Indicators of compromise
4,231 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | 9c47b2af8b8c5f3c25f237dcc375b41835904f7cd99221c7489fb3563c34c9ab | 89d74c1eaaf1e94028c8ccceef442eb2cd5b052cba3562d2b1b1a3a4ba6 9c47b2af8b8c5f3c25f237dcc375b41835904f7cd99221c7489fb3563c34c9ab 211b7b7a4c4a07b9c65fae361570dbb94666e26f0cc0fa0b32df4b09fce | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 9e6671a8af28e0ab6c37c044d85a2406b665a171ae3bef46f3e90d06e33027ae | c14153e983ae7ab793c7cd0e5ac3faf8e200894955b02e1191429eff29a 9e6671a8af28e0ab6c37c044d85a2406b665a171ae3bef46f3e90d06e33027ae 448c33094322b200c53ff016fec29469b3e52def359430113115cc70d7f | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a05805bcec72fb76b997c456e0fd6c4b219fdc51cad70d4a58c16b0b0e2d9ba1 | 3492a95257707a86992e84b5085ce9e11810a26920dbb085005081e32d3 a05805bcec72fb76b997c456e0fd6c4b219fdc51cad70d4a58c16b0b0e2d9ba1 4e953ea82b0406a5b95e31554628ad6821b1d91e9ada0d26179977f227c | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a1d5b7d69d85b1be31d9e1cb0686094cc7b1213079b2a66ace01be4bfe3fb7c3 | a21d953c394968647df6a37e1f61db04968ad1aca65ad8f261b363fa842 a1d5b7d69d85b1be31d9e1cb0686094cc7b1213079b2a66ace01be4bfe3fb7c3 4b0203492a95257707a86992e84b5085ce9e11810a26920dbb085005081 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a545288c4d491d510972d583b773f8a0c5dc355942e322cf767d33121c659c1c | 3ff35104a032dd047ca39d35ec98601c76aa02f58ad655df6deaadecb55 a545288c4d491d510972d583b773f8a0c5dc355942e322cf767d33121c659c1c 64a9bdf4ff33e8f2e74dc16d7dce0f392aa130ff9b99458778fd25d9aad | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | ae8fb2f138981f10092761768428fb312e3e49bc23d5b610e3127c1a387aede8 | 955db80cb5835158320ba94b2b55bc7028ea988b75f02adee3df40793f3 ae8fb2f138981f10092761768428fb312e3e49bc23d5b610e3127c1a387aede8 66f43e57648f01ea5f8d0d152db1df90c764eebeb701403936a15c47e29 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b01b7a5798f41a5fae54b4189db6f47c6110a0b53a4df32cb7d0f13503c5250c | 0d6a988723b33158bbeef4ab90b1bff7b521fed9cab0c5e1f5b69a01de5 b01b7a5798f41a5fae54b4189db6f47c6110a0b53a4df32cb7d0f13503c5250c fb63acfda1730132dbfbf1d46834d771156aac3f7c8e97ea136ca6edbe8 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b742162197744a8caeb09f954213a3172ed699f8375f69c40b57b8c219c5e37c | ll look at the most recent version of Cardinal RAT : SHA256 b742162197744a8caeb09f954213a3172ed699f8375f69c40b57b8c219c5e37c The l ast time we wrote about Cardinal RAT in 2017 , we loo | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | bae230d6a988723b33158bbeef4ab90b1bff7b521fed9cab0c5e1f5b69a01de5 | 34200668ac64cb63fc1a4f4ea17e956f6928a2211c945c2e07f1b25a3ef bae230d6a988723b33158bbeef4ab90b1bff7b521fed9cab0c5e1f5b69a01de5 b01b7a5798f41a5fae54b4189db6f47c6110a0b53a4df32cb7d0f13503c | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | bee6c5a506d6fb2cc129443c74b7676fbb9a79b53b92b2cac4c7fb8209592714 | ten in JavaScript, and another written in .NET. SHA256 Type bee6c5a506d6fb2cc129443c74b7676fbb9a79b53b92b2cac4c7fb8209592714 .NET 97c97ad2baef37eea023549131c192f441aa7976747166cd31095e | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | ca2a01792873233693e17fe51c4c86c05d07e31f9b579ab0444dd89733633532 | f39e54457fcfa21f5a8ed0f04095c1d4b798453770be5dda5db7d5406ac ca2a01792873233693e17fe51c4c86c05d07e31f9b579ab0444dd89733633532 