ZeroHour

Indicators of compromise

4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainlohnsteuerhilfe-aktuell-verein.deail address used to send campaign emails Email address info@lohnsteuerhilfe-aktuell-verein[.]de Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainlumalisboa.comaddress used to send campaign emails Email address no-reply@lumalisboa[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainmctci.comaddress used to send campaign emails Email address noreply@mctci[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainnuf.co.jpail address used to send campaign emails Email address info@nuf[.]co[.]jp Sender email address used to send campaign emails EmailHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainservice-nowinc.comrs of compromise (IoCs):- Type Indicator Description Domain service-nowinc[.]com Domain impersonating ServiceNow Email address gomez@serviHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domaintivityhealth.comail address used to send campaign emails Email address info@tivityhealth[.]com Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domaintovimbatista.ptail address used to send campaign emails Email address info@tovimbatista[.]pt Sender email address used to send campaign emails Email aHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
domainuinsure.co.ukassociated with a bank account Email address notifications@uinsure[.]co[.]uk Sender email address used to send campaign emails EmailHackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
Cyber Security News
· 6d ago
sha2567f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112clook ordinary. IOCs SHA-256 File Name File Type Description 7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c windirstat.exe PE32 executable; Inno Setup 6.7.1 installerResearchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
GBHackers
· 6d ago
sha256fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73at installer distributed through an SEO-poisoning campaign. fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 windirstat.tmp PE32 executable; unpacked Inno Setup stage UResearchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
GBHackers
· 6d ago
domainapimantax.otax.funbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically retrievedNew Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
Cyber Security News
· 6d ago
urlhttps://apimantax[cted outbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically rNew Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
Cyber Security News
· 6d ago
domaingitclone.orgxploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-42018/Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 6d ago
sha1513a907b69edffc3cb77a494da395178d21ef9bdmtp Second-stage payload download URL 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA-1 hash of /tmp/.z payload 2026-09-06 2026-09-08 64.207.Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 6d ago
urlhttp://3.88.162[026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second-stage payload download URL 2026-09-07Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 6d ago
urlhttp://log.gitclone[Actor IP exploiting CVE-2026-82329 2026-09-02 Not provided hxxp://log.gitclone[.]org:45678/smtp Payload download URL following CVE-2026-420Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 6d ago
domainbackup-ubt.s3.us-east-1.amazonaws.comws[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-east-1[.]amazonaws[.]com/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.bloHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainhostfxr.dllL URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/hostfxr[.]dll SloppyRAT DLL URL URL hxxps[://]backup-ubt[.]s3[.]us-eastHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainlinked4x.comfffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoaderHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainskipraid.comDomain finger.linked4x[.]com ClickFix script domain Domain skipraid[.]com CastleLoader domain URL hxxps[://]skipraid[.]com/dsVGmQTrHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainstro7121.blob.core.windows.netid[.]com/dsVGmQTrzX/default2 CastleLoader URL URL hxxps[://]stro7121[.]blob[.]core[.]windows[.]net/dpp1/config.py Python loader URL URL hxxps[://]stroHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domaintelephoneip.netible; DLLMemLoader/1.0) Python loader User-Agent Domain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRATHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domaintruesmart.orgDomain api.telephoneip[.]net SloppyRAT C2 domain Domain api.truesmart[.]org SloppyRAT C2 domain Note: IP addresses and domains are inHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
