ZeroHour

Indicators of compromise

1,137 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha2569d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d599c3b5c6b6c684637138a7f8ec9cebc KATARU ARM32 sample SHA-256 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5 KATARU AMD64 sample IP address 160[.]191.242.92 Observed TeNew KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
Cyber Security News
· 4d ago
sha2569d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc92dda71e82dc47e8efe13f30617f35f KATARU ARM32 sample SHA-256 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc KATARU ARM32 sample SHA-256 9d7cd4948a1fcbaeadc425752fce9a9New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
Cyber Security News
· 4d ago
sha256cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218and executed after Telnet credential brute forcing SHA-256 cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218 Loader or closely related loader variant SHA-256 13382c16e2New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
Cyber Security News
· 4d ago
sha2567f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112clook ordinary. IOCs SHA-256 File Name File Type Description 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c windirstat.exe PE32 executable; Inno Setup 6.7.1 installerResearchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
GBHackers
· 4d ago
sha256fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73at installer distributed through an SEO-poisoning campaign. fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 windirstat.tmp PE32 executable; unpacked Inno Setup stage UResearchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
GBHackers
· 4d ago
sha25600c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec382be8e1ddbebf3cdf4733cf989ba291f9013 SloppyRAT DLL SHA-256 00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec SloppyRAT DLL SHA-256 93273ea09bd9df881a594db8cfe1b1bbc54f4Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha2561439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffdebdbecb3322453bdc41b2113427f9f92d32d2 SloppyRAT DLL SHA-256 1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd SloppyRAT DLL SHA-256 eaa52d2d6d4daf29157e8e813247fb2e92797Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha2562f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d25e0ee093541d99a9dba5f69a264f7f3054b19 SloppyRAT DLL SHA-256 2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2 SloppyRAT DLL SHA-256 1439990ff65364a0f608a322aa3a493bc1683Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha2563a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19a5bcbf9a287d4653de7b76051bde73a94d064 SloppyRAT DLL SHA-256 3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19 SloppyRAT DLL SHA-256 2f3d95de716f330fad2330d8787ebdbecb332Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec860f6d09ddb5be36cc1766a41d77c5b89d3a56 SloppyRAT DLL SHA-256 466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8 SloppyRAT DLL SHA-256 f534a957edec74d69081665309311b791b6d1Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha2564ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56d1d8b6e9847aa6b8613493e5bc233ece3d189 SloppyRAT DLL SHA-256 4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56 SloppyRAT DLL SHA-256 466f9b8dce77b3a026fe4f833aa4949784fb8Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064e3b763bd4a4b0cdf59eeff981d8e307fcf316 SloppyRAT DLL SHA-256 518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064 SloppyRAT DLL SHA-256 3a8994928f512fffcb32e117ac45e0ee09354Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f97374e2234f2a497b19d26637018a1839e6dfd SloppyRAT DLL SHA-256 607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9 SloppyRAT DLL SHA-256 7bb025b426ae6ccbc170fbca58634b8dd77a6Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SloppyRAT DLL SHA-256 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SloppyRAT DLL SHA-256 bdcf8fe230e23692b658b62b6547374e2234fHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha2566d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f901334b8dd77a61447e48dabe9c2e2fb0d339d8b7 SloppyRAT DLL SHA-256 6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013 SloppyRAT DLL SHA-256 00c116e498799dc831c8aeb602349296c4b93Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha2567bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7f37a47f4c8aad08e6d5cbb7c19a62c6b765f9 SloppyRAT DLL SHA-256 7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7 SloppyRAT DLL SHA-256 6d50bb50d4e7d6ac36ca6d2761f382be8e1ddHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha2568774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a9900a091743cf567396201eff7731f5475768f9a SloppyRAT DLL SHA-256 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 SloppyRAT DLL SHA-256 ff142fc192daa2a83bc565e5b38ebbe05561fHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha25693273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b4649049296c4b9325535d674fe2b6e2e091878dcec SloppyRAT DLL SHA-256 93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490 SloppyRAT DLL SHA-256 971f25f84be88c4fd304d555b5e3da12f6b36Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d1b1bbc54f40f623f44427278ae96fb9b46490 SloppyRAT DLL SHA-256 971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d SloppyRAT DLL SHA-256 a13fcbb0870f2fabb7e0a8c757ee3b763bd4aHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha2569f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9as of compromise (IoCs):- Type Indicator Description SHA-256 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a SloppyRAT DLL SHA-256 8774533134d9d1514106c4090a0c5bccab455Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf3163da12f6b368e4b9ba0943961ff21ba6fa4d4d SloppyRAT DLL SHA-256 a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316 SloppyRAT DLL SHA-256 518cd57a303ff7ac2b5c4c8439aa5bcbf9a28Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SloppyRAT DLL SHA-256 bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd SloppyRAT DLL SHA-256 607212cfe73c5c84b2dd95b2c0ff37a47f4c8Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d18960b937c7beaf9ab51b03191dfcaba40b7b189 SloppyRAT DLL SHA-256 c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189 SloppyRAT DLL SHA-256 4ecb2d06510dfee1b67f5d9a68c60f6d09ddbHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b1897fb2e92797324230ee42c79f7861b2f5c341d SloppyRAT DLL SHA-256 cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189 SloppyRAT DLL SHA-256 c0ef62a2d5ca11c2eedad3561d5d1d8b6e984Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341da493bc1683cb5fc30cffc44948da29623fffd SloppyRAT DLL SHA-256 eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d SloppyRAT DLL SHA-256 cb9930d0cde5bf8e8a7ad08fe2c60b937c7beHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb4949784fb854bea4137e52609e857d439dec8 SloppyRAT DLL SHA-256 f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickFHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha256ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5c5bccab4550facdcfe03f4e02b9764343a990 SloppyRAT DLL SHA-256 ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SloppyRAT DLL SHA-256 680c3a9f5fdddfcc34856c7a67d21bbdd2b47Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 4d ago
