Indicators of compromise
4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | lohnsteuerhilfe-aktuell-verein.de | ail address used to send campaign emails Email address info@lohnsteuerhilfe-aktuell-verein[.]de Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | lumalisboa.com | address used to send campaign emails Email address no-reply@lumalisboa[.]com Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | mctci.com | address used to send campaign emails Email address noreply@mctci[.]com Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | nuf.co.jp | ail address used to send campaign emails Email address info@nuf[.]co[.]jp Sender email address used to send campaign emails Email | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | service-nowinc.com | rs of compromise (IoCs):- Type Indicator Description Domain service-nowinc[.]com Domain impersonating ServiceNow Email address gomez@servi | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | tivityhealth.com | ail address used to send campaign emails Email address info@tivityhealth[.]com Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | tovimbatista.pt | ail address used to send campaign emails Email address info@tovimbatista[.]pt Sender email address used to send campaign emails Email a | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| domain | uinsure.co.uk | associated with a bank account Email address notifications@uinsure[.]co[.]uk Sender email address used to send campaign emails Email | Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments Cyber Security News | · 6d ago |
| sha256 | 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c | look ordinary. IOCs SHA-256 File Name File Type Description 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c windirstat.exe PE32 executable; Inno Setup 6.7.1 installer | Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign GBHackers | · 6d ago |
| sha256 | fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 | at installer distributed through an SEO-poisoning campaign. fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 windirstat.tmp PE32 executable; unpacked Inno Setup stage U | Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign GBHackers | · 6d ago |
| domain | apimantax.otax.fun | bound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically retrieved | New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims Cyber Security News | · 6d ago |
| url | https://apimantax[ | cted outbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically r | New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims Cyber Security News | · 6d ago |
| domain | gitclone.org | xploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-42018/ | Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access GBHackers | · 6d ago |
| sha1 | 513a907b69edffc3cb77a494da395178d21ef9bd | mtp Second-stage payload download URL 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA-1 hash of /tmp/.z payload 2026-09-06 2026-09-08 64.207. | Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access GBHackers | · 6d ago |
| url | http://3.88.162[ | 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second-stage payload download URL 2026-09-07 | Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access GBHackers | · 6d ago |
| url | http://log.gitclone[ | Actor IP exploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-420 | Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access GBHackers | · 6d ago |
| domain | backup-ubt.s3.us-east-1.amazonaws.com | ws[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east-1[.]amazonaws[.]com/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blo | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | hostfxr.dll | L URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | linked4x.com | fffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | skipraid.com | Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader domain URL hxxps[://]skipraid[.]com/dsVGmQTr | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | stro7121.blob.core.windows.net | id[.]com/dsVGmQTrzX/default2 CastleLoader URL URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/config.py Python loader URL URL hxxps[://]stro | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | telephoneip.net | ible; DLLMemLoader/1.0) Python loader User-Agent Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | truesmart.org | Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT C2 domain Note: IP addresses and domains are in | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| domain | windows.net | m/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blob.core.windows[.]net Python downloader C2 IP address 62.106.66[.]148:443 Slopp | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec | 382be8e1ddbebf3cdf4733cf989ba291f9013 SloppyRAT DLL SHA-256 00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec SloppyRAT DLL SHA-256 93273ea09bd9df881a594db8cfe1b1bbc54f4 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd | ebdbecb3322453bdc41b2113427f9f92d32d2 SloppyRAT DLL SHA-256 1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd SloppyRAT DLL SHA-256 eaa52d2d6d4daf29157e8e813247fb2e92797 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2 | 5e0ee093541d99a9dba5f69a264f7f3054b19 SloppyRAT DLL SHA-256 2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2 SloppyRAT DLL SHA-256 1439990ff65364a0f608a322aa3a493bc1683 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19 | a5bcbf9a287d4653de7b76051bde73a94d064 SloppyRAT DLL SHA-256 