domainwindows.netm/hostfxr[.]dll SloppyRAT DLL URL Domain stro7121.blob.core.windows[.]net Python downloader C2 IP address 62.106.66[.]148:443 SloppHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha25600c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec382be8e1ddbebf3cdf4733cf989ba291f9013 SloppyRAT DLL SHA-256 00c116e498799dc831c8aeb602349296c4b9325535d674fe2b6e2e091878dcec SloppyRAT DLL SHA-256 93273ea09bd9df881a594db8cfe1b1bbc54f4Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha2561439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffdebdbecb3322453bdc41b2113427f9f92d32d2 SloppyRAT DLL SHA-256 1439990ff65364a0f608a322aa3a493bc1683cb5fc30cffc44948da29623fffd SloppyRAT DLL SHA-256 eaa52d2d6d4daf29157e8e813247fb2e92797Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha2562f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d25e0ee093541d99a9dba5f69a264f7f3054b19 SloppyRAT DLL SHA-256 2f3d95de716f330fad2330d8787ebdbecb3322453bdc41b2113427f9f92d32d2 SloppyRAT DLL SHA-256 1439990ff65364a0f608a322aa3a493bc1683Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha2563a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19a5bcbf9a287d4653de7b76051bde73a94d064 SloppyRAT DLL SHA-256 3a8994928f512fffcb32e117ac45e0ee093541d99a9dba5f69a264f7f3054b19 SloppyRAT DLL SHA-256 2f3d95de716f330fad2330d8787ebdbecb332Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec860f6d09ddb5be36cc1766a41d77c5b89d3a56 SloppyRAT DLL SHA-256 466f9b8dce77b3a026fe4f833aa4949784fb854bea4137e52609e857d439dec8 SloppyRAT DLL SHA-256 f534a957edec74d69081665309311b791b6d1Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha2564ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56d1d8b6e9847aa6b8613493e5bc233ece3d189 SloppyRAT DLL SHA-256 4ecb2d06510dfee1b67f5d9a68c60f6d09ddb5be36cc1766a41d77c5b89d3a56 SloppyRAT DLL SHA-256 466f9b8dce77b3a026fe4f833aa4949784fb8Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064e3b763bd4a4b0cdf59eeff981d8e307fcf316 SloppyRAT DLL SHA-256 518cd57a303ff7ac2b5c4c8439aa5bcbf9a287d4653de7b76051bde73a94d064 SloppyRAT DLL SHA-256 3a8994928f512fffcb32e117ac45e0ee09354Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f97374e2234f2a497b19d26637018a1839e6dfd SloppyRAT DLL SHA-256 607212cfe73c5c84b2dd95b2c0ff37a47f4c8aad08e6d5cbb7c19a62c6b765f9 SloppyRAT DLL SHA-256 7bb025b426ae6ccbc170fbca58634b8dd77a6Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SloppyRAT DLL SHA-256 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SloppyRAT DLL SHA-256 bdcf8fe230e23692b658b62b6547374e2234fHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha2566d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f901334b8dd77a61447e48dabe9c2e2fb0d339d8b7 SloppyRAT DLL SHA-256 6d50bb50d4e7d6ac36ca6d2761f382be8e1ddbebf3cdf4733cf989ba291f9013 SloppyRAT DLL SHA-256 00c116e498799dc831c8aeb602349296c4b93Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha2567bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7f37a47f4c8aad08e6d5cbb7c19a62c6b765f9 SloppyRAT DLL SHA-256 7bb025b426ae6ccbc170fbca58634b8dd77a61447e48dabe9c2e2fb0d339d8b7 SloppyRAT DLL SHA-256 6d50bb50d4e7d6ac36ca6d2761f382be8e1ddHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha2568774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a9900a091743cf567396201eff7731f5475768f9a SloppyRAT DLL SHA-256 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 SloppyRAT DLL SHA-256 ff142fc192daa2a83bc565e5b38ebbe05561fHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha25693273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b4649049296c4b9325535d674fe2b6e2e091878dcec SloppyRAT DLL SHA-256 93273ea09bd9df881a594db8cfe1b1bbc54f40f623f44427278ae96fb9b46490 SloppyRAT DLL SHA-256 971f25f84be88c4fd304d555b5e3da12f6b36Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d1b1bbc54f40f623f44427278ae96fb9b46490 SloppyRAT DLL SHA-256 971f25f84be88c4fd304d555b5e3da12f6b368e4b9ba0943961ff21ba6fa4d4d SloppyRAT DLL SHA-256 a13fcbb0870f2fabb7e0a8c757ee3b763bd4aHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha2569f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9as of compromise (IoCs):- Type Indicator Description SHA-256 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a SloppyRAT DLL SHA-256 8774533134d9d1514106c4090a0c5bccab455Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf3163da12f6b368e4b9ba0943961ff21ba6fa4d4d SloppyRAT DLL SHA-256 a13fcbb0870f2fabb7e0a8c757ee3b763bd4a4b0cdf59eeff981d8e307fcf316 SloppyRAT DLL SHA-256 518cd57a303ff7ac2b5c4c8439aa5bcbf9a28Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SloppyRAT DLL SHA-256 bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd SloppyRAT DLL SHA-256 607212cfe73c5c84b2dd95b2c0ff37a47f4c8Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d18960b937c7beaf9ab51b03191dfcaba40b7b189 SloppyRAT DLL SHA-256 c0ef62a2d5ca11c2eedad3561d5d1d8b6e9847aa6b8613493e5bc233ece3d189 SloppyRAT DLL SHA-256 4ecb2d06510dfee1b67f5d9a68c60f6d09ddbHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b1897fb2e92797324230ee42c79f7861b2f5c341d