sha25613382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4nd execute an ARM payload named vlxx.arm, with SHA-256 hash 13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4. Staging markers including condi72 and condixx link the delNew IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
GBHackers
· 4d ago
sha2566fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f634b8031ec254d98b876e59692b5fa22abc1d4 SHA-256 Hash (ARM32) 6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f SHA-256 Hash (ARM32) 9d87e6615c810907443ebd5e915f3b35099c3bNew IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
GBHackers
· 4d ago
sha2569d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d55f3b35099c3b5c6b6c684637138a7f8ec9cebc SHA-256 Hash (AMD64) 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5 IPv4 Address 160[.]191.242.92 Telnet credential brute-forceNew IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
GBHackers
· 4d ago
sha2569d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc2d548ce92dda71e82dc47e8efe13f30617f35f SHA-256 Hash (ARM32) 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc SHA-256 Hash (AMD64) 9d7cd4948a1fcbaeadc425752fce9a933bd6fcNew IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
GBHackers
· 4d ago
sha256cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218imperfect. IOCs Indicator Type Value SHA-256 Hash (Loader) cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218 SHA-256 Hash (ARM32) 13382c16e2401b07451577b46e634b8031ec25New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
GBHackers
· 4d ago
sha25629c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63dy running. Gen published the following indicators. SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 malicious DLL loader, written to disk as 7z.dll SHA-256 749China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 4d ago
sha256749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422ea63 malicious DLL loader, written to disk as 7z.dll SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e encrypted payload file, named p SHA-256 d7a3c7eb94edc0e020fChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 4d ago
sha256d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a74d675a98662e02422e encrypted payload file, named p SHA-256 d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll Domain mail.uaiChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 4d ago
sha256690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5bts. The SHA-256 of the Impacket binary the operator used is 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b , and the delivery IP was 95.181.173[.]36. The operator ranUK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Security Affairs
· 4d ago
sha256680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21be05561f3a19c7fc2d08e38c97e1986bbc5 SHA256 of SloppyRAT DLL 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SHA256 of SloppyRAT DLL bdcf8fe230e23692b658b62b6547374e223Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 4d ago
sha2568774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990091743cf567396201eff7731f5475768f9a SHA256 of SloppyRAT DLL 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 SHA256 of SloppyRAT DLL ff142fc192daa2a83bc565e5b38ebbe0556Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 4d ago
sha2569f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9avent. Indicators Of Compromise (IOCs) Indicator Description 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a SHA256 of SloppyRAT DLL 8774533134d9d1514106c4090a0c5bccab4Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 4d ago
sha256bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfdbbdd2b47d70bdfb829ff59cfa0e3bc72d21 SHA256 of SloppyRAT DLL bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd SHA256 of SloppyRAT DLL Note: IP addresses and domains areHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 4d ago
sha256ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5bccab4550facdcfe03f4e02b9764343a990 SHA256 of SloppyRAT DLL ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SHA256 of SloppyRAT DLL 680c3a9f5fdddfcc34856c7a67d21bbdd2bHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 4d ago
sha2566f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461026-20079 91.214.78[.]118 UAT-11823 Netcat reverse-shell C2 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink ELF malware 43.204.2[.]142 UAT-1198Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
GBHackers
· 4d ago
sha256b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77das MISP, VirusTotal, or your SIEM. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6fCritical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
GBHackers
· 4d ago
sha256db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8efd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar JAR-based command executor 89.34.96[.]56Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
GBHackers
· 4d ago
sha2565bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811-QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 5d ago
sha25690b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59001.exe Detection Name: W32.9F1F11A708-100.SBX.TG** SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 5d ago
sha2569896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7fsample.exe Detection Name: W32.C4DD71E347-95.SBX.TG SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 5d ago
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 5d ago
sha256c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b20055df5.dll Detection Name: Auto.90B145.282358.in02 SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 5d ago
