Indicators of compromise
4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| md5 | 0e39e8d7b641bcda4376ebbfeff7b12e | 18d1498bc3d904899d Yandex web browser %TEMP%\find.vbs MD5 : 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays a "license not found" message | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | 15eca4a3f7350423cf4db0b4c30d1968 | 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3 | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | 1ec9eff863dc4418d1498bc3d904899d | ansomware-encrypted files %TEMP%\YandexPackLoader.exe MD5 : 1ec9eff863dc4418d1498bc3d904899d Yandex web browser %TEMP%\find.vbs MD5 : 0e39e8d7b641bcda43 | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | 2a0834560ed3770fc33d7a42f8229722 | ckstargamescrashfixer.exe %TEMP%\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651 | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | 2a385fe7bed9899d77d05cb8e302d557 | a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers 35.157.111[.]131 3 | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | 57b9c56ef97a7ada98257b23577bf5e3 | rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3 | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | 60a0f58001ea7be538cd42b651924cc7 | 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | 6b49f24d5d5b49127476bc385565f8b0 | llation executable %TEMP%\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEM | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | 8da3fe3664d81226b0fb2a50a0537d4f | :\Users\Default\Local Settings\[RANDOM FILE NAME].exe MD5 : 8da3fe3664d81226b0fb2a50a0537d4f Copy of DCRAT and associated installation files 0.0.0.0 app | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | a15e280a3fd65dfaa243bbe2dbf45e97 | Compromise (IOCs) Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\checkinternetconnect | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | b9648ec8cc806e7661aabcfc91dc836c | MP%\gta6.exe %USERPROFILE%\AppData\Roaming\svchost.exe MD5: b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries read_it.txt Ransomware note left | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | dfdf5e5b78d2ec764c0e5641cf9a0d26 | IP address that DCRAT connects to %TEMP%\adminapp.exe MD5 : dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary https://discord[.]com/ | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| md5 | ea991bc9334b36a6b958f564ee716776 | 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associ | Grand Theft Auto VI hype leads to malware Huntress | · 8d ago |
| domain | leaguejazire.com | opens a WebDAV UNC path hosted on a randomized subdomain of leaguejazire[.]com , then launches the pf.ch loader through rundll32.exe usi | Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware GBHackers | · 8d ago |
| sha256 | 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 | 28a3eadc0b509386cae200993b33673b343c Gigabud sample SHA-256 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 Vwork sample SHA-256 66499653c0fff78d81db5dc319b9aaa0288dc5 | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 8d ago |
| sha256 | 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf | 1009dda5b93ed3d1cead527b02d1317426bc Gigabud sample SHA-256 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud sample SHA-256 9ca27df7938f12794bab0847434482955ca9 | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 8d ago |
| sha256 | 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c | 82955ca9adea714a34afd315c7a7be522611 Gigabud sample SHA-256 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud sample SHA-256 0710ca983741bf6a95db1b6960c1985e45b1 | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 8d ago |
| sha256 | 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc | 7986e52f913f4b5ff960ddea26075ff621ae Gigabud sample SHA-256 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud sample SHA-256 112fefc9348fa4acbb82d54d9688c96dd567 | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 8d ago |
| sha256 | 61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc | a73660c0ee810eb Modified banking application sample SHA-256 61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc Modified banking application sample Android package net.yy. | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 8d ago |
| sha256 | 66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb | c1985e45b10f276e5b26f4fae3157db283d1f3 Vwork sample SHA-256 66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb Modified banking application sample SHA-256 61274cf9f49e04e | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 8d ago |
| sha256 | 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 | c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud sample SHA-256 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud sample SHA-256 1f5d99864564c088a3260e54ad1728a3eadc | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 8d ago |
| sha256 | ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae | 1bc772c8383a4149d23a5425b13475e2d501 Gigabud sample SHA-256 ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud sample SHA-256 4fff28eecc0ab6303e4948df77671009dda5 | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 8d ago |
| sha256 | b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 | s of compromise (IoCs):- Type Indicator Description SHA-256 b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud sample SHA-256 ae6f6eeba2bd4cc948d24610d9447986e52f | Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection Cyber Security News | · 8d ago |
