Indicators of compromise
4,250 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| ipv4 | 5.9.253.173 | rklfdprel.blueelizabeth[.]top Locky post-infection traffic: 5.9.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 77.222.54.202 | 87.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5. | Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | dropbox.com | buinte[.]com - GET /Contribuinte/Iptu/ HTTPS via port 443 - dropbox[.]com - GET /s/ss6op2vxi3ggnhe/Notificacao%28Iptu-.-2017%29.zip | Malspam Targeting Brazil Continues to Evolve Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | goo.gl | downloaded the malicious zip archive: HTTPS via port 443 – goo[.]gl - GET /htm4qG HTTPS via port 443 - googleapis[.]com - GET | Malspam Targeting Brazil Continues to Evolve Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | googleapis.com | via port 443 – goo[.]gl - GET /htm4qG HTTPS via port 443 - googleapis[.]com - GET /pid/2via.html HTTP via port 80 - gov.br.impostocon | Malspam Targeting Brazil Continues to Evolve Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | impostocontribuinte.com | leapis[.]com - GET /pid/2via.html HTTP via port 80 - gov.br.impostocontribuinte[.]com - GET /Contribuinte/Iptu/ HTTPS via port 443 - dropbox[.] | Malspam Targeting Brazil Continues to Evolve Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 71eb0797db8de8ff5a9fe84b5568cd728b4b089537e4e1b5fd55b42de8b3fa07 | ow-up malware downloaded by the above SCT file SHA256 hash: 71eb0797db8de8ff5a9fe84b5568cd728b4b089537e4e1b5fd55b42de8b3fa07 File name: bxmmyDLr.exe File description: G-Buster executab | Malspam Targeting Brazil Continues to Evolve Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 94cf47c57413753ecc8c648384b475e96f13f8caca648b9240486340e1d91aa0 | other SCT file called from the first scriptlet SHA256 hash: 94cf47c57413753ecc8c648384b475e96f13f8caca648b9240486340e1d91aa0 File name: ipv3.zip File description: Follow-up malware dow | Malspam Targeting Brazil Continues to Evolve Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a4cf9811c55d0e4f2f8c783d1458ab3a5d69244287030a0a8154e89ed6ae02b0 | p archive after clicking link from the malspam SHA256 hash: a4cf9811c55d0e4f2f8c783d1458ab3a5d69244287030a0a8154e89ed6ae02b0 File name: Notificacao(Iptu-.-2017).lnk File description: E | Malspam Targeting Brazil Continues to Evolve Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b42994352613e6bf63599dac0e2d4ddaf2b868842d5f04749f437f8335a63309 | - POST /ipv3/index.php Associated file hashes: SHA256 hash: b42994352613e6bf63599dac0e2d4ddaf2b868842d5f04749f437f8335a63309 File name: Notificacao(Iptu-.-2017).zip File description: D | Malspam Targeting Brazil Continues to Evolve Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | e7374e5ec576d95155c3b35d799656aba33315edbc9cdc7f0a04ed201135843a | ndows shortcut (LNK) file from the zip archive SHA256 hash: e7374e5ec576d95155c3b35d799656aba33315edbc9cdc7f0a04ed201135843a File name: sdar7hsy_2_.sct File description: Scriptlet (SCT | Malspam Targeting Brazil Continues to Evolve Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | ed491c8d0b4ea30a3a4d78c2ee713d72b7ff4b1f90e04a86a775852953ade892 | le returned after double-clicking the LNK file SHA256 hash: ed491c8d0b4ea30a3a4d78c2ee713d72b7ff4b1f90e04a86a775852953ade892 File name: gw4c9sql_1_.sct File description: Another SCT fi | Malspam Targeting Brazil Continues to Evolve Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | faf0892be515437f9dfc86040e130533722b6149d65000969ebb334253cf4b89 | bpSv.exe) made persistent on the infected host SHA256 hash: faf0892be515437f9dfc86040e130533722b6149d65000969ebb334253cf4b89 File name: fltLib.dll File description: Malicious DLL loade | Malspam Targeting Brazil Continues to Evolve Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | healthymagination.com | . Among the expired domains Sable Squirrel has acquired are healthymagination.com, originally a General Electric health initiative, and rezil | Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware Security Affairs | · Aug 16, 2026 |
| domain | chess.com | react. Proving this data is genuine didn’t require touching chess.com’s servers at all. Every account UUID in the file is a versi | Chess.com Leak Exposes 7.3 Million Users — Evidence Points to Scraping Security Affairs | · Aug 14, 2026 |
| domain | gitlab.adswizz.com | n the same dump, including a self-hosted GitLab instance at gitlab.adswizz.com, pointed to AdsWizz, a SiriusXM subsidiary. Hudson Rock sai | 153GB of stolen credentials surface after LiteLLM supply chain attack Help Net Security | · Aug 13, 2026 |