sha256af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588application/json User-Agent: CommandExecutor/1.0 X-API-KEY: af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588 Content-Length: 49 Host: api.truesmart.org {"machine_id":"aSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 5d ago
sha2566f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461079 91.214.78[.]118 UAT-11823 Netcat-based reverse shell C2 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware sample 43.204.2[.]142 UAT-1Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cyber Security News
· 5d ago
sha256b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77de for all three observed campaigns. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6dHackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cyber Security News
· 5d ago
sha256db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e54fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar — JAR-based command executor 89.34.96[.]5Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cyber Security News
· 5d ago
sha25663be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35ele analyzed in this article has the following SHA-256 hash: 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e Dynamic analysis showed that the payload did considerably mRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 5d ago
sha25640228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8pod - image : ghcr .io / spiffe / spire - agent @ sha256 : 40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8 \ " type : \ " k8s \ " value : \ " pod - label : app : clieThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Palo Alto Unit 42
· 5d ago
sha2567e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38176_ab5c_4f2a_b5f3_3c7e4c91a9ca .slice / cri - containerd - 7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope We copied this path to a mock cgroup path and wrote oThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Palo Alto Unit 42
· 5d ago
sha25646ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899crprint associated with 178.128.87[.]160 Certificate SHA-256 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c Certificate fingerprint associated with 178.128.87[.]160 FiHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 5d ago
sha2564e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5erprint associated with 165.22.184[.]26 Certificate SHA-256 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 Certificate fingerprint associated with 178.128.87[.]160 CeHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 5d ago
sha2567d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8SockTz installers and campaign scripts Certificate SHA-256 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 Certificate fingerprint associated with 165.22.184[.]26 CerHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 5d ago
sha25687bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172eczilian financial campaign malware or tool hash File SHA-256 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec Brazilian financial campaign malware or tool hash URL hxxp[Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 5d ago
sha256a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996e fingerprint associated with 178.128.87[.]160 File SHA-256 a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 Brazilian financial campaign malware or tool hash File SHA-Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 5d ago
sha2569ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11stores. IOCs Indicator Type Value Description SHA-256 Hash 9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dcHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers
· 5d ago
sha25646ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899cingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb1162Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers
· 5d ago
sha2564e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers
· 5d ago
sha2567d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 165.22.184[.]26 Note: IP addresses and domains are intentioHackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers
· 5d ago
sha256353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA41China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
sha256779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096dploitation. Ioc TA412 Indicator Type Description First Seen 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d SHA256 driver-html.js(BlueMoon exploit JavaScript) August 2China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
sha2567d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f8228809fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
sha256e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f0041f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16cChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
sha256ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b256 driver-html.js(BlueMoon exploit JavaScript) August 2026 ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a4China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 5d ago
sha2566f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe4619. 91.214.78[.]118 UAT-11823 NetCat-based reverse shell C2. 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware. 43.204.2[.]142 UAT-11988 AActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 6d ago
sha256b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77dble on our GitHub repository here . IOC Cluster Description B037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 6d ago
sha256db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8ed0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd[.]jar – JAR-based command executor. 89.34.96[Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 6d ago
sha2561819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25ode payload used to deploy the Go reverse TCP proxy SHA-256 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25 Unpacked Go-based reverse TCP proxy executable WebSocket C2ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 6d ago
sha256279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92ation.google Amatera build during C2 communications SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 ZIP archive containing the DLL side-loading package File naClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 6d ago
sha256643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205ce\DCRCVDRV_U Driver device exposed by DCRCVDrv.sys SHA-256 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205 Shellcode payload used to deploy the Go reverse TCP proxy SClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 6d ago