4fde64e9391d36aaff700ce0be3df9e7e6303b6de114332286de694af33 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | ca8af85f7eed79a73984b2dccd3dd2148865dfed7a009842be7372e6ce18037f | 48c8a2ffab67627556075ddcad92998526d4d3802b9c2357d169531825f ca8af85f7eed79a73984b2dccd3dd2148865dfed7a009842be7372e6ce18037f 75ca794f265ebad84954f13480e0e31c17048d21c4b52e949864c951437 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | cbcb627ff2220ed269aaa58203e7e89f1988210073d35f5f4019f8ecfd012f81 | 17396e2ddfce8e60c964056d63cc3b17646c31b4a4f934c2d1fb4f5ba71 cbcb627ff2220ed269aaa58203e7e89f1988210073d35f5f4019f8ecfd012f81 267b1df7bc64c1b93b604d964f52801733fdd43efaf7742810b9277f00a | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | dab228c236d48fa1660bcec59e17e5004726741a85b0fbeef8300f29927c32d9 | 2d1824b585aa558b7cf9e9980acd665736ce9f7a124507cf46afb30c79f dab228c236d48fa1660bcec59e17e5004726741a85b0fbeef8300f29927c32d9 f75883ff35104a032dd047ca39d35ec98601c76aa02f58ad655df6deaad | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | dd8fe0e27bf798cace40ac0d58b833ba3bbf16d80175296601585ed1964465ec | c45ca3d4d4ce33981f660d23e8df4a9c0e345fdd6429d8b46f6c0528c38 dd8fe0e27bf798cace40ac0d58b833ba3bbf16d80175296601585ed1964465ec 20fec2d1824b585aa558b7cf9e9980acd665736ce9f7a124507cf46afb3 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | dfa041f6cbe9d83cdaaed90466693efca33729c99fa43b29ab8e44bb27eb0a6b | 528fc1b90b725d857cc5d45572e864c6c4948100458774f0ef6a8f11403 dfa041f6cbe9d83cdaaed90466693efca33729c99fa43b29ab8e44bb27eb0a6b 4045950ffa263b92774e92ab36b3ec52bf18f1c133b8d155819629d2ad4 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | e017651dd9e9419a7f1714f8f2cdc3d8e75aebbe6d3cfbb2de3f042f39aec3bd | df7bc64c1b93b604d964f52801733fdd43efaf7742810b9277f00ad17ff e017651dd9e9419a7f1714f8f2cdc3d8e75aebbe6d3cfbb2de3f042f39aec3bd 778090182a10fde1b4c1571d1e853e123f6ab1682e17dabe2e83468b518 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | ebd4f45cbb272bcc4954cf1bd0a5b8802a6e501688f2a1abdb6143ba616aea82 | 79517fed71682423b0192da453ec1d61a633c154fdd55bab762bcc404f3 ebd4f45cbb272bcc4954cf1bd0a5b8802a6e501688f2a1abdb6143ba616aea82 edc49bf7ec508becb088d5082c78d360f1a7cad520f6de6d8b93759b67a | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | edc49bf7ec508becb088d5082c78d360f1a7cad520f6de6d8b93759b67aac305 | 45cbb272bcc4954cf1bd0a5b8802a6e501688f2a1abdb6143ba616aea82 edc49bf7ec508becb088d5082c78d360f1a7cad520f6de6d8b93759b67aac305 7482f8c86b63ce53edcb62fc2ff2dd8e584e2164451ae0c6f2b1f4d6d0c | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | f027735c3db77e67cf7bada8862ddbb0d85a2caacbb4b2825e4acdfa863a14c9 | d349cf841d0f25e81d80a1b4bf73dd960a1f3aa71029a18e36480c80392 f027735c3db77e67cf7bada8862ddbb0d85a2caacbb4b2825e4acdfa863a14c9 75996bbfcd2b343523ed79476f9516cc7d2b041c43841e5e735db4f22ae | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | f4f52c45ca3d4d4ce33981f660d23e8df4a9c0e345fdd6429d8b46f6c0528c38 | 29e5dae8677f9db3aa7eaa96ad584c872343698e18f85349a027328b3ea f4f52c45ca3d4d4ce33981f660d23e8df4a9c0e345fdd6429d8b46f6c0528c38 dd8fe0e27bf798cace40ac0d58b833ba3bbf16d80175296601585ed1964 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | f75883ff35104a032dd047ca39d35ec98601c76aa02f58ad655df6deaadecb55 | 8c236d48fa1660bcec59e17e5004726741a85b0fbeef8300f29927c32d9 f75883ff35104a032dd047ca39d35ec98601c76aa02f58ad655df6deaadecb55 