ZeroHour

Indicators of compromise

270 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
md5aade06ec611d69f1553035f22356ccf4b37e02e77f9d6a92e DriverInstaller.exe, RUSTYSHADE File hash Aade06ec611d69f1553035f22356ccf4 Ad4afe86a835bb2f7768862d358ebd8324c05902 05bbeea42f481a3dd1APT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks
Cyber Security News
· 2h ago
md5f16f507a8ed515663a4f07050cd97a74Automata-20.zip, ZIP archive containing RUSTYMOVE File hash F16f507a8ed515663a4f07050cd97a74 00e1cc0fb1355c196c069791a02b4a5f3b57ae9470fc6cba3c2021889fbAPT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks
Cyber Security News
· 2h ago
md51dcafb7f8448683281106b06dd22409aof compromise (IoCs):- Type Indicator Description MD5 hash 1dcafb7f8448683281106b06dd22409a Associated with AdobeSync.exe MD5 hash 1f3034b706c78b35d8e3NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
Cyber Security News
· 4h ago
md51f3034b706c78b35d8e34044e68c693a683281106b06dd22409a Associated with AdobeSync.exe MD5 hash 1f3034b706c78b35d8e34044e68c693a Associated with adobe_32.exe MD5 hash 3ecd1cd627d0340c92901NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
Cyber Security News
· 4h ago
md53ecd1cd627d0340c92901a478a7caad878b35d8e34044e68c693a Associated with adobe_32.exe MD5 hash 3ecd1cd627d0340c92901a478a7caad8 Associated with App_Web_Container_1.dll MD5 hash 631fb131a5NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
Cyber Security News
· 4h ago
md54aa9fb1bf9223dfcdac920759bc7a3c7ed73e876ab Associated with App_Web_Container_1.dll MD5 hash 4aa9fb1bf9223dfcdac920759bc7a3c7 Associated with 1c-office-plugin.exe , 1cbroker.exe , and tNightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
Cyber Security News
· 4h ago
md5631fb131a56caf4ca0f287ed73e876ab478a7caad8 Associated with App_Web_Container_1.dll MD5 hash 631fb131a56caf4ca0f287ed73e876ab Associated with App_Web_Container_1.dll MD5 hash 4aa9fb1bf9NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
Cyber Security News
· 4h ago
md51dcafb7f8448683281106b06dd22409at critical defensive choke points. Indicators of compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exeNightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
GBHackers
· 6h ago
md51dcafb7f8448683281106b06dd22409at critical defensive choke points. Indicators of compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exeNightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
GBHackers
· 6h ago
md51f3034b706c78b35d8e34044e68c693af compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caNightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
GBHackers
· 6h ago
md51f3034b706c78b35d8e34044e68c693af compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caNightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
GBHackers
· 6h ago
md53ecd1cd627d0340c92901a478a7caad8AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aNightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
GBHackers
· 6h ago
md53ecd1cd627d0340c92901a478a7caad8AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aNightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
GBHackers
· 6h ago
md54aa9fb1bf9223dfcdac920759bc7a3c7d8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1c-office-plugin.exe, 1cbroker.exe, trueconf.exe Note: IP aNightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
GBHackers
· 6h ago
md54aa9fb1bf9223dfcdac920759bc7a3c7d8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1c-office-plugin.exe, 1cbroker.exe, trueconf.exe Note: IP aNightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
GBHackers
· 6h ago
md5631fb131a56caf4ca0f287ed73e876ab34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1cNightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
GBHackers
· 6h ago
md5631fb131a56caf4ca0f287ed73e876ab34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1cNightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
GBHackers
· 6h ago
md5200e61bfe54c92fb720c77c3a1661bc0lure URL hxxps://chartered.flipbookonlinevault[.]com/scanna/200e61bfe54c92fb720c77c3a1661bc0/b5ea87c2ddac3aa141bc6794b8993d1e43bd064eaae591719612becea0dGhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Cyber Security News
· 21h ago
md51a6dcfa8d4a429f5511ba3cf83addabd4 Address 58.181.61.142 Source-listed network indicator MD5 1a6dcfa8d4a429f5511ba3cf83addabd Source-listed Noodle RAT sample hash SHA-1 d3cb5381f5743b53Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md51aa9416b733743f534abea90982dcd1684500a84268792dca3 Source-listed Noodle RAT sample hash MD5 1aa9416b733743f534abea90982dcd16 Source-listed Noodle RAT sample hash SHA-1 5f283f5a5eb22bfeHackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md526f33ae36ad05582393a6d6ec6cb327390494d9ee72eece870 Source-listed Noodle RAT sample hash MD5 26f33ae36ad05582393a6d6ec6cb3273 Source-listed Noodle RAT sample hash SHA-1 313ebf27b9e1a2f1Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md53166ae39b46472d2ee53a880eb8248e0ebfe456974bb355bd2 Source-listed Noodle RAT sample hash MD5 3166ae39b46472d2ee53a880eb8248e0 Source-listed Noodle RAT sample