Indicators of compromise
4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | duckdns.org | d for data exfiltration troubleshooting Domain m-doxa-apodo.duckdns[.]org Mexican campaign infrastructure domain Domain m-doxa-geo. | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| sha256 | 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c | rprint associated with 178.128.87[.]160 Certificate SHA-256 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c Certificate fingerprint associated with 178.128.87[.]160 Fi | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| sha256 | 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 | erprint associated with 165.22.184[.]26 Certificate SHA-256 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 Certificate fingerprint associated with 178.128.87[.]160 Ce | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| sha256 | 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 | SockTz installers and campaign scripts Certificate SHA-256 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 Certificate fingerprint associated with 165.22.184[.]26 Cer | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| sha256 | 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec | zilian financial campaign malware or tool hash File SHA-256 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec Brazilian financial campaign malware or tool hash URL hxxp[ | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| sha256 | a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 | e fingerprint associated with 178.128.87[.]160 File SHA-256 a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 Brazilian financial campaign malware or tool hash File SHA- | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| url | http://167.148.195[ | 172ec Brazilian financial campaign malware or tool hash URL hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Download location for SockTz versi | Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks Cyber Security News | · 7d ago |
| md5 | 9678f71ea4cccbc3d511dc8d7f24b113 | b68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5f | Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security. GBHackers | · 7d ago |
| sha1 | 59508d071661ea70fa5fcbe6f9e2fb72506e57df | cbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df Native Mach-O Stager Binary Code Signing ID com.utils.Launc | Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security. GBHackers | · 7d ago |
| sha1 | d182eb7cba0ffa42d770d7b0d3499e49f24163a2 | om.utils.Launcher Ad-hoc signature bundle identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code Directory Hash Note: IP addresses and domains are inte | Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security. GBHackers | · 7d ago |
| sha256 | 9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11 | stores. IOCs Indicator Type Value Description SHA-256 Hash 9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dc | Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security. GBHackers | · 7d ago |
| domain | duckdns.org | cate SHA-256 Fingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f6377 | Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America GBHackers | · 7d ago |
| sha256 | 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c | ingerprint Corresponding Host/IP m-doxa-apodo.duckdns[.]org 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb1162 | Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America GBHackers | · 7d ago |
| sha256 | 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 | bec02f63776d3899c 178.128.87[.]160 m-doxa-geo.duckdns[.]org 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542 | Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America GBHackers | · 7d ago |
| sha256 | 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 | b83c0e863a8fee5 178.128.87[.]160 m-doxa-intel.duckdns[.]org 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 165.22.184[.]26 Note: IP addresses and domains are intentio | Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America GBHackers | · 7d ago |
| domain | netlas.io | Cut software and an Active Directory server. They also used Netlas.io to compile lists of potential targets. After validating the | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| ipv4 | 45.142.193.132 | he actors utilized infrastructure, including the IP address 45.142.193.132, which GreyNoise had tracked since early July for attacks a | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| ipv4 | 45.158.196.75 | paign orchestration and execution infrastructure IP address 45.158.196.75 Infrastructure used to execute campaign activity File hash | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| md5 | 528cd4e69ecfa5191adbcf6ef28667bf | Infrastructure used to execute campaign activity File hash 528cd4e69ecfa5191adbcf6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| md5 | 974decb9ff4c8f9ccb0937c96d513347 | sa_collect_small.exe — Rust LSA bootkey collector File hash 974decb9ff4c8f9ccb0937c96d513347 certipy.exe — Active Directory Certificate Services abuse t | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| md5 | a6437ac3d6798090a218520985d36a3f | 687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d6798090a218520985d36a3f collect_custom.exe — Rust custom collection tool File hash | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| md5 | ce870a91e8d27e8f663f0687abc60b04 | f6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d27e8f663f0687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d67 | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| md5 | fc92dfafa7aa741c5f2b9cbcf75d1d19 | collect_custom.exe — Rust custom collection tool File hash fc92dfafa7aa741c5f2b9cbcf75d1d19 lsa_collect_small.exe — Rust LSA bootkey collector File has | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| url | http://45.142.193[ | ing followed by Base64 encoding using certutil Download URL hxxp://45.142.193[.]132:8000/lsa_collect.exe Download location for LSA bootkey | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 7d ago |
| domain | attcdn.com | om Domain TA412 delivery and download domain September 2026 attcdn[.]com Domain TA412 delivery and download domain September 2026 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| domain | msbenefit.com | .]com Domain TA412 delivery and download domain August 2026 msbenefit[.]com Domain TA412 delivery and download domain September 2026 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| domain | secboxes.com | 26c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA412 delivery and download domain August 2026 msb | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| domain | workers.dev | d URL August 2026 extension-management-portal.centerfjdr658.workers[.]dev Hostname GemStone browser extension C&C August 2026 exten | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| sha256 | 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee | 3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA41 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| sha256 | 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d | ploitation. Ioc TA412 Indicator Type Description First Seen 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d SHA256 driver-html.js(BlueMoon exploit JavaScript) August 2 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| sha256 | 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 | 09fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| sha256 | e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 | 1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16c | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| sha256 | ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b | 256 driver-html.js(BlueMoon exploit JavaScript) August 2026 ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a4 | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| url | https://api-prod.secboxes[ | ad.