| domain | adoube.vu | email, which took them to a fake CAPTCHA lure (at https[://]adoube[.]vu/2a8ed9baefcd ). This phishing landing page displayed a fa | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | hosthiifran.screenconnect.com | was downloaded from the attacker-controlled infrastructure, hosthiifran[.]screenconnect[.]com . When the target opened their Downloads folder and exe | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | instance-uxh86b-relay.screenconnect.com | Client ( 9c1aea531ba4c511 ) configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com . The attacker used a legitimate ScreenConnect Trial Re | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | relay.goldenmelon.us | client ( d751818fd46e5ca9 ), configured to communicate with relay[.]goldenmelon[.]us . That client (again) used the native Windows command s | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | relay.illuminantgroup.net | lluminantgroup[.]net and was configured to communicate with relay[.]illuminantgroup[.]net . Both ScreenConnect clients were registered as Windows | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | scx.illuminantgroup.net | nConnect Client ( c19e38a20f1ba492 ), which downloaded from scx[.]illuminantgroup[.]net and was configured to communicate with relay[.]illumina | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | selectstructure.com.au | ed the malicious link in the message, which brought them to selectstructure[.]com[.]au/freedom/adobedocument.html . This domain uses the same | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | victory.mkc1.digitaloceanspaces.com | eader update ( AdbRdBkUpsStUp.msi ) and was downloaded from victory[.]mkc1[.]digitaloceanspaces[.]com . Once it was executed, the installer again led to th | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | wir.consultingics.com | d ScreenConnect client payload ( patch.msi ) from hxxps[://]wir[.]consultingics[.]com/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest&c=GO | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| sha256 | 41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b | ( 7c1d255d0efefde6 ) ScreenConnect.ClientSetup.exe SHA256: 41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b Initial payload: rogue ScreenConnect installer HideCursor.e | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| sha256 | 9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991 | sion binary ScreenConnect Client (9c1aea531ba4c511) SHA256: 9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991 Rogue RMM: initial ScreenConnect instance ScreenConnect Cli | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| sha256 | f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35 | ct instance ScreenConnect Client (7c1d255d0efefde6) SHA256: f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35 Rogue RMM: secondary rogue ScreenConnect instance Incident | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| sha256 | fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2 | yload: rogue ScreenConnect installer HideCursor.exe SHA256: fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2 Defense evasion binary ScreenConnect Client (9c1aea531ba4c5 | Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence Huntress | · 8d ago |
| domain | google.com | compromise (IoCs):- Type Indicator Description Domain docs.google[.]com Google-hosted documents and Sheets were used for lure hos | Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks Cyber Security News | · 8d ago |
| domain | obfuscator.io | or the fraudulent Google Docs lure document Tool or service Obfuscator[.]io JavaScript obfuscation service whose output patterns were | Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks Cyber Security News | · 8d ago |
| domain | paste.sh | and payload retrieval through the Visualization API Domain paste[.]sh Hosted first-stage JavaScript loader scripts used in the | Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks Cyber Security News | · 8d ago |
| domain | simpleswap.io | cy trading site targeted by the initial lure version Domain SimpleSwap[.]io Cryptocurrency trading site targeted by the later Tamperm | Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks Cyber Security News | · 8d ago |
| domain | swapzone.io | RL promoted for the Tampermonkey-based loader script Domain SwapZone[.]io Cryptocurrency trading site targeted by the initial lure | Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks Cyber Security News | · 8d ago |
| sha256 | 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 | 088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 Note: IP addresses and domains are intentionally defanged ( | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf | 6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud 9ca27df7938f12794bab0847434482955ca9adea714a34afd31 | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c | 2794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c Gigabud 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc | cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc Gigabud 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 | 4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf Gigabud 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 Gigabud 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae2009 | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae | 0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae Gigabud 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527 | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| sha256 | b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 | horized transfers. IOCs Malware Family SHA-256 Hash Gigabud b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 Gigabud ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960dde | GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks GBHackers | · 8d ago |
