ZeroHour

Indicators of compromise

1,985 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
md50e39e8d7b641bcda4376ebbfeff7b12e18d1498bc3d904899d Yandex web browser %TEMP%\find.vbs MD5 : 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays a "license not found" messageGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md515eca4a3f7350423cf4db0b4c30d19686ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3Grand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md51ec9eff863dc4418d1498bc3d904899dansomware-encrypted files %TEMP%\YandexPackLoader.exe MD5 : 1ec9eff863dc4418d1498bc3d904899d Yandex web browser %TEMP%\find.vbs MD5 : 0e39e8d7b641bcda43Grand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md52a0834560ed3770fc33d7a42f8229722ckstargamescrashfixer.exe %TEMP%\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651Grand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md52a385fe7bed9899d77d05cb8e302d557a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers 35.157.111[.]131 3Grand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md557b9c56ef97a7ada98257b23577bf5e3rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3Grand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md560a0f58001ea7be538cd42b651924cc7560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564eeGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md56b49f24d5d5b49127476bc385565f8b0llation executable %TEMP%\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEMGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md58da3fe3664d81226b0fb2a50a0537d4f:\Users\Default\Local Settings\[RANDOM FILE NAME].exe MD5 : 8da3fe3664d81226b0fb2a50a0537d4f Copy of DCRAT and associated installation files 0.0.0.0 appGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md5a15e280a3fd65dfaa243bbe2dbf45e97Compromise (IOCs) Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\checkinternetconnectGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md5b9648ec8cc806e7661aabcfc91dc836cMP%\gta6.exe %USERPROFILE%\AppData\Roaming\svchost.exe MD5: b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries read_it.txt Ransomware note leftGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md5dfdf5e5b78d2ec764c0e5641cf9a0d26IP address that DCRAT connects to %TEMP%\adminapp.exe MD5 : dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary https://discord[.]com/Grand Theft Auto VI hype leads to malware
Huntress
· 8d ago
md5ea991bc9334b36a6b958f564ee7167768001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domainleaguejazire.comopens a WebDAV UNC path hosted on a randomized subdomain of leaguejazire[.]com , then launches the pf.ch loader through rundll32.exe usiHackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware
GBHackers
· 8d ago
sha2560710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f328a3eadc0b509386cae200993b33673b343c Gigabud sample SHA-256 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 Vwork sample SHA-256 66499653c0fff78d81db5dc319b9aaa0288dc5Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 8d ago
sha256112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf1009dda5b93ed3d1cead527b02d1317426bc Gigabud sample SHA-256 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud sample SHA-256 9ca27df7938f12794bab0847434482955ca9Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 8d ago
sha2561f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c82955ca9adea714a34afd315c7a7be522611 Gigabud sample SHA-256 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud sample SHA-256 0710ca983741bf6a95db1b6960c1985e45b1Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 8d ago
sha2564fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc7986e52f913f4b5ff960ddea26075ff621ae Gigabud sample SHA-256 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud sample SHA-256 112fefc9348fa4acbb82d54d9688c96dd567Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 8d ago
sha25661274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbca73660c0ee810eb Modified banking application sample SHA-256 61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc Modified banking application sample Android package net.yy.Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 8d ago
sha25666499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810ebc1985e45b10f276e5b26f4fae3157db283d1f3 Vwork sample SHA-256 66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb Modified banking application sample SHA-256 61274cf9f49e04eHackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 8d ago
sha2569ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud sample SHA-256 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud sample SHA-256 1f5d99864564c088a3260e54ad1728a3eadcHackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 8d ago
sha256ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae1bc772c8383a4149d23a5425b13475e2d501 Gigabud sample SHA-256 ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud sample SHA-256 4fff28eecc0ab6303e4948df77671009dda5Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 8d ago
sha256b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501s of compromise (IoCs):- Type Indicator Description SHA-256 b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud sample SHA-256 ae6f6eeba2bd4cc948d24610d9447986e52fHackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 8d ago
