Indicators of compromise
1,985 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | domainlify.net | also registered another domain on the same day. The domain domainlify[.]net was used in the Reply-To email. Figure 7. Account informa | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 7d ago |
| domain | eemusicclass.co.uk | uerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 7d ago |
| domain | lifeones.com | info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out email | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 7d ago |
| domain | lohnsteuerhilfe-aktuell-verein.de | umalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk inf | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 7d ago |
| domain | lumalisboa.com | ications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhil | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 7d ago |
| domain | mctci.com | k info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.] | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 7d ago |
| domain | nuf.co.jp | th[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbati | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 7d ago |
| domain | service-nowinc.com | registered several domains. A ‘ServiceNow’ lookalike domain service-nowinc[.]com was registered on July 31, shortly before the campaign ac | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 7d ago |
| domain | tivityhealth.com | ated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.] | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 7d ago |
| domain | tovimbatista.pt | nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 7d ago |
| domain | uinsure.co.uk | ss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norep | Protecting organizations from AI-assisted executive impersonation and invoice fraud Microsoft Security Blog | · 7d ago |
| domain | 9342371634011778.com | following command line: "C:\Users\[redacted]\AppData\Local\9342371634011778.com" -s -L --tlsv1.2 --ssl-no-revoke -o "C:\Users\[redacted]\Ap | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | hostfxr.dll | from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name f3b980dea . The config.py | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | linked4x.com | nger.exe to download and execute a batch script from finger.linked4x[.]com as shown in the command line below: "C:\windows\system32\ | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | skipraid.com | CastleLoader and CastleRAT components were downloaded from skipraid[.]com using the User-Agent string K8VGmQTrzX . Alongside Castle | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | stro7121.blob.core.windows.net | mory. This script downloaded a SloppyRAT DLL from hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll and invoked the DLL export name | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | system.net | ieve the number of milliseconds since boot. GetTickCount64 [System.Net.Dns]::GetHostName() / domain — Retrieves the host name or d | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | windows.net | and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script’s | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| sha256 | af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588 | application/json User-Agent: CommandExecutor/1.0 X-API-KEY: af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588 Content-Length: 49 Host: api.truesmart.org {"machine_id":"a | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| url | https://stro7121.blob.core.windows[ | xe interpreter to download and execute a Python script from hxxps://stro7121.blob.core.windows[.]net/dpp1/config.py . SloppyRAT stager The config.py script | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 7d ago |
| domain | 7.tcp.eu | 67.15[.]169 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File nam | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | discord.com | 41cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | flow.lavasoft.com | le-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwa | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | mobile-service.segment.com | .com 0.0.0.0 cdn.segment.com 0.0.0.0 api.segment.io 0.0.0.0 mobile-service.segment.com Entries added to the Windows hosts file by DCRAT Domain / I | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | ngrok.io | 69 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File names / MD5 | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | telemetry.servers.getgo.com | 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0. | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | xsph.ru | he Windows hosts file by DCRAT Domain / IP address a0700877.xsph[.]ru 141.8.197[.]42 DCRAT command-and-control infrastructure F | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | 0e39e8d7b641bcda4376ebbfeff7b12e | cluded in the malicious ISO File name / MD5 %TEMP%\find.vbs 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays the fake “license not found” message E | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | 15eca4a3f7350423cf4db0b4c30d1968 | 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3 | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | 1ec9eff863dc4418d1498bc3d904899d | haos ransomware File name / MD5 %TEMP%\YandexPackLoader.exe 1ec9eff863dc4418d1498bc3d904899d Browser installer included in the malicious ISO File name / | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | 2a0834560ed3770fc33d7a42f8229722 | %\rockstargamescrashfixer.exe , %TEMP%\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651 | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | 2a385fe7bed9899d77d05cb8e302d557 | a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associated launchers IP addresses 35.157.1 | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | 57b9c56ef97a7ada98257b23577bf5e3 | TEMP%\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3 | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | 60a0f58001ea7be538cd42b651924cc7 | 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | 6b49f24d5d5b49127476bc385565f8b0 | ecutable File name / MD5 %TEMP%\checkinternetconnection.bat 6b49f24d5d5b49127476bc385565f8b0 Batch file used to confirm internet connectivity File names | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | 8da3fe3664d81226b0fb2a50a0537d4f | at , C:\Users\Default\Local Settings\[RANDOM FILE NAME].exe 8da3fe3664d81226b0fb2a50a0537d4f DCRAT installer components and binary Hosts-file entries 0. | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | a15e280a3fd65dfaa243bbe2dbf45e97 | ype Indicator Description File name / MD5 Gta6installer.exe a15e280a3fd65dfaa243bbe2dbf45e97 Initial fake installation executable File name / MD5 %TEMP% | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | b9648ec8cc806e7661aabcfc91dc836c | %TEMP%\gta6.exe , %USERPROFILE%\AppData\Roaming\svchost.exe b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries File name read_it.txt Note droppe | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | dfdf5e5b78d2ec764c0e5641cf9a0d26 | -control infrastructure File name / MD5 %TEMP%\adminapp.exe dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.] | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| md5 | ea991bc9334b36a6b958f564ee716776 | 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associate | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 7d ago |