a545288c4d491d510972d583b773f8a0c5dc355942e322cf767d33121c6 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | f9bccd349cf841d0f25e81d80a1b4bf73dd960a1f3aa71029a18e36480c80392 | 6fdb990e5e9584382a65f5cee7efd9e89c38e928beca18419bdf70ef076 f9bccd349cf841d0f25e81d80a1b4bf73dd960a1f3aa71029a18e36480c80392 f027735c3db77e67cf7bada8862ddbb0d85a2caacbb4b2825e4acdfa863 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fb63acfda1730132dbfbf1d46834d771156aac3f7c8e97ea136ca6edbe811fad | a5798f41a5fae54b4189db6f47c6110a0b53a4df32cb7d0f13503c5250c fb63acfda1730132dbfbf1d46834d771156aac3f7c8e97ea136ca6edbe811fad 268c3c9a98f2a15aaab9b0488225b0ba4e3d35efa30f6fed9052ffd3104 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fc5f7a21d953c394968647df6a37e1f61db04968ad1aca65ad8f261b363fa842 | a12404202fd25e29e754ff78703d4edd7da73cb4c283c9910fd526d47db fc5f7a21d953c394968647df6a37e1f61db04968ad1aca65ad8f261b363fa842 a1d5b7d69d85b1be31d9e1cb0686094cc7b1213079b2a66ace01be4bfe3 | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fd61a5cd1a83f68b75d47c8b6041f8640e47510925caee8176d5d81afac29134 | b7a4c4a07b9c65fae361570dbb94666e26f0cc0fa0b32df4b09fcee6de2 fd61a5cd1a83f68b75d47c8b6041f8640e47510925caee8176d5d81afac29134 84f822d9cf575aeea867e9b73f88ad4d9244293e52208644e12ff2cf13b | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 2a7da0a0acadb61fb79fa4a33130d09ecff5a904b0999d264d8c1edffeffea95 | ion = "the HERCULES malware family written in Go." hash1 = "2a7da0a0acadb61fb79fa4a33130d09ecff5a904b0999d264d8c1edffeffea95" hash2 = "6e68dafbb717daf6a505d8a95c41e5114d91c4fde70334335 | The Gopher in the Room: Analysis of GoLang Malware in the Wild Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 645ed38f2d55b2f7731d5c9223329428592497eb95c96bcd7c01a4eaeb38e137 | 6a505d8a95c41e5114d91c4fde703343356352c1ca5cd24ea" hash3 = "645ed38f2d55b2f7731d5c9223329428592497eb95c96bcd7c01a4eaeb38e137" reference = "https://github.com/EgeBalci/HERCULES" strings | The Gopher in the Room: Analysis of GoLang Malware in the Wild Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 6e68dafbb717daf6a505d8a95c41e5114d91c4fde703343356352c1ca5cd24ea | fb79fa4a33130d09ecff5a904b0999d264d8c1edffeffea95" hash2 = "6e68dafbb717daf6a505d8a95c41e5114d91c4fde703343356352c1ca5cd24ea" hash3 = "645ed38f2d55b2f7731d5c9223329428592497eb95c96bcd7 | The Gopher in the Room: Analysis of GoLang Malware in the Wild Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fc684bbf9428a4e33c390e3963c9bfa24e81cb040ccd601c6e7f5b6c193e2808 | running this is below: $ python find_interesting_strings.py fc684bbf9428a4e33c390e3963c9bfa24e81cb040ccd601c6e7f5b6c193e2808.bin 'main.encryptFile' 'main.writeLog.func1' 'main.writeLog | The Gopher in the Room: Analysis of GoLang Malware in the Wild Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 1ma.xyz | mpts that involved a callback URL that contained the domain 1ma[.]xyz , as seen in the following example: <redacted>.com.80.ref | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | automationyesterday.com | 346,888 195.54.160[.]149 250,042 canarytokens[.]com 198,954 automationyesterday[.]com 166,206 45.83.193[.]150 120,707 64.39.98[.]200 118,860 pr | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | burpcollaborator.net | .]159 80,075 interactsh[.]com 68,959 5.101.118[.]127 51,515 burpcollaborator[.]net 51,066 