ZeroHour

Indicators of compromise

228 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha256b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77das MISP, VirusTotal, or your SIEM. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6fCritical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
GBHackers
· 5d ago
sha256db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8efd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar JAR-based command executor 89.34.96[.]56Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
GBHackers
· 5d ago
sha2565bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811-QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 6d ago
sha25690b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59001.exe Detection Name: W32.9F1F11A708-100.SBX.TG** SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 6d ago
sha2569896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7fsample.exe Detection Name: W32.C4DD71E347-95.SBX.TG SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 6d ago
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 6d ago
sha256c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b20055df5.dll Detection Name: Auto.90B145.282358.in02 SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 6d ago
sha256af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588application/json User-Agent: CommandExecutor/1.0 X-API-KEY: af4c426b8c4b3b4957875206948eedae09b670f349f2ffb70df7b7a6b06cd588 Content-Length: 49 Host: api.truesmart.org {"machine_id":"aSloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz
· 6d ago
sha2566f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461079 91.214.78[.]118 UAT-11823 Netcat-based reverse shell C2 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware sample 43.204.2[.]142 UAT-1Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cyber Security News
· 6d ago
sha256b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77de for all three observed campaigns. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6dHackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cyber Security News
· 6d ago
sha256db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e54fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp — web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar — JAR-based command executor 89.34.96[.]5Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cyber Security News
· 6d ago
sha25663be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35ele analyzed in this article has the following SHA-256 hash: 63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e Dynamic analysis showed that the payload did considerably mRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS Internet Storm Center
· 6d ago
sha25640228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8pod - image : ghcr .io / spiffe / spire - agent @ sha256 : 40228af4d9a094f0fef2d7a303a3b6a689c4b4eba2fa9f7da5125b81d2d68ec8 \ " type : \ " k8s \ " value : \ " pod - label : app : clieThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Palo Alto Unit 42
· 6d ago
sha2567e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38176_ab5c_4f2a_b5f3_3c7e4c91a9ca .slice / cri - containerd - 7e1e73513947053f6ee40746fc498b1fb4f285cf175fa8336f08a38e209bda38.scope We copied this path to a mock cgroup path and wrote oThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Palo Alto Unit 42
· 6d ago
sha25646ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899crprint associated with 178.128.87[.]160 Certificate SHA-256 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c Certificate fingerprint associated with 178.128.87[.]160 FiHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 6d ago
sha2564e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5erprint associated with 165.22.184[.]26 Certificate SHA-256 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 Certificate fingerprint associated with 178.128.87[.]160 CeHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 6d ago
sha2567d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8SockTz installers and campaign scripts Certificate SHA-256 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 Certificate fingerprint associated with 165.22.184[.]26 CerHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 6d ago
sha25687bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172eczilian financial campaign malware or tool hash File SHA-256 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec Brazilian financial campaign malware or tool hash URL hxxp[Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 6d ago
sha256a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996e fingerprint associated with 178.128.87[.]160 File SHA-256 a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 Brazilian financial campaign malware or tool hash File SHA-Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 6d ago
sha2569ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11stores. IOCs Indicator Type Value Description SHA-256 Hash 9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dcHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers
· 6d ago
sha25646ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899cingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb1162Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers
· 6d ago
sha2564e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers
· 6d ago
sha2567d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 165.22.184[.]26 Note: IP addresses and domains are intentioHackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers
· 6d ago
sha256353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA41China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 6d ago
sha256779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096dploitation. Ioc TA412 Indicator Type Description First Seen 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d SHA256 driver-html.js(BlueMoon exploit JavaScript) August 2China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 6d ago
sha2567d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f8228809fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 6d ago
sha256e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f0041f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16cChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 6d ago
sha256ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b256 driver-html.js(BlueMoon exploit JavaScript) August 2026 ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a4China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 6d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.