ZeroHour

Indicators of compromise

4,250 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
ipv45.9.253.173rklfdprel.blueelizabeth[.]top Locky post-infection traffic: 5.9.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
ipv477.222.54.20287.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky
Palo Alto Unit 42
· Aug 17, 2026
domaindropbox.combuinte[.]com - GET /Contribuinte/Iptu/ HTTPS via port 443 - dropbox[.]com - GET /s/ss6op2vxi3ggnhe/Notificacao%28Iptu-.-2017%29.zipMalspam Targeting Brazil Continues to Evolve
Palo Alto Unit 42
· Aug 17, 2026
domaingoo.gldownloaded the malicious zip archive: HTTPS via port 443 – goo[.]gl - GET /htm4qG HTTPS via port 443 - googleapis[.]com - GETMalspam Targeting Brazil Continues to Evolve
Palo Alto Unit 42
· Aug 17, 2026
domaingoogleapis.comvia port 443 – goo[.]gl - GET /htm4qG HTTPS via port 443 - googleapis[.]com - GET /pid/2via.html HTTP via port 80 - gov.br.impostoconMalspam Targeting Brazil Continues to Evolve
Palo Alto Unit 42
· Aug 17, 2026
domainimpostocontribuinte.comleapis[.]com - GET /pid/2via.html HTTP via port 80 - gov.br.impostocontribuinte[.]com - GET /Contribuinte/Iptu/ HTTPS via port 443 - dropbox[.]Malspam Targeting Brazil Continues to Evolve
Palo Alto Unit 42
· Aug 17, 2026
sha25671eb0797db8de8ff5a9fe84b5568cd728b4b089537e4e1b5fd55b42de8b3fa07ow-up malware downloaded by the above SCT file SHA256 hash: 71eb0797db8de8ff5a9fe84b5568cd728b4b089537e4e1b5fd55b42de8b3fa07 File name: bxmmyDLr.exe File description: G-Buster executabMalspam Targeting Brazil Continues to Evolve
Palo Alto Unit 42
· Aug 17, 2026
sha25694cf47c57413753ecc8c648384b475e96f13f8caca648b9240486340e1d91aa0other SCT file called from the first scriptlet SHA256 hash: 94cf47c57413753ecc8c648384b475e96f13f8caca648b9240486340e1d91aa0 File name: ipv3.zip File description: Follow-up malware dowMalspam Targeting Brazil Continues to Evolve
Palo Alto Unit 42
· Aug 17, 2026
sha256a4cf9811c55d0e4f2f8c783d1458ab3a5d69244287030a0a8154e89ed6ae02b0p archive after clicking link from the malspam SHA256 hash: a4cf9811c55d0e4f2f8c783d1458ab3a5d69244287030a0a8154e89ed6ae02b0 File name: Notificacao(Iptu-.-2017).lnk File description: EMalspam Targeting Brazil Continues to Evolve
Palo Alto Unit 42
· Aug 17, 2026
sha256b42994352613e6bf63599dac0e2d4ddaf2b868842d5f04749f437f8335a63309- POST /ipv3/index.php Associated file hashes: SHA256 hash: b42994352613e6bf63599dac0e2d4ddaf2b868842d5f04749f437f8335a63309 File name: Notificacao(Iptu-.-2017).zip File description: DMalspam Targeting Brazil Continues to Evolve
Palo Alto Unit 42
· Aug 17, 2026
sha256e7374e5ec576d95155c3b35d799656aba33315edbc9cdc7f0a04ed201135843andows shortcut (LNK) file from the zip archive SHA256 hash: e7374e5ec576d95155c3b35d799656aba33315edbc9cdc7f0a04ed201135843a File name: sdar7hsy_2_.sct File description: Scriptlet (SCTMalspam Targeting Brazil Continues to Evolve
Palo Alto Unit 42
· Aug 17, 2026
sha256ed491c8d0b4ea30a3a4d78c2ee713d72b7ff4b1f90e04a86a775852953ade892le returned after double-clicking the LNK file SHA256 hash: ed491c8d0b4ea30a3a4d78c2ee713d72b7ff4b1f90e04a86a775852953ade892 File name: gw4c9sql_1_.sct File description: Another SCT fiMalspam Targeting Brazil Continues to Evolve
Palo Alto Unit 42
· Aug 17, 2026
sha256faf0892be515437f9dfc86040e130533722b6149d65000969ebb334253cf4b89bpSv.exe) made persistent on the infected host SHA256 hash: faf0892be515437f9dfc86040e130533722b6149d65000969ebb334253cf4b89 File name: fltLib.dll File description: Malicious DLL loadeMalspam Targeting Brazil Continues to Evolve
Palo Alto Unit 42
· Aug 17, 2026
domainhealthymagination.com. Among the expired domains Sable Squirrel has acquired are healthymagination.com, originally a General Electric health initiative, and rezilCrooks Are Buying Your Expired Domains and Using Them to Deliver Malware
Security Affairs
· Aug 16, 2026
domainchess.comreact. Proving this data is genuine didn’t require touching chess.com’s servers at all. Every account UUID in the file is a versiChess.com Leak Exposes 7.3 Million Users — Evidence Points to Scraping
Security Affairs
· Aug 14, 2026
domaingitlab.adswizz.comn the same dump, including a self-hosted GitLab instance at gitlab.adswizz.com, pointed to AdsWizz, a SiriusXM subsidiary. Hudson Rock sai153GB of stolen credentials surface after LiteLLM supply chain attack
Help Net Security
· Aug 13, 2026
