ZeroHour

Indicators of compromise

1,985 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domaindomainlify.netalso registered another domain on the same day. The domain domainlify[.]net was used in the Reply-To email. Figure 7. Account informaProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 7d ago
domaineemusicclass.co.ukuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email addressProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 7d ago
domainlifeones.cominfo@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out emailProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 7d ago
domainlohnsteuerhilfe-aktuell-verein.deumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk infProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 7d ago
domainlumalisboa.comications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 7d ago
domainmctci.comk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]Protecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 7d ago
domainnuf.co.jpth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatiProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 7d ago
domainservice-nowinc.comregistered several domains. A ‘ServiceNow’ lookalike domain service-nowinc[.]com was registered on July 31, shortly before the campaign acProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 7d ago
domaintivityhealth.comated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]Protecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 7d ago
domaintovimbatista.ptnuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com EmailProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 7d ago
domainuinsure.co.ukss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norepProtecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft Security Blog
· 7d ago
domain9342371634011778.comfollowing command line: "C:\Users\[redacted]\AppData\Local\9342371634011778.com" -s -L --tlsv1.2 --ssl-no-revoke -o "C:\Users\[redacted]\ApSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainhostfxr.dllfrom hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name f3b980dea . The config.pySloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainlinked4x.comnger.exe to download and execute a batch script from finger.linked4x[.]com as shown in the command line below: "C:\windows\system32\SloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainskipraid.comCastleLoader and CastleRAT components were downloaded from skipraid[.]com using the User-Agent string K8VGmQTrzX . Alongside CastleSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainstro7121.blob.core.windows.netmory. This script downloaded a SloppyRAT DLL from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export nameSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainsystem.netieve the number of milliseconds since boot. GetTickCount64 [System.Net.Dns]::GetHostName() / domain — Retrieves the host name or dSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domainwindows.netand execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script’sSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
sha256af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588application/json User-Agent: CommandExecutor/1.0 X-API-KEY: af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588 Content-Length: 49 Host: api.truesmart.org {"machine_id":"aSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
urlhttps://stro7121.blob.core.windows[xe interpreter to download and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py scriptSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 7d ago
domain7.tcp.eu67.15[.]169 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File namHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domaindiscord.com41cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-YHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domainflow.lavasoft.comle-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwaHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domainmobile-service.segment.com.com 0.0.0.0 cdn.segment.com 0.0.0.0 api.segment.io 0.0.0.0 mobile-service.segment.com Entries added to the Windows hosts file by DCRAT Domain / IHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domainngrok.io69 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File names / MD5Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domaintelemetry.servers.getgo.com0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0.Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domainxsph.ruhe Windows hosts file by DCRAT Domain / IP address a0700877.xsph[.]ru 141.8.197[.]42 DCRAT command-and-control infrastructure FHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md50e39e8d7b641bcda4376ebbfeff7b12ecluded in the malicious ISO File name / MD5 %TEMP%\find.vbs 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays the fake “license not found” message EHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md515eca4a3f7350423cf4db0b4c30d19686ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md51ec9eff863dc4418d1498bc3d904899dhaos ransomware File name / MD5 %TEMP%\YandexPackLoader.exe 1ec9eff863dc4418d1498bc3d904899d Browser installer included in the malicious ISO File name /Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md52a0834560ed3770fc33d7a42f8229722%\rockstargamescrashfixer.exe , %TEMP%\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md52a385fe7bed9899d77d05cb8e302d557a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associated launchers IP addresses 35.157.1Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md557b9c56ef97a7ada98257b23577bf5e3TEMP%\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md560a0f58001ea7be538cd42b651924cc7560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564eeHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md56b49f24d5d5b49127476bc385565f8b0ecutable File name / MD5 %TEMP%\checkinternetconnection.bat 6b49f24d5d5b49127476bc385565f8b0 Batch file used to confirm internet connectivity File namesHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md58da3fe3664d81226b0fb2a50a0537d4fat , C:\Users\Default\Local Settings\[RANDOM FILE NAME].exe 8da3fe3664d81226b0fb2a50a0537d4f DCRAT installer components and binary Hosts-file entries 0.Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md5a15e280a3fd65dfaa243bbe2dbf45e97ype Indicator Description File name / MD5 Gta6installer.exe a15e280a3fd65dfaa243bbe2dbf45e97 Initial fake installation executable File name / MD5 %TEMP%Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md5b9648ec8cc806e7661aabcfc91dc836c%TEMP%\gta6.exe , %USERPROFILE%\AppData\Roaming\svchost.exe b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries File name read_it.txt Note droppeHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md5dfdf5e5b78d2ec764c0e5641cf9a0d26-control infrastructure File name / MD5 %TEMP%\adminapp.exe dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
md5ea991bc9334b36a6b958f564ee7167768001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associateHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 7d ago
domainbloom.iof compromise (IoCs):- Type Indicator Description Domain cdn.bloom[.]io External resource host loaded through the Microsoft TeamsHackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
Cyber Security News
· 7d ago
domainlogin.microsoftonline.comst loaded through the Microsoft Teams redirect chain Domain login.microsoftonline.com Legitimate Microsoft OAuth endpoint used in the initial redHackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
Cyber Security News
· 7d ago
sha2566f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461079 91.214.78[.]118 UAT-11823 Netcat-based reverse shell C2 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware sample 43.204.2[.]142 UAT-1Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cyber Security News
· 7d ago
sha256b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77de for all three observed campaigns. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6dHackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cyber Security News
· 7d ago
sha256db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e54fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar — JAR-based command executor 89.34.96[.]5Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cyber Security News
· 7d ago
