Indicators of compromise
270 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| md5 | 41444d7018601b599beac0c60ed1bf83 | dceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 MD5: 41444d7018601b599beac0c60ed1bf83 Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 13d ago |
| md5 | 61e046145ee5cf45aeb033cd71e8b07c | d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 MD5: 61e046145ee5cf45aeb033cd71e8b07c Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 13d ago |
| md5 | 7bdbd180c081fa63ca94f9c22c457376 | 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 13d ago |
| md5 | 9a47c4d379998ade2f8f99e23a630c06 | a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 13d ago |
| md5 | 2ec37a7cc8daf20b10e1ad6221061ca5 | the malicious actor’s secure shell client hash fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5 showing an established session. Attempt number 6 shows a fa | Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd) SANS Internet Storm Center | · 14d ago |
| md5 | 3612f843a42db38f48f59d2a3597e19c | d75ee30 ” , uri =“/ ctrlt / DeviceUpgrade_1 ” , response =“ 3612f843a42db38f48f59d2a3597e19c ” , algorithm =“ MD5 ” , qop =“ auth ” , nc = 00000001 , cn | Home & Small Office Wireless Routers Exploited to Attack Gaming Servers Palo Alto Unit 42 | · Aug 18, 2026 |
| md5 | 88645cefb1f9ede0e336e3569d75ee30 | “ dslf - config ” , realm =“ HuaweiHomeGateway ” , nonce =“ 88645cefb1f9ede0e336e3569d75ee30 ” , uri =“/ ctrlt / DeviceUpgrade_1 ” , response =“ 3612f84 | Home & Small Office Wireless Routers Exploited to Attack Gaming Servers Palo Alto Unit 42 | · Aug 18, 2026 |
| md5 | f1c099d65bf94e009f5e65238caac468 | 18b34633f303949a0bb07282dedcd8e9dc Updated JenX Sample MD5: f1c099d65bf94e009f5e65238caac468 SHA256: 676813ee73d382c08765a75204be8bab6bea730ff0073de1076 | Home & Small Office Wireless Routers Exploited to Attack Gaming Servers Palo Alto Unit 42 | · Aug 18, 2026 |
| md5 | fb93601f8d4e0228276edff1c6fe635d | tinuity. Indicators of Compromise Original JenX sample MD5: fb93601f8d4e0228276edff1c6fe635d SHA256: 04463cd1a961f7cd1b77fe6c9e9f5e18b34633f303949a0bb07 | Home & Small Office Wireless Routers Exploited to Attack Gaming Servers Palo Alto Unit 42 | · Aug 18, 2026 |
| md5 | 79ad2084b057847ce2ec2e48fda64073 | 80154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2 MD5 79ad2084b057847ce2ec2e48fda64073 Compile Date 2017-12-22 11:54:03 UTC One of the first modif | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | dd1876848203d9e10abceec07282ff37 | d using AES-128 and the following static key (hex-encoded): DD1876848203D9E10ABCEEC07282FF37 Conclusion The Patchwork group continues to plague victims | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | e3e7e71a0b28b5e96cc492e636722f73 | cation with the C2 (note the additional forward slashes): //e3e7e71a0b28b5e96cc492e636722f73//4sVKAOvu3D//ABDYot0NxyG.php In the event data is uploaded | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 6fa5bcedaf124cdaccfa5548eed7f4b0 | 4d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-14 07:20:11 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 7c65565dcf5b40bd8358472d032bc8fb | 32e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-25 00:54:18 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | a5164c686c405734b7362bc6b02488cb | f9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-28 01:54:40 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | d5679158937ce288837efe62bc1d9693 | a473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-02 07:57:38 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 7cc0b212d1b8ceb808c250495d83bae4 | remainder of the analysis, the following file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 8d42c01180be7588a2a68ad96dd0cf85 | remainder of the analysis, the following file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a79 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | a1bdb1889d960e424920e57366662a59 | remainder of the analysis, the following file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef42 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 76429f8515768f9f5def697e71071f51 | l 80386, for MS Windows Architecture : 32 Bits binary MD5 : 76429f8515768f9f5def697e71071f51 SHA1 : d04ce934561934f758d77dfa944bd6743dd82cff SHA256: 775 | New Malware 'Rover' Targets Indian Ambassador to Afghanistan Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | b5aa366f452feb9f4dff3c72157ca1f9 | LuO7bIWjRO5gjPNq:JarSKu6yzoF8rpAqXYv3XOgQLfnpLuOu imphash : b5aa366f452feb9f4dff3c72157ca1f9 Date : 0x5637227B [Mon Nov 2 08:44:43 2015 UTC] Language : | New Malware 'Rover' Targets Indian