3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19 SloppyRAT DLL SHA-256 2f3d95de716f330fad2330d8787ebdbecb332 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8 | 60f6d09ddb5be36cc1766a41d77c5b89d3a56 SloppyRAT DLL SHA-256 466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8 SloppyRAT DLL SHA-256 f534a957edec74d69081665309311b791b6d1 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56 | d1d8b6e9847aa6b8613493e5bc233ece3d189 SloppyRAT DLL SHA-256 4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56 SloppyRAT DLL SHA-256 466f9b8dce77b3a026fe4f833aa4949784fb8 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064 | e3b763bd4a4b0cdf59eeff981d8e307fcf316 SloppyRAT DLL SHA-256 518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064 SloppyRAT DLL SHA-256 3a8994928f512fffcb32e117ac45e0ee09354 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9 | 7374e2234f2a497b19d26637018a1839e6dfd SloppyRAT DLL SHA-256 607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9 SloppyRAT DLL SHA-256 7bb025b426ae6ccbc170fbca58634b8dd77a6 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 | ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SloppyRAT DLL SHA-256 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SloppyRAT DLL SHA-256 bdcf8fe230e23692b658b62b6547374e2234f | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013 | 34b8dd77a61447e48dabe9c2e2fb0d339d8b7 SloppyRAT DLL SHA-256 6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013 SloppyRAT DLL SHA-256 00c116e498799dc831c8aeb602349296c4b93 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7 | f37a47f4c8aad08e6d5cbb7c19a62c6b765f9 SloppyRAT DLL SHA-256 7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7 SloppyRAT DLL SHA-256 6d50bb50d4e7d6ac36ca6d2761f382be8e1dd | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 | 0a091743cf567396201eff7731f5475768f9a SloppyRAT DLL SHA-256 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 SloppyRAT DLL SHA-256 ff142fc192daa2a83bc565e5b38ebbe05561f | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490 | 49296c4b9325535d674fe2b6e2e091878dcec SloppyRAT DLL SHA-256 93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490 SloppyRAT DLL SHA-256 971f25f84be88c4fd304d555b5e3da12f6b36 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d | 1b1bbc54f40f623f44427278ae96fb9b46490 SloppyRAT DLL SHA-256 971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d SloppyRAT DLL SHA-256 a13fcbb0870f2fabb7e0a8c757ee3b763bd4a | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a | s of compromise (IoCs):- Type Indicator Description SHA-256 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a SloppyRAT DLL SHA-256 8774533134d9d1514106c4090a0c5bccab455 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316 | 3da12f6b368e4b9ba0943961ff21ba6fa4d4d SloppyRAT DLL SHA-256 a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316 SloppyRAT DLL SHA-256 518cd57a303ff7ac2b5c4c8439aa5bcbf9a28 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd | 21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SloppyRAT DLL SHA-256 bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd SloppyRAT DLL SHA-256 607212cfe73c5c84b2dd95b2c0ff37a47f4c8 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189 | 60b937c7beaf9ab51b03191dfcaba40b7b189 SloppyRAT DLL SHA-256 c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189 SloppyRAT DLL SHA-256 4ecb2d06510dfee1b67f5d9a68c60f6d09ddb | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189 | 7fb2e92797324230ee42c79f7861b2f5c341d SloppyRAT DLL SHA-256 cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189 SloppyRAT DLL SHA-256 c0ef62a2d5ca11c2eedad3561d5d1d8b6e984 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d | a493bc1683cb5fc30cffc44948da29623fffd SloppyRAT DLL SHA-256 eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d SloppyRAT DLL SHA-256 cb9930d0cde5bf8e8a7ad08fe2c60b937c7be | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb | 4949784fb854bea4137e52609e857d439dec8 SloppyRAT DLL SHA-256 f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickF | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 | c5bccab4550facdcfe03f4e02b9764343a990 SloppyRAT DLL SHA-256 ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SloppyRAT DLL SHA-256 680c3a9f5fdddfcc34856c7a67d21bbdd2b47 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement Cyber Security News | · 6d ago |
| sha256 | 13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4 | nd execute an ARM payload named vlxx.arm, with SHA-256 hash 13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4. Staging markers including condi72 and condixx link the del | New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks GBHackers | · 6d ago |
| sha256 | 6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f | 634b8031ec254d98b876e59692b5fa22abc1d4 SHA-256 Hash (ARM32) 6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f SHA-256 Hash (ARM32) 9d87e6615c810907443ebd5e915f3b35099c3b | New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks GBHackers | · 6d ago |
| sha256 | 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5 | 5f3b35099c3b5c6b6c684637138a7f8ec9cebc SHA-256 Hash (AMD64) 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5 IPv4 Address 160[.]191.242.92 Telnet credential brute-force | New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks GBHackers | · 6d ago |
