Indicators of compromise
428 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a | 74d675a98662e02422e encrypted payload file, named p SHA-256 d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll Domain mail.uai | China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor The Hacker News | · 6d ago |
| sha256 | 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b | ts. The SHA-256 of the Impacket binary the operator used is 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b , and the delivery IP was 95.181.173[.]36. The operator ran | UK Council Attack Linked to Mass Exploitation of SonicWall Flaw Security Affairs | · 6d ago |
| sha256 | 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 | be05561f3a19c7fc2d08e38c97e1986bbc5 SHA256 of SloppyRAT DLL 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SHA256 of SloppyRAT DLL bdcf8fe230e23692b658b62b6547374e223 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| sha256 | 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 | 091743cf567396201eff7731f5475768f9a SHA256 of SloppyRAT DLL 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 SHA256 of SloppyRAT DLL ff142fc192daa2a83bc565e5b38ebbe0556 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| sha256 | 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a | vent. Indicators Of Compromise (IOCs) Indicator Description 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a SHA256 of SloppyRAT DLL 8774533134d9d1514106c4090a0c5bccab4 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| sha256 | bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd | bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SHA256 of SloppyRAT DLL bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd SHA256 of SloppyRAT DLL Note: IP addresses and domains are | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| sha256 | ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 | bccab4550facdcfe03f4e02b9764343a990 SHA256 of SloppyRAT DLL ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SHA256 of SloppyRAT DLL 680c3a9f5fdddfcc34856c7a67d21bbdd2b | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| sha256 | 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 | 026-20079 91.214.78[.]118 UAT-11823 Netcat reverse-shell C2 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink ELF malware 43.204.2[.]142 UAT-1198 | Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware GBHackers | · 6d ago |
| sha256 | b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d | as MISP, VirusTotal, or your SIEM. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6f | Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware GBHackers | · 6d ago |
| sha256 | db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e | fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar JAR-based command executor 89.34.96[.]56 | Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware GBHackers | · 6d ago |
| sha256 | 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 | -QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://ta | We've got one word for it, and it's usually the wrong one Cisco Talos | · 6d ago |
| sha256 | 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 | 001.exe Detection Name: W32.9F1F11A708-100.SBX.TG** SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://ta | We've got one word for it, and it's usually the wrong one Cisco Talos | · 6d ago |
| sha256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | sample.exe Detection Name: W32.C4DD71E347-95.SBX.TG SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta | We've got one word for it, and it's usually the wrong one Cisco Talos | · 6d ago |
| sha256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta | We've got one word for it, and it's usually the wrong one Cisco Talos | · 6d ago |
| sha256 | c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 | 0055df5.dll Detection Name: Auto.90B145.282358.in02 SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://ta | We've got one word for it, and it's usually the wrong one Cisco Talos | · 6d ago |
| sha256 | af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588 | application/json User-Agent: CommandExecutor/1.0 X-API-KEY: af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588 Content-Length: 49 Host: api.truesmart.org {"machine_id":"a | SloppyRAT: A New Tool For Ransomware Attacks Zscaler ThreatLabz | · 6d ago |
| sha256 | 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 | 079 91.214.78[.]118 UAT-11823 Netcat-based reverse shell C2 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware sample 43.204.2[.]142 UAT-1 | Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware Cyber Security News | · 6d ago |
| sha256 | b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d | e for all three observed campaigns. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6d | Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware Cyber Security News | · 6d ago |
| sha256 | db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e | 54fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar — JAR-based command executor 89.34.96[.]5 | Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware Cyber Security News | · 6d ago |
| sha256 | 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e | le analyzed in this article has the following SHA-256 hash: 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e Dynamic analysis showed that the payload did considerably m | Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th) SANS Internet Storm Center | · 6d ago |
| sha256 | 40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8 | pod - image : ghcr .io / spiffe / spire - agent @ sha256 : 40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8 \ " type : \ " k8s \ " value : \ " pod - label : app : clie | The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE Palo Alto Unit 42 | · 7d ago |
| sha256 | 7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38 | 176_ab5c_4f2a_b5f3_3c7e4c91a9ca .slice / cri - containerd - 7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope We copied this path to a mock cgroup path and wrote o | The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE Palo Alto Unit 42 | · 7d ago |