SloppyRAT DLL SHA-256 cb9930d0cde5bf8e8a7ad08fe2c60b937c7beaf9ab51b03191dfcaba40b7b189 SloppyRAT DLL SHA-256 c0ef62a2d5ca11c2eedad3561d5d1d8b6e984Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341da493bc1683cb5fc30cffc44948da29623fffd SloppyRAT DLL SHA-256 eaa52d2d6d4daf29157e8e813247fb2e92797324230ee42c79f7861b2f5c341d SloppyRAT DLL SHA-256 cb9930d0cde5bf8e8a7ad08fe2c60b937c7beHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb4949784fb854bea4137e52609e857d439dec8 SloppyRAT DLL SHA-256 f534a957edec74d69081665309311b791b6d11a3221fffa67744812d73ad98eb config.py Python script Domain finger.linked4x[.]com ClickFHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha256ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5c5bccab4550facdcfe03f4e02b9764343a990 SloppyRAT DLL SHA-256 ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SloppyRAT DLL SHA-256 680c3a9f5fdddfcc34856c7a67d21bbdd2b47Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Cyber Security News
· 6d ago
sha25613382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4nd execute an ARM payload named vlxx.arm, with SHA-256 hash 13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4. Staging markers including condi72 and condixx link the delNew IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
GBHackers
· 6d ago
sha2566fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f634b8031ec254d98b876e59692b5fa22abc1d4 SHA-256 Hash (ARM32) 6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f SHA-256 Hash (ARM32) 9d87e6615c810907443ebd5e915f3b35099c3bNew IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
GBHackers
· 6d ago
sha2569d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d55f3b35099c3b5c6b6c684637138a7f8ec9cebc SHA-256 Hash (AMD64) 9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5 IPv4 Address 160[.]191.242.92 Telnet credential brute-forceNew IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
GBHackers
· 6d ago
sha2569d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc2d548ce92dda71e82dc47e8efe13f30617f35f SHA-256 Hash (ARM32) 9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc SHA-256 Hash (AMD64) 9d7cd4948a1fcbaeadc425752fce9a933bd6fcNew IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
GBHackers
· 6d ago
sha256cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218imperfect. IOCs Indicator Type Value SHA-256 Hash (Loader) cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218 SHA-256 Hash (ARM32) 13382c16e2401b07451577b46e634b8031ec25New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
GBHackers
· 6d ago
domaingitclone.org.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / HashJFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 6d ago
sha1513a907b69edffc3cb77a494da395178d21ef9bdmtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a494da395178d21ef9bd Account 0xterror , svc_[a-zA-Z0-9]{8} , Nxploited_[a-zA-Z0-JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 6d ago
urlhttp://3.88.162[]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a4JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 6d ago
urlhttp://log.gitclone[[.]88 , 137.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / HaJFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 6d ago
domaindomainlify.nett in the fake invoice as a contact address. Another domain, domainlify[.]net, was used in Reply-To fields. The short preparation perioHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domaineemusicclass.co.ukuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email addressHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainlifeones.cominfo@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com Email address Sender email address used to send out emailHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainlohnsteuerhilfe-aktuell-verein.deumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk infHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainlumalisboa.comications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainmctci.comk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainnuf.co.jpth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatiHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainservice-nowinc.comonsumer goods’ and others (Source : Microsoft). One domain, service-nowinc[.]com, was registered on July 31, shortly before the phishing aHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domaintivityhealth.comated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domaintovimbatista.ptnuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]com EmailHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainuinsure.co.ukss Email address associated with bank account notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com norepHackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.