domainsubscription-magnetic-recommended-meat.trycloudflare.comder (MemoryLoader.cs) references a Cloudflare Quick Tunnel (subscription-magnetic-recommended-meat.trycloudflare.com), a service designed for temporary local server exposure thSMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
Security Affairs
· Aug 9, 2026
ipv4207.174.0.143timately pointing to a live WsgiDAV-based staging server at 207.174.0.143:8080.” reads the report published by Securonix. “Victims whSMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
Security Affairs
· Aug 9, 2026
domainaddssopasskey.commain (e.g., [ company].createssopasskey[.]com or [ company].addssopasskey[.]com ).” After gaining access, the attackers use automated tooHackers Impersonate IT Support to Breach Leading Financial Companies
Security Affairs
· Aug 7, 2026
domaincreatessopasskey.comlookalike credential-harvesting subdomain (e.g., [ company].createssopasskey[.]com or [ company].addssopasskey[.]com ).” After gaining accesHackers Impersonate IT Support to Breach Leading Financial Companies
Security Affairs
· Aug 7, 2026
domainepplink.netendpoints: Role Endpoint Resolves to Hosting Primary zbtctl.epplink[.]net 47.100.190[.]96 Alibaba Cloud, Shanghai Primary hardcodedResearchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
Security Affairs
· Aug 7, 2026
domainrbdg4nzqadui.wikaba.comSecondary online-string.com 45.32.81[.]152 Vultr Secondary rbdg4nzqadui[.]wikaba[.]com 43.248.136[.]125 Jiangsu Dongyun Cloud VulnCheck skippeResearchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
Security Affairs
· Aug 7, 2026
domainpasskeydeploy.comorganizations. Root domains like passkeyhelpdesk[.]com and passkeydeploy[.]com were used by more than one of the groups. Across all theGoogle Links Redact Extortion Group to BlackFile Rebrand
Infosecurity Magazine
· Aug 7, 2026
domainpasskeyhelpdesk.comins across multiple target organizations. Root domains like passkeyhelpdesk[.]com and passkeydeploy[.]com were used by more than one of theGoogle Links Redact Extortion Group to BlackFile Rebrand
Infosecurity Magazine
· Aug 7, 2026
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
md57bdbd180c081fa63ca94f9c22c45737683227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputatWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
md5c2efb2dcacba6d3ccc175b6ce1b7ed0ae6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputatWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
sha25690b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59-QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://taWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
sha2569896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f.exe Detection Name: Win.Dropper.Miner::95.sbx.tg** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://taWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://taWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
sha256a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91D001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://taWhy metaphor may dictate your security strategy
Cisco Talos
· Aug 6, 2026
ipv47.0.9.1FMC Software - 7.0 - Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar 7.2 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The Hacker News
· Aug 6, 2026
ipv47.2.11.1.1-3.sh.REL.tar 7.2 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar 7.4 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The Hacker News
· Aug 6, 2026
ipv47.4.7.1.1-4.sh.REL.tar 7.4 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar 7.6 - Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The Hacker News
· Aug 6, 2026
ipv47.6.5.1.1-3.sh.REL.tar 7.6 - Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar 7.7 - Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The Hacker News
· Aug 6, 2026
ipv47.7.12.1.1-2.sh.REL.tar 7.7 - Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar 10.0 - Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The Hacker News
· Aug 6, 2026
domainmasscan.cloudfor Years The strongest infrastructure link identified was masscan[.]cloud, which appears across TA-NATALSTATUS activity, ShadowRayTeamPCP Traced Back to 2020 Cryptojacking Operation
Infosecurity Magazine
· Aug 6, 2026
domainbitsender.toptive ones. The main domain for Poison Claude, poison-claude.bitsender[.]top, ran behind Cloudflare’s CDN, hiding its originating IP aDiscounted Claude access bought on the gray market may expose every prompt you send
