ZeroHour

Indicators of compromise

227 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha256d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcbb13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb Recovered x86 artifact and Amatera PE SHA-256 6759c72365d0cHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
sha256d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e5Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
sha256e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6cf39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11cHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
sha256ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331, InstallFix /cl and recovered InstallFix artifacts SHA-256 ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
sha256ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb1301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb Fake Ledger, Trezor and Exodus application artifacts SHA-25Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
sha256ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7ec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32bHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
sha256eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009Selectors for getData() , balanceOf() and setData() SHA-256 eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 September macOS artifact SHA-256 d4150c1c97f047c6edb14767bfHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
sha256f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f763b124f38f27da4ef52d570aac2 AccountsHelper artifact SHA-256 f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
sha256f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75eb41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f1Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 16h ago
domainopusaccel.topand loop that polls a command-and-control (C2) server ("ocr.opusaccel[.]top") to receive further instructions that are then executedChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
The Hacker News
· 17h ago
domaincode-desktop.compromoting a fake macOS disk-cleaning service, 11 using the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . ThHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 17h ago
domaincodex-craft.cominting to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 15 promoting a fake macOS disk-cleaning service, 11 usiHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 17h ago
domainhbomax-macos.comng the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . The mix shows that the operators were targeting both enHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 17h ago
domainhbomaxx.appal lure categories, including 40 advertisements pointing to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 1HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 17h ago
domainhbomaxx.uscted to counterfeit HBO Max-themed landing pages, including hbomaxx[.]us . Rather than serving a conventional installer, the siteHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 17h ago
ipv4164.90.161.147lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September maHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 17h ago
ipv4165.22.199.85rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration SeptembHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 17h ago
ipv445.94.47.204omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemenHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 17h ago
ipv477.91.65.13nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP authoHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 17h ago
domainayuthayatech.comfied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. AHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 17h ago
domainco.thfocused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performeHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 17h ago
domainhunt.io10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a compHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 17h ago
domaintriplet.coernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested tHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 17h ago
domainabchina.com.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural CreditTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 23h ago
domainccb.comk of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit Cooperatives: a cooperative or credit unioTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 23h ago
domaincom.cnNote: ICBC: Industrial and Commercial Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/AgricultuTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 23h ago
domainlzbank.comBank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abcTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 23h ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.