Ambassador to Afghanistan Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 41ee612602833345fc5bd2b98103811c | hash value of the string, MD5("Test_PC0B0D040612345678") = 41EE612602833345FC5BD2B98103811C It then appends the volume serial to the hash value and get | Analysis of Smoke Loader in New Tsunami Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 05d43d417a8f50e7b23246643fc7e03d | After decryption, the following payload was identified: MD5 05d43d417a8f50e7b23246643fc7e03d SHA1 67c05b3937d94136eda4a60a2d5fb685abc776a1 SHA256 3fee06 | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 0f1d3ed85fee2acc23a8a26e0dc12e0f | tion is provided after it is decrypted by the malware): MD5 0f1d3ed85fee2acc23a8a26e0dc12e0f SHA1 3d161de48d3f4da0aefff685253404c8b0111563 SHA256 fb94a5 | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | a2fe5dcb08ae8b72e8bc98ddc0b918e7 | oject(20180108)\Final1stspy\LoadDll\Release\LoadDll.pdb MD5 a2fe5dcb08ae8b72e8bc98ddc0b918e7 SHA1 741dbdb20d1beeb8ff809291996c8b78585cb812 SHA256 0669c7 | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | e02024f38dfb6290ce0d693539a285a9 | was identified. This file had the following properties: MD5 e02024f38dfb6290ce0d693539a285a9 SHA1 d13fc918433c705b49db74c91f56ae6c0cb5cf8d SHA256 66a0c2 | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 3e4015366126dcdbdcc8b5c508a6d25c | s For the analysis below, the following sample is used: MD5 3e4015366126dcdbdcc8b5c508a6d25c SHA1 f459f9cfbd10b136cafb19cbc233a4c8342ad984 SHA256 aef92b | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | a943e196b83c4acd9c5ce13e4c43b4f4 | l The downloaded CAB file has the following properties: MD5 a943e196b83c4acd9c5ce13e4c43b4f4 SHA1 e66e416f300c7efb90c383a7630c9cfe901ff9fd SHA256 cfe436 | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 0304674e9876530dfbea5a9b4fec7b98 | Server: affiliatecollective[.]club C2 Port: 443 Hash Value: 0304674e9876530dfbea5a9b4fec7b98 Additional C2 Servers: 0 GUID: '\xd6\x04hr\x9a\xedLN\xae\xe | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 723df0296951abd2aeed01361cec6b0d | 5a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes File Type PE32+ executable (GUI) x86-6 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| md5 | 7bdbd180c081fa63ca94f9c22c457376 | 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| md5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| md5 | 082d49ef9f14e6811d68c7e0e82e5069 | IntSvc , which loads the loader DLL named oleasapi.dll (MD5 082d49ef9f14e6811d68c7e0e82e5069 ). The ServiceMain parameter in the service’s registry entr | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 2a571f6cee42a17d873f4c942649813f | ogger located at C:\Users\Public\Pictures\AnyDesk.exe (MD5: 2a571f6cee42a17d873f4c942649813f ). They then created a scheduled task named AnyDesk to run | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 32a5985543433a4f60da2fafd873b927 | tsdump Attackers ran a malicious file named Adobe.exe (MD5 32a5985543433a4f60da2fafd873b927 ), which is a portable‑executable version of Impacket’s sec | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 37dc84e4bcad92fa28f1e7778d088283 | rd Decryptor tool C:\users\[username]\libraries\64.exe (MD5 37dc84e4bcad92fa28f1e7778d088283 ) is used to extract passwords from browsers. The tool offe | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 45cf5916fab4272a1313c26e67aa9220 | executing the script located at C:\windows\temp\in.bat (MD5 45cf5916fab4272a1313c26e67aa9220, 4e6d5c4770d5a822d7fcce6a74f7ad73). After querying the task | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 4e6d5c4770d5a822d7fcce6a74f7ad73 | \windows\temp\in.bat (MD5 45cf5916fab4272a1313c26e67aa9220, 4e6d5c4770d5a822d7fcce6a74f7ad73). After querying the task’s status, the attacker triggers i | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 5e26df131ff0a679a0a2699b723b46e3 | ther C:\Users\[username]\1.bat or C:\ProgramData\1.bat (MD5 5e26df131ff0a679a0a2699b723b46e3). The task’s status is first queried, then it is executed, | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 6ecf84fb18f6747ed08d7598364d853a | tch script located at C:\Users\<username>\Videos\1.bat (MD5 6ecf84fb18f6747ed08d7598364d853a ). Prior to executing the task, the actor queries its statu | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | b874123a80fc4f40e06872b9cb54ebc6 | the batch script C:\Users\[username]\Desktop\auto.bat (MD5 b874123a80fc4f40e06872b9cb54ebc6 ). The script created a service named Cusrxsrv , which load | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | cf903e4a1629aa0582fd0363b5786676 | services. The executable