| domain | bloom.io | f compromise (IoCs):- Type Indicator Description Domain cdn.bloom[.]io External resource host loaded through the Microsoft Teams | Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers Cyber Security News | · 7d ago |
| domain | login.microsoftonline.com | st loaded through the Microsoft Teams redirect chain Domain login.microsoftonline.com Legitimate Microsoft OAuth endpoint used in the initial red | Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers Cyber Security News | · 7d ago |
| sha256 | 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 | 079 91.214.78[.]118 UAT-11823 Netcat-based reverse shell C2 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware sample 43.204.2[.]142 UAT-1 | Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware Cyber Security News | · 7d ago |
| sha256 | b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d | e for all three observed campaigns. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6d | Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware Cyber Security News | · 7d ago |
| sha256 | db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e | 54fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar — JAR-based command executor 89.34.96[.]5 | Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware Cyber Security News | · 7d ago |
| domain | add-passkey.com | y security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | integratedsso.com | ey setup Domain add-passkey[.]com Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Do | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | keysyncos.com | O Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchroniz | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | myconnectkey.com | istration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection D | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | oktasession.com | om Passkey enrollment Domain integratedsso[.]com SSO Domain oktasession[.]com Identity-provider session Domain keysyncos[.]com Key sync | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | oskeyconnect.com | hronization Domain myconnectkey[.]com Key connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account val | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | oskeyregister.com | ey synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronizati | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | oskeysetup.com | onization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Domain oskeyregister[.]com Key registration Dom | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | oskeysync.com | r session Domain keysyncos[.]com Key synchronization Domain oskeysync[.]com Key synchronization Domain oskeysetup[.]com Key setup Dom | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | passkeyhelpdesk.com | m becoming a data breach. Type Indicator Description Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | portalsetuphub.com | validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com Portal setup Note: IP addresses and domains are intention | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | secure-passkey.com | on Domain passkeyhelpdesk[.]com Passkey support lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setu | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | setupmypasskey.com | rt lure Domain secure-passkey[.]com Passkey security Domain setupmypasskey[.]com Passkey setup Domain add-passkey[.]com Passkey enrollment | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | syncmykey.com | ey setup Domain oskeyregister[.]com Key registration Domain syncmykey[.]com Key synchronization Domain myconnectkey[.]com Key connect | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | validationsetupac.com | connection Domain oskeyconnect[.]com Key connection Domain validationsetupac[.]com Account validation and setup Domain portalsetuphub[.]com | Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data Cyber Security News | · 7d ago |
| domain | ip-109-091-184-021.um37.pools.vodafone-ip.de | utsche Telekom AG (AS3320), while 109.91.184.21 resolved to ip-109-091-184-021.um37.pools.vodafone-ip.de and belonged to a Vodafone GmbH static B2B customer pool (A | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| domain | mail3.kekew.info | erse-DNS information showed that 80.152.203.134 resolved to mail3.kekew.info and was allocated to Deutsche Telekom AG (AS3320), while 10 | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| ipv4 | 1.0.0.1 | ct() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additiona | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| ipv4 | 109.91.184.21 | resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known public resolver servi | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| ipv4 | 1.1.1.1 | nal connect() calls on TCP port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| ipv4 | 80.152.203.134 | ons were public DNS resolver infrastructure. Two addresses, 80.152.203.134 and 109.91.184.21 , did not clearly correspond to known pub | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| ipv4 | 8.8.4.4 | port 853 . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/8 | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| ipv4 | 8.8.8.8 | erified while attempts to reach an external address such as 8.8.8.8 returned Network is unreachable. This design allowed the ma | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| ipv4 | 9.9.9.10 | tions included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is commonly asso | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| ipv4 | 9.9.9.9 | . Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is com | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| sha256 | 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e | le analyzed in this article has the following SHA-256 hash: 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e Dynamic analysis showed that the payload did considerably m | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 7d ago |