31.131.16[.]127 48,119 45.66.8[.]12 46,753 185.246 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | canarytokens.com | [.]in 552,521 45.83.64[.]1 346,888 195.54.160[.]149 250,042 canarytokens[.]com 198,954 automationyesterday[.]com 166,206 45.83.193[.]150 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | interact.sh | 36,563,784 nessus[.]org 14,638,414 172.16.0.0/12 1,818,036 interact[.]sh 852,778 oob[.]li 571,042 sploit[.]in 552,521 45.83.64[.]1 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | interactsh.com | rt[.]tech 83,875 upguard[.]com 83,379 193.3.19[.]159 80,075 interactsh[.]com 68,959 5.101.118[.]127 51,515 burpcollaborator[.]net 51,0 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | nessus.org | ity scanning services are represented in this list, such as nessus[.]org as the top callback involving a remote location. Domain/I | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | oob.li | rg 14,638,414 172.16.0.0/12 1,818,036 interact[.]sh 852,778 oob[.]li 571,042 sploit[.]in 552,521 45.83.64[.]1 346,888 195.54.1 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | praetorian.com | ]com 166,206 45.83.193[.]150 120,707 64.39.98[.]200 118,860 praetorian[.]com 115,739 192.168.0.0/16 86,513 securitysupport[.]tech 83,8 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | securitysupport.tech | ]200 118,860 praetorian[.]com 115,739 192.168.0.0/16 86,513 securitysupport[.]tech 83,875 upguard[.]com 83,379 193.3.19[.]159 80,075 interac | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sploit.in | .16.0.0/12 1,818,036 interact[.]sh 852,778 oob[.]li 571,042 sploit[.]in 552,521 45.83.64[.]1 346,888 195.54.160[.]149 250,042 can | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | upguard.com | 115,739 192.168.0.0/16 86,513 securitysupport[.]tech 83,875 upguard[.]com 83,379 193.3.19[.]159 80,075 interactsh[.]com 68,959 5.10 | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://139.155.2[ | ava class file from a remote server. The EvilObj.class from hxxp://139.155.2[.]105:8081 contains the decompiled Java code as seen in Figu | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://150.60.139[ | s and execute them. The first file downloaded was hosted at hxxp://150.60.139[.]51:80/wp-content/themes/twentyseventeen/s.cmd , which cont | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://161.35.184[ | e above, the server would download a Java class file from a hxxp://161.35.184[.]54:9998/V8.class URL, which responds with a Java class fil | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://165.22.2[ | that provides the Java class that installs a coinminer. The hxxp://165.22.2[.]186:80/wp-content/themes/twentyseventeen/Exploit.class res | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://2.57.121[ | cessing this URL, the server would access a Java class from hxxp://2.57.121[.]36/Rjava.class , which contained the decompiled code seen | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://68.183.165[ | ommand attempts to download and execute an application from hxxp://68.183.165[.]105:80/wp-content/themes/twentyseventeen/xmrig64.exe , whi | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://[hostname | The HTTP POST requests would be sent to the following URLs: hxxp://[hostname].[username]8.pef.mur.1ma[.]xyz/ hxxp://[hostname].