL 680c3a9f5fdddfcc34856c7a67d21bbdd2b","pattern":"[file:hashes.'SHA-256' = 'ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5']","pattern_type":"stix","valid_from":"2026-09-11T06:17:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/hackers-deploy-new-sloppyrat-via-clickfix-to-enable-ransomware-lateral-movement/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f2f6598-378f-413d-a67b-55b75ced3257","created":"2026-09-11T05:30:08.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461","description":"Seen in \"Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware\" (GBHackers). Context: 026-20079 91.214.78[.]118 UAT-11823 Netcat reverse-shell C2 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink ELF malware 43.204.2[.]142 UAT-1198","pattern":"[file:hashes.'SHA-256' = '6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461']","pattern_type":"stix","valid_from":"2026-09-11T05:30:08.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/critical-cisco-fmc-flaws-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4be15cf6-03c0-4ad9-b38a-52facb48367e","created":"2026-09-11T05:30:08.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d","description":"Seen in \"Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware\" (GBHackers). Context: as MISP, VirusTotal, or your SIEM. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6f","pattern":"[file:hashes.'SHA-256' = 'b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d']","pattern_type":"stix","valid_from":"2026-09-11T05:30:08.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/critical-cisco-fmc-flaws-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a148911b-0383-4b4c-b4f7-e24a74719df3","created":"2026-09-11T05:30:08.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e","description":"Seen in \"Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware\" (GBHackers). Context: fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar JAR-based command executor 89.34.96[.]56","pattern":"[file:hashes.'SHA-256' = 'db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e']","pattern_type":"stix","valid_from":"2026-09-11T05:30:08.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/critical-cisco-fmc-flaws-actively-exploited/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f99a5233-69fb-42ef-bc12-1858352b4993","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: -QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://ta","pattern":"[file:hashes.'SHA-256' = '5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--038a0c33-b7a5-4740-b3e6-dd61f36b3ac9","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: 001.exe Detection Name: W32.9F1F11A708-100.SBX.TG** SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://ta","pattern":"[file:hashes.'SHA-256' = '90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e31af430-bb06-418e-b06f-41d8e76ff0aa","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: sample.exe Detection Name: W32.C4DD71E347-95.SBX.TG SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta","pattern":"[file:hashes.'SHA-256' = '9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3dd775de-6b64-4c6c-a34c-b2094cfc5451","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta","pattern":"[file:hashes.'SHA-256' = '9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--afa8d4bc-ed39-4b4a-b273-91b97555eb74","created":"2026-09-10T18:00:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2","description":"Seen in \"We've got one word for it, and it's usually the wrong one\" (Cisco Talos). Context: 0055df5.dll Detection Name: Auto.90B145.282358.in02 SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://ta","pattern":"[file:hashes.'SHA-256' = 'c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2']","pattern_type":"stix","valid_from":"2026-09-10T18:00:15.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--24bcff0c-6439-47a2-b043-18279df47bbd","created":"2026-09-10T14:43:37.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588","description":"Seen in \"SloppyRAT: A New Tool For Ransomware Attacks\" (Zscaler ThreatLabz). Context: application/json User-Agent: CommandExecutor/1.0 X-API-KEY: af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588 Content-Length: 49 Host: api.truesmart.org {\"machine_id\":\"a","pattern":"[file:hashes.'SHA-256' = 'af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588']","pattern_type":"stix","valid_from":"2026-09-10T14:43:37.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Zscaler ThreatLabz","url":"https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d0f3b8ae-a207-49a6-9e99-a9631a03107b","created":"2026-09-10T13:33:41.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461","description":"Seen in \"Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware\" (Cyber Security News). Context: 079 91.214.78[.]118 UAT-11823 Netcat-based reverse shell C2 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware sample 43.204.2[.]142 UAT-1","pattern":"[file:hashes.'SHA-256' = '6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461']","pattern_type":"stix","valid_from":"2026-09-10T13:33:41.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cisco-firewall-root-access-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f2e3a402-a33c-4960-a0a8-694105995b1e","created":"2026-09-10T13:33:41.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d","description":"Seen in \"Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware\" (Cyber Security News). Context: e for all three observed campaigns. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6d","pattern":"[file:hashes.'SHA-256' = 'b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d']","pattern_type":"stix","valid_from":"2026-09-10T13:33:41.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cisco-firewall-root-access-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--73e4edc7-604e-4675-a317-4cc54af85229","created":"2026-09-10T13:33:41.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e","description":"Seen in \"Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware\" (Cyber Security News). Context: 54fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar — JAR-based command executor 89.34.96[.]5","pattern":"[file:hashes.'SHA-256' = 'db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e']","pattern_type":"stix","valid_from":"2026-09-10T13:33:41.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/cisco-firewall-root-access-flaw/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c51d9935-d3a5-473c-a40d-c85875fc36a2","created":"2026-09-10T12:58:10.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e","description":"Seen in \"Redtail Payload Analysis &#x5b;Guest Diary&#x5d;, (Wed, Sep 9th)\" (SANS Internet Storm Center). Context: le analyzed in this article has the following SHA-256 hash: 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e Dynamic analysis showed that the payload did considerably m","pattern":"[file:hashes.'SHA-256' = '63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e']","pattern_type":"stix","valid_from":"2026-09-10T12:58:10.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33326"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be849a9a-6eb9-4c59-96ad-20e6be080e78","created":"2026-09-10T10:00:43.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8","description":"Seen in \"The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE\" (Palo Alto Unit 42). Context: pod - image : ghcr .io / spiffe / spire - agent @ sha256 : 40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8 \\ \" type : \\ \" k8s \\ \" value : \\ \" pod - label : app : clie","pattern":"[file:hashes.'SHA-256' = '40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8']","pattern_type":"stix","valid_from":"2026-09-10T10:00:43.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9190490b-fac7-4329-95a5-422a595f7e89","created":"2026-09-10T10:00:43.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38","description":"Seen in \"The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE\" (Palo Alto Unit 42). Context: 176_ab5c_4f2a_b5f3_3c7e4c91a9ca .slice / cri - containerd - 7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope We copied this path to a mock cgroup path and wrote o","pattern":"[file:hashes.'SHA-256' = '7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38']","pattern_type":"stix","valid_from":"2026-09-10T10:00:43.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--070cf52b-edbb-4fde-9122-291a9bc00fe3","created":"2026-09-10T08:06:02.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c","description":"Seen in \"Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks\" (Cyber Security News). Context: rprint associated with 178.128.87[.]160 Certificate SHA-256 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c Certificate fingerprint associated with 178.128.87[.]160 Fi","pattern":"[file:hashes.'SHA-256' = '46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c']","pattern_type":"stix","valid_from":"2026-09-10T08:06:02.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/gpt-powered-tools/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--51b73fcd-ad1e-4552-bc9d-9054f2701357","created":"2026-09-10T08:06:02.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5","description":"Seen in \"Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks\" (Cyber Security News). Context: erprint associated with 165.22.184[.]26 Certificate SHA-256 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 Certificate fingerprint associated with 178.128.87[.]160 Ce","pattern":"[file:hashes.'SHA-256' = '4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5']","pattern_type":"stix","valid_from":"2026-09-10T08:06:02.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/gpt-powered-tools/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0f665d11-6b79-4e8a-bd1b-af1b1fadcc2b","created":"2026-09-10T08:06:02.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8","description":"Seen in \"Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks\" (Cyber Security News). Context: SockTz installers and campaign scripts Certificate SHA-256 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 Certificate fingerprint associated with 165.22.184[.]26 Cer","pattern":"[file:hashes.'SHA-256' = '7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8']","pattern_type":"stix","valid_from":"2026-09-10T08:06:02.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/gpt-powered-tools/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--af3a6fde-aa20-492d-a923-9a2e5f8d1910","created":"2026-09-10T08:06:02.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec","description":"Seen in \"Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks\" (Cyber Security News). Context: zilian financial campaign malware or tool hash File SHA-256 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec Brazilian financial campaign malware or tool hash URL hxxp[","pattern":"[file:hashes.'SHA-256' = '87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec']","pattern_type":"stix","valid_from":"2026-09-10T08:06:02.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/gpt-powered-tools/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2e27602b-7fc9-4c75-a0b1-4eee9a96058e","created":"2026-09-10T08:06:02.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996","description":"Seen in \"Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks\" (Cyber Security News). Context: e fingerprint associated with 178.128.87[.]160 File SHA-256 a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 Brazilian financial campaign malware or tool hash File SHA-","pattern":"[file:hashes.'SHA-256' = 'a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996']","pattern_type":"stix","valid_from":"2026-09-10T08:06:02.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/gpt-powered-tools/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7419e7f3-5aea-4a9f-a2e7-f5b30d25639c","created":"2026-09-10T07:01:43.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11","description":"Seen in \"Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.\" (GBHackers). Context: stores. IOCs Indicator Type Value Description SHA-256 Hash 9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dc","pattern":"[file:hashes.'SHA-256' = '9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11']","pattern_type":"stix","valid_from":"2026-09-10T07:01:43.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/clickfix-lures-target-macos/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--83f01c13-2dd5-4bca-93a5-dfebe731c200","created":"2026-09-10T06:02:43.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c","description":"Seen in \"Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America\" (GBHackers). Context: ingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb1162","pattern":"[file:hashes.'SHA-256' = '46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c']","pattern_type":"stix","valid_from":"2026-09-10T06:02:43.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/llm-powered-cyberattacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2e6e7993-2bc3-43fb-97c2-281e9c9b1afe","created":"2026-09-10T06:02:43.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5","description":"Seen in \"Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America\" (GBHackers). Context: bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542","pattern":"[file:hashes.'SHA-256' = '4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5']","pattern_type":"stix","valid_from":"2026-09-10T06:02:43.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/llm-powered-cyberattacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f3c630f4-83f1-4e98-b13a-fe8b95097253","created":"2026-09-10T06:02:43.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8","description":"Seen in \"Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America\" (GBHackers). Context: b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 165.22.184[.]26 Note: IP addresses and domains are intentio","pattern":"[file:hashes.'SHA-256' = '7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8']","pattern_type":"stix","valid_from":"2026-09-10T06:02:43.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/llm-powered-cyberattacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b01d70a0-5768-457c-92d3-b708e3960e66","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: 3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA41","pattern":"[file:hashes.'SHA-256' = '353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4d8eb2ad-342c-4ba0-bf5d-ffa71173daa7","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: ploitation. Ioc TA412 Indicator Type Description First Seen 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d SHA256 driver-html.js(BlueMoon exploit JavaScript) August 2","pattern":"[file:hashes.'SHA-256' = '779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--642fa3c7-dc72-46f9-9649-f3705f8d02f6","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: 09fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03","pattern":"[file:hashes.'SHA-256' = '7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c0b814d1-d359-42cd-b54c-45ce0cfc5669","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: 1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16c","pattern":"[file:hashes.'SHA-256' = 'e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7144cabc-e1e0-4111-a892-15f7f95acf57","created":"2026-09-10T05:15:03.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b","description":"Seen in \"China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks\" (GBHackers). Context: 256 driver-html.js(BlueMoon exploit JavaScript) August 2026 ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a4","pattern":"[file:hashes.'SHA-256' = 'ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b']","pattern_type":"stix","valid_from":"2026-09-10T05:15:03.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--39b388ce-649e-4696-a8c5-b3351ee89d5a","created":"2026-09-09T16:08:59.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461","description":"Seen in \"Active exploitation of Cisco Secure Firewall Management Center vulnerabilities\" (Cisco Talos). Context: 9. 91.214.78[.]118 UAT-11823 NetCat-based reverse shell C2. 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware. 43.204.2[.]142 UAT-11988 A","pattern":"[file:hashes.'SHA-256' = '6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461']","pattern_type":"stix","valid_from":"2026-09-09T16:08:59.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/fmc-ongoing-exploitation/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6de56b22-d8a0-4692-aba7-c1e3ad0b58cd","created":"2026-09-09T16:08:59.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d","description":"Seen in \"Active exploitation of Cisco Secure Firewall Management Center vulnerabilities\" (Cisco Talos). Context: ble on our GitHub repository here . IOC Cluster Description B037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6","pattern":"[file:hashes.'SHA-256' = 'b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d']","pattern_type":"stix","valid_from":"2026-09-09T16:08:59.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/fmc-ongoing-exploitation/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f36ec722-7fb5-4f76-8d5c-a5805ed3d1f1","created":"2026-09-09T16:08:59.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e","description":"Seen in \"Active exploitation of Cisco Secure Firewall Management Center vulnerabilities\" (Cisco Talos). Context: d0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd[.]jar – JAR-based command executor. 89.34.96[","pattern":"[file:hashes.'SHA-256' = 'db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e']","pattern_type":"stix","valid_from":"2026-09-09T16:08:59.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/fmc-ongoing-exploitation/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5f57c649-640e-498b-9527-6dc13338ce5e","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: ode payload used to deploy the Go reverse TCP proxy SHA-256 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25 Unpacked Go-based reverse TCP proxy executable WebSocket C2","pattern":"[file:hashes.'SHA-256' = '1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--13dbb0e2-0544-4a50-96ad-e4346460cfc7","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: ation.google Amatera build during C2 communications SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 ZIP archive containing the DLL side-loading package File na","pattern":"[file:hashes.'SHA-256' = '279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6f605164-643d-432a-9b88-c432abf703c6","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: ce\\DCRCVDRV_U Driver device exposed by DCRCVDrv.sys SHA-256 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205 Shellcode payload used to deploy the Go reverse TCP proxy S","pattern":"[file:hashes.'SHA-256' = '643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--71728f7f-9d23-46b1-82df-3940639bd9a5","created":"2026-09-09T14:26:47.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b","description":"Seen in \"ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools\" (Cyber Security News). Context: g ZIP payload retrieved by the PowerShell installer SHA-256 bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b ZIP archive containing the unauthorized remote-access deplo","pattern":"[file:hashes.'SHA-256' = 'bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b']","pattern_type":"stix","valid_from":"2026-09-09T14:26:47.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/clearfake-deploys-crypto-stealer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--db66aeac-0e48-44bc-9ab4-1174fb019cdc","created":"2026-09-09T14:07:24.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 123289b3680c1d693db0e3702137cc55862dbe8b9a34376bcdf08bd0514b98e7","description":"Seen in \"Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs\" (Cyber Security News). Context: s of compromise (IoCs):- Type Indicator Description SHA-256 123289b3680c1d693db0e3702137cc55862dbe8b9a34376bcdf08bd0514b98e7 NodeRabbit-related sample identified by PolySwarm SHA-256 3","pattern":"[file:hashes.'SHA-256' = '123289b3680c1d693db0e3702137cc55862dbe8b9a34376bcdf08bd0514b98e7']","pattern_type":"stix","valid_from":"2026-09-09T14:07:24.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-use-fake-linkedin-job-offers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3c0e2596-b2ff-4166-b0df-312d0fc6bc45","created":"2026-09-09T14:07:24.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00","description":"Seen in \"Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs\" (Cyber Security News). Context: 7 NodeRabbit-related sample identified by PolySwarm SHA-256 307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00 NodeRabbit-related sample identified by PolySwarm Note: IP","pattern":"[file:hashes.'SHA-256' = '307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00']","pattern_type":"stix","valid_from":"2026-09-09T14:07:24.