| sha256 | 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c | rprint associated with 178.128.87[.]160 Certificate SHA-256 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c Certificate fingerprint associated with 178.128.87[.]160 Fi | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| sha256 | 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 | erprint associated with 165.22.184[.]26 Certificate SHA-256 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 Certificate fingerprint associated with 178.128.87[.]160 Ce | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| sha256 | 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 | SockTz installers and campaign scripts Certificate SHA-256 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 Certificate fingerprint associated with 165.22.184[.]26 Cer | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| sha256 | 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec | zilian financial campaign malware or tool hash File SHA-256 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec Brazilian financial campaign malware or tool hash URL hxxp[ | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| sha256 | a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 | e fingerprint associated with 178.128.87[.]160 File SHA-256 a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 Brazilian financial campaign malware or tool hash File SHA- | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| sha256 | 9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11 | stores. IOCs Indicator Type Value Description SHA-256 Hash 9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dc | Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security. GBHackers | · 7d ago |
| sha256 | 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c | ingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb1162 | Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America GBHackers | · 7d ago |
| sha256 | 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 | bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542 | Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America GBHackers | · 7d ago |
| sha256 | 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 | b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 165.22.184[.]26 Note: IP addresses and domains are intentio | Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America GBHackers | · 7d ago |
| sha256 | 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee | 3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA41 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| sha256 | 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d | ploitation. Ioc TA412 Indicator Type Description First Seen 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d SHA256 driver-html.js(BlueMoon exploit JavaScript) August 2 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| sha256 | 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 | 09fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| sha256 | e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 | 1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16c | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| sha256 | ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b | 256 driver-html.js(BlueMoon exploit JavaScript) August 2026 ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a4 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| sha256 | 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 | 9. 91.214.78[.]118 UAT-11823 NetCat-based reverse shell C2. 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware. 43.204.2[.]142 UAT-11988 A | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 7d ago |
| sha256 | b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d | ble on our GitHub repository here . IOC Cluster Description B037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6 | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 7d ago |
| sha256 | db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e | d0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd[.]jar – JAR-based command executor. 89.34.96[ | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 7d ago |
| sha256 | 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25 | ode payload used to deploy the Go reverse TCP proxy SHA-256 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25 Unpacked Go-based reverse TCP proxy executable WebSocket C2 | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 7d ago |
| sha256 | 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 | ation.google Amatera build during C2 communications SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 ZIP archive containing the DLL side-loading package File na | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 7d ago |
| sha256 | 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205 | ce\DCRCVDRV_U Driver device exposed by DCRCVDrv.sys SHA-256 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205 Shellcode payload used to deploy the Go reverse TCP proxy S | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 7d ago |
| sha256 | bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b | g ZIP payload retrieved by the PowerShell installer SHA-256 bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b ZIP archive containing the unauthorized remote-access deplo | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 7d ago |
| sha256 | 123289b3680c1d693db0e3702137cc55862dbe8b9a34376bcdf08bd0514b98e7 | s of compromise (IoCs):- Type Indicator Description SHA-256 123289b3680c1d693db0e3702137cc55862dbe8b9a34376bcdf08bd0514b98e7 NodeRabbit-related sample identified by PolySwarm SHA-256 3 | Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs Cyber Security News | · 7d ago |
| sha256 | 307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00 | 7 NodeRabbit-related sample identified by PolySwarm SHA-256 307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00 NodeRabbit-related sample identified by PolySwarm Note: IP | Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs Cyber Security News | · 7d ago |
| sha256 | 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 | 28a3eadc0b509386cae200993b33673b343c Gigabud sample SHA-256 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 Vwork sample SHA-256 66499653c0fff78d81db5dc319b9aaa0288dc5 | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 7d ago |
| sha256 | 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf | 1009dda5b93ed3d1cead527b02d1317426bc Gigabud sample SHA-256 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud sample SHA-256 9ca27df7938f12794bab0847434482955ca9 | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 7d ago |
| sha256 | 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c | 82955ca9adea714a34afd315c7a7be522611 Gigabud sample SHA-256 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud sample SHA-256 0710ca983741bf6a95db1b6960c1985e45b1 | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 7d ago |
| sha256 | 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc | 7986e52f913f4b5ff960ddea26075ff621ae Gigabud sample SHA-256 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud sample SHA-256 112fefc9348fa4acbb82d54d9688c96dd567 | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 7d ago |
| sha256 | 61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc | a73660c0ee810eb Modified banking application sample SHA-256 61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc Modified banking application sample Android package net.yy. | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 7d ago |
| sha256 | 66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb | c1985e45b10f276e5b26f4fae3157db283d1f3 Vwork sample SHA-256 66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb Modified banking application sample SHA-256 61274cf9f49e04e | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 7d ago |
