ZeroHour

Indicators of compromise

4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainduckdns.orgd for data exfiltration troubleshooting Domain m-doxa-apodo.duckdns[.]org Mexican campaign infrastructure domain Domain m-doxa-geo.Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 7d ago
sha25646ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899crprint associated with 178.128.87[.]160 Certificate SHA-256 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c Certificate fingerprint associated with 178.128.87[.]160 FiHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 7d ago
sha2564e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5erprint associated with 165.22.184[.]26 Certificate SHA-256 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 Certificate fingerprint associated with 178.128.87[.]160 CeHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 7d ago
sha2567d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8SockTz installers and campaign scripts Certificate SHA-256 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 Certificate fingerprint associated with 165.22.184[.]26 CerHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 7d ago
sha25687bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172eczilian financial campaign malware or tool hash File SHA-256 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec Brazilian financial campaign malware or tool hash URL hxxp[Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 7d ago
sha256a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996e fingerprint associated with 178.128.87[.]160 File SHA-256 a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 Brazilian financial campaign malware or tool hash File SHA-Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 7d ago
urlhttp://167.148.195[172ec Brazilian financial campaign malware or tool hash URL hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Download location for SockTz versiHackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Cyber Security News
· 7d ago
md59678f71ea4cccbc3d511dc8d7f24b113b68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5fHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers
· 7d ago
sha159508d071661ea70fa5fcbe6f9e2fb72506e57dfcbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df Native Mach-O Stager Binary Code Signing ID com.utils.LauncHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers
· 7d ago
sha1d182eb7cba0ffa42d770d7b0d3499e49f24163a2om.utils.Launcher Ad-hoc signature bundle identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code Directory Hash Note: IP addresses and domains are inteHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers
· 7d ago
sha2569ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11stores. IOCs Indicator Type Value Description SHA-256 Hash 9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dcHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers
· 7d ago
domainduckdns.orgcate SHA-256 Fingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f6377Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers
· 7d ago
sha25646ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899cingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb1162Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers
· 7d ago
sha2564e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers
· 7d ago
sha2567d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 165.22.184[.]26 Note: IP addresses and domains are intentioHackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
GBHackers
· 7d ago
domainnetlas.ioCut software and an Active Directory server. They also used Netlas.io to compile lists of potential targets. After validating theHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
ipv445.142.193.132he actors utilized infrastructure, including the IP address 45.142.193.132, which GreyNoise had tracked since early July for attacks aHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
ipv445.158.196.75paign orchestration and execution infrastructure IP address 45.158.196.75 Infrastructure used to execute campaign activity File hashHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
md5528cd4e69ecfa5191adbcf6ef28667bfInfrastructure used to execute campaign activity File hash 528cd4e69ecfa5191adbcf6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8dHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
md5974decb9ff4c8f9ccb0937c96d513347sa_collect_small.exe — Rust LSA bootkey collector File hash 974decb9ff4c8f9ccb0937c96d513347 certipy.exe — Active Directory Certificate Services abuse tHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
md5a6437ac3d6798090a218520985d36a3f687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d6798090a218520985d36a3f collect_custom.exe — Rust custom collection tool File hashHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
md5ce870a91e8d27e8f663f0687abc60b04f6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d27e8f663f0687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d67Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
md5fc92dfafa7aa741c5f2b9cbcf75d1d19collect_custom.exe — Rust custom collection tool File hash fc92dfafa7aa741c5f2b9cbcf75d1d19 lsa_collect_small.exe — Rust LSA bootkey collector File hasHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
urlhttp://45.142.193[ing followed by Base64 encoding using certutil Download URL hxxp://45.142.193[.]132:8000/lsa_collect.exe Download location for LSA bootkeyHackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
GBHackers
· 7d ago
domainattcdn.comom Domain TA412 delivery and download domain September 2026 attcdn[.]com Domain TA412 delivery and download domain September 2026China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
domainmsbenefit.com.]com Domain TA412 delivery and download domain August 2026 msbenefit[.]com Domain TA412 delivery and download domain September 2026China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
domainsecboxes.com26c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA412 delivery and download domain August 2026 msbChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
domainworkers.devd URL August 2026 extension-management-portal.centerfjdr658.workers[.]dev Hostname GemStone browser extension C&C August 2026 extenChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
sha256353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA41China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
sha256779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096dploitation. Ioc TA412 Indicator Type Description First Seen 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d SHA256 driver-html.js(BlueMoon exploit JavaScript) August 2China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
sha2567d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f8228809fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