Help Net Security
· Aug 6, 2026
domainclaudeopus.shopa phishing warning on the site, but had taken no action on claudeopus[.]shop even though that domain also runs behind Cloudflare. EcomDiscounted Claude access bought on the gray market may expose every prompt you send
Help Net Security
· Aug 6, 2026
domainqq.comsed by Chinese internet users, and the top email domain was qq.com, which is a popular email service in China,” Okta wrote. ThDiscounted Claude access bought on the gray market may expose every prompt you send
Help Net Security
· Aug 6, 2026
ipv4206.72.242.124shed three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and chU.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
Security Affairs
· Aug 5, 2026
ipv4206.72.242.162dresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and check logs for sigU.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
Security Affairs
· Aug 5, 2026
ipv48.19.75.217ny also published three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to bU.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
Security Affairs
· Aug 5, 2026
domainbkofamerica.comid not point to Bank of America's legitimate domain, but to bkofamerica[.]com. The link in the message pointed, again, not to Bank of AFake Bank of America Phishing Scam Installs Remote Access Malware
Infosecurity Magazine
· Aug 5, 2026
domainkleinschnitg.comthe message pointed, again, not to Bank of America, but to kleinschnitg[.]com, which then opened a page on sectioncompil[.]com from whiFake Bank of America Phishing Scam Installs Remote Access Malware
Infosecurity Magazine
· Aug 5, 2026
domainsectioncompil.comica, but to kleinschnitg[.]com, which then opened a page on sectioncompil[.]com from which the malicious zip originated. The researchersFake Bank of America Phishing Scam Installs Remote Access Malware
Infosecurity Magazine
· Aug 5, 2026
domainealerts.bkofamerica.comd account restrictions,” the email, sent from onlinebanking@ealerts[.]bkofamerica[.]com , tries to push them to follow the link without thinkinBank of America impersonators weaponize ScreenConnect, then make it hard to remove
Help Net Security
· Aug 5, 2026
domainkleinschnitg.compages are easily identifiable: they are hosted on domains ( kleinschnitg[.]com , sectioncompil[.]com ) that look nothing thing like theBank of America impersonators weaponize ScreenConnect, then make it hard to remove
Help Net Security
· Aug 5, 2026
domainsectioncompil.comtifiable: they are hosted on domains ( kleinschnitg[.]com , sectioncompil[.]com ) that look nothing thing like the legitimate BoA domain.Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
Help Net Security
· Aug 5, 2026
domainhelprans.comegistrar that accepts cryptocurrency payments. Domain Name: HELPRANS[.]COM Registry Domain ID: 3106477703_DOMAIN_COM-VRSN RegistrarINC Ransomware is Calling Victims - Pressure Tactics Post SonicWall Zero
Security Affairs
· Aug 4, 2026
domainwhois.ordertld.commain ID: 3106477703_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.ordertld.com Registrar URL: http://www.ordertld.com Updated Date: 2026-0INC Ransomware is Calling Victims - Pressure Tactics Post SonicWall Zero
Security Affairs
· Aug 4, 2026
domainbraintree.nett Package Delivers Skimmer — A malicious .NET package named Braintree.Net has been found to impersonate Braintree's legitimate Braint⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
The Hacker News
· Aug 4, 2026
domaindweb.linkention – we posted on this subject in 2023. The ipfs.io and dweb.link domains function as IPFS gateways. The principal risk assocPhishers are hijacking legitimate cloud infrastructure
Kaspersky Securelist
· Aug 4, 2026
domainipfs.iont close attention – we posted on this subject in 2023. The ipfs.io and dweb.link domains function as IPFS gateways. The princiPhishers are hijacking legitimate cloud infrastructure
Kaspersky Securelist
· Aug 4, 2026
domaintubely.comigBasket set of "shoppers," a gaming set, and others). The “tubely[.]com” domain is not new, and neither is the behavior. Public f“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
Cisco Talos
· Aug 4, 2026
domainsocket.iorol server through a public blockchain transaction, opens a Socket.IO remote access channel, and stages a Python credential stealTwo Compromised joyfill npm Packages Run RAT When Imported Into Node.js
The Hacker News
· Aug 4, 2026