[username | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://[hostname | [.]xyz/ hxxp://[hostname].[username]5.pef.mur.1ma[.]xyz:53/ hxxps://[hostname].[username]4.pef.mur.1ma[.]xyz/ The DNS tunneling involves | Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | discordapp.com | osted file is retrieved from the following URL: hxxps://cdn.discordapp[.]com/attachments/928503440139771947/930108637681184768/Tbopbh. | Threat Brief: Ongoing Russia and Ukraine Cyber Activity Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 111.111.111.111 | ping.exe" ) and action_process_image_command_line contains "111.111.111.111 -n 5 -w 10" | fields _time , agent_hostname , actor_effecti | Threat Brief: Ongoing Russia and Ukraine Cyber Activity Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://cdn.discordapp[ | cious. The hosted file is retrieved from the following URL: hxxps://cdn.discordapp[.]com/attachments/928503440139771947/930108637681184768/Tbop | Threat Brief: Ongoing Russia and Ukraine Cyber Activity Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 172.104.31.117 | iginated from the following IP addresses: IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ip | Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022 Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 191.37.248.120 | llowing IP addresses: IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ipv4 18.216.140.250 Ip | Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022 Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 84.17.48.94 | : IoC Type IoC Ipv4 172.104.31.117 Ipv4 191.37.248.120 Ipv4 84.17.48.94 Ipv4 193.106.191.71 Ipv4 18.216.140.250 Ipv4 18.221.234.103 | Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 3cx.com | w glcloudservice[.]com/v1/status pbxsources[.]com/queue www.3cx[.]com/blog/event-trainings/ Note that the www.3cx[.]com URL abo | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | akamaicontainer.com | iofactory.com|.*zacharryblogs.com" OR dns_query_name ~ = ".*akamaicontainer.com|.*akamaitechcloudservices.com|.*azuredeploystore.com|.*azur | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | akamaitechcloudservices.com | 62a88896c57bbe3b6456bd090 icon10.ico and icon11.ico hxxps://akamaitechcloudservices[.]com/v2/storage d51a790d187439ce030cf763237e992e9196e9aa41797a | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | azuredeploystore.com | 1720d77c47b97d97c3b0cf43ade5d96bf724639bd icon4.ico hxxps://azuredeploystore[.]com/cloud/services c13d49ed325dec9551906bafb6de9ec947e5ff936e | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | azureonlinestorage.com | 237e992e9196e9aa41797a94956681b6279d1b9a icon12.ico hxxps://azureonlinestorage[.]com/azure/storage 4e08e4ffc699e0a1de4a5225a0b4920933fbb9cf123 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | githubusercontent.com | s a randomly generated number between 1 and 15: hxxps://raw.githubusercontent[.]com/IconStorages/images/main/icon[1-15].ico This request look | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | glcloudservice.com | 0242efd78fd4ed0c344ac6469611ec72defa6b2d icon14.ico hxxps://glcloudservice[.]com/v1/console f47c883f59a4802514c57680de3f41f690871e26f250c6 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | msedgepackageinfo.com | a0b4920933fbb9cf123cde33e1674fde6d61444f icon13.ico hxxps://msedgepackageinfo[.]com/microsoft-edge 