is dropped to %TEMP%\fc.exe (MD5: cf903e4a1629aa0582fd0363b5786676) and writes its output to %TEMP%\result.txt . Using Fscan, | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| md5 | 7bdbd180c081fa63ca94f9c22c457376 | 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| md5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| md5 | ded73d04bb3e3525226de64c38a332e3 | 6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 MD5: ded73d04bb3e3525226de64c38a332e3 Talos Rep: https://talosintelligence.com/talos_file_reputat | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| md5 | 18f61c6d686cffd131c9fd3f3437064b | AD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 25480dad40152ef3d0c6d38eecc9bd9b | FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F34 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 34a7f28e0bb69b0d49bacc88bdf20ac1 | D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe 34A7F28E0BB69B0D49BACC88BDF20AC1 run.exe, run2.exe, genie.exe 5D62C1349B8981C396C9A23F4F8F05 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 34b8828635f88078735799a3c1ac8e28 | 4F8F053C genie_encrypt.exe A8842616C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB3 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 3a4479b51890373bfc4a011ef41fe376 | D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F069660166D61FD74F911 GenieLocker for Linux and | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 58c0dda52b8f069660166d61fd74f911 | 7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F069660166D61FD74F911 GenieLocker for Linux and ESXi 9201E35E2993612612919A3C7130 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 5d62c1349b8981c396c9a23f4f8f053c | Trojan for Windows The Windows version of GenieLocker (MD5: 5d62c1349b8981c396c9a23f4f8f053c) is primarily written in C, but compiled with the C++ libra | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 780c8f4c6f077da4da96582987920362 | 0C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 7dad78584795aa5c160520cc6accf260 | E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 824ca1e906cc073ee5b0f3519df69a8f | 50DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6A | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 9201e35e2993612612919a3c71302cab | ounterpart, the Linux and ESXi version of GenieLocker (MD5: 9201e35e2993612612919a3c71302cab) is simpler: there is no secret argument, anti‑debugging te | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 9969a8221312dba70dd5cbddf83a146c | F260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 9cd514ff2809ce0b993e3b8649e82a94 | C3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EEC | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | a50eaaf514f4f84e61ca2455a8789753 | ntact: [email protected] . GenieLocker for Windows A50EAAF514F4F84E61CA2455A8789753 kftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | a8842616c9057d5cf6e1fe1fa8c3c160 | enie.exe 5D62C1349B8981C396C9A23F4F8F053C genie_encrypt.exe A8842616C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | b893eafed0659f70d4ac250f09073723 | 221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373B | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | c68b6862725777651085650db34947fc | 8635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906C | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | d3e06eb34d8eee7ef92cac3ad0a20ff5 | 16C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF280 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | d661cf666b9acbab7cfeae1127a261a9 | 6E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F0696 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | d87d0b01d95acc936b7dc47b8f41937a | B50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe 34A7F28E0BB69B0D49BACC88BDF20AC1 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | de3cfbb50f66079bfee20a6f64e59433 | 6F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | f08f476f26b01d142ca73923de65fc0c | 50EAAF514F4F84E61CA2455A8789753 kftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | f7b9e36e94163a9a303160945f99267a | 064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | fd46a80c2f45577263328984edf7f4dc | ftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 42f847597109da2a220391bb09d00676 | e WebSocket tunneling tool 5FA15EF96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CC6F498 BridgeHead WebSocket tunne | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | 5fa15ef96808ea82f0a6176f0bb4b386 | DBED163679 – sspicli.dll ArcBridge WebSocket tunneling tool 5FA15EF96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33C | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | 6038d42af0affd1fb263f470c0956f6b | 606599C7272CFB33CC6F498 BridgeHead WebSocket tunneling tool 6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7 | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | a239e655709a2518dd0b7bdbed163679 | [email protected] . File hashes NightLedger backdoor A239E655709A2518DD0B7BDBED163679 – sspicli.dll ArcBridge WebSocket tunneling tool 5FA15EF968 | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | ae628efa305387b633dce82f9364875b | tunneling tool 6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthrea | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | afb1c1583606599c7272cfb33cc6f498 | F96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CC6F498 BridgeHead WebSocket tunneling tool 6038D42AF0AFFD1FB263F47 | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | c832ecd135781b11f59e3fffb3d2b6ac | ocess of threat hunting, we detected another variant ( MD5: C832ECD135781B11F59E3FFFB3D2B6AC ) that shares the same dynamic-resolve stub pattern. This v | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | c90f0efadbf322e5eb1c4103a38c30e6 | .dll F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll D09B14A2FE01C7363ECC56F5D046162C – IP | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | d09b14a2fe01c7363ecc56f5d046162c | .dll C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll D09B14A2FE01C7363ECC56F5D046162C – IPHLPAPI.dll Domains and IPs smartconnect[.]azurewebsites | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | f7d36cc5904a53252d2bb3d21615134f | 6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll C90F0EFADBF322E5EB1C4103A38C30E6 – li | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | c99f29ac08454855b3d538960bb2f34f | ctive loader codenamed MIXEDKEY to decrypt the contents of "C99F29AC08454855B3D538960BB2F34F.PCPKEY" and execute it. Both TELESHIM and MIXEDKEY have bee | TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments The Hacker News | · Jul 27, 2026 |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| md5 | 770dbe473180366d7b539ff2c188e551 | fd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a MD5: 770dbe473180366d7b539ff2c188e551 Talos Rep: https://talosintelligence.com/talos_file_reputat | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| md5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| md5 | dbd8dbecaa80795c135137d69921fdba | 05ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba MD5: dbd8dbecaa80795c135137d69921fdba Talos Rep: https://talosintelligence.com/talos_file_reputat | Don’t swing at everything Cisco Talos | · Jul 23, 2026 |
| md5 | 19f8befcb035f52bf70094e6b4f5779a | 483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | 64e9d1950e42bc98486dfd9919463d1c | 95F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD5 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | 7f223ee0716ce2ad56f55d3744419449 | 8486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | 846ef7c1c7323849b2a778c5e4cda162 | E0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | 93a1569d5d5ab2c4761fedf84f83709e | B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4761FEDF84F83709E C2 IP addresses 152.32.160[.]239 8.220.194[.]108 8.220.214[ | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | cb6c4c70a3b171fa3404b8e1a3382116 | 6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA356 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | cbbb6d483737ea3566726e51752dff40 | A3404B8E1A3382116 64E9D1950E42BC98486DFD9919463D1C Stowaway CBBB6D483737EA3566726E51752DFF40 7F223EE0716CE2AD56F55D3744419449 19F8BEFCB035F52BF70094E6B4 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | d08a059e8b815e3b891505bc8777fc28 | F70094E6B4F5779A 846EF7C1C7323849B2A778C5E4CDA162 TmcLoader D08A059E8B815E3B891505BC8777FC28 93A1569D5D5AB2C4761FEDF84F83709E C2 IP addresses 152.32.160 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | d6e86bf8a90e9b632add5fa495f97fbc | A690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6C4C70A3B171FA3404B8E1A3382116 64E9D195 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | dc506ff7bb72735444fb3703a6bee6d8 | mise File hashes GoSerpent EBFFD5A76AAA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5FA495F97FBC ThumbcacheService CB6 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
| md5 | ebffd5a76aaa690bcdb922f82e0bacc5 | the future. Indicators of compromise File hashes GoSerpent EBFFD5A76AAA690BCDB922F82E0BACC5 DC506FF7BB72735444FB3703A6BEE6D8 McMx D6E86BF8A90E9B632ADD5 | GoSerpent backdoor attacks in Southeast Asia Kaspersky Securelist | · Jul 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.