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-use-fake-linkedin-job-offers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--270850ad-2db7-4631-9c68-b7eebb04256a","created":"2026-09-09T13:11:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3","description":"Seen in \"Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection\" (Cyber Security News). Context: 28a3eadc0b509386cae200993b33673b343c Gigabud sample SHA-256 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 Vwork sample SHA-256 66499653c0fff78d81db5dc319b9aaa0288dc5","pattern":"[file:hashes.'SHA-256' = '0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3']","pattern_type":"stix","valid_from":"2026-09-09T13:11:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-clone-banking-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--107af1ef-75c8-472b-93c0-e4f1011180f5","created":"2026-09-09T13:11:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf","description":"Seen in \"Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection\" (Cyber Security News). Context: 1009dda5b93ed3d1cead527b02d1317426bc Gigabud sample SHA-256 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud sample SHA-256 9ca27df7938f12794bab0847434482955ca9","pattern":"[file:hashes.'SHA-256' = '112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf']","pattern_type":"stix","valid_from":"2026-09-09T13:11:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-clone-banking-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1d26f17c-f9f1-499f-afc3-efb9253d28cb","created":"2026-09-09T13:11:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c","description":"Seen in \"Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection\" (Cyber Security News). Context: 82955ca9adea714a34afd315c7a7be522611 Gigabud sample SHA-256 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud sample SHA-256 0710ca983741bf6a95db1b6960c1985e45b1","pattern":"[file:hashes.'SHA-256' = '1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c']","pattern_type":"stix","valid_from":"2026-09-09T13:11:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-clone-banking-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ea73aeb2-c657-4a84-903d-efff81ab96a8","created":"2026-09-09T13:11:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc","description":"Seen in \"Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection\" (Cyber Security News). Context: 7986e52f913f4b5ff960ddea26075ff621ae Gigabud sample SHA-256 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud sample SHA-256 112fefc9348fa4acbb82d54d9688c96dd567","pattern":"[file:hashes.'SHA-256' = '4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc']","pattern_type":"stix","valid_from":"2026-09-09T13:11:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-clone-banking-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--95726a9d-ee45-4545-ba8e-37963c14e510","created":"2026-09-09T13:11:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc","description":"Seen in \"Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection\" (Cyber Security News). Context: a73660c0ee810eb Modified banking application sample SHA-256 61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc Modified banking application sample Android package net.yy.","pattern":"[file:hashes.'SHA-256' = '61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc']","pattern_type":"stix","valid_from":"2026-09-09T13:11:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-clone-banking-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c8c13985-82d8-4964-9194-87ef17bff12a","created":"2026-09-09T13:11:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb","description":"Seen in \"Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection\" (Cyber Security News). Context: c1985e45b10f276e5b26f4fae3157db283d1f3 Vwork sample SHA-256 66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb Modified banking application sample SHA-256 61274cf9f49e04e","pattern":"[file:hashes.'SHA-256' = '66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb']","pattern_type":"stix","valid_from":"2026-09-09T13:11:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-clone-banking-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--388c8bda-82ad-4c6c-aa0e-7a2ccbb1ebe4","created":"2026-09-09T13:11:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611","description":"Seen in \"Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection\" (Cyber Security News). Context: c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud sample SHA-256 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud sample SHA-256 1f5d99864564c088a3260e54ad1728a3eadc","pattern":"[file:hashes.'SHA-256' = '9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611']","pattern_type":"stix","valid_from":"2026-09-09T13:11:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-clone-banking-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c4a5d2a7-705f-4d5d-ad79-b8f194cd2928","created":"2026-09-09T13:11:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae","description":"Seen in \"Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection\" (Cyber Security News). Context: 1bc772c8383a4149d23a5425b13475e2d501 Gigabud sample SHA-256 ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud sample SHA-256 4fff28eecc0ab6303e4948df77671009dda5","pattern":"[file:hashes.'SHA-256' = 'ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae']","pattern_type":"stix","valid_from":"2026-09-09T13:11:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-clone-banking-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--152c4366-57af-4d1f-8588-c9107af5a27e","created":"2026-09-09T13:11:36.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501","description":"Seen in \"Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection\" (Cyber Security News). Context: s of compromise (IoCs):- Type Indicator Description SHA-256 b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud sample SHA-256 ae6f6eeba2bd4cc948d24610d9447986e52f","pattern":"[file:hashes.'SHA-256' = 'b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501']","pattern_type":"stix","valid_from":"2026-09-09T13:11:36.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-clone-banking-apps/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--083cb0da-ada9-4aa2-b118-2bb4a86a166a","created":"2026-09-09T13:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b","description":"Seen in \"Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence\" (Huntress). Context: ( 7c1d255d0efefde6 ) ScreenConnect.ClientSetup.exe SHA256: 41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b Initial payload: rogue ScreenConnect installer HideCursor.e","pattern":"[file:hashes.'SHA-256' = '41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b']","pattern_type":"stix","valid_from":"2026-09-09T13:00:00.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/phishing-bitb-rmm-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5cc6437d-56db-4d2f-9649-7dfebfd35857","created":"2026-09-09T13:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991","description":"Seen in \"Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence\" (Huntress). Context: sion binary ScreenConnect Client (9c1aea531ba4c511) SHA256: 9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991 Rogue RMM: initial ScreenConnect instance ScreenConnect Cli","pattern":"[file:hashes.'SHA-256' = '9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991']","pattern_type":"stix","valid_from":"2026-09-09T13:00:00.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/phishing-bitb-rmm-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60f752ff-1fac-4847-a7af-51dd989a596e","created":"2026-09-09T13:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35","description":"Seen in \"Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence\" (Huntress). Context: ct instance ScreenConnect Client (7c1d255d0efefde6) SHA256: f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35 Rogue RMM: secondary rogue ScreenConnect instance Incident","pattern":"[file:hashes.'SHA-256' = 'f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35']","pattern_type":"stix","valid_from":"2026-09-09T13:00:00.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/phishing-bitb-rmm-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d05fbac2-b147-44ca-8ee5-7e7e651a29ab","created":"2026-09-09T13:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2","description":"Seen in \"Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence\" (Huntress). Context: yload: rogue ScreenConnect installer HideCursor.exe SHA256: fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2 Defense evasion binary ScreenConnect Client (9c1aea531ba4c5","pattern":"[file:hashes.'SHA-256' = 'fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2']","pattern_type":"stix","valid_from":"2026-09-09T13:00:00.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/phishing-bitb-rmm-attacks"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--849e12f6-ccf8-434a-8c78-cefd095fb3d1","created":"2026-09-09T10:49:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3","description":"Seen in \"GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks\" (GBHackers). Context: 088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 Note: IP addresses and domains are intentionally defanged (","pattern":"[file:hashes.'SHA-256' = '0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3']","pattern_type":"stix","valid_from":"2026-09-09T10:49:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/gigabud-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f3766ab9-a3d1-4929-84c8-245fe4c3633e","created":"2026-09-09T10:49:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf","description":"Seen in \"GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks\" (GBHackers). Context: 6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud 9ca27df7938f12794bab0847434482955ca9adea714a34afd31","pattern":"[file:hashes.'SHA-256' = '112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf']","pattern_type":"stix","valid_from":"2026-09-09T10:49:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/gigabud-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--39f7d61a-5cb3-40e4-8630-340015a29919","created":"2026-09-09T10:49:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c","description":"Seen in \"GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks\" (GBHackers). Context: 2794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae","pattern":"[file:hashes.'SHA-256' = '1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c']","pattern_type":"stix","valid_from":"2026-09-09T10:49:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/gigabud-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3fe75df0-af10-4aea-84dc-e466859b63e8","created":"2026-09-09T10:49:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc","description":"Seen in \"GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks\" (GBHackers). Context: cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f","pattern":"[file:hashes.'SHA-256' = '4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc']","pattern_type":"stix","valid_from":"2026-09-09T10:49:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/gigabud-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--75b2e7e4-6370-4aa4-b25d-c095d3f959d0","created":"2026-09-09T10:49:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611","description":"Seen in \"GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks\" (GBHackers). Context: 4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae2009","pattern":"[file:hashes.'SHA-256' = '9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611']","pattern_type":"stix","valid_from":"2026-09-09T10:49:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/gigabud-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3393cdba-64c2-4e47-b546-e72239a337f4","created":"2026-09-09T10:49:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae","description":"Seen in \"GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks\" (GBHackers). Context: 0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527","pattern":"[file:hashes.'SHA-256' = 'ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae']","pattern_type":"stix","valid_from":"2026-09-09T10:49:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/gigabud-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f815c0d2-8cb3-4216-9ead-3071a8823a40","created":"2026-09-09T10:49:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501","description":"Seen in \"GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks\" (GBHackers). Context: horized transfers. IOCs Malware Family SHA-256 Hash Gigabud b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960dde","pattern":"[file:hashes.'SHA-256' = 'b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501']","pattern_type":"stix","valid_from":"2026-09-09T10:49:58.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/gigabud-banking-malware/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d4525c0-5bcd-41d3-af33-f7e6277d88da","created":"2026-09-09T08:50:44.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9","description":"Seen in \"PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory\" (Security Affairs). Context: upgrade images. The SHA-256 hash of the analyzed sample is 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 . F5 has published remediation and compromise assessment gu","pattern":"[file:hashes.'SHA-256' = '26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9']","pattern_type":"stix","valid_from":"2026-09-09T08:50:44.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198746/malware/poisonedrefresh-a-fileless-linux-rootkit-that-injects-php-web-shells-into-f5-big-ip-apm-server-memory.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--525fce89-ce2c-4f6a-91f0-44729398ce19","created":"2026-09-09T07:47:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a","description":"Seen in \"Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners\" (Cyber Security News). Context: identifier observed in the RDP certificate TLS fingerprint 420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a Pinned mining-pool certificate fingerprint in the newest pa","pattern":"[file:hashes.'SHA-256' = '420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a']","pattern_type":"stix","valid_from":"2026-09-09T07:47:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cyber Security News","url":"https://cybersecuritynews.com/hackers-turn-redis-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4f913b0-3fb6-4ce1-aa5d-0f98dd5792a0","created":"2026-09-09T07:36:49.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9","description":"Seen in \"F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans\" (The Hacker News). Context: inding a socket under /run, or starting /bin/bash SHA-256 : 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 File, weak on its own : changes to the three .php3 scripts.","pattern":"[file:hashes.'SHA-256' = '26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9']","pattern_type":"stix","valid_from":"2026-09-09T07:36:49.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49ecd013-efc3-4346-9b89-cb093e065c81","created":"2026-09-08T13:28:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3","description":"Seen in \"Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs\" (GBHackers). Context: 13d3a54ffb35caed529bff49055ec5 Malicious MSI loader package 0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3 Second-stage DLL (rundll32-loaded module) Note: IP addresse","pattern":"[file:hashes.'SHA-256' = '0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3']","pattern_type":"stix","valid_from":"2026-09-08T13:28:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/it-support-on-microsoft-teams/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--99205e5a-4c98-4461-a4b0-80147a415513","created":"2026-09-08T13:28:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d","description":"Seen in \"Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs\" (GBHackers). Context: e compromised machine. IOCs Indicator (SHA-256) Description 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d Malicious MSI loader package (silent msiexec install) a4d14","pattern":"[file:hashes.'SHA-256' = '4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d']","pattern_type":"stix","valid_from":"2026-09-08T13:28:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/it-support-on-microsoft-teams/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--89ef08f9-75c4-4ba3-bd76-9bb3249527d7","created":"2026-09-08T13:28:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676","description":"Seen in \"Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs\" (GBHackers). Context: c389d Malicious MSI loader package (silent msiexec install) a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676 Malicious MSI loader package cc6d0f3f47afeba018173604e34f52","pattern":"[file:hashes.'SHA-256' = 'a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676']","pattern_type":"stix","valid_from":"2026-09-08T13:28:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/it-support-on-microsoft-teams/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7df26aa7-6ab1-4b0a-8621-6100ac3a6dc6","created":"2026-09-08T13:28:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5","description":"Seen in \"Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs\" (GBHackers). Context: f019d0110e31a44bb70fc77d1d1676 Malicious MSI loader package cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5 Malicious MSI loader package 0d2fc28af246f62f27e49207d1f64e","pattern":"[file:hashes.'SHA-256' = 'cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5']","pattern_type":"stix","valid_from":"2026-09-08T13:28:45.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"GBHackers","url":"https://gbhackers.com/it-support-on-microsoft-teams/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b9791603-c2f2-41f5-b06d-2bfc93689c49","created":"2026-09-08T10:01:07.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92","description":"Seen in \"ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager\" (Cisco Talos). Context: most recently observed response was a ZIP archive, SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92. The archive included the file \"platform_experience_helper.","pattern":"[file:hashes.'SHA-256' = '279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92']","pattern_type":"stix","valid_from":"2026-09-08T10:01:07.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/clearfake-webdav-infection-chain/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--58a3328a-c98e-4d1c-9fca-03a50739b980","created":"2026-09-06T13:46:02.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e","description":"Seen in \"Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”\" (Security Affairs). Context: b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e (serve.py). Follow me on Twitter: @securityaffairs and Face","pattern":"[file:hashes.'SHA-256' = '6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e']","pattern_type":"stix","valid_from":"2026-09-06T13:46:02.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198538/security/your-mikrotik-router-may-already-be-compromised-look-for-ssh-user-2.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--47cffd37-29b3-49b9-a196-f42544da42e0","created":"2026-09-06T13:46:02.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d","description":"Seen in \"Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”\" (Security Affairs). Context: nalysis: IPs 82.192.72[.]4 and 103.102.31[.]18; file hashes 6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b","pattern":"[file:hashes.'SHA-256' = '6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d']","pattern_type":"stix","valid_from":"2026-09-06T13:46:02.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198538/security/your-mikrotik-router-may-already-be-compromised-look-for-ssh-user-2.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8701ceb9-2e36-4f8d-9c2b-08488ac0c7bb","created":"2026-09-06T13:46:02.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd","description":"Seen in \"Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”\" (Security Affairs). Context: b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36f","pattern":"[file:hashes.'SHA-256' = '972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd']","pattern_type":"stix","valid_from":"2026-09-06T13:46:02.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Security Affairs","url":"https://securityaffairs.com/198538/security/your-mikrotik-router-may-already-be-compromised-look-for-ssh-user-2.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b11658e-7293-4da6-aef5-bc039d06ec54","created":"2026-09-06T08:34:20.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa","description":"Seen in \"Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner\" (The Hacker News). Context: 4987ae9eb21bf5e67de5e9461b09655165ee4 (REVSTEALER) SHA-256: 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa (ProManager) SHA-256: 7c08cf409194056a8517865e5d3433d1499bb","pattern":"[file:hashes.'SHA-256' = '13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa']","pattern_type":"stix","valid_from":"2026-09-06T08:34:20.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7268c564-120d-4429-a084-e6642f8408d0","created":"2026-09-06T08:34:20.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2","description":"Seen in \"Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner\" (The Hacker News). Context: 3433d1499bb8262263b55b49b8b07d9d182fcb (WinUpdate) SHA-256: 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2 (SoftManager) SHA-256: c66d2b77b9e85c53391891212413ad9a99eb","pattern":"[file:hashes.'SHA-256' = '14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2']","pattern_type":"stix","valid_from":"2026-09-06T08:34:20.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4ecf365-c6a6-4b93-a125-281e9d13822b","created":"2026-09-06T08:34:20.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb","description":"Seen in \"Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner\" (The Hacker News). Context: 580b453ce4987acbe2c4c4d04833f55ebccfa (ProManager) SHA-256: 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb (WinUpdate) SHA-256: 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de","pattern":"[file:hashes.'SHA-256' = '7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb']","pattern_type":"stix","valid_from":"2026-09-06T08:34:20.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6e0510cb-23f9-47a7-8093-44530219e4ee","created":"2026-09-06T08:34:20.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4","description":"Seen in \"Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner\" (The Hacker News). Context: eset is enough. Selected indicators of compromise: SHA-256: adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4 (REVSTEALER) SHA-256: 13d7237d7289e67c2d806a65d52580b453ce4","pattern":"[file:hashes.'SHA-256' = 'adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4']","pattern_type":"stix","valid_from":"2026-09-06T08:34:20.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d186cf3b-ff8a-4b75-a168-e98fe8016854","created":"2026-09-06T08:34:20.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5","description":"Seen in \"Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner\" (The Hacker News). Context: 7dd9fff7de9719c2a43ad123fe843dd4e4e2 (SoftManager) SHA-256: c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 (LockAppHost) Domain: monitor5.roast-core85[.]click (REVSTE","pattern":"[file:hashes.'SHA-256' = 'c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5']","pattern_type":"stix","valid_from":"2026-09-06T08:34:20.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--54a14fe1-c0a4-4ca6-aa62-7953b419386c","created":"2026-09-05T20:14:47.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220","description":"Seen in \"Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores\" (The Hacker News). Context: 705adec1902a1d06ef (on disk on both Disrex stores) SHA-256: 251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220 (running in memory on one Disrex store) Domain: 247.cdnflar","pattern":"[file:hashes.'SHA-256' = '251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220']","pattern_type":"stix","valid_from":"2026-09-05T20:14:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a67cc2d5-4551-49f0-9239-2f4441eb2f7d","created":"2026-09-05T20:14:47.