| sha256 | 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc | 2d548ce92dda71e82dc47e8efe13f30617f35f SHA-256 Hash (ARM32) 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc SHA-256 Hash (AMD64) 9d7cd4948a1fcbaeadc425752fce9a933bd6fc | New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks GBHackers | · 6d ago |
| sha256 | cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218 | imperfect. IOCs Indicator Type Value SHA-256 Hash (Loader) cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218 SHA-256 Hash (ARM32) 13382c16e2401b07451577b46e634b8031ec25 | New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks GBHackers | · 6d ago |
| domain | gitclone.org | .184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash | JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control Cyber Security News | · 6d ago |
| sha1 | 513a907b69edffc3cb77a494da395178d21ef9bd | mtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a494da395178d21ef9bd Account 0xterror , svc_[a-zA-Z0-9]{8} , Nxploited_[a-zA-Z0- | JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control Cyber Security News | · 6d ago |
| url | http://3.88.162[ | ]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a4 | JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control Cyber Security News | · 6d ago |
| url | http://log.gitclone[ | [.]88 , 137.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Ha | JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control Cyber Security News | · 6d ago |
| domain | domainlify.net | t in the fake invoice as a contact address. Another domain, domainlify[.]net, was used in Reply-To fields. The short preparation perio | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | eemusicclass.co.uk | uerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | lifeones.com | info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out email | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | lohnsteuerhilfe-aktuell-verein.de | umalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk inf | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | lumalisboa.com | ications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhil | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | mctci.com | k info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.] | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | nuf.co.jp | th[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbati | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | service-nowinc.com | onsumer goods’ and others (Source : Microsoft). One domain, service-nowinc[.]com, was registered on July 31, shortly before the phishing a | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | tivityhealth.com | ated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.] | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | tovimbatista.pt | nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | uinsure.co.uk | ss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norep | Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. GBHackers | · 6d ago |
| domain | noht1ng.top | il.uaiubifas[.]top backdoor command server, port 443 Domain noht1ng[.]top hosted the exploit page IP 8.218.50[.]207 staging server, | China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor The Hacker News | · 6d ago |
| domain | uaiubifas.top | hind is GRAYRABBIT. The backdoor reaches its server at mail.uaiubifas[.]top on port 443, and the traffic there is plain TCP scrambled | China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor The Hacker News | · 6d ago |
| sha256 | 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 | dy running. Gen published the following indicators. SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 malicious DLL loader, written to disk as 7z.dll SHA-256 749 | China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor The Hacker News | · 6d ago |
| sha256 | 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e | a63 malicious DLL loader, written to disk as 7z.dll SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e encrypted payload file, named p SHA-256 d7a3c7eb94edc0e020f | China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor The Hacker News | · 6d ago |
| sha256 | d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a | 74d675a98662e02422e encrypted payload file, named p SHA-256 d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll Domain mail.uai | China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor The Hacker News | · 6d ago |
| domain | apimantax.otax.fun | Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and published as | Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files GBHackers | · 6d ago |
| url | https://apimantax[ | lution. Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and publ | Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files GBHackers | · 6d ago |
| domain | hunt.io | e automated campaigns was effectively less than three days. Hunt.io’s AttackCapture system crawled the attacker’s open director | UK Council Attack Linked to Mass Exploitation of SonicWall Flaw Security Affairs | · 6d ago |
| sha256 | 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b | ts. The SHA-256 of the Impacket binary the operator used is 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b , and the delivery IP was 95.181.173[.]36. The operator ran | UK Council Attack Linked to Mass Exploitation of SonicWall Flaw Security Affairs | · 6d ago |