GBHackers
· 6d ago
domainnoht1ng.topil.uaiubifas[.]top backdoor command server, port 443 Domain noht1ng[.]top hosted the exploit page IP 8.218.50[.]207 staging server,China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 6d ago
domainuaiubifas.tophind is GRAYRABBIT. The backdoor reaches its server at mail.uaiubifas[.]top on port 443, and the traffic there is plain TCP scrambledChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 6d ago
sha25629c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63dy running. Gen published the following indicators. SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 malicious DLL loader, written to disk as 7z.dll SHA-256 749China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 6d ago
sha256749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422ea63 malicious DLL loader, written to disk as 7z.dll SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e encrypted payload file, named p SHA-256 d7a3c7eb94edc0e020fChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 6d ago
sha256d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a74d675a98662e02422e encrypted payload file, named p SHA-256 d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll Domain mail.uaiChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
The Hacker News
· 6d ago
domainapimantax.otax.funMantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and published asMantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
GBHackers
· 6d ago
urlhttps://apimantax[lution. Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and publMantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
GBHackers
· 6d ago
domainhunt.ioe automated campaigns was effectively less than three days. Hunt.io’s AttackCapture system crawled the attacker’s open directorUK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Security Affairs
· 6d ago
sha256690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5bts. The SHA-256 of the Impacket binary the operator used is 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b , and the delivery IP was 95.181.173[.]36. The operator ranUK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Security Affairs
· 6d ago
domainlinked4x.comirectories. Security teams should also hunt for the domains linked4x[.]com , skipraid[.]com , and the observed Azure Blob Storage paHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 6d ago
domainskipraid.comthe download of CastleLoader and CastleRAT components from skipraid[.]com , using the distinctive K8VGmQTrzX User-Agent string. CasHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 6d ago
sha256680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21be05561f3a19c7fc2d08e38c97e1986bbc5 SHA256 of SloppyRAT DLL 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 SHA256 of SloppyRAT DLL bdcf8fe230e23692b658b62b6547374e223Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 6d ago
sha2568774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990091743cf567396201eff7731f5475768f9a SHA256 of SloppyRAT DLL 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 SHA256 of SloppyRAT DLL ff142fc192daa2a83bc565e5b38ebbe0556Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 6d ago
sha2569f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9avent. Indicators Of Compromise (IOCs) Indicator Description 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a SHA256 of SloppyRAT DLL 8774533134d9d1514106c4090a0c5bccab4Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 6d ago
sha256bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfdbbdd2b47d70bdfb829ff59cfa0e3bc72d21 SHA256 of SloppyRAT DLL bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd SHA256 of SloppyRAT DLL Note: IP addresses and domains areHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 6d ago
sha256ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5bccab4550facdcfe03f4e02b9764343a990 SHA256 of SloppyRAT DLL ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 SHA256 of SloppyRAT DLL 680c3a9f5fdddfcc34856c7a67d21bbdd2bHackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
GBHackers
· 6d ago
sha2566f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461026-20079 91.214.78[.]118 UAT-11823 Netcat reverse-shell C2 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink ELF malware 43.204.2[.]142 UAT-1198Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
GBHackers
· 6d ago
sha256b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77das MISP, VirusTotal, or your SIEM. IOC Cluster Description b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6fCritical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
GBHackers
· 6d ago
sha256db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8efd0fdfd07162cb4eb2acbef77d UAT-12197 home.jsp JSP web shell db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd.jar JAR-based command executor 89.34.96[.]56Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
GBHackers
· 6d ago
domaingitclone.org-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2026Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 6d ago
sha1513a907b69edffc3cb77a494da395178d21ef9bd026-42018/CVE-2026-42016 exploitation 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA1 of /tmp/.z payload 2026-09-06 2026-09-08 64.207.232[.]Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 6d ago
urlhttp://3.88.162[026-42018/CVE-2026-42016 exploitation 2026-09-06 2026-09-08 hxxp://3.88.162[.]79:36789/smtp Second load of payload after CVE-2026-42018/Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 6d ago
urlhttp://log.gitclone[loiting CVE-2026-42018/CVE-2026-42016 2026-08-28 2026-09-07 hxxp://log.gitclone[.]org:45678/smtp Payload download after CVE-2026-42018/CVE-2Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 6d ago
ipv445.142.193.132irm GreyNoise, which traced the campaign’s orchestration to 45.142.193.132 on August 31. “The adversary went from an empty workspace tHundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
The Register · Security
· 7d ago
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 7d ago
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 7d ago
md59a47c4d379998ade2f8f99e23a630c06a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputatWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 7d ago
md5c2efb2dcacba6d3ccc175b6ce1b7ed0ae6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputatWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 7d ago
md5f3e82419a43220a7a222fc01b7607adc8fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://talosintelligence.com/talos_file_reputatWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 7d ago
sha2565bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811-QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 7d ago
sha25690b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59001.exe Detection Name: W32.9F1F11A708-100.SBX.TG** SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 7d ago
sha2569896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7fsample.exe Detection Name: W32.C4DD71E347-95.SBX.TG SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 7d ago
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 7d ago
sha256c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b20055df5.dll Detection Name: Auto.90B145.282358.in02 SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://taWe've got one word for it, and it's usually the wrong one
Cisco Talos
· 7d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.