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06ef","description":"Seen in \"Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores\" (The Hacker News). Context: b2b05d81391285eebc2af664641a26a7 (Sansec's sample) SHA-256: 8334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06ef (on disk on both Disrex stores) SHA-256: 251fabd50d7b18a8b5","pattern":"[file:hashes.'SHA-256' = '8334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06ef']","pattern_type":"stix","valid_from":"2026-09-05T20:14:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--de99ad59-5895-41be-a473-6208a922dad4","created":"2026-09-05T20:14:47.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7","description":"Seen in \"Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores\" (The Hacker News). Context: /gvfsd-user , with a variant pointing at /tmp/.kw_ SHA-256: e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 (Sansec's sample) SHA-256: 8334b434fa3fe9f59cebe9609b11e0b1","pattern":"[file:hashes.'SHA-256' = 'e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7']","pattern_type":"stix","valid_from":"2026-09-05T20:14:47.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--42053470-59c1-4183-92b2-b79c4a04d3a2","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1a3374ffac5b0a62467612f264c49792d206304d4514409c982325c91231375d","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: a3e82 kworker-linux-arm64 (new build, 209.141.43.95) sha256 1a3374ffac5b0a62467612f264c49792d206304d4514409c982325c91231375d chronyd variant, captured from /proc/<pid>/exe /tmp/.kw_<ra","pattern":"[file:hashes.'SHA-256' = '1a3374ffac5b0a62467612f264c49792d206304d4514409c982325c91231375d']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e681a56-6ad4-45b9-891d-84b5b95a6109","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: 60e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 sha256 4352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e kworker-linux-x64 (new build, 209.141.43.95), 2270031 bytes","pattern":"[file:hashes.'SHA-256' = '4352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe63d70c-89db-4712-ac49-b78c7387e08b","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: 61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 sha256 b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 sha256 4352cabaa451e5a894535fbcc4d46628701303322a13745cb547","pattern":"[file:hashes.'SHA-256' = 'b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e9de4b22-7e15-4785-ba78-28d85a0558fe","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: -linux-x64 (new build, 209.141.43.95), 2270031 bytes sha256 d2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82 kworker-linux-arm64 (new build, 209.141.43.95) sha256 1a337","pattern":"[file:hashes.'SHA-256' = 'd2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bbb69a2c-b001-4f2c-a5f5-2786e4850f9d","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d61217ca0bca83204302fa7b41935ce36f73764559c156d5c980f2fedddffb6e","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: d second attacker (unrelated tooling, same victims): sha256 d61217ca0bca83204302fa7b41935ce36f73764559c156d5c980f2fedddffb6e PHP dropper pub/media/catalog/product/cache/ss_<10hex>/sync","pattern":"[file:hashes.'SHA-256' = 'd61217ca0bca83204302fa7b41935ce36f73764559c156d5c980f2fedddffb6e']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--73db92a3-aa98-4f65-970c-1abc3ad6acdb","created":"2026-09-05T00:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7","description":"Seen in \"StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack\" (Sansec (Magento / e-commerce security)). Context: n-requests 2.15.0 on the implant operator's requests sha256 e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 sha256 b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4e","pattern":"[file:hashes.'SHA-256' = 'e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7']","pattern_type":"stix","valid_from":"2026-09-05T00:00:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Sansec (Magento / e-commerce security)","url":"https://sansec.io/research/stylesmuggler-0day"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9415efaf-a2f9-4870-83ac-da94bbb2c728","created":"2026-09-04T14:51:13.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5","description":"Seen in \"New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic\" (The Hacker News). Context: 9142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 SHA-256 - 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 The Hacker News confirmed on September 4 that none of the s","pattern":"[file:hashes.'SHA-256' = '4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5']","pattern_type":"stix","valid_from":"2026-09-04T14:51:13.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b3c9470f-57d1-4ca0-a2ca-3273781aea1d","created":"2026-09-04T14:51:13.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558","description":"Seen in \"New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic\" (The Hacker News). Context: File - /var/lib/snapd/g580 File - /tmp/jasper-log SHA-256 - 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 SHA-256 - 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1","pattern":"[file:hashes.'SHA-256' = '72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558']","pattern_type":"stix","valid_from":"2026-09-04T14:51:13.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6ec76ec8-ce65-46a8-bf8c-848f6aee677b","created":"2026-09-04T12:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe","description":"Seen in \"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors\" (Rapid7 Blog). Context: audit / audit.log , cmd.log , secure , syslog , auth.log . 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe and fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ad","pattern":"[file:hashes.'SHA-256' = '09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe']","pattern_type":"stix","valid_from":"2026-09-04T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Rapid7 Blog","url":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4e589325-a51f-49e5-9e7d-b98695eb024c","created":"2026-09-04T12:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5","description":"Seen in \"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors\" (Rapid7 Blog). Context: hrough it, completing the watering-hole loop. SSH keylogger 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 intercepts legitimate users' plaintext passwords and saves","pattern":"[file:hashes.'SHA-256' = '4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5']","pattern_type":"stix","valid_from":"2026-09-04T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Rapid7 Blog","url":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0671eedf-18f9-4740-8b44-e3a60477a414","created":"2026-09-04T12:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91","description":"Seen in \"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors\" (Rapid7 Blog). Context: ound to be delivered by a stager. CurlRAT Stager The stager 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91 starts by decrypting its configuration strings using a 1-by","pattern":"[file:hashes.'SHA-256' = '5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91']","pattern_type":"stix","valid_from":"2026-09-04T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Rapid7 Blog","url":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5f81618f-7f41-47d6-8e41-50a84caf3d13","created":"2026-09-04T12:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558","description":"Seen in \"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors\" (Rapid7 Blog). Context: er. Ted backdoor The TA recompiled the HAProxy build 2.8.12 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 (18MB) to include a custom plugin (named ted_plugin ) leavi","pattern":"[file:hashes.'SHA-256' = '72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558']","pattern_type":"stix","valid_from":"2026-09-04T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Rapid7 Blog","url":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6323be6e-e745-405d-911b-2c7f072addab","created":"2026-09-04T12:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c","description":"Seen in \"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors\" (Rapid7 Blog). Context: ryption (Figure 8). Figure 8: Default configuration curlRAT 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c ⠀ The atd_get_info() is a recon routine likely used to deci","pattern":"[file:hashes.'SHA-256' = '8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c']","pattern_type":"stix","valid_from":"2026-09-04T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Rapid7 Blog","url":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b8462226-33ea-46d0-a297-61abbad5f5f5","created":"2026-09-04T12:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61","description":"Seen in \"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors\" (Rapid7 Blog). Context: d4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe and fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61 are a different variant of the stager that fetches backdoor","pattern":"[file:hashes.'SHA-256' = 'fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61']","pattern_type":"stix","valid_from":"2026-09-04T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Rapid7 Blog","url":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--84916f58-a779-45be-b846-8af83b3e8001","created":"2026-09-04T12:00:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3","description":"Seen in \"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors\" (Rapid7 Blog). Context: epath used to hide config/staging files. As for the stager, feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3 starts by decrypting configuration strings using a 1-byte X","pattern":"[file:hashes.'SHA-256' = 'feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3']","pattern_type":"stix","valid_from":"2026-09-04T12:00:00.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Rapid7 Blog","url":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fcf6253e-052b-4c38-aa18-0ec771bb04cd","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: 001.exe Detection Name: W32.9F1F11A708-100.SBX.TG** SHA256: 228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 MD5: 61e046145ee5cf45aeb033cd71e8b07c Talos Rep: https://ta","pattern":"[file:hashes.'SHA-256' = '228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3fd806a0-965d-4c0a-946f-eb4ff672da1d","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: sample.exe Detection Name: W32.C4DD71E347-95.SBX.TG SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 MD5: 41444d7018601b599beac0c60ed1bf83 Talos Rep: https://ta","pattern":"[file:hashes.'SHA-256' = '38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e98aef00-bcc4-4a02-9d93-877d02aead11","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: content.js Detection Name: W32.38D053135D-95.SBX.TG SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta","pattern":"[file:hashes.'SHA-256' = '9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6ecabefd-756e-4a56-b1db-99725c6442dd","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta","pattern":"[file:hashes.'SHA-256' = '9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d0b9ff0-3f82-4ca4-a3bf-98f380210cc1","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: tGuard.exe Detection Name: W32.228C316455-95.SBX.TG SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://ta","pattern":"[file:hashes.'SHA-256' = 'a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8eec70b-8d86-4824-a2c3-0b04d7550b9e","created":"2026-09-03T18:00:13.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2","description":"Seen in \"The story behind the intelligence\" (Cisco Talos). Context: .exe Detection Name: Win.Dropper.Miner::95.sbx.tg** SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://ta","pattern":"[file:hashes.'SHA-256' = 'c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2']","pattern_type":"stix","valid_from":"2026-09-03T18:00:13.000Z","labels":["auto-extracted","industry"],"confidence":30,"external_references":[{"source_name":"Cisco Talos","url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--02c8b427-e0bb-489a-a446-87a2ddeb4312","created":"2026-09-03T10:00:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c","description":"Seen in \"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America\" (Palo Alto Unit 42). Context: 648aa4e0425b83c0e863a8fee5 5 178.128.87[.]160 June 19, 2026 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c 5 178.128.87[.]160 Table 2. Certificate procurement timelin","pattern":"[file:hashes.'SHA-256' = '46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c']","pattern_type":"stix","valid_from":"2026-09-03T10:00:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1e69eea2-a462-42c2-9605-d0a7bd1743eb","created":"2026-09-03T10:00:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5","description":"Seen in \"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America\" (Palo Alto Unit 42). Context: 23187010c4d38dbf88fcb40bf8 1 165.22.184[.]26 April 20, 2026 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 5 178.128.87[.]160 June 19, 2026 46ac289ce0c13666de616446f5","pattern":"[file:hashes.'SHA-256' = '4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5']","pattern_type":"stix","valid_from":"2026-09-03T10:00:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8363990c-faaf-4301-872d-0af9b5305cd7","created":"2026-09-03T10:00:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8","description":"Seen in \"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America\" (Palo Alto Unit 42). Context: ture. Date Certificate SHA-256 Hash SANs Host Feb. 27, 2026 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 1 165.22.184[.]26 April 20, 2026 4e218e70afdbb116209ec0ebe8","pattern":"[file:hashes.'SHA-256' = '7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8']","pattern_type":"stix","valid_from":"2026-09-03T10:00:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f887df40-55e1-4b3f-832b-30d2d767945f","created":"2026-09-03T10:00:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec","description":"Seen in \"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America\" (Palo Alto Unit 42). Context: cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec URL: hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Additiona","pattern":"[file:hashes.'SHA-256' = '87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec']","pattern_type":"stix","valid_from":"2026-09-03T10:00:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ab0718ea-e9fb-4f6f-b237-7d755a2cf831","created":"2026-09-03T10:00:58.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996","description":"Seen in \"Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America\" (Palo Alto Unit 42). Context: 65.22.184[.]26 Brazilian Financial Campaign SHA-256 hashes: a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee","pattern":"[file:hashes.'SHA-256' = 'a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996']","pattern_type":"stix","valid_from":"2026-09-03T10:00:58.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f52b3684-93dd-40b4-ae09-00260e69987b","created":"2026-09-03T08:50:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020","description":"Seen in \"Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity\" (Huntress). Context: s. 7a4d7d66502d4260 Malicious ScreenConnect ID 1.vbs SHA256 08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020 VBScript file executed through wscript.exe . 2.vbs SHA256 d","pattern":"[file:hashes.'SHA-256' = '08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020']","pattern_type":"stix","valid_from":"2026-09-03T08:50:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/rogue-screenconnect-installations"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bd23da75-75e3-4feb-8f9d-e66e037a2492","created":"2026-09-03T08:50:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66","description":"Seen in \"Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity\" (Huntress). Context: 0 VBScript file executed through wscript.exe . 3.vbs SHA256 110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66 VBScript file executed through wscript.exe . 4.vbs SHA256 d","pattern":"[file:hashes.'SHA-256' = '110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66']","pattern_type":"stix","valid_from":"2026-09-03T08:50:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/rogue-screenconnect-installations"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2c3e41a7-c4bc-4d16-8e23-44a31846dc99","created":"2026-09-03T08:50:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260","description":"Seen in \"Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity\" (Huntress). Context: 836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457 19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260 VBScript file executed through wscript.exe . 3.vbs SHA256 1","pattern":"[file:hashes.'SHA-256' = '19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260']","pattern_type":"stix","valid_from":"2026-09-03T08:50:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/rogue-screenconnect-installations"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6ab3c8b5-d47b-429b-ad3e-e466ccc4660c","created":"2026-09-03T08:50:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457","description":"Seen in \"Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity\" (Huntress). Context: 0 VBScript file executed through wscript.exe . 2.vbs SHA256 de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457 19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117","pattern":"[file:hashes.'SHA-256' = 'de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457']","pattern_type":"stix","valid_from":"2026-09-03T08:50:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/rogue-screenconnect-installations"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--95e71d9f-c00d-44de-afbd-a66b9196c265","created":"2026-09-03T08:50:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede","description":"Seen in \"Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity\" (Huntress). Context: 6 VBScript file executed through wscript.exe . 4.vbs SHA256 de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede VBScript file executed through wscript.exe . Trojan:Script/","pattern":"[file:hashes.'SHA-256' = 'de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede']","pattern_type":"stix","valid_from":"2026-09-03T08:50:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/rogue-screenconnect-installations"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--84c105f7-3da0-45da-82c6-bb578aaf1b4a","created":"2026-09-03T08:50:00.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de","description":"Seen in \"Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity\" (Huntress). Context: Defender Detection for 4.vbs WindowsServiceHost.vbs SHA256 ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de VBScript file executed through wscript.exe . WindowsService","pattern":"[file:hashes.'SHA-256' = 'ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de']","pattern_type":"stix","valid_from":"2026-09-03T08:50:00.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Huntress","url":"https://www.huntress.com/blog/rogue-screenconnect-installations"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a8603be7-732e-426a-80b5-960bec91f6ba","created":"2026-09-02T13:12:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 73e74402b3a61c7bab289fc11347bd54c7fcdc2fa2e410f4c3de9d6cd7377d48","description":"Seen in \"BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access\" (The Hacker News). Context: n the official scanner , whose retrieved-script SHA-256 was 73e74402b3a61c7bab289fc11347bd54c7fcdc2fa2e410f4c3de9d6cd7377d48 when checked on September 2, 2026. Contact support before r","pattern":"[file:hashes.'SHA-256' = '73e74402b3a61c7bab289fc11347bd54c7fcdc2fa2e410f4c3de9d6cd7377d48']","pattern_type":"stix","valid_from":"2026-09-02T13:12:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--52e03449-de41-4db3-b827-e8b820d23f33","created":"2026-09-02T13:12:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7","description":"Seen in \"BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access\" (The Hacker News). Context: oad - /usr/lib/jvm/.cache/jre-runtime.dat Payload SHA-256 - b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7 Marker file - /usr/lib/jvm/.cache/.installed Marker file -","pattern":"[file:hashes.'SHA-256' = 'b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7']","pattern_type":"stix","valid_from":"2026-09-02T13:12:45.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c8631f5e-4edb-4517-908d-7aa31fb129c8","created":"2026-09-02T12:22:02.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3","description":"Seen in \"Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control\" (The Hacker News). Context: ckage - io.base.one887 Application - StrεαmTV Pro SHA-256 - ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 Package - io.meat.hint Application - Sistema de vídeo C2 IP","pattern":"[file:hashes.'SHA-256' = 'ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3']","pattern_type":"stix","valid_from":"2026-09-02T12:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--00c23311-4c7a-4976-8393-4d6ea24ee43b","created":"2026-09-02T12:22:02.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c","description":"Seen in \"Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control\" (The Hacker News). Context: d the following indicators of compromise (IoCs) - SHA-256 - e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c Package - io.base.one887 Application - StrεαmTV Pro SHA-256","pattern":"[file:hashes.'SHA-256' = 'e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c']","pattern_type":"stix","valid_from":"2026-09-02T12:22:02.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"The Hacker News","url":"https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0161fc28-3afc-4c0a-826f-bd4b8e6d36c3","created":"2026-09-01T22:48:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17","description":"Seen in \"Counterfeit installers to system compromise: Tracking a deceptive software download campaign\" (Microsoft Security Blog). Context: ocessFolderPath C:\\ProgramData\\.exe InitiatingProcessSHA256 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17 InitiatingProcessCommandLine \".exe\" InitiatingProcessCreati","pattern":"[file:hashes.'SHA-256' = '1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17']","pattern_type":"stix","valid_from":"2026-09-01T22:48:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b287fd9e-8f08-46f1-a758-2dd424f4a687","created":"2026-09-01T22:48:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8","description":"Seen in \"Counterfeit installers to system compromise: Tracking a deceptive software download campaign\" (Microsoft Security Blog). Context: ogram Files (x86)\\72q1o6\\40gK5T.exe InitiatingProcessSHA256 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8 InitiatingProcessCommandLine \"40gK5T.exe\" InitiatingProcess","pattern":"[file:hashes.'SHA-256' = '6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8']","pattern_type":"stix","valid_from":"2026-09-01T22:48:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Microsoft Security Blog","url":"https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1c5f27e1-85a9-4436-af41-1c72bc9d55f0","created":"2026-09-01T21:30:18.