sha256bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69bg ZIP payload retrieved by the PowerShell installer SHA-256 bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b ZIP archive containing the unauthorized remote-access deploClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 6d ago
sha256123289b3680c1d693db0e3702137cc55862dbe8b9a34376bcdf08bd0514b98e7s of compromise (IoCs):- Type Indicator Description SHA-256 123289b3680c1d693db0e3702137cc55862dbe8b9a34376bcdf08bd0514b98e7 NodeRabbit-related sample identified by PolySwarm SHA-256 3Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs
Cyber Security News
· 6d ago
sha256307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd007 NodeRabbit-related sample identified by PolySwarm SHA-256 307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00 NodeRabbit-related sample identified by PolySwarm Note: IPHackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs
Cyber Security News
· 6d ago
sha2560710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f328a3eadc0b509386cae200993b33673b343c Gigabud sample SHA-256 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 Vwork sample SHA-256 66499653c0fff78d81db5dc319b9aaa0288dc5Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 6d ago
sha256112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf1009dda5b93ed3d1cead527b02d1317426bc Gigabud sample SHA-256 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud sample SHA-256 9ca27df7938f12794bab0847434482955ca9Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 6d ago
sha2561f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c82955ca9adea714a34afd315c7a7be522611 Gigabud sample SHA-256 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud sample SHA-256 0710ca983741bf6a95db1b6960c1985e45b1Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 6d ago
sha2564fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc7986e52f913f4b5ff960ddea26075ff621ae Gigabud sample SHA-256 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud sample SHA-256 112fefc9348fa4acbb82d54d9688c96dd567Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 6d ago
sha25661274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbca73660c0ee810eb Modified banking application sample SHA-256 61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc Modified banking application sample Android package net.yy.Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 6d ago
sha25666499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810ebc1985e45b10f276e5b26f4fae3157db283d1f3 Vwork sample SHA-256 66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb Modified banking application sample SHA-256 61274cf9f49e04eHackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 6d ago
sha2569ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud sample SHA-256 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud sample SHA-256 1f5d99864564c088a3260e54ad1728a3eadcHackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 6d ago
sha256ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae1bc772c8383a4149d23a5425b13475e2d501 Gigabud sample SHA-256 ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud sample SHA-256 4fff28eecc0ab6303e4948df77671009dda5Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 6d ago
sha256b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501s of compromise (IoCs):- Type Indicator Description SHA-256 b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud sample SHA-256 ae6f6eeba2bd4cc948d24610d9447986e52fHackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Cyber Security News
· 6d ago
sha25641d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b( 7c1d255d0efefde6 ) ScreenConnect.ClientSetup.exe SHA256: 41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b Initial payload: rogue ScreenConnect installer HideCursor.ePhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 6d ago
sha2569f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991sion binary ScreenConnect Client (9c1aea531ba4c511) SHA256: 9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991 Rogue RMM: initial ScreenConnect instance ScreenConnect CliPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 6d ago
sha256f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35ct instance ScreenConnect Client (7c1d255d0efefde6) SHA256: f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35 Rogue RMM: secondary rogue ScreenConnect instance IncidentPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 6d ago
sha256fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2yload: rogue ScreenConnect installer HideCursor.exe SHA256: fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2 Defense evasion binary ScreenConnect Client (9c1aea531ba4c5Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress
· 6d ago
sha2560710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 Note: IP addresses and domains are intentionally defanged (GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 6d ago
sha256112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud 9ca27df7938f12794bab0847434482955ca9adea714a34afd31GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 6d ago
sha2561f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c2794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4faeGoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 6d ago
sha2564fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bccc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7fGoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 6d ago
sha2569ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be5226114acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae2009GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 6d ago
sha256ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 6d ago
sha256b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501horized transfers. IOCs Malware Family SHA-256 Hash Gigabud b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddeGoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GBHackers
· 6d ago
sha25626bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9upgrade images. The SHA-256 hash of the analyzed sample is 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 . F5 has published remediation and compromise assessment guPoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
Security Affairs
· 6d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.