domainadoube.vuemail, which took them to a fake CAPTCHA lure (at https[://]adoube[.]vu/2a8ed9baefcd ). This phishing landing page displayed a faPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainhosthiifran.screenconnect.comwas downloaded from the attacker-controlled infrastructure, hosthiifran[.]screenconnect[.]com . When the target opened their Downloads folder and exePhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domaininstance-uxh86b-relay.screenconnect.comClient ( 9c1aea531ba4c511 ) configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com . The attacker used a legitimate ScreenConnect Trial RePhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainrelay.goldenmelon.usclient ( d751818fd46e5ca9 ), configured to communicate with relay[.]goldenmelon[.]us . That client (again) used the native Windows command sPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainrelay.illuminantgroup.netlluminantgroup[.]net and was configured to communicate with relay[.]illuminantgroup[.]net . Both ScreenConnect clients were registered as WindowsPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainscx.illuminantgroup.netnConnect Client ( c19e38a20f1ba492 ), which downloaded from scx[.]illuminantgroup[.]net and was configured to communicate with relay[.]illuminaPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainselectstructure.com.aued the malicious link in the message, which brought them to selectstructure[.]com[.]au/freedom/adobedocument.html . This domain uses the samePhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainvictory.mkc1.digitaloceanspaces.comeader update ( AdbRdBkUpsStUp.msi ) and was downloaded from victory[.]mkc1[.]digitaloceanspaces[.]com . Once it was executed, the installer again led to thPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domainwir.consultingics.comd ScreenConnect client payload ( patch.msi ) from hxxps[://]wir[.]consultingics[.]com/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest&c=GOPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
sha25641d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b( 7c1d255d0efefde6 ) ScreenConnect.ClientSetup.exe SHA256: 41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b Initial payload: rogue ScreenConnect installer HideCursor.ePhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
sha2569f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991sion binary ScreenConnect Client (9c1aea531ba4c511) SHA256: 9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991 Rogue RMM: initial ScreenConnect instance ScreenConnect CliPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
sha256f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35ct instance ScreenConnect Client (7c1d255d0efefde6) SHA256: f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35 Rogue RMM: secondary rogue ScreenConnect instance IncidentPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
sha256fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2yload: rogue ScreenConnect installer HideCursor.exe SHA256: fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2 Defense evasion binary ScreenConnect Client (9c1aea531ba4c5Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 8d ago
domaingoogle.comcompromise (IoCs):- Type Indicator Description Domain docs.google[.]com Google-hosted documents and Sheets were used for lure hosHackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cyber Security News
· 8d ago
domainobfuscator.ioor the fraudulent Google Docs lure document Tool or service Obfuscator[.]io JavaScript obfuscation service whose output patterns wereHackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cyber Security News
· 8d ago
domainpaste.shand payload retrieval through the Visualization API Domain paste[.]sh Hosted first-stage JavaScript loader scripts used in theHackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cyber Security News
· 8d ago
domainsimpleswap.iocy trading site targeted by the initial lure version Domain SimpleSwap[.]io Cryptocurrency trading site targeted by the later TampermHackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cyber Security News
· 8d ago
domainswapzone.ioRL promoted for the Tampermonkey-based loader script Domain SwapZone[.]io Cryptocurrency trading site targeted by the initial lureHackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cyber Security News
· 8d ago
sha2560710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 Note: IP addresses and domains are intentionally defanged (GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 8d ago
sha256112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud 9ca27df7938f12794bab0847434482955ca9adea714a34afd31GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 8d ago
sha2561f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c2794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4faeGoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 8d ago
sha2564fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bccc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7fGoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 8d ago
sha2569ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be5226114acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae2009GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 8d ago
sha256ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 8d ago
sha256b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501horized transfers. IOCs Malware Family SHA-256 Hash Gigabud b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddeGoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 8d ago