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 47d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911","description":"Seen in \"Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)\" (SANS Internet Storm Center). Context: e: Zip archive data, at least v2.0 to extract SHA-256 hash: 47d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911 File size: 1,553 bytes File name: 868283789726483.lNk File","pattern":"[file:hashes.'SHA-256' = '47d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911']","pattern_type":"stix","valid_from":"2026-09-01T21:30:18.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33300"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2bc46095-d7a9-4bce-bfaf-86e222352efe","created":"2026-09-01T21:30:18.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63ca","description":"Seen in \"Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)\" (SANS Internet Storm Center). Context: he infection, doesn't appear to be malicious: SHA-256 hash: a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63ca File size: 266,242 bytes File type: PE32+ executable (DLL)","pattern":"[file:hashes.'SHA-256' = 'a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63ca']","pattern_type":"stix","valid_from":"2026-09-01T21:30:18.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33300"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9c4af791-3475-4f3a-9db4-165e7b61c98d","created":"2026-09-01T21:30:18.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869","description":"Seen in \"Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)\" (SANS Internet Storm Center). Context: d zip archive and extracted Windows shortcut: SHA-256 hash: cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869 File size: 1,661 bytes File name: 868283789726483.zip File","pattern":"[file:hashes.'SHA-256' = 'cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869']","pattern_type":"stix","valid_from":"2026-09-01T21:30:18.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33300"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9020c433-d500-4426-b680-69d7172a98ff","created":"2026-09-01T21:30:18.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4","description":"Seen in \"Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)\" (SANS Internet Storm Center). Context: It script for the persistent Guildma malware: SHA-256 hash: f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4 File size: 277,874 bytes File type: Data File location: C:\\","pattern":"[file:hashes.'SHA-256' = 'f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4']","pattern_type":"stix","valid_from":"2026-09-01T21:30:18.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33300"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d783ac5d-a2a0-4715-9cd0-472903175295","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 2548f5b1613f6ebba2ff589c7b3416ccdd066b73644d4d212232beb1cecd9c31","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: 38b360d8a836c038da4920e8c1ae620988b120613c0b1f MIPS-ELF nvr 2548f5b1613f6ebba2ff589c7b3416ccdd066b73644d4d212232beb1cecd9c31 Shell script Pty1 a4ba50129408f9f52ddabe5bfd5bfb46aea0ca48f","pattern":"[file:hashes.'SHA-256' = '2548f5b1613f6ebba2ff589c7b3416ccdd066b73644d4d212232beb1cecd9c31']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--429a5773-02b0-422e-aeef-b5d966e3395a","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 492780a9ac9f03305538b360d8a836c038da4920e8c1ae620988b120613c0b1f","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: s.shadow.mods[.]net Samples Filename SHA256 File type tty0 492780a9ac9f03305538b360d8a836c038da4920e8c1ae620988b120613c0b1f MIPS-ELF nvr 2548f5b1613f6ebba2ff589c7b3416ccdd066b73644d4d","pattern":"[file:hashes.'SHA-256' = '492780a9ac9f03305538b360d8a836c038da4920e8c1ae620988b120613c0b1f']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--276a675f-c644-4fc9-a46f-199f9f301457","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 72123c51bcdf8c1784654d9e2470e69131872407408aa3cf775ea0ace87bb9a0","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: c04ae2ae8f2792711203de50d3d16de3a9f83baaf5435 MIPS-ELF Pty5 72123c51bcdf8c1784654d9e2470e69131872407408aa3cf775ea0ace87bb9a0 ARM-ELF Pty6 cee20e79f20d35b95645f0cbda1897302e6e554c50f3e6","pattern":"[file:hashes.'SHA-256' = '72123c51bcdf8c1784654d9e2470e69131872407408aa3cf775ea0ace87bb9a0']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bf37159e-b6fb-417d-bc19-146c88af5f43","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7325742dc0d939542d4c04ae2ae8f2792711203de50d3d16de3a9f83baaf5435","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: abe5bfd5bfb46aea0ca48fb616f495f2610b2f1729687 MIPS-ELF Pty3 7325742dc0d939542d4c04ae2ae8f2792711203de50d3d16de3a9f83baaf5435 MIPS-ELF Pty5 72123c51bcdf8c1784654d9e2470e69131872407408aa","pattern":"[file:hashes.'SHA-256' = '7325742dc0d939542d4c04ae2ae8f2792711203de50d3d16de3a9f83baaf5435']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--58e00b0d-7d2d-4157-b217-aa63e0b2f0e0","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a4ba50129408f9f52ddabe5bfd5bfb46aea0ca48fb616f495f2610b2f1729687","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: c7b3416ccdd066b73644d4d212232beb1cecd9c31 Shell script Pty1 a4ba50129408f9f52ddabe5bfd5bfb46aea0ca48fb616f495f2610b2f1729687 MIPS-ELF Pty3 7325742dc0d939542d4c04ae2ae8f2792711203de50d3","pattern":"[file:hashes.'SHA-256' = 'a4ba50129408f9f52ddabe5bfd5bfb46aea0ca48fb616f495f2610b2f1729687']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--743e781f-b9ec-4dd7-a68a-de6456bab325","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: cee20e79f20d35b95645f0cbda1897302e6e554c50f3e6754ce9293e3c1ba11c","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: 654d9e2470e69131872407408aa3cf775ea0ace87bb9a0 ARM-ELF Pty6 cee20e79f20d35b95645f0cbda1897302e6e554c50f3e6754ce9293e3c1ba11c ARM-ELF daymon dc52a1193ecf6096192f771ae663de6e0389840cb5ce","pattern":"[file:hashes.'SHA-256' = 'cee20e79f20d35b95645f0cbda1897302e6e554c50f3e6754ce9293e3c1ba11c']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2b7e51cc-ea54-4f8d-afa3-48c6ad433fd9","created":"2026-08-19T12:06:09.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: dc52a1193ecf6096192f771ae663de6e0389840cb5ceb7b979091333ce6f7f02","description":"Seen in \"Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices\" (Palo Alto Unit 42). Context: f0cbda1897302e6e554c50f3e6754ce9293e3c1ba11c ARM-ELF daymon dc52a1193ecf6096192f771ae663de6e0389840cb5ceb7b979091333ce6f7f02 ARM-ELF","pattern":"[file:hashes.'SHA-256' = 'dc52a1193ecf6096192f771ae663de6e0389840cb5ceb7b979091333ce6f7f02']","pattern_type":"stix","valid_from":"2026-08-19T12:06:09.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e035cd4-c66f-4901-b3ec-c8360019d1f1","created":"2026-08-19T12:05:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 14c351d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd36358","description":"Seen in \"Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self\" (Palo Alto Unit 42). Context: aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0412e4 14c351d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd36358 6d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c1952","pattern":"[file:hashes.'SHA-256' = '14c351d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd36358']","pattern_type":"stix","valid_from":"2026-08-19T12:05:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/los-zetas-from-eleethub-botnet/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ac90d04e-e3bf-4014-a3d7-6f58eecf2f00","created":"2026-08-19T12:05:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c195267c9b","description":"Seen in \"Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self\" (Palo Alto Unit 42). Context: 1d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd36358 6d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c195267c9b C2 servers eleethub[.]com irc.eleethub[.]com ghost.eleethub","pattern":"[file:hashes.'SHA-256' = '6d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c195267c9b']","pattern_type":"stix","valid_from":"2026-08-19T12:05:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/los-zetas-from-eleethub-botnet/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f9fb6f25-4826-4e40-89c0-dc0902cb573e","created":"2026-08-19T12:05:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7ed8fc4ad8014da327278b6afc26a2b4d4c8326a681be2d2b33fb2386eade3c6","description":"Seen in \"Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self\" (Palo Alto Unit 42). Context: nets targeting IoT devices Indicators of Compromise Samples 7ed8fc4ad8014da327278b6afc26a2b4d4c8326a681be2d2b33fb2386eade3c6 dbef55cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187","pattern":"[file:hashes.'SHA-256' = '7ed8fc4ad8014da327278b6afc26a2b4d4c8326a681be2d2b33fb2386eade3c6']","pattern_type":"stix","valid_from":"2026-08-19T12:05:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/los-zetas-from-eleethub-botnet/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c1d7912d-2384-4e7c-9402-496872f03a85","created":"2026-08-19T12:05:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d9001aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0412e4","description":"Seen in \"Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self\" (Palo Alto Unit 42). Context: 5cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187e8ef6 d9001aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0412e4 14c351d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd","pattern":"[file:hashes.'SHA-256' = 'd9001aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0412e4']","pattern_type":"stix","valid_from":"2026-08-19T12:05:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/los-zetas-from-eleethub-botnet/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--65060ccf-e65d-46eb-a03e-36061b3a470b","created":"2026-08-19T12:05:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: dbef55cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187e8ef6","description":"Seen in \"Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self\" (Palo Alto Unit 42). Context: c4ad8014da327278b6afc26a2b4d4c8326a681be2d2b33fb2386eade3c6 dbef55cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187e8ef6 d9001aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0","pattern":"[file:hashes.'SHA-256' = 'dbef55cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187e8ef6']","pattern_type":"stix","valid_from":"2026-08-19T12:05:48.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/los-zetas-from-eleethub-botnet/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3ea570ab-6fc4-4907-b79c-65c6d3e75853","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0039231b2fd5e5a3d86ae3b626d35b8fed7f2887a58e32b480ac82cd82150f7c","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 41b1 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.mpsl 0039231b2fd5e5a3d86ae3b626d35b8fed7f2887a58e32b480ac82cd82150f7c Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.ppc 9d55a","pattern":"[file:hashes.'SHA-256' = '0039231b2fd5e5a3d86ae3b626d35b8fed7f2887a58e32b480ac82cd82150f7c']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4e1fdba2-13d3-4da6-9315-2123e8acef34","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 02d48570f1089e2e7f4f9256bb033136c773834af31054e477e094e48cba110e","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 0f30 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.m68k 02d48570f1089e2e7f4f9256bb033136c773834af31054e477e094e48cba110e Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.mips 45ff","pattern":"[file:hashes.'SHA-256' = '02d48570f1089e2e7f4f9256bb033136c773834af31054e477e094e48cba110e']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--af85d994-2fea-4596-abf3-b9721a5c02f1","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 02f08ccc4a4136c89276135664267e08f1bb6795842a84c06c15478d3c3101e6","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 80a5 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.sh4 02f08ccc4a4136c89276135664267e08f1bb6795842a84c06c15478d3c3101e6 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.x86 f467","pattern":"[file:hashes.'SHA-256' = '02f08ccc4a4136c89276135664267e08f1bb6795842a84c06c15478d3c3101e6']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bbce5af6-7bf2-408d-a163-a7f66722ecfd","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 05102e5abb23c761426c2c0f19f70f650938ea9e9295ccbb92349513c1d26c63","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 8684e17 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.mips 05102e5abb23c761426c2c0f19f70f650938ea9e9295ccbb92349513c1d26c63 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.mpsl cc996d1","pattern":"[file:hashes.'SHA-256' = '05102e5abb23c761426c2c0f19f70f650938ea9e9295ccbb92349513c1d26c63']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d2b7a18f-42f4-44ef-8c74-0ad5019f2797","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 087fc3206ddb94e80118e7e7f0215c88409a0071b657d21071e15b7917f7cc4e","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 3e61 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.arm6 087fc3206ddb94e80118e7e7f0215c88409a0071b657d21071e15b7917f7cc4e Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.arm7 33f7","pattern":"[file:hashes.'SHA-256' = '087fc3206ddb94e80118e7e7f0215c88409a0071b657d21071e15b7917f7cc4e']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc22330f-a790-40e3-b87f-07e4ffb61c0c","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0a664a74fcc00910170edcd5f548569b40c2c5d58fc5ced1f475dbe938684e17","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 5da833f Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.m68k 0a664a74fcc00910170edcd5f548569b40c2c5d58fc5ced1f475dbe938684e17 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.mips 05102e5","pattern":"[file:hashes.'SHA-256' = '0a664a74fcc00910170edcd5f548569b40c2c5d58fc5ced1f475dbe938684e17']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d3d3572e-bda8-4079-98ad-3ebe131de928","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0bbdb062ecfae7e1b59084a5e5fe052908ecfdea7db0777a9c318e9e55fdb5ff","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 7d871 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.ppc 0bbdb062ecfae7e1b59084a5e5fe052908ecfdea7db0777a9c318e9e55fdb5ff Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.sh4 77a1f","pattern":"[file:hashes.'SHA-256' = '0bbdb062ecfae7e1b59084a5e5fe052908ecfdea7db0777a9c318e9e55fdb5ff']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--01002666-47f2-432e-b3ac-3fdb83b6bc08","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0c4ec06f32d5f15846239d224d68086cbeaf513b63f0fcafa4eddd8e18a3d372","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: ea04b Mar 11, 2021 12:59 UTC 203[.]159.80.241/bins/dark.ppc 0c4ec06f32d5f15846239d224d68086cbeaf513b63f0fcafa4eddd8e18a3d372 Mar 11, 2021 12:30 UTC 203[.]159.80.241/bins/dark.sh4 2f590","pattern":"[file:hashes.'SHA-256' = '0c4ec06f32d5f15846239d224d68086cbeaf513b63f0fcafa4eddd8e18a3d372']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--94fbf35c-b730-43d6-8215-cc029e8f6fce","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1d9496814d35d9e302d7e99339e9730fc81c022bc085c0711b73ebad962cbc2b","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 2f4420a Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.mpsl 1d9496814d35d9e302d7e99339e9730fc81c022bc085c0711b73ebad962cbc2b Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.ppc 971b5a96","pattern":"[file:hashes.'SHA-256' = '1d9496814d35d9e302d7e99339e9730fc81c022bc085c0711b73ebad962cbc2b']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e499e55-a2cf-4898-812d-9be4bbd40c66","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1e56f8ca44f84eff212805fa061ecb0f6fb8bc9499ff2e541ad3c43fb2f4420a","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 54d23ba Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.mips 1e56f8ca44f84eff212805fa061ecb0f6fb8bc9499ff2e541ad3c43fb2f4420a Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.mpsl 1d94968","pattern":"[file:hashes.'SHA-256' = '1e56f8ca44f84eff212805fa061ecb0f6fb8bc9499ff2e541ad3c43fb2f4420a']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8aef226e-7712-43cb-8e08-c389367bda18","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 2102b6a9f4b6745b0963ac3040945fb351c3d7df5b8e75dbc4ebf587c921998f","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: cbe Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.arm5 2102b6a9f4b6745b0963ac3040945fb351c3d7df5b8e75dbc4ebf587c921998f Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.arm6 bfd","pattern":"[file:hashes.'SHA-256' = '2102b6a9f4b6745b0963ac3040945fb351c3d7df5b8e75dbc4ebf587c921998f']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2aaa1d06-39ce-49a7-a8f4-4a87f06c57a4","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 2a09719254934fe8ee8f200a0a7537d35a293fe1f8d0e396e23374e9b209f273","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: a75f6 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.x86 2a09719254934fe8ee8f200a0a7537d35a293fe1f8d0e396e23374e9b209f273","pattern":"[file:hashes.'SHA-256' = '2a09719254934fe8ee8f200a0a7537d35a293fe1f8d0e396e23374e9b209f273']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--acdafdbb-a734-4aa8-a22f-29ab98cf4c40","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 2f590f5af68dd30cdd51de85cb55dd16160ffce16dd326b2ac4c85e0007fca51","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 3d372 Mar 11, 2021 12:30 UTC 203[.]159.80.241/bins/dark.sh4 2f590f5af68dd30cdd51de85cb55dd16160ffce16dd326b2ac4c85e0007fca51 Mar 11, 2021 12:30 UTC 203[.]159.80.241/bins/dark.m68k cd59","pattern":"[file:hashes.'SHA-256' = '2f590f5af68dd30cdd51de85cb55dd16160ffce16dd326b2ac4c85e0007fca51']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7886a3d5-2856-4207-9f48-b39a1542db31","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 33f75999a3b4c354b6281399e541b97fd6463c5cd2ab13a538522d72a8870f30","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: cc4e Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.arm7 33f75999a3b4c354b6281399e541b97fd6463c5cd2ab13a538522d72a8870f30 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.m68k 02d4","pattern":"[file:hashes.'SHA-256' = '33f75999a3b4c354b6281399e541b97fd6463c5cd2ab13a538522d72a8870f30']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9fe62dc1-9f8e-4934-8be6-d340e52304aa","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 38d8f2d17b3b676f5258a28b6b4093a1c3cdfa0d34d97c80d86686a3cff7ed55","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 83aa Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.arm7 38d8f2d17b3b676f5258a28b6b4093a1c3cdfa0d34d97c80d86686a3cff7ed55 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.m68k b066","pattern":"[file:hashes.'SHA-256' = '38d8f2d17b3b676f5258a28b6b4093a1c3cdfa0d34d97c80d86686a3cff7ed55']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--35952db4-9355-40fe-9fc0-febbd2a3885c","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 3c47dceb9b8fbb0d40c3f1efa8ebc8d7dcf82aa0af46c4486ec3fc8ca29a83b2","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 689 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.mips 3c47dceb9b8fbb0d40c3f1efa8ebc8d7dcf82aa0af46c4486ec3fc8ca29a83b2 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.mpsl d31","pattern":"[file:hashes.'SHA-256' = '3c47dceb9b8fbb0d40c3f1efa8ebc8d7dcf82aa0af46c4486ec3fc8ca29a83b2']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--57f3825a-95e3-47ba-85f0-cd817476b1f6","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 40808fb06796aeb740368b9bc322c12193d1bebb8e5eeddc420a98db6ac82689","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: a8d Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.m68k 40808fb06796aeb740368b9bc322c12193d1bebb8e5eeddc420a98db6ac82689 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.mips 3c4","pattern":"[file:hashes.'SHA-256' = '40808fb06796aeb740368b9bc322c12193d1bebb8e5eeddc420a98db6ac82689']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--11a60058-bea0-4b54-a7a0-de1f5a93bded","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4414bf4f41663a6458372bcc4743d6e50bbb2d40c26d71bcb945926c98cd5537","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: bf1e Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.arm6 4414bf4f41663a6458372bcc4743d6e50bbb2d40c26d71bcb945926c98cd5537 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.arm7 8d0b","pattern":"[file:hashes.'SHA-256' = '4414bf4f41663a6458372bcc4743d6e50bbb2d40c26d71bcb945926c98cd5537']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2df95b3c-0f93-4984-b72a-b7080efcc80d","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 45ff08b1de872379f965d423a0f4e1f2e82f0ea8d101220b83d3aed3b2e7f1c9","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 110e Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.mips 45ff08b1de872379f965d423a0f4e1f2e82f0ea8d101220b83d3aed3b2e7f1c9 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.mpsl 85ac","pattern":"[file:hashes.'SHA-256' = '45ff08b1de872379f965d423a0f4e1f2e82f0ea8d101220b83d3aed3b2e7f1c9']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--88dd17ba-050b-4748-a741-67f2f28766ca","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4f69555ab71b49c2c1067f0907eb73b185327b57c566a8311ba9f9e58f4e85a5","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: c2 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/brute/nbrute.arm 4f69555ab71b49c2c1067f0907eb73b185327b57c566a8311ba9f9e58f4e85a5 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/brute/nbrute.mips a","pattern":"[file:hashes.'SHA-256' = '4f69555ab71b49c2c1067f0907eb73b185327b57c566a8311ba9f9e58f4e85a5']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ac1bab08-66d3-4279-9f5a-88e678c4ed82","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4f6a9d2c775e0ba38189390aa7975973209f8e703d6f974c2ab67c97ad263204","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: ba7d Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.mpsl 