| md5 | 15eca4a3f7350423cf4db0b4c30d1968 | 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3 | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 7d ago |
| md5 | 2a0834560ed3770fc33d7a42f8229722 | ckstargamescrashfixer.exe %TEMP%\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651 | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 7d ago |
| md5 | 2a385fe7bed9899d77d05cb8e302d557 | a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers Note: IP addresses | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 7d ago |
| md5 | 57b9c56ef97a7ada98257b23577bf5e3 | rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3 | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 7d ago |
| md5 | 60a0f58001ea7be538cd42b651924cc7 | 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 7d ago |
| md5 | 6b49f24d5d5b49127476bc385565f8b0 | llation executable %TEMP%\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEM | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 7d ago |
| md5 | a15e280a3fd65dfaa243bbe2dbf45e97 | -clean media. IOCs Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\checkinternetconnect | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 7d ago |
| md5 | ea991bc9334b36a6b958f564ee716776 | 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associ | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 7d ago |
| domain | bloom.io | r ultimately leads Teams to load external content from cdn. bloom[.]io. Rather than displaying that content as a normal external | New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners GBHackers | · 7d ago |
| domain | example.com | >/<path> (Figure 1). Figure 1. SPIFFE ID. The middle part ( example[.]com ) in Figure 1 is the trust domain, the issuer of identity | The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE Palo Alto Unit 42 | · 7d ago |
| sha256 | 40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8 | pod - image : ghcr .io / spiffe / spire - agent @ sha256 : 40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8 \ " type : \ " k8s \ " value : \ " pod - label : app : clie | The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE Palo Alto Unit 42 | · 7d ago |
| sha256 | 7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38 | 176_ab5c_4f2a_b5f3_3c7e4c91a9ca .slice / cri - containerd - 7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope We copied this path to a mock cgroup path and wrote o | The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE Palo Alto Unit 42 | · 7d ago |
| domain | asia.newsinweb.com | drivinguber.com Primary command-and-control host C2 domain asia.newsinweb.com Regional fallback command-and-control host C2 domain usa.ne | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| domain | drivinguber.com | ist Possible renamed LaunchAgent persistence file C2 domain drivinguber.com Primary command-and-control host C2 domain asia.newsinweb.c | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| domain | newsinweb.com | m Regional fallback command-and-control host C2 root domain newsinweb.com Root domain used for fallback infrastructure Download URI / | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| domain | usa.newsinweb.com | eb.com Regional fallback command-and-control host C2 domain usa.newsinweb.com Regional fallback command-and-control host C2 root domain n | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| md5 | 9678f71ea4cccbc3d511dc8d7f24b113 | 25f44db68a MacSync sample hash reported by SEQRITE MD5 hash 9678f71ea4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6 | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| md5 | de62a2f47d1c7dec2997f931a050a615 | h used for stolen-data uploads HTTP request header api-key: de62a2f47d1c7dec2997f931a050a615 API key observed in MacSync network requests HTTP User-Agen | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| sha1 | 59508d071661ea70fa5fcbe6f9e2fb72506e57df | a4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df MacSync sample SHA-1 hash Code-signing identifier com.utils | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| sha1 | d182eb7cba0ffa42d770d7b0d3499e49f24163a2 | ils.Launcher Ad-hoc-signed MacSync stager identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code directory hash associated with the sample Staged archi | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 7d ago |
| domain | clck.ru | t file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp, where it confirms that it has an internet connect | Fake GTA 6 download delivers malware-packed bundle to impatient gamers Help Net Security | · 7d ago |
| domain | add-passkey.com | helpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operator | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | contoso.add-passkey.com | e operators commonly use organization-specific URLs such as contoso[.]add-passkey[.]com, which makes the fraudulent destination appear more cre | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | integratedsso.com | ure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organi | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | keysyncos.com | ins SSO oktasession[.]com Domains Identity-provider session keysyncos[.]com Domains Key synchronization Note: IP addresses and domain | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | oktasession.com | ypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[.]com. The operators commonly use organization-specific URLs su | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | passkeyhelpdesk.com | subdomain. Examples of observed lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[ | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | secure-passkey.com | observed lure infrastructure include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[. | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
| domain | setupmypasskey.com | ucture include passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, add-passkey[.]com, integratedsso[.]com, and oktasession[ | Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts GBHackers | · 7d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.