domainadd-passkey.comy security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO DomainHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainintegratedsso.comey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session DoHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainkeysyncos.comO Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchronizHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainmyconnectkey.comistration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection DHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainoktasession.comom Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key syncHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainoskeyconnect.comhronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account valHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainoskeyregister.comey synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronizatiHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainoskeysetup.comonization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration DomHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainoskeysync.comr session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup DomHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainpasskeyhelpdesk.comm becoming a data breach. Type Indicator Description Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com PasskeyHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainportalsetuphub.comvalidationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com Portal setup Note: IP addresses and domains are intentionHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainsecure-passkey.comon Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setuHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainsetupmypasskey.comrt lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollmentHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainsyncmykey.comey setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connectHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainvalidationsetupac.comconnection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]comHackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Cyber Security News
· 7d ago
domainip-109-091-184-021.um37.pools.vodafone-ip.deutsche Telekom AG (AS3320), while 109.91.184.21 resolved to ip-109-091-184-021.um37.pools.vodafone-ip.de and belonged to a Vodafone GmbH static B2B customer pool (ARedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
domainmail3.kekew.infoerse-DNS information showed that 80.152.203.134 resolved to mail3.kekew.info and was allocated to Deutsche Telekom AG (AS3320), while 10Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
ipv41.0.0.1ct() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additionaRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
ipv4109.91.184.21resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known public resolver serviRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
ipv41.1.1.1nal connect() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and severalRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
ipv480.152.203.134ons were public DNS resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known pubRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
ipv48.8.4.4port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/8Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
ipv48.8.8.8erified while attempts to reach an external address such as 8.8.8.8 returned Network is unreachable. This design allowed the maRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
ipv49.9.9.10tions included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is commonly assoRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
ipv49.9.9.9. Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is comRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
sha25663be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35ele analyzed in this article has the following SHA-256 hash: 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e Dynamic analysis showed that the payload did considerably mRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 7d ago
md515eca4a3f7350423cf4db0b4c30d19686ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md52a0834560ed3770fc33d7a42f8229722ckstargamescrashfixer.exe %TEMP%\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md52a385fe7bed9899d77d05cb8e302d557a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers Note: IP addressesFake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md557b9c56ef97a7ada98257b23577bf5e3rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md560a0f58001ea7be538cd42b651924cc7560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564eeFake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md56b49f24d5d5b49127476bc385565f8b0llation executable %TEMP%\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEMFake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md5a15e280a3fd65dfaa243bbe2dbf45e97-clean media. IOCs Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\checkinternetconnectFake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md5ea991bc9334b36a6b958f564ee7167768001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associFake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
domainbloom.ior ultimately leads Teams to load external content from cdn. bloom[.]io. Rather than displaying that content as a normal externalNew Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
GBHackers
· 7d ago
domainexample.com>/<path> (Figure 1). Figure 1. SPIFFE ID. The middle part ( example[.]com ) in Figure 1 is the trust domain, the issuer of identityThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Palo Alto Unit 42
· 7d ago
sha25640228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8pod - image : ghcr .io / spiffe / spire - agent @ sha256 : 40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8 \ " type : \ " k8s \ " value : \ " pod - label : app : clieThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Palo Alto Unit 42
· 7d ago
sha2567e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38176_ab5c_4f2a_b5f3_3c7e4c91a9ca .slice / cri - containerd - 7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope We copied this path to a mock cgroup path and wrote oThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Palo Alto Unit 42
· 7d ago
domainasia.newsinweb.comdrivinguber.com Primary command-and-control host C2 domain asia.newsinweb.com Regional fallback command-and-control host C2 domain usa.neHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
domaindrivinguber.comist Possible renamed LaunchAgent persistence file C2 domain drivinguber.com Primary command-and-control host C2 domain asia.newsinweb.cHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
domainnewsinweb.comm Regional fallback command-and-control host C2 root domain newsinweb.com Root domain used for fallback infrastructure Download URI /Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
domainusa.newsinweb.comeb.com Regional fallback command-and-control host C2 domain usa.newsinweb.com Regional fallback command-and-control host C2 root domain nHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
md59678f71ea4cccbc3d511dc8d7f24b11325f44db68a MacSync sample hash reported by SEQRITE MD5 hash 9678f71ea4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
md5de62a2f47d1c7dec2997f931a050a615h used for stolen-data uploads HTTP request header api-key: de62a2f47d1c7dec2997f931a050a615 API key observed in MacSync network requests HTTP User-AgenHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
sha159508d071661ea70fa5fcbe6f9e2fb72506e57dfa4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df MacSync sample SHA-1 hash Code-signing identifier com.utilsHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
sha1d182eb7cba0ffa42d770d7b0d3499e49f24163a2ils.Launcher Ad-hoc-signed MacSync stager identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code directory hash associated with the sample Staged archiHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
domainclck.rut file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp, where it confirms that it has an internet connectFake GTA 6 download delivers malware-packed bundle to impatient gamers
Help Net Security
· 7d ago
domainadd-passkey.comhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operatorHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domaincontoso.add-passkey.come operators commonly use organization-specific URLs such as contoso[.]add-passkey[.]com, which makes the fraudulent destination appear more creHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainintegratedsso.comure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organiHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainkeysyncos.comins SSO oktasession[.]com Domains Identity-provider session keysyncos[.]com Domains Key synchronization Note: IP addresses and domainHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainoktasession.comypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organization-specific URLs suHackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainpasskeyhelpdesk.comsubdomain. Examples of observed lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainsecure-passkey.comobserved lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago
domainsetupmypasskey.comucture include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
GBHackers
· 7d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.