4f6a9d2c775e0ba38189390aa7975973209f8e703d6f974c2ab67c97ad263204 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.ppc c2640","pattern":"[file:hashes.'SHA-256' = '4f6a9d2c775e0ba38189390aa7975973209f8e703d6f974c2ab67c97ad263204']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--730b94e3-c959-429b-b580-961e47274865","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4fe20e73217d0bde39616ebf6f50f0f27882f939537561849f7b17968c5b8e30","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 4f5c25975e Feb 23, 2021 09:03 UTC 185[.]239.242.63/lolol.sh 4fe20e73217d0bde39616ebf6f50f0f27882f939537561849f7b17968c5b8e30 Feb 22, 2021 16:30 UTC 37[.]46.150.102/bins/dark.mpsl 6b1be","pattern":"[file:hashes.'SHA-256' = '4fe20e73217d0bde39616ebf6f50f0f27882f939537561849f7b17968c5b8e30']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9e394494-85c9-46da-8624-bef312e6e91a","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 515dc2fd8819c7fc82395acc4c7fb5b2903982a5f48bc26bc8d0235bc0664d1f","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: c07c8ec Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.arm6 515dc2fd8819c7fc82395acc4c7fb5b2903982a5f48bc26bc8d0235bc0664d1f Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.arm7 a9c4ea4","pattern":"[file:hashes.'SHA-256' = '515dc2fd8819c7fc82395acc4c7fb5b2903982a5f48bc26bc8d0235bc0664d1f']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--80902d72-fc9f-4e00-a792-aefaab764125","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 519b2d04e80c2cb7c000a3c00cb30098df363bd825281b2b7384d964b832df3b","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: be23 Mar 11, 2021 19:22 UTC 203[.]159.80.241/bins/dark.arm7 519b2d04e80c2cb7c000a3c00cb30098df363bd825281b2b7384d964b832df3b Mar 11, 2021 19:22 UTC 203[.]159.80.241/bins/dark.arm6 7a57","pattern":"[file:hashes.'SHA-256' = '519b2d04e80c2cb7c000a3c00cb30098df363bd825281b2b7384d964b832df3b']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9ac7e223-8321-4db1-88d3-c7dcfb53f10a","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 528179f34ed9a6e69f582c23b3cbb50343164bf0e5995624a8d16f8b0df202e8","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 6b1287 Feb 22, 2021 16:30 UTC 37[.]46.150.102/bins/dark.sh4 528179f34ed9a6e69f582c23b3cbb50343164bf0e5995624a8d16f8b0df202e8 Feb 22, 2021 16:30 UTC 37[.]46.150.102/bins/dark.x86 f05d21","pattern":"[file:hashes.'SHA-256' = '528179f34ed9a6e69f582c23b3cbb50343164bf0e5995624a8d16f8b0df202e8']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3450f1a9-581c-445d-a153-f2a78ae66daf","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5446350c771766589e6d79e8185e10fcc0a6681eb76723b7f26dfef03c9080a5","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 8e8f Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.ppc 5446350c771766589e6d79e8185e10fcc0a6681eb76723b7f26dfef03c9080a5 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.sh4 02f0","pattern":"[file:hashes.'SHA-256' = '5446350c771766589e6d79e8185e10fcc0a6681eb76723b7f26dfef03c9080a5']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d714526a-c685-47e3-9603-d0bdabc8cf73","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5525b282df49206e76e884ca0f86806ddc97ec08343bab1d9a98f029a2697b08","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 97521 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.arm 5525b282df49206e76e884ca0f86806ddc97ec08343bab1d9a98f029a2697b08 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.arm5 b82b","pattern":"[file:hashes.'SHA-256' = '5525b282df49206e76e884ca0f86806ddc97ec08343bab1d9a98f029a2697b08']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7dd91328-6ac6-4c55-bf3c-8937e13b6a27","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 554bee9f896a7a013804485894875348ff760b08ff7b0ae14c210e2b37da75f6","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 542b5 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.sh4 554bee9f896a7a013804485894875348ff760b08ff7b0ae14c210e2b37da75f6 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.x86 2a097","pattern":"[file:hashes.'SHA-256' = '554bee9f896a7a013804485894875348ff760b08ff7b0ae14c210e2b37da75f6']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d35843b7-fda3-4b99-a09d-b4bf86153f12","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5715d9c632c646c856f2775de8e98c00cade29f7bfb6fbe33a5741b01e897521","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: c804b97c2d Feb 24, 2021 15:59 UTC 185[.]239.242.63/lolol.sh 5715d9c632c646c856f2775de8e98c00cade29f7bfb6fbe33a5741b01e897521 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.arm 5525b","pattern":"[file:hashes.'SHA-256' = '5715d9c632c646c856f2775de8e98c00cade29f7bfb6fbe33a5741b01e897521']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5cae7370-b81e-4cb7-8a12-80858405b926","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5d7487a5d6febb015a21a98eddffc617cfc06453fe2a7dacac6e1719f56c56fb","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 4a13 Mar 11, 2021 19:22 UTC 203[.]159.80.241/bins/dark.arm5 5d7487a5d6febb015a21a98eddffc617cfc06453fe2a7dacac6e1719f56c56fb Mar 11, 2021 19:22 UTC 203[.]159.80.241/bins/dark.mpsl e9d0","pattern":"[file:hashes.'SHA-256' = '5d7487a5d6febb015a21a98eddffc617cfc06453fe2a7dacac6e1719f56c56fb']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--602a4171-becd-44a6-b1d3-5ae569bb18a5","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 60135a7817a0a1734c2e211a8613873548f4611fddc8666890f6a69860c43e61","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: A256 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.arm5 60135a7817a0a1734c2e211a8613873548f4611fddc8666890f6a69860c43e61 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.arm6 087f","pattern":"[file:hashes.'SHA-256' = '60135a7817a0a1734c2e211a8613873548f4611fddc8666890f6a69860c43e61']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4e49d97d-6094-4f33-beae-ed0c237c8acc","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 63e66d6f0ddf5fea5b1f71643bdb30f3fff4531c364b6fd1b0e0e0cfe5da833f","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: fbe004b8 Mar 5, 2021 14:13 UTC 45[.]133.1.133/bins/dark.ppc 63e66d6f0ddf5fea5b1f71643bdb30f3fff4531c364b6fd1b0e0e0cfe5da833f Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.m68k 0a664a7","pattern":"[file:hashes.'SHA-256' = '63e66d6f0ddf5fea5b1f71643bdb30f3fff4531c364b6fd1b0e0e0cfe5da833f']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8cd3fc2-0eb2-4d0e-af89-d3b69f13bd9b","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 64f9bc6e925fd2f538c89fd8a8c25d11521b9fcc51c8c5308e9850c990bea04b","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 2ff4f Mar 11, 2021 13:12 UTC 203[.]159.80.241/bins/dark.x86 64f9bc6e925fd2f538c89fd8a8c25d11521b9fcc51c8c5308e9850c990bea04b Mar 11, 2021 12:59 UTC 203[.]159.80.241/bins/dark.ppc 0c4ec","pattern":"[file:hashes.'SHA-256' = '64f9bc6e925fd2f538c89fd8a8c25d11521b9fcc51c8c5308e9850c990bea04b']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5676d448-f873-4b9d-8591-83eb91a9b0f8","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 667640d293e4ce2287546fc2e0056ee14f414868bf5b77f72078096c516a9fb0","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: eac4 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.mpsl 667640d293e4ce2287546fc2e0056ee14f414868bf5b77f72078096c516a9fb0 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.ppc beb0b","pattern":"[file:hashes.'SHA-256' = '667640d293e4ce2287546fc2e0056ee14f414868bf5b77f72078096c516a9fb0']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--652c46d7-65ef-41f1-87ab-ef5fa9d1fff8","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 66ea76a427b69f153486f962baff29d4a68393e985c7d88c94d773b25ad4964a","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 0302 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.m68k 66ea76a427b69f153486f962baff29d4a68393e985c7d88c94d773b25ad4964a Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.mips def1","pattern":"[file:hashes.'SHA-256' = '66ea76a427b69f153486f962baff29d4a68393e985c7d88c94d773b25ad4964a']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dc4abd2a-9069-4936-84ee-5a5cf0789af0","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6a68acd757fab908b2455c9b5882c25ab4a550121c2badb960b0a514a04a8d3d","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: e30 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/brute/combo.txt 6a68acd757fab908b2455c9b5882c25ab4a550121c2badb960b0a514a04a8d3d Feb 16, 2021, 11:01 UTC 37[.]46.150.102/brute/nbrute.386 ba","pattern":"[file:hashes.'SHA-256' = '6a68acd757fab908b2455c9b5882c25ab4a550121c2badb960b0a514a04a8d3d']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--788514c1-c990-435d-9965-a7ac18d98840","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6b1bea5f17eb2c16815b8cb87d6e24e707248e5384fc4dd33c86c189657c73ff","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: b8e30 Feb 22, 2021 16:30 UTC 37[.]46.150.102/bins/dark.mpsl 6b1bea5f17eb2c16815b8cb87d6e24e707248e5384fc4dd33c86c189657c73ff Feb 22, 2021 16:30 UTC 37[.]46.150.102/bins/dark.ppc 918395","pattern":"[file:hashes.'SHA-256' = '6b1bea5f17eb2c16815b8cb87d6e24e707248e5384fc4dd33c86c189657c73ff']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a2eba921-0715-4aa0-9c1e-ccf1b83adbc0","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 73aaf3ce3e5ea7a598f01d727e8278ff64ff0067fc2f2b22387b09de64c2ff4f","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: efb8 Mar 11, 2021 19:22 UTC 203[.]159.80.241/bins/dark.mips 73aaf3ce3e5ea7a598f01d727e8278ff64ff0067fc2f2b22387b09de64c2ff4f Mar 11, 2021 13:12 UTC 203[.]159.80.241/bins/dark.x86 64f9b","pattern":"[file:hashes.'SHA-256' = '73aaf3ce3e5ea7a598f01d727e8278ff64ff0067fc2f2b22387b09de64c2ff4f']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e106312d-4570-4cd0-b388-46727890f6b0","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 73b35ddbf9784a6f6ebad7f5a1f4965daedc2f92cbb45a9cb76e61c0104bf553","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 10dd6 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.sh4 73b35ddbf9784a6f6ebad7f5a1f4965daedc2f92cbb45a9cb76e61c0104bf553 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.x86 a925f","pattern":"[file:hashes.'SHA-256' = '73b35ddbf9784a6f6ebad7f5a1f4965daedc2f92cbb45a9cb76e61c0104bf553']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4f071c32-072e-4421-b7c5-594e813c159f","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 74ab77e1069c6fb32925e89563c57f09c842cad0de6ab6b7c9ec2fa44d2641b1","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 6854 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.mips 74ab77e1069c6fb32925e89563c57f09c842cad0de6ab6b7c9ec2fa44d2641b1 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.mpsl 0039","pattern":"[file:hashes.'SHA-256' = '74ab77e1069c6fb32925e89563c57f09c842cad0de6ab6b7c9ec2fa44d2641b1']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f98124dd-0010-4900-a9c6-53289e77c8e0","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 77a1f62dc76cc9ee2d924008a0fdcc329396021f027ebe1cfa468f9625c2455b","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: db5ff Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.sh4 77a1f62dc76cc9ee2d924008a0fdcc329396021f027ebe1cfa468f9625c2455b Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.x86 8d116","pattern":"[file:hashes.'SHA-256' = '77a1f62dc76cc9ee2d924008a0fdcc329396021f027ebe1cfa468f9625c2455b']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c1abc538-f7e9-4404-9465-7da2cd87e1b7","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7a571f666c8f272cce1ee7ad75520a013bbed800e7d0c80a17804500a3474a13","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: df3b Mar 11, 2021 19:22 UTC 203[.]159.80.241/bins/dark.arm6 7a571f666c8f272cce1ee7ad75520a013bbed800e7d0c80a17804500a3474a13 Mar 11, 2021 19:22 UTC 203[.]159.80.241/bins/dark.arm5 5d74","pattern":"[file:hashes.'SHA-256' = '7a571f666c8f272cce1ee7ad75520a013bbed800e7d0c80a17804500a3474a13']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fe43dd85-01c0-4950-a8ef-17c96408707c","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7aa437a562f3a956cf60fce652e6a0fb2d3c7cda0e5312c1a7fa62e177c45906","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 16629 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.sh4 7aa437a562f3a956cf60fce652e6a0fb2d3c7cda0e5312c1a7fa62e177c45906 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.x86 8e65d","pattern":"[file:hashes.'SHA-256' = '7aa437a562f3a956cf60fce652e6a0fb2d3c7cda0e5312c1a7fa62e177c45906']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3ad459a9-702c-49a6-abad-00818270e19f","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 80cd13bfcc2fc29096abf18525d17766700a6d25a9806e55c7b7de776cba0302","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 2f47 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.arm7 80cd13bfcc2fc29096abf18525d17766700a6d25a9806e55c7b7de776cba0302 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.m68k 66ea","pattern":"[file:hashes.'SHA-256' = '80cd13bfcc2fc29096abf18525d17766700a6d25a9806e55c7b7de776cba0302']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dad8a086-5390-4f85-a8ab-2eb303b49f53","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8524826a687491c6bfd161df3e4fb2f537f50ea32834d7710dcf3b788a5ddfc2","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: Feb 16, 2021, 11:01 UTC 37[.]46.150.102/brute/nbrute.amd64 8524826a687491c6bfd161df3e4fb2f537f50ea32834d7710dcf3b788a5ddfc2 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/brute/nbrute.arm 4f","pattern":"[file:hashes.'SHA-256' = '8524826a687491c6bfd161df3e4fb2f537f50ea32834d7710dcf3b788a5ddfc2']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5425d819-6519-4d53-8d1e-7c784b3daade","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 85acead88180809d47524aac87d6f76799e7c0a1729d9614446be73aa8e7d871","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: f1c9 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.mpsl 85acead88180809d47524aac87d6f76799e7c0a1729d9614446be73aa8e7d871 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.ppc 0bbdb","pattern":"[file:hashes.'SHA-256' = '85acead88180809d47524aac87d6f76799e7c0a1729d9614446be73aa8e7d871']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60002d55-5775-415e-ae57-a646d36b7dcc","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8cc6375f2eabe865e8400f27381a513a69e4100748458c3d2c706f3d4002bf1e","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 31cf Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.arm5 8cc6375f2eabe865e8400f27381a513a69e4100748458c3d2c706f3d4002bf1e Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.arm6 4414","pattern":"[file:hashes.'SHA-256' = '8cc6375f2eabe865e8400f27381a513a69e4100748458c3d2c706f3d4002bf1e']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d369eaed-af23-443f-97b0-70fbfd275318","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8d0beb4b143dc4a9543b4bc5d7f44a6771a973709aaf8c3a4754d120b99d0afd","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 5537 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.arm7 8d0beb4b143dc4a9543b4bc5d7f44a6771a973709aaf8c3a4754d120b99d0afd Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.m68k f977","pattern":"[file:hashes.'SHA-256' = '8d0beb4b143dc4a9543b4bc5d7f44a6771a973709aaf8c3a4754d120b99d0afd']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b2cc4152-7acb-4669-99d9-146c0043f511","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8d11635019b077d36ce7de2a3ca9261f126e0ff5808f722fcb967e7cd000be23","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 2455b Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.x86 8d11635019b077d36ce7de2a3ca9261f126e0ff5808f722fcb967e7cd000be23 Mar 11, 2021 19:22 UTC 203[.]159.80.241/bins/dark.arm7 519b","pattern":"[file:hashes.'SHA-256' = '8d11635019b077d36ce7de2a3ca9261f126e0ff5808f722fcb967e7cd000be23']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--20097026-bef6-4bf9-b110-68f83ffc423a","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8e65d7b16939834e1cd86b36b495924d34f10a8c477b53c9c8e648c804b97c2d","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 45906 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.x86 8e65d7b16939834e1cd86b36b495924d34f10a8c477b53c9c8e648c804b97c2d Feb 24, 2021 15:59 UTC 185[.]239.242.63/lolol.sh 5715d9c632","pattern":"[file:hashes.'SHA-256' = '8e65d7b16939834e1cd86b36b495924d34f10a8c477b53c9c8e648c804b97c2d']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a91b54b0-7b6f-4ce1-b327-cc21b127309c","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 904b086dbf3e8f4dd1711d758d54675ce2d6002ff607a72d72d7e3aea612ba7d","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: b7e7 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.mips 904b086dbf3e8f4dd1711d758d54675ce2d6002ff607a72d72d7e3aea612ba7d Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.mpsl 4f6a","pattern":"[file:hashes.'SHA-256' = '904b086dbf3e8f4dd1711d758d54675ce2d6002ff607a72d72d7e3aea612ba7d']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3ecd862e-37b0-4e66-b3c2-d21a13de07b4","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 918395bac079ab747736246b9d84e66921774d3eb95bb47045704624646b1287","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 7c73ff Feb 22, 2021 16:30 UTC 37[.]46.150.102/bins/dark.ppc 918395bac079ab747736246b9d84e66921774d3eb95bb47045704624646b1287 Feb 22, 2021 16:30 UTC 37[.]46.150.102/bins/dark.sh4 528179","pattern":"[file:hashes.'SHA-256' = '918395bac079ab747736246b9d84e66921774d3eb95bb47045704624646b1287']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3bfcdfff-17b5-474b-a89e-d28b63ffcead","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 971b5a96d84ca0d7dd906b639cd97a04835013be32356d09037cff64516c73bf","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 962cbc2b Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.ppc 971b5a96d84ca0d7dd906b639cd97a04835013be32356d09037cff64516c73bf Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.sh4 e2a6ac51","pattern":"[file:hashes.'SHA-256' = '971b5a96d84ca0d7dd906b639cd97a04835013be32356d09037cff64516c73bf']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--630d4d26-780d-4fcb-b511-ecb35e35d699","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9aa0ded21b8c21075a6ad24180befc47dbfeb3985a433f1baa6181ec945a19b9","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: a74093e2 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.x86 9aa0ded21b8c21075a6ad24180befc47dbfeb3985a433f1baa6181ec945a19b9 Mar 3, 2021 14:24 UTC 45[.]133.1.133/lolol.sh ecae298b18493","pattern":"[file:hashes.'SHA-256' = '9aa0ded21b8c21075a6ad24180befc47dbfeb3985a433f1baa6181ec945a19b9']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--91637f35-ce18-44b4-a720-c07f51a4788b","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 9d55aa1d9841be74cdc0c9d0a9fe2f20e0704ea30c721a7b2dcae02675416629","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 50f7c Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.ppc 9d55aa1d9841be74cdc0c9d0a9fe2f20e0704ea30c721a7b2dcae02675416629 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.sh4 7aa43","pattern":"[file:hashes.'SHA-256' = '9d55aa1d9841be74cdc0c9d0a9fe2f20e0704ea30c721a7b2dcae02675416629']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cdb9eea1-3919-4062-badf-d849084d7b11","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a447bb67be310702807ff148f53f2b4c64ddba0c37f92caf6acabdfaa9ad6603","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 37ca Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.arm5 a447bb67be310702807ff148f53f2b4c64ddba0c37f92caf6acabdfaa9ad6603 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.arm6 b212","pattern":"[file:hashes.'SHA-256' = 'a447bb67be310702807ff148f53f2b4c64ddba0c37f92caf6acabdfaa9ad6603']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9d61186c-cb56-4f9b-868d-0d6bedae7a4c","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a5c2b758da21d7895c7945de8684c9b27370af6c5bf48ce3d94626261982659f","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 5 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/brute/nbrute.mips a5c2b758da21d7895c7945de8684c9b27370af6c5bf48ce3d94626261982659f Feb 16, 2021, 11:01 UTC 37[.]46.150.102/brute/nbrute.mipsle","pattern":"[file:hashes.'SHA-256' = 'a5c2b758da21d7895c7945de8684c9b27370af6c5bf48ce3d94626261982659f']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--da58bf09-48a3-459d-8873-7c4423ead6ee","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a5ca43106a713c4a8e978575b8685889c244501288b9fa7c7dc7f1e8c5ef1291","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: a7a641a2 Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.x86 a5ca43106a713c4a8e978575b8685889c244501288b9fa7c7dc7f1e8c5ef1291 Feb 26, 2021 13:14 UTC iotlmao[.]xyz/bins/dark.m68k a6cb635","pattern":"[file:hashes.'SHA-256' = 'a5ca43106a713c4a8e978575b8685889c244501288b9fa7c7dc7f1e8c5ef1291']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3cd6eae6-3f1f-461e-b616-a6d575d850ce","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a6cb6356432ca83467f6da2168be2aabbabe5d2f2dd4c01d6c4a93d01a57df53","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 5ef1291 Feb 26, 2021 13:14 UTC iotlmao[.]xyz/bins/dark.m68k a6cb6356432ca83467f6da2168be2aabbabe5d2f2dd4c01d6c4a93d01a57df53 Feb 26, 2021 13:14 UTC iotlmao[.]xyz/bins/dark.sh4 c686712f","pattern":"[file:hashes.'SHA-256' = 'a6cb6356432ca83467f6da2168be2aabbabe5d2f2dd4c01d6c4a93d01a57df53']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--970f0cab-d53c-4ed8-91b6-a9ef49ee79b6","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a925f0486b33f3f05d610d33c5a4b6bb2d5531c89e804e001ec01c4f5c25975e","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: bf553 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.x86 a925f0486b33f3f05d610d33c5a4b6bb2d5531c89e804e001ec01c4f5c25975e Feb 23, 2021 09:03 UTC 185[.]239.242.63/lolol.sh 4fe20e7321","pattern":"[file:hashes.'SHA-256' = 'a925f0486b33f3f05d610d33c5a4b6bb2d5531c89e804e001ec01c4f5c25975e']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2d61250f-583b-4279-9318-eb67cbf02719","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a9c4ea40b08ce4281c2dc9776355186dfc5649f9ec2b36c32fa5540f8d2aef2d","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 0664d1f Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.arm7 a9c4ea40b08ce4281c2dc9776355186dfc5649f9ec2b36c32fa5540f8d2aef2d Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.m68k ac75cb7","pattern":"[file:hashes.'SHA-256' = 'a9c4ea40b08ce4281c2dc9776355186dfc5649f9ec2b36c32fa5540f8d2aef2d']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--36b65d73-2c5f-4796-98b5-5c9f84c38478","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ac75cb71c2f052141a238b8f7215d5a0956f7034cf90f231d228ce58254d23ba","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: d2aef2d Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.m68k ac75cb71c2f052141a238b8f7215d5a0956f7034cf90f231d228ce58254d23ba Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.mips 1e56f8c","pattern":"[file:hashes.'SHA-256' = 'ac75cb71c2f052141a238b8f7215d5a0956f7034cf90f231d228ce58254d23ba']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--daa16176-7dcd-4781-9733-792cdcae98e8","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b066b1c1d019fc97e3649b99ad10294783b13a12b67d34b9c8500e762c37b7e7","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: ed55 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.m68k b066b1c1d019fc97e3649b99ad10294783b13a12b67d34b9c8500e762c37b7e7 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.mips 904b","pattern":"[file:hashes.'SHA-256' = 'b066b1c1d019fc97e3649b99ad10294783b13a12b67d34b9c8500e762c37b7e7']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5422e2fe-87be-42df-886c-e5f3e4c1194b","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b2122c5a9c738d964fa770760db40d6708de377e2e671feccb836054ceda2f47","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 6603 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.arm6 b2122c5a9c738d964fa770760db40d6708de377e2e671feccb836054ceda2f47 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.arm7 80cd","pattern":"[file:hashes.'SHA-256' = 'b2122c5a9c738d964fa770760db40d6708de377e2e671feccb836054ceda2f47']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6abf5700-f78c-4e0f-b812-c2813cd8bfad","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b37da8e6afa2b3223b1f8f73e6801cf3fed3c0f114cfb9c134b5f06322a337ca","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: Feb 16, 2021, 11:01 UTC 37[.]46.150.102/brute/nbrute.mipsle b37da8e6afa2b3223b1f8f73e6801cf3fed3c0f114cfb9c134b5f06322a337ca Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.arm5 a447","pattern":"[file:hashes.'SHA-256' = 'b37da8e6afa2b3223b1f8f73e6801cf3fed3c0f114cfb9c134b5f06322a337ca']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8286bc9f-2c3d-4a1c-969e-fa969751d883","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b3a20c8dfa5adaa8247c4d2097f3cc8423b4e270c9735f616628bf9bde583cbe","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 2e780a7807a Feb 22, 2021 16:30 UTC 37[.]46.150.102/lolol.sh b3a20c8dfa5adaa8247c4d2097f3cc8423b4e270c9735f616628bf9bde583cbe Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.arm5 210","pattern":"[file:hashes.'SHA-256' = 'b3a20c8dfa5adaa8247c4d2097f3cc8423b4e270c9735f616628bf9bde583cbe']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a99ba647-55d8-4ec2-a5c1-5e43fda77e58","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b82b8957a4397eae1061a74fb7a8014cbbcbe7064d4edf2e0b15233fd2ce8cca","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 7b08 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.arm5 b82b8957a4397eae1061a74fb7a8014cbbcbe7064d4edf2e0b15233fd2ce8cca Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.arm6 ec9d","pattern":"[file:hashes.'SHA-256' = 'b82b8957a4397eae1061a74fb7a8014cbbcbe7064d4edf2e0b15233fd2ce8cca']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8d32f735-5d29-4e3d-8ee7-92dc2923e3bc","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: baedd59eba62c289dcb722588895eb165f4a1570b3c012efc3dcc60d3bdea521","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 3d Feb 16, 2021, 11:01 UTC 37[.]46.150.102/brute/nbrute.386 baedd59eba62c289dcb722588895eb165f4a1570b3c012efc3dcc60d3bdea521 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/brute/nbrute.amd64","pattern":"[file:hashes.'SHA-256' = 'baedd59eba62c289dcb722588895eb165f4a1570b3c012efc3dcc60d3bdea521']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3e66bf7c-6e2b-4318-8e26-a8dd3db1c04a","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: beb0b7178b242f2dba21c3d91abf80e8738847b8086d2a42e9352738c83542b5","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: a9fb0 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.ppc beb0b7178b242f2dba21c3d91abf80e8738847b8086d2a42e9352738c83542b5 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.sh4 554be","pattern":"[file:hashes.'SHA-256' = 'beb0b7178b242f2dba21c3d91abf80e8738847b8086d2a42e9352738c83542b5']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--561c6643-0258-4f91-9b93-1010a8f0ae9f","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: bfd14a2f5c26501efb5d4010839b7d0bbc9a639d86ab5d12af663de598f15427","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 98f Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.arm6 bfd14a2f5c26501efb5d4010839b7d0bbc9a639d86ab5d12af663de598f15427 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.arm7 d9f","pattern":"[file:hashes.'SHA-256' = 'bfd14a2f5c26501efb5d4010839b7d0bbc9a639d86ab5d12af663de598f15427']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--6eb1cd91-19c8-4332-b724-34104772d463","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c26401490ab9343b023f1f89b39d8d32835a795117ef7d7a129871bc05010dd6","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 63204 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.ppc c26401490ab9343b023f1f89b39d8d32835a795117ef7d7a129871bc05010dd6 Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.sh4 73b35","pattern":"[file:hashes.'SHA-256' = 'c26401490ab9343b023f1f89b39d8d32835a795117ef7d7a129871bc05010dd6']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2708d1c5-555e-4753-b52b-b6793fec99bf","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c686712f9be64e3d2957754ce181e5b4680b205cb6773b85b35df57983ed31cf","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 1a57df53 Feb 26, 2021 13:14 UTC iotlmao[.]xyz/bins/dark.sh4 c686712f9be64e3d2957754ce181e5b4680b205cb6773b85b35df57983ed31cf Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.arm5 8cc6","pattern":"[file:hashes.'SHA-256' = 'c686712f9be64e3d2957754ce181e5b4680b205cb6773b85b35df57983ed31cf']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--77b2175d-34bc-4a0e-9cdc-7a6b8d4bfce7","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: cc996d19c3e9b732b5f61fb7a2ad20a4f9e1fd7e62f484f15c7cc984a32dec01","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 1d26c63 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.mpsl cc996d19c3e9b732b5f61fb7a2ad20a4f9e1fd7e62f484f15c7cc984a32dec01 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.sh4 f05225fe","pattern":"[file:hashes.'SHA-256' = 'cc996d19c3e9b732b5f61fb7a2ad20a4f9e1fd7e62f484f15c7cc984a32dec01']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--49360317-c9c9-4ab2-9729-fa1a712a8de9","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: cd59c912b9af910db1880d6fb86cd6cb656477552cf2c2fc82e372bafbe004b8","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: ca51 Mar 11, 2021 12:30 UTC 203[.]159.80.241/bins/dark.m68k cd59c912b9af910db1880d6fb86cd6cb656477552cf2c2fc82e372bafbe004b8 Mar 5, 2021 14:13 UTC 45[.]133.1.133/bins/dark.ppc 63e66d6f","pattern":"[file:hashes.'SHA-256' = 'cd59c912b9af910db1880d6fb86cd6cb656477552cf2c2fc82e372bafbe004b8']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3b91c985-2e86-4091-9594-332b7c96119d","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d31f1fecde01cc37950dc5b5330cd72e8ab1943f251bdfa5990f0d9d3a0a8e8f","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 3b2 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.mpsl d31f1fecde01cc37950dc5b5330cd72e8ab1943f251bdfa5990f0d9d3a0a8e8f Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.ppc 5446","pattern":"[file:hashes.'SHA-256' = 'd31f1fecde01cc37950dc5b5330cd72e8ab1943f251bdfa5990f0d9d3a0a8e8f']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1d14c3a8-00df-4790-8529-fa07df5dbeb9","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d9f7504b3fe81f5264da5f23bdb7529f6d1dd713e28a92828180787729872a8d","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 427 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.arm7 d9f7504b3fe81f5264da5f23bdb7529f6d1dd713e28a92828180787729872a8d Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.m68k 408","pattern":"[file:hashes.'SHA-256' = 'd9f7504b3fe81f5264da5f23bdb7529f6d1dd713e28a92828180787729872a8d']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--020e3066-885d-4370-af57-5255e166114e","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: def1959fae2d8a3dfe606126ceb9d5403deae97a4b4e216dc8e60354980eeac4","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 964a Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.mips def1959fae2d8a3dfe606126ceb9d5403deae97a4b4e216dc8e60354980eeac4 Feb 16, 2021, 11:01 UTC 37[.]46.150.102/bins/dark.mpsl 6676","pattern":"[file:hashes.'SHA-256' = 'def1959fae2d8a3dfe606126ceb9d5403deae97a4b4e216dc8e60354980eeac4']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0e1afeb5-855c-4fca-a312-7c3488f3b366","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e2a6ac516ec8b5dcc76becc26cf992434882d490d8f2c9d7071298dba7a641a2","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 516c73bf Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.sh4 e2a6ac516ec8b5dcc76becc26cf992434882d490d8f2c9d7071298dba7a641a2 Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.x86 a5ca4310","pattern":"[file:hashes.'SHA-256' = 'e2a6ac516ec8b5dcc76becc26cf992434882d490d8f2c9d7071298dba7a641a2']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e4bf1101-b9f2-417c-b920-e7cf02b4853a","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e9d056afe12210ddf98967e3291127ef9d0d24cbd36862ebc8b0726a565eefb8","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 56fb Mar 11, 2021 19:22 UTC 203[.]159.80.241/bins/dark.mpsl e9d056afe12210ddf98967e3291127ef9d0d24cbd36862ebc8b0726a565eefb8 Mar 11, 2021 19:22 UTC 203[.]159.80.241/bins/dark.mips 73aa","pattern":"[file:hashes.'SHA-256' = 'e9d056afe12210ddf98967e3291127ef9d0d24cbd36862ebc8b0726a565eefb8']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--01292cf9-b9d4-4876-8b19-35f1c5c07301","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ec9dc19758ba74fb254c69d2b60ae1012b1bd65390e936990e4bd8573bcb83aa","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 8cca Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.arm6 ec9dc19758ba74fb254c69d2b60ae1012b1bd65390e936990e4bd8573bcb83aa Feb 23, 2021 09:03 UTC 185[.]239.242.63/bins/dark.arm7 38d8","pattern":"[file:hashes.'SHA-256' = 'ec9dc19758ba74fb254c69d2b60ae1012b1bd65390e936990e4bd8573bcb83aa']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b999e9b5-5529-4182-aa26-c5ce889a3f8b","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ecae298b18493bf2366f6081e8215a474cce4554e07a7b2380a7f8e8a3a9a37d","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 181ec945a19b9 Mar 3, 2021 14:24 UTC 45[.]133.1.133/lolol.sh ecae298b18493bf2366f6081e8215a474cce4554e07a7b2380a7f8e8a3a9a37d Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.arm5 fb940b1","pattern":"[file:hashes.'SHA-256' = 'ecae298b18493bf2366f6081e8215a474cce4554e07a7b2380a7f8e8a3a9a37d']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d24618b7-4e26-4eb6-9ef0-019ab40c3f25","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f05225fec1fda7c6405e6961207ee12e198272d352144f516e970829a74093e2","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: a32dec01 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.sh4 f05225fec1fda7c6405e6961207ee12e198272d352144f516e970829a74093e2 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.x86 9aa0ded2","pattern":"[file:hashes.'SHA-256' = 'f05225fec1fda7c6405e6961207ee12e198272d352144f516e970829a74093e2']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8e57ad6a-7bf8-451b-b542-7ae9faef9f3b","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f05d21a5b4b72a761c1540f1400dff7e39f10ac1c8b843ec8986d2e780a7807a","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: f202e8 Feb 22, 2021 16:30 UTC 37[.]46.150.102/bins/dark.x86 f05d21a5b4b72a761c1540f1400dff7e39f10ac1c8b843ec8986d2e780a7807a Feb 22, 2021 16:30 UTC 37[.]46.150.102/lolol.sh b3a20c8dfa5","pattern":"[file:hashes.'SHA-256' = 'f05d21a5b4b72a761c1540f1400dff7e39f10ac1c8b843ec8986d2e780a7807a']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a57f1835-af95-40ab-92a7-02cfcf457bcc","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f467e6335a4a0250a17d61b3d138b31998f3e6669e1fcd1c3648db1b44b55ffa","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 01e6 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.x86 f467e6335a4a0250a17d61b3d138b31998f3e6669e1fcd1c3648db1b44b55ffa Feb 22, 2021, 12:32 UTC 185[.]239.242.63/lolol.sh 4fe20e732","pattern":"[file:hashes.'SHA-256' = 'f467e6335a4a0250a17d61b3d138b31998f3e6669e1fcd1c3648db1b44b55ffa']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b9055cf8-992b-463f-8c76-36edea462ac5","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f9770197d2254e6d5d4cb872b07dc25feb2994d4d5f0b3c854a98f9dfa3c6854","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 0afd Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.m68k f9770197d2254e6d5d4cb872b07dc25feb2994d4d5f0b3c854a98f9dfa3c6854 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.mips 74ab","pattern":"[file:hashes.'SHA-256' = 'f9770197d2254e6d5d4cb872b07dc25feb2994d4d5f0b3c854a98f9dfa3c6854']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--293d188c-7e19-4877-b9db-4bf4bd6dd62e","created":"2026-08-19T12:04:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: fb940b1049e0e95c03adb7a2750347108cadf6b19ef4149a5103f7625c07c8ec","description":"Seen in \"New Mirai Variant Targeting Network Security Devices\" (Palo Alto Unit 42). Context: 3a9a37d Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.arm5 fb940b1049e0e95c03adb7a2750347108cadf6b19ef4149a5103f7625c07c8ec Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.arm6 515dc2f","pattern":"[file:hashes.'SHA-256' = 'fb940b1049e0e95c03adb7a2750347108cadf6b19ef4149a5103f7625c07c8ec']","pattern_type":"stix","valid_from":"2026-08-19T12:04:51.000Z","labels":["auto-extracted","exploit"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ff8c0c4c-0e75-422d-bf59-fa89ae48906d","created":"2026-08-19T12:04:32.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 2fd9cb69ef30c0d00a61851b2d96350a9be68c7f1f25a31f896082cfbf39559a","description":"Seen in \"FrostyGoop’s Zoom-In: A Closer Look into the Malware Artifacts, Behaviors and Network Communications\" (Palo Alto Unit 42). Context: Windows executable file for FrostyGoop malware SHA256 hash: 2fd9cb69ef30c0d00a61851b2d96350a9be68c7f1f25a31f896082cfbf39559a File size: 3.4 MB (3,359,232 bytes) File type: PE32+ execut","pattern":"[file:hashes.'SHA-256' = '2fd9cb69ef30c0d00a61851b2d96350a9be68c7f1f25a31f896082cfbf39559a']","pattern_type":"stix","valid_from":"2026-08-19T12:04:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/frostygoop-malware-analysis/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c923721c-9678-47de-83a1-1105a0c02bc7","created":"2026-08-19T12:04:32.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5d2e4fd08f81e3b2eb2f3eaae16eb32ae02e760afc36fa17f4649322f6da53fb","description":"Seen in \"FrostyGoop’s Zoom-In: A Closer Look into the Malware Artifacts, Behaviors and Network Communications\" (Palo Alto Unit 42). Context: he two FrostyGoop samples have the following SHA256 hashes: 5d2e4fd08f81e3b2eb2f3eaae16eb32ae02e760afc36fa17f4649322f6da53fb a63ba88ad869085f1625729708ba65e87f5b37d7be9153b3db1a1b0e3fe","pattern":"[file:hashes.'SHA-256' = '5d2e4fd08f81e3b2eb2f3eaae16eb32ae02e760afc36fa17f4649322f6da53fb']","pattern_type":"stix","valid_from":"2026-08-19T12:04:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/frostygoop-malware-analysis/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4ceacb91-ddfc-43a0-8aa3-b377a374b511","created":"2026-08-19T12:04:32.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a63ba88ad869085f1625729708ba65e87f5b37d7be9153b3db1a1b0e3fed309c","description":"Seen in \"FrostyGoop’s Zoom-In: A Closer Look into the Malware Artifacts, Behaviors and Network Communications\" (Palo Alto Unit 42). Context: fd08f81e3b2eb2f3eaae16eb32ae02e760afc36fa17f4649322f6da53fb a63ba88ad869085f1625729708ba65e87f5b37d7be9153b3db1a1b0e3fed309c The task_test.json configuration file only has a function c","pattern":"[file:hashes.'SHA-256' = 'a63ba88ad869085f1625729708ba65e87f5b37d7be9153b3db1a1b0e3fed309c']","pattern_type":"stix","valid_from":"2026-08-19T12:04:32.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/frostygoop-malware-analysis/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--322f0ef9-5adb-4b85-b02f-2176e300b785","created":"2026-08-19T12:03:38.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 71dfbb171eca4ef9d02ff630b56e5283bbef7b375d4dbe9e8c9531bef312fa8d","description":"Seen in \"TuxBot v3: Inside an IoT Botnet Framework With LLM\" (Palo Alto Unit 42). Context: 6 The first TuxBot sample appears on VirusTotal SHA256 hash 71dfbb171eca4ef9d02ff630b56e5283bbef7b375d4dbe9e8c9531bef312fa8d , x86_64 debug build with symbols March 5, 2026 C2 server f","pattern":"[file:hashes.'SHA-256' = '71dfbb171eca4ef9d02ff630b56e5283bbef7b375d4dbe9e8c9531bef312fa8d']","pattern_type":"stix","valid_from":"2026-08-19T12:03:38.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--70cfc672-593c-4dae-840c-73cceba5301b","created":"2026-08-18T04:46:34.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 04463cd1a961f7cd1b77fe6c9e9f5e18b34633f303949a0bb07282dedcd8e9dc","description":"Seen in \"Home & Small Office Wireless Routers Exploited to Attack Gaming Servers\" (Palo Alto Unit 42). Context: l JenX sample MD5: fb93601f8d4e0228276edff1c6fe635d SHA256: 04463cd1a961f7cd1b77fe6c9e9f5e18b34633f303949a0bb07282dedcd8e9dc Updated JenX Sample MD5: f1c099d65bf94e009f5e65238caac468 S","pattern":"[file:hashes.'SHA-256' = '04463cd1a961f7cd1b77fe6c9e9f5e18b34633f303949a0bb07282dedcd8e9dc']","pattern_type":"stix","valid_from":"2026-08-18T04:46:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/home-small-office-wireless-routers-exploited-to-attack-gaming-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cbe97289-57b9-43bc-87a4-e0e95eb7e9cb","created":"2026-08-18T04:46:34.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 676813ee73d382c08765a75204be8bab6bea730ff0073de10765091a8decdf07","description":"Seen in \"Home & Small Office Wireless Routers Exploited to Attack Gaming Servers\" (Palo Alto Unit 42). Context: eam uncovered an updated variant of Gafgyt malware (SHA256: 676813ee73d382c08765a75204be8bab6bea730ff0073de10765091a8decdf07 ) derived from JenX variant, and after analyzing the sample","pattern":"[file:hashes.'SHA-256' = '676813ee73d382c08765a75204be8bab6bea730ff0073de10765091a8decdf07']","pattern_type":"stix","valid_from":"2026-08-18T04:46:34.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/home-small-office-wireless-routers-exploited-to-attack-gaming-servers/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f3d4fc4a-b8df-4a3f-9fc2-a5e8466b0337","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 07d5509988b1aa6f8d5203bc4b75e6d7be6acf5055831cc961a51d3e921f96bd","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: 02c2119f62762f78523aa7cbc96ef1 Figure 2 Lure extracted from 07d5509988b1aa6f8d5203bc4b75e6d7be6acf5055831cc961a51d3e921f96bd Figure 3 Lure extracted from b8abf94017b159f8c1f0746dca24b4","pattern":"[file:hashes.'SHA-256' = '07d5509988b1aa6f8d5203bc4b75e6d7be6acf5055831cc961a51d3e921f96bd']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c65f592e-c08c-45bc-8186-86da66032bed","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 290ac98de80154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: research blog, we are discussing the following file: SHA256 290ac98de80154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2 MD5 79ad2084b057847ce2ec2e48fda64073 Compile Date 2017-12-2","pattern":"[file:hashes.'SHA-256' = '290ac98de80154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c18e29a2-8719-4368-82b0-7484f7b68ff5","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a67220bcf289af6a99a9760c05d197d09502c2119f62762f78523aa7cbc96ef1","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: n be seen in the images below: Figure 1 Lure extracted from a67220bcf289af6a99a9760c05d197d09502c2119f62762f78523aa7cbc96ef1 Figure 2 Lure extracted from 07d5509988b1aa6f8d5203bc4b75e6","pattern":"[file:hashes.'SHA-256' = 'a67220bcf289af6a99a9760c05d197d09502c2119f62762f78523aa7cbc96ef1']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b181ccd8-d6a8-4559-8d3b-8512da4c104d","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ab4f86a3144642346a3a40e500ace71badc06a962758522ca13801b40e9e7f4a","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: 67e92b49169c24051ee9de41327ee5e6ac7c2 BADNEWS SHA256 Hashes ab4f86a3144642346a3a40e500ace71badc06a962758522ca13801b40e9e7f4a 290ac98de80154705794e96d0c6d657c948b7dff7abf25ea817585e4c92","pattern":"[file:hashes.'SHA-256' = 'ab4f86a3144642346a3a40e500ace71badc06a962758522ca13801b40e9e7f4a']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--16fa5059-59ba-4c00-91d4-ca7b662dbf36","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b8abf94017b159f8c1f0746dca24b4eeaf7e27d2ffa83ca053a87deb7560a571","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: 6acf5055831cc961a51d3e921f96bd Figure 3 Lure extracted from b8abf94017b159f8c1f0746dca24b4eeaf7e27d2ffa83ca053a87deb7560a571 Figure 4 Lure extracted from d486ed118a425d902044fb7a84267e","pattern":"[file:hashes.'SHA-256' = 'b8abf94017b159f8c1f0746dca24b4eeaf7e27d2ffa83ca053a87deb7560a571']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0de3dd4b-6d5b-43fa-abfe-d8380e19ee89","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d486ed118a425d902044fb7a84267e92b49169c24051ee9de41327ee5e6ac7c2","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: 7e27d2ffa83ca053a87deb7560a571 Figure 4 Lure extracted from d486ed118a425d902044fb7a84267e92b49169c24051ee9de41327ee5e6ac7c2 and fd8394b2ff9cd00380dc2b5a870e15183f1dc3bd82ca6ee58f055b4","pattern":"[file:hashes.'SHA-256' = 'd486ed118a425d902044fb7a84267e92b49169c24051ee9de41327ee5e6ac7c2']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--56f78f09-8e63-41ae-b181-9de80194ad5a","created":"2026-08-17T13:24:45.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: fd8394b2ff9cd00380dc2b5a870e15183f1dc3bd82ca6ee58f055b44074c7fd4","description":"Seen in \"Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent\" (Palo Alto Unit 42). Context: a425d902044fb7a84267e92b49169c24051ee9de41327ee5e6ac7c2 and fd8394b2ff9cd00380dc2b5a870e15183f1dc3bd82ca6ee58f055b44074c7fd4 The payload from each of the malicious documents is an upda","pattern":"[file:hashes.'SHA-256' = 'fd8394b2ff9cd00380dc2b5a870e15183f1dc3bd82ca6ee58f055b44074c7fd4']","pattern_type":"stix","valid_from":"2026-08-17T13:24:45.