| domain | amazingshield.xyz | , redundant agent. This Python script is downloaded from aa.amazingshield[.]xyz . The installer downloads a legitimate Python distributio | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | atthelake.info | rring SEO Domain Search Keyword Victim IP Windows_10 Chrome atthelake[.]info hwidspoofer 5.xxx.xx.xxx Windows_10 Chrome atthelake[.]in | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | crowdstri.com | hostname and processor architecture. The Python agent used crowdstri[.]com as its C2 domain. This appears to be a deliberate typosqu | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | crowdstrike.com | its C2 domain. This appears to be a deliberate typosquat of crowdstrike[.]com , designed to blend into logs and evade quick security re | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | extentrack.com | t extracts and runs eld2.tmp which contacts the affiliate’s extentrack[.]com install tracker. eld2.tmp drops and loads Adblock.dll , w | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | mqsearch.com | : Search hijacking : Changes the default search provider to mqsearch[.]com , a domain that masquerades as a search engine Extension | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | noiseship.cfd | h affiliate ID CID=2855 . Second intrusion set : Browsed to noiseship[.]cfd , a domain registered just 39 days earlier, and downloade | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | pcsdkflyer.ca | ling, as well as file execution. The C2 server address, reg.pcsdkflyer[.]ca , is decoded from a 39-byte configuration blob using Base | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | stryper.info | rst part of Insomnia RAT is a Node.js agent downloaded from stryper[.]info/aa.js . While the prior variant targeted Windows, Linux a | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | voyagemist.space | This temporary file transmits an initial tracking beacon to voyagemist[.]space . This is another gating mechanism: depending on the stru | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Palo Alto Unit 42 | · 8d ago |
| domain | bloom.io | Teams, which then loads an external resource hosted on cdn.bloom[.]io. It is this resource that is converted by the browser int | New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser SecurityWeek | · 8d ago |
| ipv4 | 146.103.99.177 | Incident responders should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js fil | Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT GBHackers | · 8d ago |
| ipv4 | 46.151.29.58 | s should search for outbound sessions to 146.103.99.177 and 46.151.29.58, inspect the /tmp/ directory for .i.js files, and review ru | Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT GBHackers | · 8d ago |
| url | https://146[ | s. The initial stager downloads a second-stage payload from hxxps://146[.]103[.]99[.]177:8443/0c5b76709523, decodes it, and XOR-decr | Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT GBHackers | · 8d ago |
| sha256 | 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 | upgrade images. The SHA-256 hash of the analyzed sample is 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 . F5 has published remediation and compromise assessment gu | PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory Security Affairs | · 8d ago |
| domain | socket.ayakliborsa.net | pool endpoint used by botnet-deployed XMRig Domain and port socket.ayakliborsa.net:8081 Live operator-controlled hostname resolving to 188.245 | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 173.212.244.25 | IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA targets IP address 2 | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 188.245.99.156 | f compromise (IoCs):- Type Indicator Description IP address 188.245.99.156 Operator host used for rogue Redis replication, command-and | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 194.48.248.105 | Recurring WordPress exploitation target IP address and port 194.48.248.105:8081 Earlier open directory linked by cryptocurrency wallet | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 20.198.10.42 | target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed develo | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 213.6.207.123 | hip unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional observed development and QA tar | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 23.235.223.49 | 5 Additional observed development and QA targets IP address 23.235.223.49 Recurring WordPress exploitation target IP address and port | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 34.166.99.116 | eused QA or test target, ownership unconfirmed IP addresses 34.166.99.116 , 20.198.10.42 , 213.6.207.123 , 173.212.244.25 Additional | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 45.155.102.89 | stname> Victim check-in request pattern IP address and port 45.155.102.89:10128 Local mining pool proxy used on the operator host Dom | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 47.250.92.230 | -controlled hostname resolving to 188.245.99.156 IP address 47.250.92.230 Frequently reused QA or test target, ownership unconfirmed | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| sha256 | 420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a | identifier observed in the RDP certificate TLS fingerprint 420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a Pinned mining-pool certificate fingerprint in the newest pa | Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners Cyber Security News | · 8d ago |
| ipv4 | 15.1.10.8 | 0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nearly a year old. Ireland's N | F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News | · 8d ago |
| ipv4 | 16.1.6.1 | .0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15.1.10 15.1.10.8 The patch that fixes this is nea | F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News | · 8d ago |