| sha256 | 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 | c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud sample SHA-256 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud sample SHA-256 1f5d99864564c088a3260e54ad1728a3eadc | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 7d ago |
| sha256 | ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae | 1bc772c8383a4149d23a5425b13475e2d501 Gigabud sample SHA-256 ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud sample SHA-256 4fff28eecc0ab6303e4948df77671009dda5 | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 7d ago |
| sha256 | b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 | s of compromise (IoCs):- Type Indicator Description SHA-256 b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud sample SHA-256 ae6f6eeba2bd4cc948d24610d9447986e52f | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 7d ago |
| sha256 | 41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b | ( 7c1d255d0efefde6 ) ScreenConnect.ClientSetup.exe SHA256: 41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b Initial payload: rogue ScreenConnect installer HideCursor.e | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 7d ago |
| sha256 | 9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991 | sion binary ScreenConnect Client (9c1aea531ba4c511) SHA256: 9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991 Rogue RMM: initial ScreenConnect instance ScreenConnect Cli | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 7d ago |
| sha256 | f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35 | ct instance ScreenConnect Client (7c1d255d0efefde6) SHA256: f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35 Rogue RMM: secondary rogue ScreenConnect instance Incident | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 7d ago |
| sha256 | fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2 | yload: rogue ScreenConnect installer HideCursor.exe SHA256: fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2 Defense evasion binary ScreenConnect Client (9c1aea531ba4c5 | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 7d ago |
| sha256 | 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 | 088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 Note: IP addresses and domains are intentionally defanged ( | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf | 6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud 9ca27df7938f12794bab0847434482955ca9adea714a34afd31 | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c | 2794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc | cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 | 4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae2009 | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae | 0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527 | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 | horized transfers. IOCs Malware Family SHA-256 Hash Gigabud b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960dde | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 | upgrade images. The SHA-256 hash of the analyzed sample is 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 . F5 has published remediation and compromise assessment gu | PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory Security Affairs | · 8d ago |
| sha256 | 420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a | identifier observed in the RDP certificate TLS fingerprint 420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a Pinned mining-pool certificate fingerprint in the newest pa | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| sha256 | 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 | inding a socket under /run, or starting /bin/bash SHA-256 : 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 File, weak on its own : changes to the three .php3 scripts. | F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News | · 8d ago |
| sha256 | 0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3 | 13d3a54ffb35caed529bff49055ec5 Malicious MSI loader package 0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3 Second-stage DLL (rundll32-loaded module) Note: IP addresse | Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs GBHackers | · 8d ago |
| sha256 | 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d | e compromised machine. IOCs Indicator (SHA-256) Description 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d Malicious MSI loader package (silent msiexec install) a4d14 | Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs GBHackers | · 8d ago |
| sha256 | a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676 | c389d Malicious MSI loader package (silent msiexec install) a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676 Malicious MSI loader package cc6d0f3f47afeba018173604e34f52 | Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs GBHackers | · 8d ago |
| sha256 | cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5 | f019d0110e31a44bb70fc77d1d1676 Malicious MSI loader package cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5 Malicious MSI loader package 0d2fc28af246f62f27e49207d1f64e | Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs GBHackers | · 8d ago |
| sha256 | 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 | most recently observed response was a ZIP archive, SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92. The archive included the file "platform_experience_helper. | ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager Cisco Talos | · 9d ago |
| sha256 | 6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e | b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36f40ea2da57538367ac9b89e (serve.py). Follow me on Twitter: @securityaffairs and Face | Your MikroTik Router May Already Be Compromised: Look for SSH User “-2” Security Affairs | · 10d ago |
| sha256 | 6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d | nalysis: IPs 82.192.72[.]4 and 103.102.31[.]18; file hashes 6e95f70fdbabb57881b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b | Your MikroTik Router May Already Be Compromised: Look for SSH User “-2” Security Affairs | · 10d ago |
| sha256 | 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd | b3f5b2c8465d4b17ba901100704efb1278bb3386e6729d (ftpsrv.py), 972b474b896f9fac3cd6b5b8476b410b8f39fbedee8a3b0c745d6e3b328d7dcd (launch.sh), and 6dca83338d60467b65b7789d4d59754e40a7aaa36f | Your MikroTik Router May Already Be Compromised: Look for SSH User “-2” Security Affairs | · 10d ago |