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2f4e3733-081c-4fdd-a54f-a21bca455073","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0517b62233c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: During runtime, the following plugin was identified: SHA256 0517b62233c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686","pattern":"[file:hashes.'SHA-256' = '0517b62233c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5bb400b4-df51-4f24-a7c5-6eae086b38c7","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0bb20a9570a9b1e3a72203951268ffe83af6dcae7342a790fe195a2ef109d855","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: ted to this IP address: SHA256 Description Connection to IP 0bb20a9570a9b1e3a72203951268ffe83af6dcae7342a790fe195a2ef109d855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c356","pattern":"[file:hashes.'SHA-256' = '0bb20a9570a9b1e3a72203951268ffe83af6dcae7342a790fe195a2ef109d855']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5a1e2787-db50-47cf-8982-64cbd9828ea2","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 119572fafe502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: For the analysis below, we used the following file: SHA256 119572fafe502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bceda","pattern":"[file:hashes.'SHA-256' = '119572fafe502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--45b62aa3-3c12-4b0d-80a6-657a2541834e","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1dc5966572e94afc2fbcf8e93e3382eef4e4d7b5bc02f24069c403a28fa6a458","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: o 2 / RU SYSTEM Cluster B Case 2: Delivery via HTA Loader - 1dc5966572e94afc2fbcf8e93e3382eef4e4d7b5bc02f24069c403a28fa6a458 In this case the attackers sent an HTML Application file (.","pattern":"[file:hashes.'SHA-256' = '1dc5966572e94afc2fbcf8e93e3382eef4e4d7b5bc02f24069c403a28fa6a458']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f80a5bae-3e87-46b4-865b-bf87c8fab3fe","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6aad1408a72e7adc88c2e60631a6eee3d77f18a70e4eee868623588612efdd31","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: ,helloworld2,sqmAddTostream,DllEntryPoint microsoftfuckedup 6aad1408a72e7adc88c2e60631a6eee3d77f18a70e4eee868623588612efdd31 The following actions are performed with the additional fun","pattern":"[file:hashes.'SHA-256' = '6aad1408a72e7adc88c2e60631a6eee3d77f18a70e4eee868623588612efdd31']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3bfb2b65-696b-4ae7-9657-efc7b0323e00","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: a789a282e0d65a050cccae66c56632245af1c8a589ace2ca5ca79572289fd483","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: w. Cluster A Case 1: Delivery via document property macro – a789a282e0d65a050cccae66c56632245af1c8a589ace2ca5ca79572289fd483 In our research we found at least one attack against a comp","pattern":"[file:hashes.'SHA-256' = 'a789a282e0d65a050cccae66c56632245af1c8a589ace2ca5ca79572289fd483']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--1fdbe6fd-bbbe-4f17-b0e9-f4fe7b672194","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b099c31515947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: or that sample. The retrieved plugin was as follows: SHA256 b099c31515947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dc","pattern":"[file:hashes.'SHA-256' = 'b099c31515947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e3000f5f-fc8d-4aea-a493-164f3cd63d69","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: bcd37f1d625772c162350e5383903fe8dbed341ebf0dc38035be5078624c039e","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: es have additional unique differences: Hash Functions Mutex bcd37f1d625772c162350e5383903fe8dbed341ebf0dc38035be5078624c039e helloworld helloworld1,helloworld2,sqmAddTostream,DllEntryP","pattern":"[file:hashes.'SHA-256' = 'bcd37f1d625772c162350e5383903fe8dbed341ebf0dc38035be5078624c039e']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2590dc25-ca3e-48b6-91e3-77052eb3df9d","created":"2026-08-17T13:24:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d","description":"Seen in \"RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families\" (Palo Alto Unit 42). Context: d855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d PLAINTEE Hosted on 89.46.222.97 Digging in further, the mal","pattern":"[file:hashes.'SHA-256' = 'c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d']","pattern_type":"stix","valid_from":"2026-08-17T13:24:28.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--876d2219-0d37-4d25-90af-32d9f0ef3448","created":"2026-08-17T13:23:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 8ac7909730269d62efaf898d1a5e87251aadccf4349cd95564ad6a3634ba4ef4","description":"Seen in \"Upatre Continued to Evolve with new Anti\" (Palo Alto Unit 42). Context: omise associated with this analysis include: Upatre SHA256: 8ac7909730269d62efaf898d1a5e87251aadccf4349cd95564ad6a3634ba4ef4 Cthonic SHA256: 94a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01","pattern":"[file:hashes.'SHA-256' = '8ac7909730269d62efaf898d1a5e87251aadccf4349cd95564ad6a3634ba4ef4']","pattern_type":"stix","valid_from":"2026-08-17T13:23:28.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-upatre-continues-evolve-new-anti-analysis-techniques/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--fd8493f9-a3f9-4c2d-8dfa-bbcc08fb6967","created":"2026-08-17T13:23:28.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 94a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01335c36ba3b6e5d3635b83","description":"Seen in \"Upatre Continued to Evolve with new Anti\" (Palo Alto Unit 42). Context: ample configured with the same dot-bit domains. The sample, 94a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01335c36ba3b6e5d3635b83, was compiled six days after our Upatre sample and delivere","pattern":"[file:hashes.'SHA-256' = '94a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01335c36ba3b6e5d3635b83']","pattern_type":"stix","valid_from":"2026-08-17T13:23:28.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/unit42-upatre-continues-evolve-new-anti-analysis-techniques/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--51d23d12-504e-4eeb-9a88-5c5b32bf2d37","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0b2a794bac4bf650b6ba537137504162520b67266449be979679afbb14e8e5c0","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: d0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a794bac4bf650b6ba537137504162520b67266449be979679afbb14e8e5c0 Compile Timestamp 2019-01-07 07:13:47 UTC PDB String c:\\Use","pattern":"[file:hashes.'SHA-256' = '0b2a794bac4bf650b6ba537137504162520b67266449be979679afbb14e8e5c0']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--456727a1-1626-4d80-bb4d-d8e583493c4e","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd956e706a5fd57","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: 83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd956e706a5fd57 Compile Timestamp 2018-12-06 11:14:45 UTC Table 1 ArtraDown","pattern":"[file:hashes.'SHA-256' = 'ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd956e706a5fd57']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8ff93983-5fe3-4412-b811-e61596805bce","created":"2026-08-17T13:22:21.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbca0b0aaa3b2c22","description":"Seen in \"Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan\" (Palo Alto Unit 42). Context: 662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbca0b0aaa3b2c22 Compile Timestamp 2018-07-30 09:18:37 UTC PDB String d:\\C++","pattern":"[file:hashes.'SHA-256' = 'f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbca0b0aaa3b2c22']","pattern_type":"stix","valid_from":"2026-08-17T13:22:21.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/multiple-artradownloader-variants-used-by-bitter-to-target-pakistan/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5aeab79f-0bc0-4316-ad08-595bfe458d98","created":"2026-08-17T13:22:04.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0282b7705f13f9d9811b722f8d7ef8fef907bee2ef00bf8ec89df5e7d96d81ff","description":"Seen in \"New Python-Based Payload MechaFlounder Used by Chafer\" (Palo Alto Unit 42). Context: [.]com/update.php?req=<redacted>&m=d This payload, (SHA256: 0282b7705f13f9d9811b722f8d7ef8fef907bee2ef00bf8ec89df5e7d96d81ff), which we are tracking as MechaFlounder, was developed in","pattern":"[file:hashes.'SHA-256' = '0282b7705f13f9d9811b722f8d7ef8fef907bee2ef00bf8ec89df5e7d96d81ff']","pattern_type":"stix","valid_from":"2026-08-17T13:22:04.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/new-python-based-payload-mechaflounder-used-by-chafer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c424a8c5-31b4-4138-8d72-336a79702772","created":"2026-08-17T13:22:04.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1b2fee00d28782076178a63e669d2306c37ba0c417708d4dc1f751765c3f94e1","description":"Seen in \"New Python-Based Payload MechaFlounder Used by Chafer\" (Palo Alto Unit 42). Context: hows a VBScript run by an OilRig delivery document (SHA256: 1b2fee00d28782076178a63e669d2306c37ba0c417708d4dc1f751765c3f94e1) on the left compared to a Chafer AutoIT script (SHA256: 33","pattern":"[file:hashes.'SHA-256' = '1b2fee00d28782076178a63e669d2306c37ba0c417708d4dc1f751765c3f94e1']","pattern_type":"stix","valid_from":"2026-08-17T13:22:04.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/new-python-based-payload-mechaflounder-used-by-chafer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2912fae2-5a18-4bf9-b6d2-6d1ba77175a8","created":"2026-08-17T13:22:04.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 332fab21cb0f2f50774fccf94fc7ae905a21b37fe66010dcef6b71c140bb7fa1","description":"Seen in \"New Python-Based Payload MechaFlounder Used by Chafer\" (Palo Alto Unit 42). Context: e1) on the left compared to a Chafer AutoIT script (SHA256: 332fab21cb0f2f50774fccf94fc7ae905a21b37fe66010dcef6b71c140bb7fa1) on the right, which have colored boxes surrounding code ov","pattern":"[file:hashes.'SHA-256' = '332fab21cb0f2f50774fccf94fc7ae905a21b37fe66010dcef6b71c140bb7fa1']","pattern_type":"stix","valid_from":"2026-08-17T13:22:04.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/new-python-based-payload-mechaflounder-used-by-chafer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4a1d757e-f468-4afb-882c-26759898ac3a","created":"2026-08-17T13:21:46.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 5f762589cdb8955308db4bba140129f172bf2dbc1e979137b6cc7949f7b19e6f","description":"Seen in \"Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign\" (Palo Alto Unit 42). Context: ooter of Activity.doc file is actually an RTF file (SHA256: 5f762589cdb8955308db4bba140129f172bf2dbc1e979137b6cc7949f7b19e6f ) that loads an embedded Excel document with a heavily obfu","pattern":"[file:hashes.'SHA-256' = '5f762589cdb8955308db4bba140129f172bf2dbc1e979137b6cc7949f7b19e6f']","pattern_type":"stix","valid_from":"2026-08-17T13:21:46.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f1d7f65-5da7-4837-9303-4f02c33d27c7","created":"2026-08-17T13:21:46.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d7c92a8aa03478155de6813c35e84727ac9d383e27ba751d833e5efba3d77946","description":"Seen in \"Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign\" (Palo Alto Unit 42). Context: document attached with the filename “Activity.doc” (SHA256: d7c92a8aa03478155de6813c35e84727ac9d383e27ba751d833e5efba3d77946 ) that attempted to load a remote OLE document via Template","pattern":"[file:hashes.'SHA-256' = 'd7c92a8aa03478155de6813c35e84727ac9d383e27ba751d833e5efba3d77946']","pattern_type":"stix","valid_from":"2026-08-17T13:21:46.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--549e55d4-0056-4c6c-9071-eb3d49ea4f49","created":"2026-08-17T13:21:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 892d5e8e763073648dfebcfd4c89526989d909d6189826a974f17e2311de8bc4","description":"Seen in \"xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations\" (Palo Alto Unit 42). Context: soka\\\\Hisoka\\\\obj\\\\Debug\\\\inetinfo.sys.pdb The file SHA256: 892d5e8e763073648dfebcfd4c89526989d909d6189826a974f17e2311de8bc4 was used in reference to the below analysis on Hisoka v0.8.","pattern":"[file:hashes.'SHA-256' = '892d5e8e763073648dfebcfd4c89526989d909d6189826a974f17e2311de8bc4']","pattern_type":"stix","valid_from":"2026-08-17T13:21:29.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/xhunt-campaign-attacks-on-kuwait-shipping-and-transportation-organizations/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--38086e46-2dc3-4460-a3a8-aca5ed05d0be","created":"2026-08-17T13:19:12.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: eccc65711cbd154f680e8c8ef343d53f29e4a6237510abd4ad1eab5742b035b3","description":"Seen in \"xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection\" (Palo Alto Unit 42). Context: HY200 DNS Tunneling Protocol We analyzed the file ( SHA256: eccc65711cbd154f680e8c8ef343d53f29e4a6237510abd4ad1eab5742b035b3) in order to understand the capabilities of the payload and","pattern":"[file:hashes.'SHA-256' = 'eccc65711cbd154f680e8c8ef343d53f29e4a6237510abd4ad1eab5742b035b3']","pattern_type":"stix","valid_from":"2026-08-17T13:19:12.000Z","labels":["auto-extracted","threat-actor"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/more-xhunt-new-powershell-backdoor-blocked-through-dns-tunnel-detection/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--06941e9c-3aba-4c80-ae4c-70dd0c77200b","created":"2026-08-17T13:18:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 24e3fa3fb1df9bd70071e5b957d180cd51bcf10bab690fa7db7425ca6652c47c","description":"Seen in \"TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks\" (Palo Alto Unit 42). Context: yload SHA256 11/7/19 clementeolmos[.]com/supp.php erfd1.exe 24e3fa3fb1df9bd70071e5b957d180cd51bcf10bab690fa7db7425ca6652c47c e9fd22631de9c918ac834eb14e01c76aa4d33069c7622daafcd03b4f157","pattern":"[file:hashes.'SHA-256' = '24e3fa3fb1df9bd70071e5b957d180cd51bcf10bab690fa7db7425ca6652c47c']","pattern_type":"stix","valid_from":"2026-08-17T13:18:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/trickbot-campaign-uses-fake-payroll-emails-to-conduct-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--01a48332-9f03-4ffe-a263-038e83a33b6d","created":"2026-08-17T13:18:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7d6ff8baebedba414c9f15060f0a8470965369cbc1088e9f21e2b5289b42a747","description":"Seen in \"TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks\" (Palo Alto Unit 42). Context: rt.exe lindaspryinteriordesign[.]com/supp.php nfdusdarm.exe 7d6ff8baebedba414c9f15060f0a8470965369cbc1088e9f21e2b5289b42a747 Table 2. Trickbot Payload Download Locations The two payloa","pattern":"[file:hashes.'SHA-256' = '7d6ff8baebedba414c9f15060f0a8470965369cbc1088e9f21e2b5289b42a747']","pattern_type":"stix","valid_from":"2026-08-17T13:18:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/trickbot-campaign-uses-fake-payroll-emails-to-conduct-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--cc3155fa-5619-4a35-b5ed-fb2445f4e82c","created":"2026-08-17T13:18:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b3d2e7158620ece90fbc062892db55bf564c6154eb85facab57a459e3bd1156f","description":"Seen in \"TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks\" (Palo Alto Unit 42). Context: 59fb55a330d1a8e51d913404651b8d785d4ae8c9c655c57b4efbfe71a64 b3d2e7158620ece90fbc062892db55bf564c6154eb85facab57a459e3bd1156f Table 3. Additional Trickbot payloads observed Conclusion B","pattern":"[file:hashes.'SHA-256' = 'b3d2e7158620ece90fbc062892db55bf564c6154eb85facab57a459e3bd1156f']","pattern_type":"stix","valid_from":"2026-08-17T13:18:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/trickbot-campaign-uses-fake-payroll-emails-to-conduct-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0faffe6b-97ed-4bb4-af52-1ca50f82fea8","created":"2026-08-17T13:18:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b8c2329906b4712caa0f8ca7941553b3ed6da1cd1f5cb70f1409df5bc1f0ee4a","description":"Seen in \"TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks\" (Palo Alto Unit 42). Context: ing Theme File Name SHA256 Annual bonus StatementReport.exe b8c2329906b4712caa0f8ca7941553b3ed6da1cd1f5cb70f1409df5bc1f0ee4a Payroll Preview_Report.exe f8aaf313cc213258c6976cd55c8c0d04","pattern":"[file:hashes.'SHA-256' = 'b8c2329906b4712caa0f8ca7941553b3ed6da1cd1f5cb70f1409df5bc1f0ee4a']","pattern_type":"stix","valid_from":"2026-08-17T13:18:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/trickbot-campaign-uses-fake-payroll-emails-to-conduct-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--929c4225-d5b2-4a94-a30a-c2eb2b0f7857","created":"2026-08-17T13:18:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d1e0902fd1e8b3951e2aec057a938db9eebe4a0efa573343d89703482cafb2d8","description":"Seen in \"TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks\" (Palo Alto Unit 42). Context: HA256 StatementReport.exe savute[.]in/supp.php nfdsus12.exe d1e0902fd1e8b3951e2aec057a938db9eebe4a0efa573343d89703482cafb2d8 Preview_Report.exe lindaspryinteriordesign[.]com/supp.php n","pattern":"[file:hashes.'SHA-256' = 'd1e0902fd1e8b3951e2aec057a938db9eebe4a0efa573343d89703482cafb2d8']","pattern_type":"stix","valid_from":"2026-08-17T13:18:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/trickbot-campaign-uses-fake-payroll-emails-to-conduct-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8fdafa9-7a55-4568-8661-0e9a29dd6171","created":"2026-08-17T13:18:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d7687e1d98484b093e8da7fb666b2d644197fc3ea22b3931a6150c259479b0c6","description":"Seen in \"TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks\" (Palo Alto Unit 42). Context: 2631de9c918ac834eb14e01c76aa4d33069c7622daafcd03b4f1574aad0 d7687e1d98484b093e8da7fb666b2d644197fc3ea22b3931a6150c259479b0c6 dc8f259fb55a330d1a8e51d913404651b8d785d4ae8c9c655c57b4efbfe","pattern":"[file:hashes.'SHA-256' = 'd7687e1d98484b093e8da7fb666b2d644197fc3ea22b3931a6150c259479b0c6']","pattern_type":"stix","valid_from":"2026-08-17T13:18:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/trickbot-campaign-uses-fake-payroll-emails-to-conduct-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--f8696d0f-98a4-40dc-af65-7911eecc8ee6","created":"2026-08-17T13:18:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: dc8f259fb55a330d1a8e51d913404651b8d785d4ae8c9c655c57b4efbfe71a64","description":"Seen in \"TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks\" (Palo Alto Unit 42). Context: 11/19/19 maisonmarielouise[.]org/supp.php SetupDesktop.exe dc8f259fb55a330d1a8e51d913404651b8d785d4ae8c9c655c57b4efbfe71a64 b3d2e7158620ece90fbc062892db55bf564c6154eb85facab57a459e3bd","pattern":"[file:hashes.'SHA-256' = 'dc8f259fb55a330d1a8e51d913404651b8d785d4ae8c9c655c57b4efbfe71a64']","pattern_type":"stix","valid_from":"2026-08-17T13:18:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/trickbot-campaign-uses-fake-payroll-emails-to-conduct-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--24fdc038-d609-43ec-a4e5-10dc15eae919","created":"2026-08-17T13:18:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e9fd22631de9c918ac834eb14e01c76aa4d33069c7622daafcd03b4f1574aad0","description":"Seen in \"TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks\" (Palo Alto Unit 42). Context: a3fb1df9bd70071e5b957d180cd51bcf10bab690fa7db7425ca6652c47c e9fd22631de9c918ac834eb14e01c76aa4d33069c7622daafcd03b4f1574aad0 d7687e1d98484b093e8da7fb666b2d644197fc3ea22b3931a6150c25947","pattern":"[file:hashes.'SHA-256' = 'e9fd22631de9c918ac834eb14e01c76aa4d33069c7622daafcd03b4f1574aad0']","pattern_type":"stix","valid_from":"2026-08-17T13:18:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/trickbot-campaign-uses-fake-payroll-emails-to-conduct-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--40a23af8-fb2c-453e-b244-e3390f676885","created":"2026-08-17T13:18:48.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: f8aaf313cc213258c6976cd55c8c0d048f61b0f3b196d768fbf51779786b6ac6","description":"Seen in \"TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks\" (Palo Alto Unit 42). Context: ed6da1cd1f5cb70f1409df5bc1f0ee4a Payroll Preview_Report.exe f8aaf313cc213258c6976cd55c8c0d048f61b0f3b196d768fbf51779786b6ac6 Table 1. Trickbot downloader files Both of these downloader","pattern":"[file:hashes.'SHA-256' = 'f8aaf313cc213258c6976cd55c8c0d048f61b0f3b196d768fbf51779786b6ac6']","pattern_type":"stix","valid_from":"2026-08-17T13:18:48.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/trickbot-campaign-uses-fake-payroll-emails-to-conduct-phishing-attacks/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--39ef6eea-bb55-4ce7-97d8-d11ba07277ef","created":"2026-08-17T13:18:13.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 41d27d53c5d41003bc9913476a3afd3961b561b120ee8bfde327a5f0d22a040a","description":"Seen in \"Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT\" (Palo Alto Unit 42). Context: be downloaded when using msiexec. The MSI payload (SHA256: 41D27D53C5D41003BC9913476A3AFD3961B561B120EE8BFDE327A5F0D22A040A ) was built using an unregistered version from www.exemsi[.","pattern":"[file:hashes.'SHA-256' = '41d27d53c5d41003bc9913476a3afd3961b561b120ee8bfde327a5f0d22a040a']","pattern_type":"stix","valid_from":"2026-08-17T13:18:13.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cortex-xdr-detects-netsupport-manager-rat-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--b58bdd87-a982-4337-94a1-80b8fb0d488a","created":"2026-08-17T13:18:13.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 68ca2458e0db9739258ce9e22aadd2423002b2cc779033d78d6abec1db534ac2","description":"Seen in \"Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT\" (Palo Alto Unit 42). Context: e macro code below. The hash for this macro code is SHA256: 68ca2458e0db9739258ce9e22aadd2423002b2cc779033d78d6abec1db534ac2 If the user enters an incorrect password, they are presente","pattern":"[file:hashes.'SHA-256' = '68ca2458e0db9739258ce9e22aadd2423002b2cc779033d78d6abec1db534ac2']","pattern_type":"stix","valid_from":"2026-08-17T13:18:13.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cortex-xdr-detects-netsupport-manager-rat-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--47bdabb3-8c12-4ff8-a393-508e46c6111e","created":"2026-08-17T13:18:13.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: e9440a5d2dfe2453ae5b69a9c096f8d4cf9e059d469c5de67380d76e02dd6975","description":"Seen in \"Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT\" (Palo Alto Unit 42). Context: able macros. The document used for this analysis is SHA256: E9440A5D2DFE2453AE5B69A9C096F8D4CF9E059D469C5DE67380D76E02DD6975 Figure 4. Delivery document disguised as NortonLifeLock. To","pattern":"[file:hashes.'SHA-256' = 'e9440a5d2dfe2453ae5b69a9c096f8d4cf9e059d469c5de67380d76e02dd6975']","pattern_type":"stix","valid_from":"2026-08-17T13:18:13.000Z","labels":["auto-extracted","phishing-fraud"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/cortex-xdr-detects-netsupport-manager-rat-campaign/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e120eb3e-66a3-4e99-9e44-f745d78e0de1","created":"2026-08-17T13:06:35.