domainamazingshield.xyz, redundant agent. This Python script is downloaded from aa.amazingshield[.]xyz . The installer downloads a legitimate Python distributioUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainatthelake.inforring SEO Domain Search Keyword Victim IP Windows_10 Chrome atthelake[.]info hwidspoofer 5.xxx.xx.xxx Windows_10 Chrome atthelake[.]inUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domaincrowdstri.comhostname and processor architecture. The Python agent used crowdstri[.]com as its C2 domain. This appears to be a deliberate typosquUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domaincrowdstrike.comits C2 domain. This appears to be a deliberate typosquat of crowdstrike[.]com , designed to blend into logs and evade quick security reUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainextentrack.comt extracts and runs eld2.tmp which contacts the affiliate’s extentrack[.]com install tracker. eld2.tmp drops and loads Adblock.dll , wUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainmqsearch.com: Search hijacking : Changes the default search provider to mqsearch[.]com , a domain that masquerades as a search engine ExtensionUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainnoiseship.cfdh affiliate ID CID=2855 . Second intrusion set : Browsed to noiseship[.]cfd , a domain registered just 39 days earlier, and downloadeUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainpcsdkflyer.caling, as well as file execution. The C2 server address, reg.pcsdkflyer[.]ca , is decoded from a 39-byte configuration blob using BaseUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainstryper.inforst part of Insomnia RAT is a Node.js agent downloaded from stryper[.]info/aa.js . While the prior variant targeted Windows, Linux aUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainvoyagemist.spaceThis temporary file transmits an initial tracking beacon to voyagemist[.]space . This is another gating mechanism: depending on the struUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42
· 8d ago
domainbloom.ioTeams, which then loads an external resource hosted on cdn.bloom[.]io. It is this resource that is converted by the browser intNew Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
SecurityWeek
· 8d ago
ipv4146.103.99.177Incident responders should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js filHackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
GBHackers
· 8d ago
ipv446.151.29.58s should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js files, and review ruHackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
GBHackers
· 8d ago
urlhttps://146[s. The initial stager downloads a second-stage payload from hxxps://146[.]103[.]99[.]177:8443/0c5b76709523, decodes it, and XOR-decrHackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
GBHackers
· 8d ago
sha25626bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9upgrade images. The SHA-256 hash of the analyzed sample is 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 . F5 has published remediation and compromise assessment guPoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
Security Affairs
· 8d ago
domainsocket.ayakliborsa.netpool endpoint used by botnet-deployed XMRig Domain and port socket.ayakliborsa.net:8081 Live operator-controlled hostname resolving to 188.245Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv4173.212.244.25IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA targets IP address 2Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv4188.245.99.156f compromise (IoCs):- Type Indicator Description IP address 188.245.99.156 Operator host used for rogue Redis replication, command-andHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv4194.48.248.105Recurring WordPress exploitation target IP address and port 194.48.248.105:8081 Earlier open directory linked by cryptocurrency walletHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv420.198.10.42target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed develoHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv4213.6.207.123hip unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA tarHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv423.235.223.495 Additional observed development and QA targets IP address 23.235.223.49 Recurring WordPress exploitation target IP address and portHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv434.166.99.116eused QA or test target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 AdditionalHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv445.155.102.89stname> Victim check-in request pattern IP address and port 45.155.102.89:10128 Local mining pool proxy used on the operator host DomHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv447.250.92.230-controlled hostname resolving to 188.245.99.156 IP address 47.250.92.230 Frequently reused QA or test target, ownership unconfirmedHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
sha256420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2aidentifier observed in the RDP certificate TLS fingerprint 420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a Pinned mining-pool certificate fingerprint in the newest paHackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners
Cyber Security News
· 8d ago
ipv415.1.10.80 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nearly a year old. Ireland's NF5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