hash SHA-1 974e94efa9515e53Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md53c230061e5a16cc559b0a7f025f0825064b115a150d8dcf204 Source-listed Noodle RAT sample hash MD5 3c230061e5a16cc559b0a7f025f08250 Source-listed Noodle RAT sample hash SHA-256 4f4d405d32d76aHackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md55b11b38bf0eb3f0952f306ad5be9d5ebAddress 124.230.195.242 Source-listed network indicator MD5 5b11b38bf0eb3f0952f306ad5be9d5eb Source-listed Noodle RAT sample hash SHA-1 99fbd400260206d8Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md563af61806ff5060c77a526375f843c29991195d1dbc7b8d82d Source-listed Noodle RAT sample hash MD5 63af61806ff5060c77a526375f843c29 Source-listed Noodle RAT sample hash IPv4 Address 58.181.61Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md5832e5ff3482cd9e4fba4e2fe22799cd896b7452420a8fdd254 Source-listed Noodle RAT sample hash MD5 832e5ff3482cd9e4fba4e2fe22799cd8 Source-listed Noodle RAT sample hash SHA-1 ebda1aecbe1a9cf3Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md58d9fa801432654ebfe456974bb355bd2bbbe993b1ce8aea140 Source-listed Noodle RAT sample hash MD5 8d9fa801432654ebfe456974bb355bd2 Source-listed Noodle RAT sample hash MD5 3166ae39b46472d2eeHackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md5ba2ff4a8b689fab54670cf87b4008528Address 137.220.158.91 Source-listed network indicator MD5 ba2ff4a8b689fab54670cf87b4008528 Source-listed Noodle RAT sample hash SHA-1 dd0012a6ba2ffda2Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md5eff8675fac22c49107a2a42d3c735f10c29e8f916f0592575f Source-listed Noodle RAT sample hash MD5 eff8675fac22c49107a2a42d3c735f10 Source-listed Noodle RAT sample hash SHA-1 e17f76e0b4c47a5fHackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md5f070ad0d01de3696b7452420a8fdd254cae15d8b6b7d67e7e5 Source-listed Noodle RAT sample hash MD5 f070ad0d01de3696b7452420a8fdd254 Source-listed Noodle RAT sample hash MD5 832e5ff3482cd9e4fbHackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md5f1a04ffaa889c11b99b33610e4a87dec6f8aab98d4ae55eae4 Source-listed Noodle RAT sample hash MD5 f1a04ffaa889c11b99b33610e4a87dec Source-listed Noodle RAT sample hash SHA-1 199af4936e44ed89Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md5f2e641d14aaff8fa4872a157d9d1be827d2418b5a60f8525d7 Source-listed Noodle RAT sample hash MD5 f2e641d14aaff8fa4872a157d9d1be82 Source-listed Noodle RAT sample hash SHA-1 3a05ce5e3eea58d5Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Cyber Security News
· 22h ago
md51dcafb7f8448683281106b06dd22409aateral movement across the network Indicators of compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exeNightEagle targets Russian companies
Kaspersky Securelist
· 1d ago
md51f3034b706c78b35d8e34044e68c693af compromise 1dcafb7f8448683281106b06dd22409a AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caNightEagle targets Russian companies
Kaspersky Securelist
· 1d ago
md53ecd1cd627d0340c92901a478a7caad8AdobeSync.exe 1f3034b706c78b35d8e34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aNightEagle targets Russian companies
Kaspersky Securelist
· 1d ago
md54aa9fb1bf9223dfcdac920759bc7a3c7d8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1c-office-plugin.exe, 1cbroker.exe, trueconf.exe https://giNightEagle targets Russian companies
Kaspersky Securelist
· 1d ago
md5631fb131a56caf4ca0f287ed73e876ab34044e68c693a adobe_32.exe 3ecd1cd627d0340c92901a478a7caad8 631fb131a56caf4ca0f287ed73e876ab App_Web_Container_1.dll 4aa9fb1bf9223dfcdac920759bc7a3c7 1cNightEagle targets Russian companies
Kaspersky Securelist
· 1d ago
md55c92d3b8734b4f498752f735a1ca0987n installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.]The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs
· 3d ago
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 6d ago
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 6d ago
md59a47c4d379998ade2f8f99e23a630c06a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputatWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 6d ago
md5c2efb2dcacba6d3ccc175b6ce1b7ed0ae6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputatWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 6d ago
md5f3e82419a43220a7a222fc01b7607adc8fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://talosintelligence.com/talos_file_reputatWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 6d ago