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-prod.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evid | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| url | https://download.secboxes[ | ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://download.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api- | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| url | https://evidence.msbenefit[ | od.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidence.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| url | https://project.secboxes[ | n[.]com Hostname TA412 BlueMoon exploit page September 2026 hxxps://project.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps:// | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| url | https://recommendation-letter.secboxes[ | ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps:// | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| url | https://zki0y83.msbenefit[ | .msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki0y83.msbenefit[.]com:443/feed URL Download URL August 2026 extension-manage | China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks GBHackers | · 7d ago |
| domain | bloom.io | s. Teams loads a resource hosted on an external domain, cdn.bloom[.]io, which ultimately results in the phishing page being rend | Cybercriminals are building phishing pages that exist only inside victims’ browsers Help Net Security | · 7d ago |
| ipv4 | 9.20.4.14 | ewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions U | Cisco security advisory (AV26-197) – Update 3 Canadian Centre for Cyber Security | · 8d ago |
| ipv4 | 62.60.130.193 | ll log failed login attempts with a 401 status code: ::ffff:62.60.130.193 - - [09/09/2026:15:26:14 +0000] "POST /api2/json/access/tic | Scans for Proxmox Servers, (Wed, Sep 9th) SANS Internet Storm Center | · 8d ago |
| domain | add-passkey.com | lpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkey[.]com† SSO and identity provider integratedsso[.]com†, oktasess | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | companyname.maliciousdomain.com | uman trust. The actor creates domains following the pattern companyname[.]maliciousdomain[.]com to impersonate organization-specific authentication por | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | contoso.add-passkey.com | can persuade users to proceed with authentication. Example: contoso[.]add-passkey[.]com . The me Domain examples, defanged Passkey passkeyhelpd | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | integratedsso.com | trar involvement in the activity. For example, company-name.integratedsso[.]com and company-name.secure-passkey[.]com illustrate how the | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | keysyncos.com | sso[.]com†, oktasession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | myconnectkey.com | om, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetu | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | oktasession.com | skey[.]com† SSO and identity provider integratedsso[.]com†, oktasession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[ | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | oskeyconnect.com | , oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verification validationsetupac[.]com, portalset | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | oskeyregister.com | ization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | oskeysetup.com | setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | oskeysync.com | ession[.]com Key setup and synchronization keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | passkeyhelpdesk.com | dd-passkey[.]com . The me Domain examples, defanged Passkey passkeyhelpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passke | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | portalsetuphub.com | nnect[.]com Setup and verification validationsetupac[.]com, portalsetuphub[.]com Step 3-4 : User identity compromise From one sign-in to b | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | secure-passkey.com | example, company-name.integratedsso[.]com and company-name.secure-passkey[.]com illustrate how the same company name can appear under dif | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | setupmypasskey.com | anged Passkey passkeyhelpdesk[.]com, secure-passkey[.]com†, setupmypasskey[.]com†, add-passkey[.]com† SSO and identity provider integrated | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | syncmykey.com | om, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, oskeyconnect[.]com Setup and verific | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | validationsetupac.com | connectkey[.]com, oskeyconnect[.]com Setup and verification validationsetupac[.]com, portalsetuphub[.]com Step 3-4 : User identity compromise | Passkey-themed social engineering leads to identity and cloud compromise Microsoft Security Blog | · 8d ago |
| domain | cmd.jar | same directory. The threat actors used the JAR file (named “cmd[.]jar”) to query the compromised systems’ internal databases to | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 8d ago |
| domain | home.jsp | 25a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6f6daa90c6879911cd89 | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 8d ago |
| domain | java.io | and line and executes it using /bin/sh -c <command>. import java.io.BufferedReader; import java.io.InputStreamReader; public cl | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 8d ago |
| domain | license.tmp | “package_info.pl” to execute an attacker-crafted malicious “license[.]tmp” file with root privileges. The malicious file consisted | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 8d ago |
| sha256 | 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 | 9. 91.214.78[.]118 UAT-11823 NetCat-based reverse shell C2. 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware. 43.204.2[.]142 UAT-11988 A | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 8d ago |
| sha256 | b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d | ble on our GitHub repository here . IOC Cluster Description B037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6 | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 8d ago |
| sha256 | db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e | d0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp – web shell. Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd[.]jar – JAR-based command executor. 89.34.96[ | Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos | · 8d ago |