The Hacker News
· 8d ago
ipv416.1.6.1.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is neaF5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
The Hacker News
· 8d ago
ipv417.5.1.3s. Versions known to be vulnerable Fixed in 17.5.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
The Hacker News
· 8d ago
sha25626bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9inding a socket under /run, or starting /bin/bash SHA-256 : 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 File, weak on its own : changes to the three .php3 scripts.F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
The Hacker News
· 8d ago
domainhunt.iooop from believed-write to confirmed shell access (Source : Hunt.io). The flaw can allow a remote, unauthenticated attacker toMassive Redis Cryptojacking Campaign Hijacks Thousands of Linux Servers
GBHackers
· 8d ago
domainmoneroocean.streamocal mining pool/proxy used by the operator’s own host pool.moneroocean[.]stream:443 Domain:port Mining pool used by botnet-deployed XMRigMassive Redis Cryptojacking Campaign Hijacks Thousands of Linux Servers
GBHackers
· 8d ago
ipv445.142.193.132investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against inAgents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
ipv445.158.196.7545.142.193.132 Used to orchestrate and execute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
md5528cd4e69ecfa5191adbcf6ef28667bfute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
md5974decb9ff4c8f9ccb0937c96d513347f75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9ff4c8f9ccb0937c96d513347 (certipy.exe) ADCS Abuse Tool Administrator17 Adversary creAgents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
md5a6437ac3d6798090a218520985d36a3f27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741cAgents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
md5ce870a91e8d27e8f663f0687abc60b04fa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a2185Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
md5fc92dfafa7aa741c5f2b9cbcf75d1d19a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c5f2b9cbcf75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
domainasp.netMode [7]. Deploy an EDR solution. Rotate SharePoint Server ASP.NET machine keys [8] and restart IIS using iisreset.exe . It is2026-004: Critical Vulnerability in SharePoint Exploited
CERT-EU Advisories
· 9d ago
ipv420.12.5.3end of software maintenance); all versions 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.12026-002: Multiple Vulnerabilities in Cisco Products
CERT-EU Advisories
· 9d ago
ipv420.12.6.1s 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.13 (end of software maintenance); all vers2026-002: Multiple Vulnerabilities in Cisco Products
CERT-EU Advisories
· 9d ago
ipv420.15.4.2(end of software maintenance); all versions 20.15 up until 20.15.4.2; all versions 20.16 (end of software maintenance); all vers2026-002: Multiple Vulnerabilities in Cisco Products
CERT-EU Advisories
· 9d ago
ipv420.9.8.29 (end of software maintenance); all versions 20.9 up until 20.9.8.2; all versions 20.11 (end of software maintenance); all vers2026-002: Multiple Vulnerabilities in Cisco Products
CERT-EU Advisories
· 9d ago
domainoast.sites writable, and exfiltrates the data through requests to an oast.site subdomain, which is typically seen in security tests that uAdobe fixes critical Magento zero-day exploited to backdoor servers
BleepingComputer
· 9d ago
sha2560d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e313d3a54ffb35caed529bff49055ec5 Malicious MSI loader package 0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3 Second-stage DLL (rundll32-loaded module) Note: IP addresseHackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs
GBHackers
· 9d ago
sha2564cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389de compromised machine. IOCs Indicator (SHA-256) Description 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d Malicious MSI loader package (silent msiexec install) a4d14Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs
GBHackers
· 9d ago
sha256a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676c389d Malicious MSI loader package (silent msiexec install) a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676 Malicious MSI loader package cc6d0f3f47afeba018173604e34f52Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs
GBHackers
· 9d ago
sha256cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5f019d0110e31a44bb70fc77d1d1676 Malicious MSI loader package cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5 Malicious MSI loader package 0d2fc28af246f62f27e49207d1f64eHackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs
GBHackers
· 9d ago
domainitemrange.comystarting.com Historical Ethereum resolver C2 domain Domain itemrange.com Most recently recorded Ethereum resolver C2 domain URL httpHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
domainpublisherresolution.comsed address from April 2026, designated monitor-only Domain publisherresolution.com First C2 domain written to the Ethereum resolver contract DHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago
domainresumeacceptable.comC2 domain written to the Ethereum resolver contract Domain resumeacceptable.com Historical Ethereum resolver C2 domain Domain simultaneouslHackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
Cyber Security News
· 9d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.