8c0b7d90f14c55d4f1d0f17e0242efd78fd4ed0c34 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | msstorageazure.com | f4771e897fb5a617998aa4876e0e1baa5fbb8e25c icon1.ico hxxps://msstorageazure[.]com/window d459aa0a63140ccc647e9026bfd1fccd4c310c262a88896c57 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | msstorageboxes.com | fb6de9ec947e5ff936e7e40877feb2ba4bb176396 icon5.ico hxxps://msstorageboxes[.]com/office f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0e046 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | officeaddons.com | 4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 icon6.ico hxxps://officeaddons[.]com/technologies 2487b4e3c950d56fb15316245b3c51fbd70717838f6f | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | officestoragebox.com | 33a48e228c32bcf26bd98e51310efd48e80c1789f icon2.ico hxxps://officestoragebox[.]com/api/session 268d4e399dbbb42ee1cd64d0da72c57214ac987efbb50 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pbxcloudeservices.com | 10ce22d71e05b20bad74d53fae158dc752a65782e icon9.ico hxxps://pbxcloudeservices[.]com/phonesystem Table 1. Icon files hosted at GitHub account | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pbxphonenetwork.com | acharryblogs[.]com/xmlquery pbxcloudeservices[.]com/network pbxphonenetwork[.]com/phone akamaitechcloudservices[.]com/v2/fileapi azureonlin | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pbxsources.com | de3f41f690871e26f250c6e890651ba71027e4d3 icon15.ico hxxps://pbxsources[.]com/exchange 2c9957ea04d033d68b769f333a48e228c32bcf26bd98e513 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sourceslabs.com | 45b3c51fbd70717838f6f82f32db2efcc4d9da6de icon7.ico hxxps://sourceslabs[.]com/downloads e059c8c8b01d6f3af32257fc2b6fe188d5f4359c308b368 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | visualstudiofactory.com | 0da72c57214ac987efbb509c46cc57ea6b214beca icon3.ico hxxps://visualstudiofactory[.]com/workload c62dce8a77d777774e059cf1720d77c47b97d97c3b0cf43a | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | zacharryblogs.com | c2b6fe188d5f4359c308b3684b1e0db2071c3425c icon8.ico hxxps://zacharryblogs[.]com/feed d0f1984b4fe896d0024533510ce22d71e05b20bad74d53fae158 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 11be1803e2e307b647a8a7e02d128335c448ff741bf06bf52b332e0bbf423b03 | 21ab420c443ab7b15ed42aed91fd31ce833896 Malicious ffmpeg.dll 11be1803e2e307b647a8a7e02d128335c448ff741bf06bf52b332e0bbf423b03 Malicious d3dcompiler_47.dll c485674ee63ec8d4e8fde980078817 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 2487b4e3c950d56fb15316245b3c51fbd70717838f6f82f32db2efcc4d9da6de | e6e6e3182 icon6.ico hxxps://officeaddons[.]com/technologies 2487b4e3c950d56fb15316245b3c51fbd70717838f6f82f32db2efcc4d9da6de icon7.ico hxxps://sourceslabs[.]com/downloads e059c8c8b01d6 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 268d4e399dbbb42ee1cd64d0da72c57214ac987efbb509c46cc57ea6b214beca | c1789f icon2.ico hxxps://officestoragebox[.]com/api/session 268d4e399dbbb42ee1cd64d0da72c57214ac987efbb509c46cc57ea6b214beca icon3.ico hxxps://visualstudiofactory[.]com/workload c62dce | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 2c9957ea04d033d68b769f333a48e228c32bcf26bd98e51310efd48e80c1789f | 651ba71027e4d3 icon15.ico hxxps://pbxsources[.]com/exchange 2c9957ea04d033d68b769f333a48e228c32bcf26bd98e51310efd48e80c1789f