md50e39e8d7b641bcda4376ebbfeff7b12ecluded in the malicious ISO File name / MD5 %TEMP%\find.vbs 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays the fake “license not found” message EHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md515eca4a3f7350423cf4db0b4c30d19686ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md51ec9eff863dc4418d1498bc3d904899dhaos ransomware File name / MD5 %TEMP%\YandexPackLoader.exe 1ec9eff863dc4418d1498bc3d904899d Browser installer included in the malicious ISO File name /Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md52a0834560ed3770fc33d7a42f8229722%\rockstargamescrashfixer.exe , %TEMP%\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md52a385fe7bed9899d77d05cb8e302d557a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associated launchers IP addresses 35.157.1Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md557b9c56ef97a7ada98257b23577bf5e3TEMP%\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md560a0f58001ea7be538cd42b651924cc7560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564eeHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md56b49f24d5d5b49127476bc385565f8b0ecutable File name / MD5 %TEMP%\checkinternetconnection.bat 6b49f24d5d5b49127476bc385565f8b0 Batch file used to confirm internet connectivity File namesHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md58da3fe3664d81226b0fb2a50a0537d4fat , C:\Users\Default\Local Settings\[RANDOM FILE NAME].exe 8da3fe3664d81226b0fb2a50a0537d4f DCRAT installer components and binary Hosts-file entries 0.Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md5a15e280a3fd65dfaa243bbe2dbf45e97ype Indicator Description File name / MD5 Gta6installer.exe a15e280a3fd65dfaa243bbe2dbf45e97 Initial fake installation executable File name / MD5 %TEMP%Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md5b9648ec8cc806e7661aabcfc91dc836c%TEMP%\gta6.exe , %USERPROFILE%\AppData\Roaming\svchost.exe b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries File name read_it.txt Note droppeHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md5dfdf5e5b78d2ec764c0e5641cf9a0d26-control infrastructure File name / MD5 %TEMP%\adminapp.exe dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md5ea991bc9334b36a6b958f564ee7167768001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associateHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News
· 6d ago
md515eca4a3f7350423cf4db0b4c30d19686ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md52a0834560ed3770fc33d7a42f8229722ckstargamescrashfixer.exe %TEMP%\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md52a385fe7bed9899d77d05cb8e302d557a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers Note: IP addressesFake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md557b9c56ef97a7ada98257b23577bf5e3rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md560a0f58001ea7be538cd42b651924cc7560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564eeFake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md56b49f24d5d5b49127476bc385565f8b0llation executable %TEMP%\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEMFake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md5a15e280a3fd65dfaa243bbe2dbf45e97-clean media. IOCs Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\checkinternetconnectFake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md5ea991bc9334b36a6b958f564ee7167768001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associFake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers
· 7d ago
md59678f71ea4cccbc3d511dc8d7f24b11325f44db68a MacSync sample hash reported by SEQRITE MD5 hash 9678f71ea4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
md5de62a2f47d1c7dec2997f931a050a615h used for stolen-data uploads HTTP request header api-key: de62a2f47d1c7dec2997f931a050a615 API key observed in MacSync network requests HTTP User-AgenHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 7d ago
md59678f71ea4cccbc3d511dc8d7f24b113b68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5fHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers
· 7d ago
md5528cd4e69ecfa5191adbcf6ef28667bfInfrastructure used to execute campaign activity File hash 528cd4e69ecfa5191adbcf6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8dHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
md5974decb9ff4c8f9ccb0937c96d513347sa_collect_small.exe — Rust LSA bootkey collector File hash 974decb9ff4c8f9ccb0937c96d513347 certipy.exe — Active Directory Certificate Services abuse tHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
md5a6437ac3d6798090a218520985d36a3f687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d6798090a218520985d36a3f collect_custom.exe — Rust custom collection tool File hashHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
md5ce870a91e8d27e8f663f0687abc60b04f6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d27e8f663f0687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d67Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
md5fc92dfafa7aa741c5f2b9cbcf75d1d19collect_custom.exe — Rust custom collection tool File hash fc92dfafa7aa741c5f2b9cbcf75d1d19 lsa_collect_small.exe — Rust LSA bootkey collector File hasHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