| domain | linked4x.com | irectories. Security teams should also hunt for the domains linked4x[.]com , skipraid[.]com , and the observed Azure Blob Storage pa | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| domain | skipraid.com | the download of CastleLoader and CastleRAT components from skipraid[.]com , using the distinctive K8VGmQTrzX User-Agent string. Cas | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| sha256 | 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 | be05561f3a19c7fc2d08e38c97e1986bbc5 SHA256 of SloppyRAT DLL 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SHA256 of SloppyRAT DLL bdcf8fe230e23692b658b62b6547374e223 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| sha256 | 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 | 091743cf567396201eff7731f5475768f9a SHA256 of SloppyRAT DLL 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 SHA256 of SloppyRAT DLL ff142fc192daa2a83bc565e5b38ebbe0556 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| sha256 | 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a | vent. Indicators Of Compromise (IOCs) Indicator Description 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a SHA256 of SloppyRAT DLL 8774533134d9d1514106c4090a0c5bccab4 | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| sha256 | bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd | bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SHA256 of SloppyRAT DLL bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd SHA256 of SloppyRAT DLL Note: IP addresses and domains are | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| sha256 | ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 | bccab4550facdcfe03f4e02b9764343a990 SHA256 of SloppyRAT DLL ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SHA256 of SloppyRAT DLL 680c3a9f5fdddfcc34856c7a67d21bbdd2b | Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement GBHackers | · 6d ago |
| sha256 | 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 | 026-20079 91.214.78[.]118 UAT-11823 Netcat reverse-shell C2 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink ELF malware 43.204.2[.]142 UAT-1198 | Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware GBHackers | · 6d ago |
| sha256 | b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d | as MISP, VirusTotal, or your SIEM. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6f | Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware GBHackers | · 6d ago |
| sha256 | db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e | fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar JAR-based command executor 89.34.96[.]56 | Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware GBHackers | · 6d ago |
| domain | gitclone.org | -2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2026 | Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Blog | · 6d ago |
| sha1 | 513a907b69edffc3cb77a494da395178d21ef9bd | 026-42018/CVE-2026-42016 exploitation 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA1 of /tmp/.z payload 2026-09-06 2026-09-08 64.207.232[.] | Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Blog | · 6d ago |
| url | http://3.88.162[ | 026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second load of payload after CVE-2026-42018/ | Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Blog | · 6d ago |
| url | http://log.gitclone[ | loiting CVE-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2 | Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Blog | · 6d ago |
| ipv4 | 45.142.193.132 | irm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31. “The adversary went from an empty workspace t | Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script The Register · Security | · 7d ago |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | We've got one word for it, and it's usually the wrong one Cisco Talos | · 7d ago |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | We've got one word for it, and it's usually the wrong one Cisco Talos | · 7d ago |
| md5 | 9a47c4d379998ade2f8f99e23a630c06 | a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputat | We've got one word for it, and it's usually the wrong one Cisco Talos | · 7d ago |
| md5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat | We've got one word for it, and it's usually the wrong one Cisco Talos | · 7d ago |
| md5 | f3e82419a43220a7a222fc01b7607adc | 8fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://talosintelligence.com/talos_file_reputat | We've got one word for it, and it's usually the wrong one Cisco Talos | · 7d ago |
| sha256 | 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 | -QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://ta | We've got one word for it, and it's usually the wrong one Cisco Talos | · 7d ago |
| sha256 | 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 | 001.exe Detection Name: W32.9F1F11A708-100.SBX.TG** SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://ta | We've got one word for it, and it's usually the wrong one Cisco Talos | · 7d ago |
| sha256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | sample.exe Detection Name: W32.C4DD71E347-95.SBX.TG SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta | We've got one word for it, and it's usually the wrong one Cisco Talos | · 7d ago |
| sha256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta | We've got one word for it, and it's usually the wrong one Cisco Talos | · 7d ago |
| sha256 | c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 | 0055df5.dll Detection Name: Auto.90B145.282358.in02 SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://ta | We've got one word for it, and it's usually the wrong one Cisco Talos | · 7d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.