Indicators of compromise
227 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb | b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb Recovered x86 artifact and Amatera PE SHA-256 6759c72365d0c | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540 | 506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e5 | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c | f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331 | , InstallFix /cl and recovered InstallFix artifacts SHA-256 ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1a | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb | 1301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb Fake Ledger, Trezor and Exodus application artifacts SHA-25 | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7 | ec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 | Selectors for getData() , balanceOf() and setData() SHA-256 eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 September macOS artifact SHA-256 d4150c1c97f047c6edb14767bf | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7 | 63b124f38f27da4ef52d570aac2 AccountsHelper artifact SHA-256 f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287 | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e | b41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f1 | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | opusaccel.top | and loop that polls a command-and-control (C2) server ("ocr.opusaccel[.]top") to receive further instructions that are then executed | China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE The Hacker News | · 17h ago |
| domain | code-desktop.com | promoting a fake macOS disk-cleaning service, 11 using the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . Th | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| domain | codex-craft.com | inting to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 15 promoting a fake macOS disk-cleaning service, 11 usi | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| domain | hbomax-macos.com | ng the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . The mix shows that the operators were targeting both en | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| domain | hbomaxx.app | al lure categories, including 40 advertisements pointing to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 1 | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| domain | hbomaxx.us | cted to counterfeit HBO Max-themed landing pages, including hbomaxx[.]us . Rather than serving a conventional installer, the site | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| ipv4 | 164.90.161.147 | lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September ma | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| ipv4 | 165.22.199.85 | rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration Septemb | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| ipv4 | 45.94.47.204 | omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemen | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| ipv4 | 77.91.65.13 | nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP autho | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| domain | ayuthayatech.com | fied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. A | Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor GBHackers | · 17h ago |
| domain | co.th | focused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performe | Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor GBHackers | · 17h ago |
| domain | hunt.io | 10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a comp | Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor GBHackers | · 17h ago |
| domain | triplet.co | ernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested t | Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor GBHackers | · 17h ago |
| domain | abchina.com | .]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit | Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group Recorded Future | · 23h ago |
| domain | ccb.com | k of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit Cooperatives: a cooperative or credit unio | Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group Recorded Future | · 23h ago |
| domain | com.cn | Note: ICBC: Industrial and Commercial Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultu | Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group Recorded Future | · 23h ago |
| domain | lzbank.com | Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abc | Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group Recorded Future | · 23h ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.