icon2.ico hxxps://officestoragebox[.]com/api/session 268d4e | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4e08e4ffc699e0a1de4a5225a0b4920933fbb9cf123cde33e1674fde6d61444f | a icon12.ico hxxps://azureonlinestorage[.]com/azure/storage 4e08e4ffc699e0a1de4a5225a0b4920933fbb9cf123cde33e1674fde6d61444f icon13.ico hxxps://msedgepackageinfo[.]com/microsoft-edge 8 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 5407cda7d3a75e7b1e030b1f33337a56f293578ffa8b3ae19c671051ed314290 | f9be345823b4fdcf5d868 3CXDesktopApp-18.12.407.msi Installer 5407cda7d3a75e7b1e030b1f33337a56f293578ffa8b3ae19c671051ed314290 3CXDesktopApp-18.11.1213.dmg Installer e6bbc33815b9f20b0cf8 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 59e1edf4d82fae4978e97512b0331b7eb21dd4b838b850ba46794d9c7a2c0983 | main protected. Indicators of Compromise SHA256 Description 59e1edf4d82fae4978e97512b0331b7eb21dd4b838b850ba46794d9c7a2c0983 3CXDesktopApp-18.12.416.msi Installer aa124a4b4df12b34e74ee | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 7986bbaee8940da11ce089383521ab420c443ab7b15ed42aed91fd31ce833896 | c6010a4297e321 3CXDesktopApp-18.12.416-full.nupkg Installer 7986bbaee8940da11ce089383521ab420c443ab7b15ed42aed91fd31ce833896 Malicious ffmpeg.dll 11be1803e2e307b647a8a7e02d128335c448ff | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 7c55c3dfa373b6b342390938029cb76ef31f609d9a07780772c6010a4297e321 | 28b5891336706da0dbcec 3CXDesktopApp-18.12.416.dmg Installer 7c55c3dfa373b6b342390938029cb76ef31f609d9a07780772c6010a4297e321 3CXDesktopApp-18.12.416-full.nupkg Installer 7986bbaee8940d | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 8c0b7d90f14c55d4f1d0f17e0242efd78fd4ed0c344ac6469611ec72defa6b2d | f icon13.ico hxxps://msedgepackageinfo[.]com/microsoft-edge 8c0b7d90f14c55d4f1d0f17e0242efd78fd4ed0c344ac6469611ec72defa6b2d icon14.ico hxxps://glcloudservice[.]com/v1/console f47c883f | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a541e5fc421c358e0a2b07bf4771e897fb5a617998aa4876e0e1baa5fbb8e25c | from within the file. SHA256 Icon Filename C2 URL Extracted a541e5fc421c358e0a2b07bf4771e897fb5a617998aa4876e0e1baa5fbb8e25c icon1.ico hxxps://msstorageazure[.]com/window d459aa0a63140 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a64fa9f1c76457ecc58402142a8728ce34ccba378c17318b3340083eeb7acc67 | 573e5d9973caa676f58086c99561382d7 Malicious libffmpeg.dylib a64fa9f1c76457ecc58402142a8728ce34ccba378c17318b3340083eeb7acc67 Malicious libffmpeg.dylib URL Description msstorageazure[.] | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | aa124a4b4df12b34e74ee7f6c683b2ebec4ce9a8edcf9be345823b4fdcf5d868 | 850ba46794d9c7a2c0983 3CXDesktopApp-18.12.416.msi Installer aa124a4b4df12b34e74ee7f6c683b2ebec4ce9a8edcf9be345823b4fdcf5d868 3CXDesktopApp-18.12.407.msi Installer 5407cda7d3a75e7b1e030 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | aa4e398b3bd8645016d8090ffc77d15f926a8e69258642191deb4e68688ff973 | 88175a8b02d3f9416d0e763360fff7f8eb4e02 Malicious ffmpeg.dll aa4e398b3bd8645016d8090ffc77d15f926a8e69258642191deb4e68688ff973 Malicious DLL in d3dcompiler_47.dll fee4f9dabc094df24d83ec1 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | c13d49ed325dec9551906bafb6de9ec947e5ff936e7e40877feb2ba4bb176396 | 9bd icon4.ico hxxps://azuredeploystore[.]com/cloud/services c13d49ed325dec9551906bafb6de9ec947e5ff936e7e40877feb2ba4bb176396 