ZeroHour

Indicators of compromise

26 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha1072558bc1a539e9936584647df51fb1797c982b0mes writes: https://github.com/unrealircd/unrealircd/commit/072558bc1a539e9936584647df51fb1797c982b0. It's a great example of the shape of many LLM-reported (I'Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations
oss-security
· 2d ago
sha1513a907b69edffc3cb77a494da395178d21ef9bdmtp Second-stage payload download URL 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA-1 hash of /tmp/.z payload 2026-09-06 2026-09-08 64.207.Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 4d ago
sha1513a907b69edffc3cb77a494da395178d21ef9bdmtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a494da395178d21ef9bd Account 0xterror , svc_[a-zA-Z0-9]{8} , Nxploited_[a-zA-Z0-JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 4d ago
sha1513a907b69edffc3cb77a494da395178d21ef9bd026-42018/CVE-2026-42016 exploitation 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA1 of /tmp/.z payload 2026-09-06 2026-09-08 64.207.232[.]Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 5d ago
sha159508d071661ea70fa5fcbe6f9e2fb72506e57dfa4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df MacSync sample SHA-1 hash Code-signing identifier com.utilsHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 5d ago
sha1d182eb7cba0ffa42d770d7b0d3499e49f24163a2ils.Launcher Ad-hoc-signed MacSync stager identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code directory hash associated with the sample Staged archiHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 5d ago
sha159508d071661ea70fa5fcbe6f9e2fb72506e57dfcbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df Native Mach-O Stager Binary Code Signing ID com.utils.LauncHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers
· 5d ago
sha1d182eb7cba0ffa42d770d7b0d3499e49f24163a2om.utils.Launcher Ad-hoc signature bundle identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code Directory Hash Note: IP addresses and domains are inteHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers
· 5d ago
sha1286dd3ff41526b582ef48830de239dffbaa61f90Sep 05 Hi, https://github.com/util-linux/util-linux/commit/286dd3ff41526b582ef48830de239dffbaa61f90 Regards, SalvatoreRe: Vulnerability fixes in util-linux-2.42.3
oss-security
· 10d ago
sha103defdda9397e7536cf39951246483a0339ccd35c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-2RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· 29d ago
sha10bdb44255e9472d80ee0197d0bfad7d8eb4a18e96239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-0RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· 29d ago
sha125ba920cb440b4a1c127c8eb0fb23ee783c9e01a502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-1RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· 29d ago
sha1ac3f20ddc2567af0b050c672ecd59dddab1fe55e947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-2RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· 29d ago
sha1177837d0fa5bfd274abe79d80a01cfe2374b4cd9ing file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbcaMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· 29d ago
sha189a7861acb7983ad712ae9206131c96454a1b3d8ing file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a794bac4bf650b6ba537137504162520b67266449be979679Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· 29d ago
sha1d2c161ce52240b61d632607a2262890327d82502ing file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd9Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· 29d ago
sha1d04ce934561934f758d77dfa944bd6743dd82cff2 Bits binary MD5 : 76429f8515768f9f5def697e71071f51 SHA1 : d04ce934561934f758d77dfa944bd6743dd82cff SHA256: 7757517ae6b4d513a57826f9ab65bd070d99d25ac526cfae3e9New Malware 'Rover' Targets Indian Ambassador to Afghanistan
Palo Alto Unit 42
· 29d ago
sha141ee612602833345fc5bd2b98103811c12345678ique ID. "41EE612602833345FC5BD2B98103811C" + "12345678" = "41EE612602833345FC5BD2B98103811C12345678" Next, Smoke Loader generates two strings based on the firsAnalysis of Smoke Loader in New Tsunami Campaign
Palo Alto Unit 42
· 29d ago
sha13d161de48d3f4da0aefff685253404c8b0111563by the malware): MD5 0f1d3ed85fee2acc23a8a26e0dc12e0f SHA1 3d161de48d3f4da0aefff685253404c8b0111563 SHA256 fb94a5e30de7afd1d9072ccedd90a249374f687f16170e1986d6NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· 29d ago
sha167c05b3937d94136eda4a60a2d5fb685abc776a1d was identified: MD5 05d43d417a8f50e7b23246643fc7e03d SHA1 67c05b3937d94136eda4a60a2d5fb685abc776a1 SHA256 3fee068bf90ffbeb25549eb52be0456609b1decfe91cda1967ebNOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· 29d ago
sha1741dbdb20d1beeb8ff809291996c8b78585cb812lease\LoadDll.pdb MD5 a2fe5dcb08ae8b72e8bc98ddc0b918e7 SHA1 741dbdb20d1beeb8ff809291996c8b78585cb812 SHA256 0669c71740134323793429d10518576b42941f9eee0def6057edNOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· 29d ago
sha1d13fc918433c705b49db74c91f56ae6c0cb5cf8dowing properties: MD5 e02024f38dfb6290ce0d693539a285a9 SHA1 d13fc918433c705b49db74c91f56ae6c0cb5cf8d SHA256 66a0c294ee8f3507d723a376065798631906128ce79bd6dfd8f0NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· 29d ago
sha1e66e416f300c7efb90c383a7630c9cfe901ff9fdowing properties: MD5 a943e196b83c4acd9c5ce13e4c43b4f4 SHA1 e66e416f300c7efb90c383a7630c9cfe901ff9fd SHA256 cfe436c1f0ce5eb7ac61b32cd073cc4e4b21d5016ceef77575beThe Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· 29d ago
sha1f459f9cfbd10b136cafb19cbc233a4c8342ad984g sample is used: MD5 3e4015366126dcdbdcc8b5c508a6d25c SHA1 f459f9cfbd10b136cafb19cbc233a4c8342ad984 SHA256 aef92be267a05cbff83aec0f23d33dfe0c4cdc71f9a424f5a2e5The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· 29d ago
sha1ba6d10e36f41c4ebc85f6beb95afd2b7c92406adc3c689899dc4e75fdbdd0ab076ac457de7fb83645fb735a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes FExploring the Latest Mispadu Stealer Variant
Palo Alto Unit 42
· 29d ago
sha182cb695f463b93b9cc089253cd6b5e32dce46c350477 - main . zip Type = zip Physical Size = 2360 Comment = 82cb695f463b93b9cc089253cd6b5e32dce46c35 Date Time Attr Size Compressed Name ------------------- ---Fake CVE-2023
Palo Alto Unit 42
· 29d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.