| ipv4 | 45.142.193.132 | nfrastructure. The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for prob | Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide Cyber Security News | · 8d ago |
| domain | bsc.rpc.blxrbdn.com | e-loaded by the Chrome component BNB Smart Chain RPC domain bsc[.]rpc[.]blxrbdn[.]com RPC endpoint queried by ZigCryptoStealer BNB Smart Ch | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | bsc-testnet-rpc.publicnode.com | Cs):- Type Indicator Description BNB Smart Chain RPC domain bsc-testnet-rpc[.]publicnode[.]com RPC service queried by the initial ClearFake browser sc | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | fd.gstats-api-contact.cc | ed by ZigCryptoStealer to obtain C2 configuration C2 domain fd[.]gstats-api-contact[.]cc Historical ZigCryptoStealer contract value C2 domain pk | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | github.com | address for the verification.google branch TLS SNI and Host github[.]com Hostname presented by the verification.google Amatera bui | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | hub.log | werShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by the PowerShell installer SHA-256 | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | jewel.js | proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload for the verification.google | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | kffd3.vexlatech.cc | r[.]cc Historical ZigCryptoStealer contract value C2 domain kffd3[.]vexlatech[.]cc Historical ZigCryptoStealer contract value C2 domain st | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | kffd3.vogueatelier.cc | r[.]cc Historical ZigCryptoStealer contract value C2 domain kffd3[.]vogueatelier[.]cc Historical ZigCryptoStealer contract value C2 domain kf | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | kr.cedar2glanz.ru | nt for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload for the verific | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | lb.propertyfind.cc | t[.]cc Historical ZigCryptoStealer contract value C2 domain lb[.]propertyfind[.]cc ZigCryptoStealer C2 domain returned during analysis Dri | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | leaguejazire.com | 1fEb11A5 macOS-specific second-stage contract WebDAV domain leaguejazire[.]com Randomized subdomains used for Windows WebDAV delivery Do | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | paternal-angrily.com | ion file for the remote-access client Remote-access gateway paternal-angrily[.]com:443 Configured remote-access HTTP gateway IPv4 address 21 | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | phys.stunned-amniotic.com | verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by the PowerShell insta | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | pkg.vogueatelier.cc | t[.]cc Historical ZigCryptoStealer contract value C2 domain pkg[.]vogueatelier[.]cc Historical ZigCryptoStealer contract value C2 domain kf | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | riyazinikokar.xyz | ndomized subdomains used for Windows WebDAV delivery Domain riyazinikokar[.]xyz macOS ClickFix request infrastructure File name pf.ch Web | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | static.quorashift.cc | h[.]cc Historical ZigCryptoStealer contract value C2 domain static[.]quorashift[.]cc Historical ZigCryptoStealer contract value C2 domain lb | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | telegra.ph | bserved at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch to | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| domain | update.dubbedmuch.cc | ed Go-based reverse TCP proxy executable WebSocket C2 wss://update[.]dubbedmuch[.]cc/ Hard-coded C2 endpoint for the reverse TCP proxy Power | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| sha256 | 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25 | ode payload used to deploy the Go reverse TCP proxy SHA-256 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25 Unpacked Go-based reverse TCP proxy executable WebSocket C2 | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| sha256 | 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 | ation.google Amatera build during C2 communications SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92 ZIP archive containing the DLL side-loading package File na | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| sha256 | 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205 | ce\DCRCVDRV_U Driver device exposed by DCRCVDrv.sys SHA-256 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205 Shellcode payload used to deploy the Go reverse TCP proxy S | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| sha256 | bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b | g ZIP payload retrieved by the PowerShell installer SHA-256 bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b ZIP archive containing the unauthorized remote-access deplo | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| url | https://kr[ | 2 endpoint for the reverse TCP proxy PowerShell payload URL hxxps://kr[.]cedar2glanz[.]ru/jewel[.]js Secondary PowerShell payload f | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| url | https://phys[ | for the verification.google branch PowerShell download URL hxxps://phys[.]stunned-amniotic[.]com/hub[.]log ZIP payload retrieved by | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| url | https://telegra[ | loader observed at the Ukrainian organization Dead-drop URL hxxps://telegra[.]ph/Functions-04-03 Public page used by the Amatera branch | ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools Cyber Security News | · 8d ago |
| sha256 | 123289b3680c1d693db0e3702137cc55862dbe8b9a34376bcdf08bd0514b98e7 | s of compromise (IoCs):- Type Indicator Description SHA-256 123289b3680c1d693db0e3702137cc55862dbe8b9a34376bcdf08bd0514b98e7 NodeRabbit-related sample identified by PolySwarm SHA-256 3 | Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs Cyber Security News | · 8d ago |
| sha256 | 307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00 | 7 NodeRabbit-related sample identified by PolySwarm SHA-256 307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00 NodeRabbit-related sample identified by PolySwarm Note: IP | Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs Cyber Security News | · 8d ago |
| domain | clck.ru | t file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp , where it confirms that it has an internet connec | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | discord.com | end the information it steals to the following URL: https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | flow.lavasoft.com | le-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwa | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | ngrok.io | to secure tunneling services provided by ngrok at 7.tcp.eu.ngrok[.]io:12684 . Three more copies of NJRAT ( license.exe , rockst | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | telemetry.servers.getgo.com | 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0. | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | xsph.ru | and then deletes itself. The RAT then connects to a0700877.xsph[.]ru ( 141.8.197[.]42 ). This domain has been on blocklists fo | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.