icon5.ico hxxps://msstorageboxes[.]com/office f1bf4078141d7 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | c485674ee63ec8d4e8fde9800788175a8b02d3f9416d0e763360fff7f8eb4e02 | 48ff741bf06bf52b332e0bbf423b03 Malicious d3dcompiler_47.dll c485674ee63ec8d4e8fde9800788175a8b02d3f9416d0e763360fff7f8eb4e02 Malicious ffmpeg.dll aa4e398b3bd8645016d8090ffc77d15f926a8e | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | c62dce8a77d777774e059cf1720d77c47b97d97c3b0cf43ade5d96bf724639bd | 14beca icon3.ico hxxps://visualstudiofactory[.]com/workload c62dce8a77d777774e059cf1720d77c47b97d97c3b0cf43ade5d96bf724639bd icon4.ico hxxps://azuredeploystore[.]com/cloud/services c13 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d0f1984b4fe896d0024533510ce22d71e05b20bad74d53fae158dc752a65782e | b1e0db2071c3425c icon8.ico hxxps://zacharryblogs[.]com/feed d0f1984b4fe896d0024533510ce22d71e05b20bad74d53fae158dc752a65782e icon9.ico hxxps://pbxcloudeservices[.]com/phonesystem Table | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d459aa0a63140ccc647e9026bfd1fccd4c310c262a88896c57bbe3b6456bd090 | 1baa5fbb8e25c icon1.ico hxxps://msstorageazure[.]com/window d459aa0a63140ccc647e9026bfd1fccd4c310c262a88896c57bbe3b6456bd090 icon10.ico and icon11.ico hxxps://akamaitechcloudservices[. | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d51a790d187439ce030cf763237e992e9196e9aa41797a94956681b6279d1b9a | icon11.ico hxxps://akamaitechcloudservices[.]com/v2/storage d51a790d187439ce030cf763237e992e9196e9aa41797a94956681b6279d1b9a icon12.ico hxxps://azureonlinestorage[.]com/azure/storage 4 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | e059c8c8b01d6f3af32257fc2b6fe188d5f4359c308b3684b1e0db2071c3425c | 2efcc4d9da6de icon7.ico hxxps://sourceslabs[.]com/downloads e059c8c8b01d6f3af32257fc2b6fe188d5f4359c308b3684b1e0db2071c3425c icon8.ico hxxps://zacharryblogs[.]com/feed d0f1984b4fe896d0 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | e6bbc33815b9f20b0cf832d7401dd893fbc467c800728b5891336706da0dbcec | 3ae19c671051ed314290 3CXDesktopApp-18.11.1213.dmg Installer e6bbc33815b9f20b0cf832d7401dd893fbc467c800728b5891336706da0dbcec 3CXDesktopApp-18.12.416.dmg Installer 7c55c3dfa373b6b342390 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 | b2ba4bb176396 icon5.ico hxxps://msstorageboxes[.]com/office f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 icon6.ico hxxps://officeaddons[.]com/technologies 2487b4e3c | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | f47c883f59a4802514c57680de3f41f690871e26f250c6e890651ba71027e4d3 | defa6b2d icon14.ico hxxps://glcloudservice[.]com/v1/console f47c883f59a4802514c57680de3f41f690871e26f250c6e890651ba71027e4d3 icon15.ico hxxps://pbxsources[.]com/exchange 2c9957ea04d033 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fee4f9dabc094df24d83ec1a8c4e4ff573e5d9973caa676f58086c99561382d7 | 58642191deb4e68688ff973 Malicious DLL in d3dcompiler_47.dll fee4f9dabc094df24d83ec1a8c4e4ff573e5d9973caa676f58086c99561382d7 Malicious libffmpeg.dylib a64fa9f1c76457ecc58402142a8728ce3 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://akamaitechcloudservices[ | d4c310c262a88896c57bbe3b6456bd090 icon10.ico and icon11.ico hxxps://akamaitechcloudservices[.]com/v2/storage d51a790d187439ce030cf763237e992e9196e9aa417 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.