md50e39e8d7b641bcda4376ebbfeff7b12e18d1498bc3d904899d Yandex web browser %TEMP%\find.vbs MD5 : 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays a "license not found" messageGrand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md515eca4a3f7350423cf4db0b4c30d19686ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3Grand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md51ec9eff863dc4418d1498bc3d904899dansomware-encrypted files %TEMP%\YandexPackLoader.exe MD5 : 1ec9eff863dc4418d1498bc3d904899d Yandex web browser %TEMP%\find.vbs MD5 : 0e39e8d7b641bcda43Grand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md52a0834560ed3770fc33d7a42f8229722ckstargamescrashfixer.exe %TEMP%\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651Grand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md52a385fe7bed9899d77d05cb8e302d557a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers 35.157.111[.]131 3Grand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md557b9c56ef97a7ada98257b23577bf5e3rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3Grand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md560a0f58001ea7be538cd42b651924cc7560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564eeGrand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md56b49f24d5d5b49127476bc385565f8b0llation executable %TEMP%\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEMGrand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md58da3fe3664d81226b0fb2a50a0537d4f:\Users\Default\Local Settings\[RANDOM FILE NAME].exe MD5 : 8da3fe3664d81226b0fb2a50a0537d4f Copy of DCRAT and associated installation files 0.0.0.0 appGrand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md5a15e280a3fd65dfaa243bbe2dbf45e97Compromise (IOCs) Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\checkinternetconnectGrand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md5b9648ec8cc806e7661aabcfc91dc836cMP%\gta6.exe %USERPROFILE%\AppData\Roaming\svchost.exe MD5: b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries read_it.txt Ransomware note leftGrand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md5dfdf5e5b78d2ec764c0e5641cf9a0d26IP address that DCRAT connects to %TEMP%\adminapp.exe MD5 : dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary https://discord[.]com/Grand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md5ea991bc9334b36a6b958f564ee7167768001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associGrand Theft Auto VI hype leads to malware
Huntress
· 7d ago
md5528cd4e69ecfa5191adbcf6ef28667bfute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
md5974decb9ff4c8f9ccb0937c96d513347f75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9ff4c8f9ccb0937c96d513347 (certipy.exe) ADCS Abuse Tool Administrator17 Adversary creAgents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
md5a6437ac3d6798090a218520985d36a3f27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741cAgents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
md5ce870a91e8d27e8f663f0687abc60b04fa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a2185Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
md5fc92dfafa7aa741c5f2b9cbcf75d1d19a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c5f2b9cbcf75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
GreyNoise
· 8d ago
md5581e2e2265d0c1509b3799c5a9039374encrypted payload we observed was generated on 2025-11-11 ( 581e2e2265d0c1509b3799c5a9039374 ). The AES key is not stored in the malware bundle itself.JSCeal Hides Crypto Malware in V8 Bytecode
Security Affairs
· 10d ago
md55568cd69c754b392121f1dbb8f900fdar IPv4 (Tzulo VPN) 23.234.97[.]68 Intruder IPv4 (Tzulo VPN) 5568cd69c754b392121f1dbb8f900fda Malicious Cloudflare tunnel account tag Update: 8/6/26 @ 5:Critical N-able N-central Vulnerability and Active Exploitation
Huntress
· 11d ago
md5fced27f6d57702565353ecc11722533b/cache/ss_<10hex>/sync_<10hex>.php web shell X-Cache-Token: fced27f6d57702565353ecc11722533b header the web shell requires, 404 without it 457cfa2fb7p5.StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec (Magento / e-commerce security)
· 12d ago
md5c8c68e629bba773a10ac80012d10bf19tore File - ~/cache/haproxy-1000.cache File - /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 File - /var/lib/snapd/g580 File - /tmp/jasper-log SHA-256 -New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News
· 12d ago
md5c8c68e629bba773a10ac80012d10bf19and saves them to an encrypted log file under /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 . Figure 2: hardcoded master passwords in userauth_passwd()DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
md5ecd427ea8330a4ff73618483e00b9b41main – img.darklights.store – authenticating with api_token/ecd427ea8330a4ff73618483e00b9b41 and setting the User-token header to the victim ID to fetchDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7 Blog
· 13d ago
md57916c33688385525078bee504c90f359upport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.toml Registry keys: HKLM\Software\synapse\Config\SAngry Birds: Toy Ghouls’ new toys
Kaspersky Securelist
· 13d ago
md5bfadbeee63a4f0bf19ec9deb8fa58f58t.Zapchast.abwo File names and MD5 hashes: cplsupport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.tomAngry Birds: Toy Ghouls’ new toys
Kaspersky Securelist
· 13d ago
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 13d ago
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatThe story behind the intelligence
Cisco Talos
· 13d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.