sha256e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f0041f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16cChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
sha256ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b256 driver-html.js(BlueMoon exploit JavaScript) August 2026 ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a4China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
urlhttps://api-prod.secboxes[ad.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-prod.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
urlhttps://download.secboxes[ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://download.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
urlhttps://evidence.msbenefit[od.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidence.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zkiChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
urlhttps://project.secboxes[n[.]com Hostname TA412 BlueMoon exploit page September 2026 hxxps://project.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
urlhttps://recommendation-letter.secboxes[ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
urlhttps://zki0y83.msbenefit[.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki0y83.msbenefit[.]com:443/feed URL Download URL August 2026 extension-manageChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers
· 7d ago
domainbloom.ios. Teams loads a resource hosted on an external domain, cdn.bloom[.]io, which ultimately results in the phishing page being rendCybercriminals are building phishing pages that exist only inside victims’ browsers
Help Net Security
· 7d ago
ipv49.20.4.14ewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions UCisco security advisory (AV26-197) – Update 3
Canadian Centre for Cyber Security
· 8d ago
ipv462.60.130.193ll log failed login attempts with a 401 status code: ::ffff:62.60.130.193 - - [09/09/2026:15:26:14 +0000] "POST /api2/json/access/ticScans for Proxmox Servers, (Wed, Sep 9th)
SANS Internet Storm Center
· 8d ago
domainadd-passkey.comlpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkey[.]com† SSO and identity provider integratedsso[.]com†, oktasessPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domaincompanyname.maliciousdomain.comuman trust. The actor creates domains following the pattern companyname[.]maliciousdomain[.]com to impersonate organization-specific authentication porPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domaincontoso.add-passkey.comcan persuade users to proceed with authentication. Example: contoso[.]add-passkey[.]com . The me Domain examples, defanged Passkey passkeyhelpdPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainintegratedsso.comtrar involvement in the activity. For example, company-name.integratedsso[.]com and company-name.secure-passkey[.]com illustrate how thePasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainkeysyncos.comsso[.]com†, oktasession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com,Passkey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainmyconnectkey.comom, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetuPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainoktasession.comskey[.]com† SSO and identity provider integratedsso[.]com†, oktasession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[Passkey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainoskeyconnect.com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetupac[.]com, portalsetPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainoskeyregister.comization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]comPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainoskeysetup.comsetup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]comPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainoskeysync.comession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com,Passkey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainpasskeyhelpdesk.comdd-passkey[.]com . The me Domain examples, defanged Passkey passkeyhelpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkePasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainportalsetuphub.comnnect[.]com Setup and verification validationsetupac[.]com, portalsetuphub[.]com Step 3-4 : User identity compromise From one sign-in to bPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainsecure-passkey.comexample, company-name.integratedsso[.]com and company-name.secure-passkey[.]com illustrate how the same company name can appear under difPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainsetupmypasskey.comanged Passkey passkeyhelpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkey[.]com† SSO and identity provider integratedPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainsyncmykey.comom, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verificPasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domainvalidationsetupac.comconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetupac[.]com, portalsetuphub[.]com Step 3-4 : User identity compromisePasskey-themed social engineering leads to identity and cloud compromise
Microsoft Security Blog
· 8d ago
domaincmd.jarsame directory. The threat actors used the JAR file (named “cmd[.]jar”) to query the compromised systems’ internal databases toActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 8d ago
domainhome.jsp25a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6f6daa90c6879911cd89Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 8d ago
domainjava.ioand line and executes it using /bin/sh -c <command>. import java.io.BufferedReader; import java.io.InputStreamReader; public clActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 8d ago
domainlicense.tmp“package_info.pl” to execute an attacker-crafted malicious “license[.]tmp” file with root privileges. The malicious file consistedActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 8d ago
sha2566f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe4619. 91.214.78[.]118 UAT-11823 NetCat-based reverse shell C2. 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware. 43.204.2[.]142 UAT-11988 AActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 8d ago
sha256b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77dble on our GitHub repository here . IOC Cluster Description B037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 8d ago
sha256db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8ed0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd[.]jar – JAR-based command executor. 89.34.96[Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos
· 8d ago
ipv445.142.193.132nfrastructure. The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for probHackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide
Cyber Security News
· 8d ago