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 69ae50160f22494759f89e2b318fe3f1342a87eeeeb4829fefaeafa4a560d57e","description":"Seen in \"Trends in Web Threats: Attackers Were More Active During Holiday Season\" (Palo Alto Unit 42). Context: 0200 Indicators of Compromise Malicious Web Skimmer SHA256: 69ae50160f22494759f89e2b318fe3f1342a87eeeeb4829fefaeafa4a560d57e Acknowledgements We would like to thank Billy Melicher, Ale","pattern":"[file:hashes.'SHA-256' = '69ae50160f22494759f89e2b318fe3f1342a87eeeeb4829fefaeafa4a560d57e']","pattern_type":"stix","valid_from":"2026-08-17T13:06:35.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/web-threats-malicious-host-urls/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--8540bdfc-d1a7-4937-a3a0-d715d3f81dde","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 06fc99956bd2afceebbcd157c71908f8ce9ddc81a830cbe86a2a3f4ff79da5f4","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: A226EE541D7A0027C31FF05578E2 MooBot executable file. mipsel 06FC99956BD2AFCEEBBCD157C71908F8CE9DDC81A830CBE86A2A3F4FF79DA5F4 MooBot executable file. sh4 4BFF052C7FBF3F7AD025D7DBAB8BD98","pattern":"[file:hashes.'SHA-256' = '06fc99956bd2afceebbcd157c71908f8ce9ddc81a830cbe86a2a3f4ff79da5f4']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--90567ebc-471b-4c56-9633-a97afe5c50eb","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 188bce5483a9bdc618e0ee9f3c961ff5356009572738ab703057857e8477a36b","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: 103F74397C46A21697B7D9C0448BE6 MooBot executable file. i686 188BCE5483A9BDC618E0EE9F3C961FF5356009572738AB703057857E8477A36B MooBot executable file. mips 4567979788B37FBED6EEDA02B3C15F","pattern":"[file:hashes.'SHA-256' = '188bce5483a9bdc618e0ee9f3c961ff5356009572738ab703057857e8477a36b']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--dbef9f6f-2f80-4b13-a663-d571d9bf079c","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 36dcaf547c212b6228ca5a45a3f3a778271fbaf8e198ede305d801bc98893d5a","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: mised system, and renames the binary files to Android . arc 36DCAF547C212B6228CA5A45A3F3A778271FBAF8E198EDE305D801BC98893D5A MooBot executable file. arm 88B858B1411992509B0F2997877402D","pattern":"[file:hashes.'SHA-256' = '36dcaf547c212b6228ca5a45a3f3a778271fbaf8e198ede305d801bc98893d5a']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2656dabc-2614-47cf-ac9e-1e0183f529be","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 3b12aba8c92a15ef2a917f7c03a5216342e7d2626b025523c62308fc799b0737","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: 3F7AD025D7DBAB8BD985B6CAC79381EB3F8616BEF98FCB01D871 x86_64 3B12ABA8C92A15EF2A917F7C03A5216342E7D2626B025523C62308FC799B0737 Table 4. MooBot samples. Additional Resources New Mirai Var","pattern":"[file:hashes.'SHA-256' = '3b12aba8c92a15ef2a917f7c03a5216342e7d2626b025523c62308fc799b0737']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4c77a88d-9366-4e1c-b96c-5d5a750be99c","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4567979788b37fbed6eeda02b3c15fafe3e0a226ee541d7a0027c31ff05578e2","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: 6009572738AB703057857E8477A36B MooBot executable file. mips 4567979788B37FBED6EEDA02B3C15FAFE3E0A226EE541D7A0027C31FF05578E2 MooBot executable file. mipsel 06FC99956BD2AFCEEBBCD157C719","pattern":"[file:hashes.'SHA-256' = '4567979788b37fbed6eeda02b3c15fafe3e0a226ee541d7a0027c31ff05578e2']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--555d9545-be74-4683-8c79-913b93560f21","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 46bb6e2f80b6cb96ff7d0f78b3bdbc496b69eb7f22ce15efcaa275f07cfae075","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: system and renames the binary files to Realtek . wget[.]sh 46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07CFAE075 The script downloader. It downloads MooBot onto the comprom","pattern":"[file:hashes.'SHA-256' = '46bb6e2f80b6cb96ff7d0f78b3bdbc496b69eb7f22ce15efcaa275f07cfae075']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d97e9b1f-df2f-4594-af45-ed6aa2832198","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4bff052c7fbf3f7ad025d7dbab8bd985b6cac79381eb3f8616bef98fcb01d871","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: E9DDC81A830CBE86A2A3F4FF79DA5F4 MooBot executable file. sh4 4BFF052C7FBF3F7AD025D7DBAB8BD985B6CAC79381EB3F8616BEF98FCB01D871 MooBot executable file. x86_64 4BFF052C7FBF3F7AD025D7DBAB8B","pattern":"[file:hashes.'SHA-256' = '4bff052c7fbf3f7ad025d7dbab8bd985b6cac79381eb3f8616bef98fcb01d871']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7e80bb99-269b-49e4-9674-526b0abc89f2","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7123b2de979d85615c35fca99fa40e0b5fbca25f2c7654b083808653c9e4d616","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: 82902E538C2F7146C8666192893258 MooBot executable file. arm7 7123B2DE979D85615C35FCA99FA40E0B5FBCA25F2C7654B083808653C9E4D616 MooBot executable file. i586 CC3E92C52BBCF56CCFFB6F6E2942A6","pattern":"[file:hashes.'SHA-256' = '7123b2de979d85615c35fca99fa40e0b5fbca25f2c7654b083808653c9e4d616']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--688ae88b-bc0d-4218-a3d4-8fa3c825639f","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 72153e51ea461452263dbb8f658bddc8fb82902e538c2f7146c8666192893258","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: 49D3014776C1FB527C3B2E3086EBAB MooBot executable file. arm6 72153E51EA461452263DBB8F658BDDC8FB82902E538C2F7146C8666192893258 MooBot executable file. arm7 7123B2DE979D85615C35FCA99FA40E","pattern":"[file:hashes.'SHA-256' = '72153e51ea461452263dbb8f658bddc8fb82902e538c2f7146c8666192893258']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--acf097aa-59b6-4811-89e0-e067c2a33e67","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 88b858b1411992509b0f2997877402d8bd9e378e4e21efe024d61e25b29daa08","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: 71FBAF8E198EDE305D801BC98893D5A MooBot executable file. arm 88B858B1411992509B0F2997877402D8BD9E378E4E21EFE024D61E25B29DAA08 MooBot executable file. arm5 D7564C7E6F606EC3A04BE3AC63FDEF","pattern":"[file:hashes.'SHA-256' = '88b858b1411992509b0f2997877402d8bd9e378e4e21efe024d61e25b29daa08']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--702dee39-c97c-4e84-a828-2a9e1e3b67d9","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: b7ee57a42c6a4545ac6d6c29e1075fa1628e1d09b8c1572c848a70112d4c90a1","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: own in the following table: File Name SHA256 Description rt B7EE57A42C6A4545AC6D6C29E1075FA1628E1D09B8C1572C848A70112D4C90A1 A script downloader. It downloads MooBot onto the compromis","pattern":"[file:hashes.'SHA-256' = 'b7ee57a42c6a4545ac6d6c29e1075fa1628e1d09b8c1572c848a70112d4c90a1']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--63c6d3d2-f740-4dbe-963f-606fc1375cb2","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: cc3e92c52bbcf56ccffb6f6e2942a676b3103f74397c46a21697b7d9c0448be6","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: BCA25F2C7654B083808653C9E4D616 MooBot executable file. i586 CC3E92C52BBCF56CCFFB6F6E2942A676B3103F74397C46A21697B7D9C0448BE6 MooBot executable file. i686 188BCE5483A9BDC618E0EE9F3C961F","pattern":"[file:hashes.'SHA-256' = 'cc3e92c52bbcf56ccffb6f6e2942a676b3103f74397c46a21697b7d9c0448be6']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--15daa48b-258e-4cf6-b072-879d4fae4446","created":"2026-08-17T13:06:15.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: d7564c7e6f606ec3a04be3ac63fdef2fde49d3014776c1fb527c3b2e3086ebab","description":"Seen in \"Mirai Variant MooBot Targeting D\" (Palo Alto Unit 42). Context: 9E378E4E21EFE024D61E25B29DAA08 MooBot executable file. arm5 D7564C7E6F606EC3A04BE3AC63FDEF2FDE49D3014776C1FB527C3B2E3086EBAB MooBot executable file. arm6 72153E51EA461452263DBB8F658BDD","pattern":"[file:hashes.'SHA-256' = 'd7564c7e6f606ec3a04be3ac63fdef2fde49d3014776c1fb527c3b2e3086ebab']","pattern_type":"stix","valid_from":"2026-08-17T13:06:15.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/moobot-d-link-devices/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--9f0f2818-5dc7-421b-9894-c9ba379d917e","created":"2026-08-17T13:05:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 79eedf9c1b974992a4beada1bd6343ecadece0b413acccd4deded4a49a4ad220","description":"Seen in \"Trends in Web Threats: Old Web Skimmer Still Active Today\" (Palo Alto Unit 42). Context: 0200 Indicators of Compromise Malicious Web Skimmer SHA256: 79eedf9c1b974992a4beada1bd6343ecadece0b413acccd4deded4a49a4ad220 992cfcb5790664d02204e5356e3dd6e109f0cba90b8e552598f2afb11f4","pattern":"[file:hashes.'SHA-256' = '79eedf9c1b974992a4beada1bd6343ecadece0b413acccd4deded4a49a4ad220']","pattern_type":"stix","valid_from":"2026-08-17T13:05:51.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/web-threat-trends-web-skimmer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--0cabcfc1-9695-44d1-ad7c-2d30e87546d3","created":"2026-08-17T13:05:51.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 992cfcb5790664d02204e5356e3dd6e109f0cba90b8e552598f2afb11f468a1f","description":"Seen in \"Trends in Web Threats: Old Web Skimmer Still Active Today\" (Palo Alto Unit 42). Context: er malware campaigns, such as the following Trojan (SHA256: 992cfcb5790664d02204e5356e3dd6e109f0cba90b8e552598f2afb11f468a1f ). They connect to these IPs through the domain voques-tfr[","pattern":"[file:hashes.'SHA-256' = '992cfcb5790664d02204e5356e3dd6e109f0cba90b8e552598f2afb11f468a1f']","pattern_type":"stix","valid_from":"2026-08-17T13:05:51.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/web-threat-trends-web-skimmer/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5e25ba93-93d3-4ac4-a287-63c183b9b169","created":"2026-08-17T13:05:35.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: bb38741575706a94cc1a3ab43d445b641b2c225f408d67a76d3302ca1233e122","description":"Seen in \"Trends in Web Threats in CY Q2 2022: Malicious JavaScript Downloaders Are Evolving\" (Palo Alto Unit 42). Context: 0200 Indicators of Compromise Malicious Web Skimmer SHA256: bb38741575706a94cc1a3ab43d445b641b2c225f408d67a76d3302ca1233e122 Train[.]developfirstline[.]com Js[.]digestcolect[.]com stat","pattern":"[file:hashes.'SHA-256' = 'bb38741575706a94cc1a3ab43d445b641b2c225f408d67a76d3302ca1233e122']","pattern_type":"stix","valid_from":"2026-08-17T13:05:35.000Z","labels":["auto-extracted","research"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/web-threats-malicious-javascript-downloader/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5fb1c633-eded-462f-8aee-29ce6e10db1d","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 0837de91aa6bd52ef79d744daba4238a5a48a79eb91cb1a727da3e97d5b36329","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 8.49[.]79 104.244.72[.]64 Artifacts Shell Script Downloader 0837de91aa6bd52ef79d744daba4238a5a48a79eb91cb1a727da3e97d5b36329 c32f8df3cb019e83e0ac49ab0462c59ec70733c3d516ade011727408751","pattern":"[file:hashes.'SHA-256' = '0837de91aa6bd52ef79d744daba4238a5a48a79eb91cb1a727da3e97d5b36329']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--60c0387f-61e7-4c86-994c-a2edd0f42c43","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1218da43a62da76927484bca73a3eee53425c54625147f8d01149bcef2f09d1e","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 0acc478bf09658a679a4689f34598fe6e92086efe82900242f3cc5b7aec 1218da43a62da76927484bca73a3eee53425c54625147f8d01149bcef2f09d1e 2944db28e4505fc439599dae15b10bf57b7cf6c2597f618f41b99bfc654","pattern":"[file:hashes.'SHA-256' = '1218da43a62da76927484bca73a3eee53425c54625147f8d01149bcef2f09d1e']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--34c7a1c9-9bc5-4c1e-9215-6ecc54f7f769","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1cf3879d9e93d1ff30ce5ec0f64ff15b1db7d8237160c83efed688d800e5ef12","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 589A53BDEC49C624F3CB2FC8319218DF721F486E2F15F3C07ABED97AAE6 1cf3879d9e93d1ff30ce5ec0f64ff15b1db7d8237160c83efed688d800e5ef12 c5be50880e2b5a8a8d43a5f1fd6f5d36fc665ab9b4031a9b6a4d5222200","pattern":"[file:hashes.'SHA-256' = '1cf3879d9e93d1ff30ce5ec0f64ff15b1db7d8237160c83efed688d800e5ef12']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--be54f7f2-8891-41f2-ba0b-2dcdaed160df","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 1dc4777dac6dc4e8c650241e211311c4a418a35ebded72fcdd6bcb965ccf918b","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 41985c466c131e48b9ba0d1bb80bdb7556c941ee84aa461fe2efbf1e853 1dc4777dac6dc4e8c650241e211311c4a418a35ebded72fcdd6bcb965ccf918b 3e69e8ed741ab39b0914f7e95bf13b2f0ae9f3c1227dcffdea3369e03e8","pattern":"[file:hashes.'SHA-256' = '1dc4777dac6dc4e8c650241e211311c4a418a35ebded72fcdd6bcb965ccf918b']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e759267f-8ee7-4def-8cac-bce59a3d8454","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 210f3f1ffd2ec66a5076a7fea5d83caa8bbcdb0f3bc3bd030c77eded6f4b5d90","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 90f6e4d92b511fcde9a712b1a8405c5333e0ad78a4c676a64b22412e149 210f3f1ffd2ec66a5076a7fea5d83caa8bbcdb0f3bc3bd030c77eded6f4b5d90 73cc00acc478bf09658a679a4689f34598fe6e92086efe82900242f3cc5","pattern":"[file:hashes.'SHA-256' = '210f3f1ffd2ec66a5076a7fea5d83caa8bbcdb0f3bc3bd030c77eded6f4b5d90']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a0ab3a68-0f88-47b5-a195-eefe5f242381","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 2944db28e4505fc439599dae15b10bf57b7cf6c2597f618f41b99bfc65443c61","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: a43a62da76927484bca73a3eee53425c54625147f8d01149bcef2f09d1e 2944db28e4505fc439599dae15b10bf57b7cf6c2597f618f41b99bfc65443c61 4bffc171c0748cc9e3398b1ce8135b125f54f46752768c981c45d3390e8","pattern":"[file:hashes.'SHA-256' = '2944db28e4505fc439599dae15b10bf57b7cf6c2597f618f41b99bfc65443c61']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c8e73731-7a01-403a-8d2b-16bf97df3dc0","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 31926da5ca004a11c1f46947edb220afe3a53f81cf245b3afae7ea1abaec7c38","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: f1be47233b358889d0594c14409309818d86347d September Campaign 31926da5ca004a11c1f46947edb220afe3a53f81cf245b3afae7ea1abaec7c38 eed4690f6e4d92b511fcde9a712b1a8405c5333e0ad78a4c676a64b2241","pattern":"[file:hashes.'SHA-256' = '31926da5ca004a11c1f46947edb220afe3a53f81cf245b3afae7ea1abaec7c38']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--7f948674-691d-4ca0-bd0c-e5e5a8293768","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 3e69e8ed741ab39b0914f7e95bf13b2f0ae9f3c1227dcffdea3369e03e8bb792","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 77dac6dc4e8c650241e211311c4a418a35ebded72fcdd6bcb965ccf918b 3e69e8ed741ab39b0914f7e95bf13b2f0ae9f3c1227dcffdea3369e03e8bb792 b2e4ee94783062658ddf2c41e9acafb401d0f93e3848c027383a5ca1928","pattern":"[file:hashes.'SHA-256' = '3e69e8ed741ab39b0914f7e95bf13b2f0ae9f3c1227dcffdea3369e03e8bb792']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--bcc2fdf8-2024-4f31-bfe5-293141e31c8a","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 3f3fb70e16d65f5f4b21777b87c9aae6072022c3dfbefd177f37c8aef4a6aeee","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: a88de9b566ce980a8188674319039d2fbe13b049859f8fe4821c92f9200 3f3fb70e16d65f5f4b21777b87c9aae6072022c3dfbefd177f37c8aef4a6aeee 67379740ed15e8da8604cc1f0ea715c8641674de66e553c461b3ae782a5","pattern":"[file:hashes.'SHA-256' = '3f3fb70e16d65f5f4b21777b87c9aae6072022c3dfbefd177f37c8aef4a6aeee']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--4dc3f5c4-7d21-409b-986b-31a8de92e6ff","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 4bffc171c0748cc9e3398b1ce8135b125f54f46752768c981c45d3390e8359a1","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: b28e4505fc439599dae15b10bf57b7cf6c2597f618f41b99bfc65443c61 4bffc171c0748cc9e3398b1ce8135b125f54f46752768c981c45d3390e8359a1 b3a17934f6f72941b9a60097ab09228d873a2f8737ee0ea93b08e5f1cc3","pattern":"[file:hashes.'SHA-256' = '4bffc171c0748cc9e3398b1ce8135b125f54f46752768c981c45d3390e8359a1']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--5ec6faf6-6b4b-46c3-aca2-50a5a7b24538","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6229041985c466c131e48b9ba0d1bb80bdb7556c941ee84aa461fe2efbf1e853","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 9320f07d7eade9af523297b4bcfd0e0af187272e368e889c988a55ed78e 6229041985c466c131e48b9ba0d1bb80bdb7556c941ee84aa461fe2efbf1e853 1dc4777dac6dc4e8c650241e211311c4a418a35ebded72fcdd6bcb965cc","pattern":"[file:hashes.'SHA-256' = '6229041985c466c131e48b9ba0d1bb80bdb7556c941ee84aa461fe2efbf1e853']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ffee33d9-bbf6-4d20-bdf7-0bddb952b51d","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 63acd589a53bdec49c624f3cb2fc8319218df721f486e2f15f3c07abed97aae6","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: b3b7cb2d57ca1e89999b0b1da80fb9658dff6e44 December Campaign: 63ACD589A53BDEC49C624F3CB2FC8319218DF721F486E2F15F3C07ABED97AAE6 1cf3879d9e93d1ff30ce5ec0f64ff15b1db7d8237160c83efed688d800e","pattern":"[file:hashes.'SHA-256' = '63acd589a53bdec49c624f3cb2fc8319218df721f486e2f15f3c07abed97aae6']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--e64d0ba0-2e1e-487e-b96d-f5b700eb360d","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 64545e94daafba191669333e1dd0c6e1190df47e0742bd515911cce0cdbd4fd1","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 9a8c4f9bb28582c485549b328d6123e8aea33009ce7657f7fc0ef829e03 64545e94daafba191669333e1dd0c6e1190df47e0742bd515911cce0cdbd4fd1 69bb44736817dabe88e3014c6207ba702f644fb43f6feaec23091af0b52","pattern":"[file:hashes.'SHA-256' = '64545e94daafba191669333e1dd0c6e1190df47e0742bd515911cce0cdbd4fd1']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ebddf65c-e6ad-4f54-9ff6-2a8faf69edf9","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 67379740ed15e8da8604cc1f0ea715c8641674de66e553c461b3ae782a5d0cbe","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 70e16d65f5f4b21777b87c9aae6072022c3dfbefd177f37c8aef4a6aeee 67379740ed15e8da8604cc1f0ea715c8641674de66e553c461b3ae782a5d0cbe ab3d61a76197003822252124e89987d061d6a4a33b9891cea778d3708cd","pattern":"[file:hashes.'SHA-256' = '67379740ed15e8da8604cc1f0ea715c8641674de66e553c461b3ae782a5d0cbe']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--238f8720-73f5-4987-b449-d5dd28a91a19","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 69bb44736817dabe88e3014c6207ba702f644fb43f6feaec23091af0b5224bc6","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: e94daafba191669333e1dd0c6e1190df47e0742bd515911cce0cdbd4fd1 69bb44736817dabe88e3014c6207ba702f644fb43f6feaec23091af0b5224bc6 eaa387fcc12f2d8a7d42f12d27e7dccb4f3e11492a7d3a3a1ce830a11b5","pattern":"[file:hashes.'SHA-256' = '69bb44736817dabe88e3014c6207ba702f644fb43f6feaec23091af0b5224bc6']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--ba0dc021-bf3b-431a-b61c-2ce7cd49de0f","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 6f654198e8efd5aff1c7a903353967d0e96aeff0402cb0a79fabbc10d18c63d2","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 1a76197003822252124e89987d061d6a4a33b9891cea778d3708cd50447 6f654198e8efd5aff1c7a903353967d0e96aeff0402cb0a79fabbc10d18c63d2 c288c200cf7bbebe7a81fd42ca1bd4c6cb6080f28f2cec297a0d3e6aff7","pattern":"[file:hashes.'SHA-256' = '6f654198e8efd5aff1c7a903353967d0e96aeff0402cb0a79fabbc10d18c63d2']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--2de1c39e-71b2-4ee4-b708-c08793d20f4c","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 73cc00acc478bf09658a679a4689f34598fe6e92086efe82900242f3cc5b7aec","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: f1ffd2ec66a5076a7fea5d83caa8bbcdb0f3bc3bd030c77eded6f4b5d90 73cc00acc478bf09658a679a4689f34598fe6e92086efe82900242f3cc5b7aec 1218da43a62da76927484bca73a3eee53425c54625147f8d01149bcef2f","pattern":"[file:hashes.'SHA-256' = '73cc00acc478bf09658a679a4689f34598fe6e92086efe82900242f3cc5b7aec']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--3d35ebda-0403-4df8-bc14-03c15f069aea","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7bc99c87a1e0582b5f15f40141226862fbe726b496e1e77c7f95993e8e945733","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 420a978434e2b6a9e9b85b688a44593fa V3G4 Sample July Campaign 7bc99c87a1e0582b5f15f40141226862fbe726b496e1e77c7f95993e8e945733 88f7b9a8c4f9bb28582c485549b328d6123e8aea33009ce7657f7fc0ef8","pattern":"[file:hashes.'SHA-256' = '7bc99c87a1e0582b5f15f40141226862fbe726b496e1e77c7f95993e8e945733']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--58d3a036-7263-4835-9a45-7022e1bc7646","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7d9cdf3afb1d52f49d82b1ffe28a3da08c6aeeaa8c5047ba37c73802d2cd9ec2","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 6cabbb90dfe9cd75f12c01fb64766dd1ec0f4247dbf8f4477dd64407fbf 7d9cdf3afb1d52f49d82b1ffe28a3da08c6aeeaa8c5047ba37c73802d2cd9ec2 9a0d39265b53e1959df49dbc8727ad344abc12a8bc0bd8d8b76f8b15052","pattern":"[file:hashes.'SHA-256' = '7d9cdf3afb1d52f49d82b1ffe28a3da08c6aeeaa8c5047ba37c73802d2cd9ec2']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--d83500b5-5764-402f-8052-075c62c1a8d2","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 7dea8dac3f455f3a57fecfa5a047439126556858c239e73cd8feec2dc13bae2c","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: 0391279b014e53d73c2216a84bd528e18f1f633ba0101288aa963f77c5b 7dea8dac3f455f3a57fecfa5a047439126556858c239e73cd8feec2dc13bae2c a10ce475f64f3821ab32c88f6b013effd40843dd575ceaab46a57f134c2","pattern":"[file:hashes.'SHA-256' = '7dea8dac3f455f3a57fecfa5a047439126556858c239e73cd8feec2dc13bae2c']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--12f5963b-b5af-4479-8040-d928ba679292","created":"2026-08-17T13:05:29.000Z","modified":"2026-09-16T18:44:51.103Z","created_by_ref":"identity--8bfc562e-5b64-431c-9443-0dcc771ec6e8","name":"sha256: 88f7b9a8c4f9bb28582c485549b328d6123e8aea33009ce7657f7fc0ef829e03","description":"Seen in \"Mirai Variant V3G4 Targets IoT Devices\" (Palo Alto Unit 42). Context: c87a1e0582b5f15f40141226862fbe726b496e1e77c7f95993e8e945733 88f7b9a8c4f9bb28582c485549b328d6123e8aea33009ce7657f7fc0ef829e03 64545e94daafba191669333e1dd0c6e1190df47e0742bd515911cce0cdb","pattern":"[file:hashes.'SHA-256' = '88f7b9a8c4f9bb28582c485549b328d6123e8aea33009ce7657f7fc0ef829e03']","pattern_type":"stix","valid_from":"2026-08-17T13:05:29.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"Palo Alto Unit 42","url":"https://unit42.paloaltonetworks.com/mirai-variant-v3g4/"}]}]}