domainip-api.coma blockchain SmartLoader starts by sending a GET request to ip-api.com to collect the victim’s IP address, country, city, time zonAI developers targeted via trojanized GitHub repositories
Help Net Security
· Aug 4, 2026
ipv4104.243.35.63match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to originate from pCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
The Hacker News
· Aug 3, 2026
ipv4216.152.148.54compromise (IoCs), all of which match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emaCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
The Hacker News
· Aug 3, 2026
ipv4216.152.151.204s), all of which match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to orCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
The Hacker News
· Aug 3, 2026
ipv45.180.41.35hared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to originate from previously coCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
The Hacker News
· Aug 3, 2026
domaincontent.powerapps.comand the breach notice page references assets on Microsoft’s content.powerapps.com domain, which corroborates the platform connection. That saPNLD Confirms Data Breach Affecting UK Police and Justice Staff
Security Affairs
· Aug 3, 2026
domainus.zoom.06webin.usinvestor/partnership call." The entire domain scheme being 'us.zoom.06webin.us' and such makes it really easy for someone to fall for theiBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The Hacker News
· Aug 1, 2026
ipv46.1.7.10h 8.0.5, and Rails 8.1.0 through 8.1.3. Rails 6.0.0 through 6.1.7.10 releases are affected only when Active Storage is configureCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News
· Jul 31, 2026
ipv47.2.3.1tt Security list the affected ranges as Rails 7.0.0 through 7.2.3.1, Rails 8.0.0 through 8.0.5, and Rails 8.1.0 through 8.1.3.Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News
· Jul 31, 2026
ipv47.2.3.2no backport, so affected applications must upgrade to Rails 7.2.3.2 or later. Operators should upgrade to Rails 7.2.3.2, 8.0.5.Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News
· Jul 31, 2026
ipv48.0.5.1.2.3.2 or later. Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the applicaCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News
· Jul 31, 2026
ipv48.1.3.1ter. Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the application processCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News
· Jul 31, 2026
domaindns.multitoconference.comhen creates a stream socket using a hard‑coded C2 address ( dns[.]multitoconference[.]com ) and port 443. It gathers the following information frOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
domaindns.ssentialserv.xyze, the attacker at first checked connectivity to the domain dns[.]ssentialserv[.]xyz as shown below. At the time of our research, the domainOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md5082d49ef9f14e6811d68c7e0e82e5069IntSvc , which loads the loader DLL named oleasapi.dll (MD5 082d49ef9f14e6811d68c7e0e82e5069 ). The ServiceMain parameter in the service’s registry entrOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md52a571f6cee42a17d873f4c942649813fogger located at C:\Users\Public\Pictures\AnyDesk.exe (MD5: 2a571f6cee42a17d873f4c942649813f ). They then created a scheduled task named AnyDesk to runOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md532a5985543433a4f60da2fafd873b927tsdump Attackers ran a malicious file named Adobe.exe (MD5 32a5985543433a4f60da2fafd873b927 ), which is a portable‑executable version of Impacket’s secOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md537dc84e4bcad92fa28f1e7778d088283rd Decryptor tool C:\users\[username]\libraries\64.exe (MD5 37dc84e4bcad92fa28f1e7778d088283 ) is used to extract passwords from browsers. The tool offeOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md545cf5916fab4272a1313c26e67aa9220executing the script located at C:\windows\temp\in.bat (MD5 45cf5916fab4272a1313c26e67aa9220, 4e6d5c4770d5a822d7fcce6a74f7ad73). After querying the taskOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md54e6d5c4770d5a822d7fcce6a74f7ad73\windows\temp\in.bat (MD5 45cf5916fab4272a1313c26e67aa9220, 4e6d5c4770d5a822d7fcce6a74f7ad73). After querying the task’s status, the attacker triggers iOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md55e26df131ff0a679a0a2699b723b46e3ther C:\Users\[username]\1.bat or C:\ProgramData\1.bat (MD5 5e26df131ff0a679a0a2699b723b46e3). The task’s status is first queried, then it is executed,OctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md56ecf84fb18f6747ed08d7598364d853atch script located at C:\Users\<username>\Videos\1.bat (MD5 6ecf84fb18f6747ed08d7598364d853a ). Prior to executing the task, the actor queries its statuOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md5b874123a80fc4f40e06872b9cb54ebc6the batch script C:\Users\[username]\Desktop\auto.bat (MD5 b874123a80fc4f40e06872b9cb54ebc6 ). The script created a service named Cusrxsrv , which loadOctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