domainbsc.rpc.blxrbdn.come-loaded by the Chrome component BNB Smart Chain RPC domain bsc[.]rpc[.]blxrbdn[.]com RPC endpoint queried by ZigCryptoStealer BNB Smart ChClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainbsc-testnet-rpc.publicnode.comCs):- Type Indicator Description BNB Smart Chain RPC domain bsc-testnet-rpc[.]publicnode[.]com RPC service queried by the initial ClearFake browser scClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainfd.gstats-api-contact.cced by ZigCryptoStealer to obtain C2 configuration C2 domain fd[.]gstats-api-contact[.]cc Historical ZigCryptoStealer contract value C2 domain pkClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domaingithub.comaddress for the verification.google branch TLS SNI and Host github[.]com Hostname presented by the verification.google Amatera buiClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainhub.logwerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by the PowerShell installer SHA-256ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainjewel.jsproxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload for the verification.googleClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainkffd3.vexlatech.ccr[.]cc Historical ZigCryptoStealer contract value C2 domain kffd3[.]vexlatech[.]cc Historical ZigCryptoStealer contract value C2 domain stClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainkffd3.vogueatelier.ccr[.]cc Historical ZigCryptoStealer contract value C2 domain kffd3[.]vogueatelier[.]cc Historical ZigCryptoStealer contract value C2 domain kfClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainkr.cedar2glanz.runt for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload for the verificClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainlb.propertyfind.cct[.]cc Historical ZigCryptoStealer contract value C2 domain lb[.]propertyfind[.]cc ZigCryptoStealer C2 domain returned during analysis DriClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainleaguejazire.com1fEb11A5 macOS-specific second-stage contract WebDAV domain leaguejazire[.]com Randomized subdomains used for Windows WebDAV delivery DoClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainpaternal-angrily.comion file for the remote-access client Remote-access gateway paternal-angrily[.]com:443 Configured remote-access HTTP gateway IPv4 address 21ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainphys.stunned-amniotic.comverification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by the PowerShell instaClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainpkg.vogueatelier.cct[.]cc Historical ZigCryptoStealer contract value C2 domain pkg[.]vogueatelier[.]cc Historical ZigCryptoStealer contract value C2 domain kfClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainriyazinikokar.xyzndomized subdomains used for Windows WebDAV delivery Domain riyazinikokar[.]xyz macOS ClickFix request infrastructure File name pf.ch WebClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainstatic.quorashift.cch[.]cc Historical ZigCryptoStealer contract value C2 domain static[.]quorashift[.]cc Historical ZigCryptoStealer contract value C2 domain lbClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domaintelegra.phbserved at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch toClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
domainupdate.dubbedmuch.cced Go-based reverse TCP proxy executable WebSocket C2 wss://update[.]dubbedmuch[.]cc/ Hard-coded C2 endpoint for the reverse TCP proxy PowerClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
sha2561819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25ode payload used to deploy the Go reverse TCP proxy SHA-256 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25 Unpacked Go-based reverse TCP proxy executable WebSocket C2ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
sha256279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92ation.google Amatera build during C2 communications SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 ZIP archive containing the DLL side-loading package File naClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
sha256643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205ce\DCRCVDRV_U Driver device exposed by DCRCVDrv.sys SHA-256 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205 Shellcode payload used to deploy the Go reverse TCP proxy SClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
sha256bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69bg ZIP payload retrieved by the PowerShell installer SHA-256 bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b ZIP archive containing the unauthorized remote-access deploClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
urlhttps://kr[2 endpoint for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload fClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
urlhttps://phys[for the verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved byClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
urlhttps://telegra[loader observed at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branchClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools
Cyber Security News
· 8d ago
sha256123289b3680c1d693db0e3702137cc55862dbe8b9a34376bcdf08bd0514b98e7s of compromise (IoCs):- Type Indicator Description SHA-256 123289b3680c1d693db0e3702137cc55862dbe8b9a34376bcdf08bd0514b98e7 NodeRabbit-related sample identified by PolySwarm SHA-256 3Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs
Cyber Security News
· 8d ago
sha256307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd007 NodeRabbit-related sample identified by PolySwarm SHA-256 307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00 NodeRabbit-related sample identified by PolySwarm Note: IPHackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs
Cyber Security News
· 8d ago
domainclck.rut file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp , where it confirms that it has an internet connecGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domaindiscord.comend the information it steals to the following URL: https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-YGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domainflow.lavasoft.comle-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwaGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domainngrok.ioto secure tunneling services provided by ngrok at 7.tcp.eu.ngrok[.]io:12684 . Three more copies of NJRAT ( license.exe , rockstGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domaintelemetry.servers.getgo.com0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0.Grand Theft Auto VI hype leads to malware
Huntress
· 8d ago
domainxsph.ruand then deletes itself. The RAT then connects to a0700877.xsph[.]ru ( 141.8.197[.]42 ). This domain has been on blocklists foGrand Theft Auto VI hype leads to malware
Huntress
· 8d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.