| sha256 | 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa | 4987ae9eb21bf5e67de5e9461b09655165ee4 (REVSTEALER) SHA-256: 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa (ProManager) SHA-256: 7c08cf409194056a8517865e5d3433d1499bb | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| sha256 | 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2 | 3433d1499bb8262263b55b49b8b07d9d182fcb (WinUpdate) SHA-256: 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2 (SoftManager) SHA-256: c66d2b77b9e85c53391891212413ad9a99eb | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| sha256 | 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb | 580b453ce4987acbe2c4c4d04833f55ebccfa (ProManager) SHA-256: 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb (WinUpdate) SHA-256: 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| sha256 | adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4 | eset is enough. Selected indicators of compromise: SHA-256: adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4 (REVSTEALER) SHA-256: 13d7237d7289e67c2d806a65d52580b453ce4 | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| sha256 | c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 | 7dd9fff7de9719c2a43ad123fe843dd4e4e2 (SoftManager) SHA-256: c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 (LockAppHost) Domain: monitor5.roast-core85[.]click (REVSTE | Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner The Hacker News | · 11d ago |
| sha256 | 251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220 | 705adec1902a1d06ef (on disk on both Disrex stores) SHA-256: 251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220 (running in memory on one Disrex store) Domain: 247.cdnflar | Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores The Hacker News | · 11d ago |
| sha256 | 8334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06ef | b2b05d81391285eebc2af664641a26a7 (Sansec's sample) SHA-256: 8334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06ef (on disk on both Disrex stores) SHA-256: 251fabd50d7b18a8b5 | Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores The Hacker News | · 11d ago |
| sha256 | e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 | /gvfsd-user , with a variant pointing at /tmp/.kw_ SHA-256: e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 (Sansec's sample) SHA-256: 8334b434fa3fe9f59cebe9609b11e0b1 | Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores The Hacker News | · 11d ago |
| sha256 | 1a3374ffac5b0a62467612f264c49792d206304d4514409c982325c91231375d | a3e82 kworker-linux-arm64 (new build, 209.141.43.95) sha256 1a3374ffac5b0a62467612f264c49792d206304d4514409c982325c91231375d chronyd variant, captured from /proc/<pid>/exe /tmp/.kw_<ra | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | 4352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e | 60e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 sha256 4352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e kworker-linux-x64 (new build, 209.141.43.95), 2270031 bytes | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 | 61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 sha256 b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420 sha256 4352cabaa451e5a894535fbcc4d46628701303322a13745cb547 | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | d2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82 | -linux-x64 (new build, 209.141.43.95), 2270031 bytes sha256 d2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82 kworker-linux-arm64 (new build, 209.141.43.95) sha256 1a337 | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | d61217ca0bca83204302fa7b41935ce36f73764559c156d5c980f2fedddffb6e | d second attacker (unrelated tooling, same victims): sha256 d61217ca0bca83204302fa7b41935ce36f73764559c156d5c980f2fedddffb6e PHP dropper pub/media/catalog/product/cache/ss_<10hex>/sync | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 | n-requests 2.15.0 on the implant operator's requests sha256 e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 sha256 b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4e | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 12d ago |
| sha256 | 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 | 9142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 SHA-256 - 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 The Hacker News confirmed on September 4 that none of the s | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 12d ago |
| sha256 | 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 | File - /var/lib/snapd/g580 File - /tmp/jasper-log SHA-256 - 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 SHA-256 - 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1 | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 12d ago |
| sha256 | 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe | audit / audit.log , cmd.log , secure , syslog , auth.log . 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe and fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ad | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 12d ago |
| sha256 | 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 | hrough it, completing the watering-hole loop. SSH keylogger 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 intercepts legitimate users' plaintext passwords and saves | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 12d ago |
| sha256 | 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91 | ound to be delivered by a stager. CurlRAT Stager The stager 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91 starts by decrypting its configuration strings using a 1-by | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 12d ago |
| sha256 | 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 | er. Ted backdoor The TA recompiled the HAProxy build 2.8.12 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 (18MB) to include a custom plugin (named ted_plugin ) leavi | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 12d ago |
| sha256 | 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c | ryption (Figure 8). Figure 8: Default configuration curlRAT 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c ⠀ The atd_get_info() is a recon routine likely used to deci | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 12d ago |
| sha256 | fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61 | d4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe and fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61 are a different variant of the stager that fetches backdoor | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 12d ago |
| sha256 | feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3 | epath used to hide config/staging files. As for the stager, feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3 starts by decrypting configuration strings using a 1-byte X | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 12d ago |
| sha256 | 228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 | 001.exe Detection Name: W32.9F1F11A708-100.SBX.TG** SHA256: 228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 MD5: 61e046145ee5cf45aeb033cd71e8b07c Talos Rep: https://ta | The story behind the intelligence Cisco Talos | · 13d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.