md5cf903e4a1629aa0582fd0363b5786676services. The executable is dropped to %TEMP%\fc.exe (MD5: cf903e4a1629aa0582fd0363b5786676) and writes its output to %TEMP%\result.txt . Using Fscan,OctLurk and SilkLurk: new Backdoors in Central Asia
Kaspersky Securelist
· Jul 31, 2026
domainhunt.io, uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and independent journalist NetAskari started wiResearchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App
Security Affairs
· Jul 30, 2026
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
md57bdbd180c081fa63ca94f9c22c45737683227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputatYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
md5c2efb2dcacba6d3ccc175b6ce1b7ed0ae6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputatYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
md5ded73d04bb3e3525226de64c38a332e36dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 MD5: ded73d04bb3e3525226de64c38a332e3 Talos Rep: https://talosintelligence.com/talos_file_reputatYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
sha25690b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59: f_000177.exe Detection Name: W32.Trojan.29jq.1201 SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://taYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
sha2569896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f.exe Detection Name: Win.Dropper.Miner::95.sbx.tg** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://taYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://taYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
sha256a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91VID001.exe Detection Name: Win.Worm.Coinminer::1201 SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://taYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
sha256fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1-QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 MD5: ded73d04bb3e3525226de64c38a332e3 Talos Rep: https://taYou were onto something with “It’s the Climb,” Miley
Cisco Talos
· Jul 30, 2026
domainrg-telemetry.sbsfiguration responsible for fetching the actual C2 servers: "rg-telemetry[.]sbs/api" and "th-updates[.]sbs/analytics." "Each contract wasDPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto
The Hacker News
· Jul 30, 2026
domainth-updates.sbstching the actual C2 servers: "rg-telemetry[.]sbs/api" and "th-updates[.]sbs/analytics." "Each contract was created by a throwaway walDPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto
The Hacker News
· Jul 30, 2026
domainfwgcloud.comevices. AI DIGITAL HUMANS The domain for the Fengwo Group — fwgcloud[.]com — claims the company is “redefining the boundaries of humRead This Before You Buy That TV Streaming Stick
Krebs on Security
· Jul 30, 2026
domaincubepilot.orgnknown threat actors are said to have gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercepThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
The Hacker News
· Jul 30, 2026
domainjshosting.mesame reverse-tunnelling address 176.65.128[.]26. The domain jshosting[.]me was used to distribute exploit scripts in both sets of atHackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
The Hacker News
· Jul 30, 2026
ipv41.1.4.4Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as tHackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
The Hacker News
· Jul 30, 2026
ipv41.1.4.6rity Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed releaseHackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
The Hacker News
· Jul 30, 2026
ipv47.0.9.1ease Hot Fix Name 7.0 Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar 7.2 Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
Security Affairs
· Jul 30, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.