| ipv4 | 17.5.1.3 | s. Versions known to be vulnerable Fixed in 17.5.0 - 17.5.1 17.5.1.3 17.1.0 - 17.1.2 17.1.3 16.1.0 - 16.1.6 16.1.6.1 15.1.0 - 15 | F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News | · 8d ago |
| sha256 | 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 | inding a socket under /run, or starting /bin/bash SHA-256 : 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 File, weak on its own : changes to the three .php3 scripts. | F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans The Hacker News | · 8d ago |
| domain | hunt.io | oop from believed-write to confirmed shell access (Source : Hunt.io). The flaw can allow a remote, unauthenticated attacker to | Massive Redis Cryptojacking Campaign Hijacks Thousands of Linux Servers GBHackers | · 8d ago |
| domain | moneroocean.stream | ocal mining pool/proxy used by the operator’s own host pool.moneroocean[.]stream:443 Domain:port Mining pool used by botnet-deployed XMRig | Massive Redis Cryptojacking Campaign Hijacks Thousands of Linux Servers GBHackers | · 8d ago |
| ipv4 | 45.142.193.132 | investigation. GreyNoise has been tracking malicious use of 45.142.193.132 since early July 2026 due to its use for attacks against in | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 8d ago |
| ipv4 | 45.158.196.75 | 45.142.193.132 Used to orchestrate and execute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667 | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 8d ago |
| md5 | 528cd4e69ecfa5191adbcf6ef28667bf | ute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0 | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 8d ago |
| md5 | 974decb9ff4c8f9ccb0937c96d513347 | f75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9ff4c8f9ccb0937c96d513347 (certipy.exe) ADCS Abuse Tool Administrator17 Adversary cre | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 8d ago |
| md5 | a6437ac3d6798090a218520985d36a3f | 27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 8d ago |
| md5 | ce870a91e8d27e8f663f0687abc60b04 | fa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a2185 | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 8d ago |
| md5 | fc92dfafa7aa741c5f2b9cbcf75d1d19 | a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c5f2b9cbcf75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9 | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 8d ago |
| domain | asp.net | Mode [7]. Deploy an EDR solution. Rotate SharePoint Server ASP.NET machine keys [8] and restart IIS using iisreset.exe . It is | 2026-004: Critical Vulnerability in SharePoint Exploited CERT-EU Advisories | · 9d ago |
| ipv4 | 20.12.5.3 | end of software maintenance); all versions 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.1 | 2026-002: Multiple Vulnerabilities in Cisco Products CERT-EU Advisories | · 9d ago |
| ipv4 | 20.12.6.1 | s 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.13 (end of software maintenance); all vers | 2026-002: Multiple Vulnerabilities in Cisco Products CERT-EU Advisories | · 9d ago |
| ipv4 | 20.15.4.2 | (end of software maintenance); all versions 20.15 up until 20.15.4.2; all versions 20.16 (end of software maintenance); all vers | 2026-002: Multiple Vulnerabilities in Cisco Products CERT-EU Advisories | · 9d ago |
| ipv4 | 20.9.8.2 | 9 (end of software maintenance); all versions 20.9 up until 20.9.8.2; all versions 20.11 (end of software maintenance); all vers | 2026-002: Multiple Vulnerabilities in Cisco Products CERT-EU Advisories | · 9d ago |
| domain | oast.site | s writable, and exfiltrates the data through requests to an oast.site subdomain, which is typically seen in security tests that u | Adobe fixes critical Magento zero-day exploited to backdoor servers BleepingComputer | · 9d ago |
| sha256 | 0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3 | 13d3a54ffb35caed529bff49055ec5 Malicious MSI loader package 0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3 Second-stage DLL (rundll32-loaded module) Note: IP addresse | Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs GBHackers | · 9d ago |
| sha256 | 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d | e compromised machine. IOCs Indicator (SHA-256) Description 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d Malicious MSI loader package (silent msiexec install) a4d14 | Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs GBHackers | · 9d ago |
| sha256 | a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676 | c389d Malicious MSI loader package (silent msiexec install) a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676 Malicious MSI loader package cc6d0f3f47afeba018173604e34f52 | Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs GBHackers | · 9d ago |
| sha256 | cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5 | f019d0110e31a44bb70fc77d1d1676 Malicious MSI loader package cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5 Malicious MSI loader package 0d2fc28af246f62f27e49207d1f64e | Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs GBHackers | · 9d ago |
| domain | itemrange.com | ystarting.com Historical Ethereum resolver C2 domain Domain itemrange.com Most recently recorded Ethereum resolver C2 domain URL http | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| domain | publisherresolution.com | sed address from April 2026, designated monitor-only Domain publisherresolution.com First C2 domain written to the Ethereum resolver contract D | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
| domain | resumeacceptable.com | C2 domain written to the Ethereum resolver contract Domain resumeacceptable.com Historical Ethereum resolver C2 domain Domain simultaneousl | Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain Cyber Security News | · 9d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.