| domain | subscription-magnetic-recommended-meat.trycloudflare.com | der (MemoryLoader.cs) references a Cloudflare Quick Tunnel (subscription-magnetic-recommended-meat.trycloudflare.com), a service designed for temporary local server exposure th | SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access Security Affairs | · Aug 9, 2026 |
| ipv4 | 207.174.0.143 | timately pointing to a live WsgiDAV-based staging server at 207.174.0.143:8080.” reads the report published by Securonix. “Victims wh | SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access Security Affairs | · Aug 9, 2026 |
| domain | addssopasskey.com | main (e.g., [ company].createssopasskey[.]com or [ company].addssopasskey[.]com ).” After gaining access, the attackers use automated too | Hackers Impersonate IT Support to Breach Leading Financial Companies Security Affairs | · Aug 7, 2026 |
| domain | createssopasskey.com | lookalike credential-harvesting subdomain (e.g., [ company].createssopasskey[.]com or [ company].addssopasskey[.]com ).” After gaining acces | Hackers Impersonate IT Support to Breach Leading Financial Companies Security Affairs | · Aug 7, 2026 |
| domain | epplink.net | endpoints: Role Endpoint Resolves to Hosting Primary zbtctl.epplink[.]net 47.100.190[.]96 Alibaba Cloud, Shanghai Primary hardcoded | Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access Security Affairs | · Aug 7, 2026 |
| domain | rbdg4nzqadui.wikaba.com | Secondary online-string.com 45.32.81[.]152 Vultr Secondary rbdg4nzqadui[.]wikaba[.]com 43.248.136[.]125 Jiangsu Dongyun Cloud VulnCheck skippe | Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access Security Affairs | · Aug 7, 2026 |
| domain | passkeydeploy.com | organizations. Root domains like passkeyhelpdesk[.]com and passkeydeploy[.]com were used by more than one of the groups. Across all the | Google Links Redact Extortion Group to BlackFile Rebrand Infosecurity Magazine | · Aug 7, 2026 |
| domain | passkeyhelpdesk.com | ins across multiple target organizations. Root domains like passkeyhelpdesk[.]com and passkeydeploy[.]com were used by more than one of the | Google Links Redact Extortion Group to BlackFile Rebrand Infosecurity Magazine | · Aug 7, 2026 |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| md5 | 7bdbd180c081fa63ca94f9c22c457376 | 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| md5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| sha256 | 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 | -QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://ta | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| sha256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | .exe Detection Name: Win.Dropper.Miner::95.sbx.tg** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| sha256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| sha256 | a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 | D001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://ta | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| ipv4 | 7.0.9.1 | FMC Software - 7.0 - Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar 7.2 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7. | Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The Hacker News | · Aug 6, 2026 |
| ipv4 | 7.2.11.1 | .1-3.sh.REL.tar 7.2 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar 7.4 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7. | Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The Hacker News | · Aug 6, 2026 |
| ipv4 | 7.4.7.1 | .1-4.sh.REL.tar 7.4 - Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar 7.6 - Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7. | Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The Hacker News | · Aug 6, 2026 |
| ipv4 | 7.6.5.1 | .1-3.sh.REL.tar 7.6 - Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar 7.7 - Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7. | Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The Hacker News | · Aug 6, 2026 |
| ipv4 | 7.7.12.1 | .1-2.sh.REL.tar 7.7 - Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar 10.0 - Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10 | Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data The Hacker News | · Aug 6, 2026 |
| domain | masscan.cloud | for Years The strongest infrastructure link identified was masscan[.]cloud, which appears across TA-NATALSTATUS activity, ShadowRay | TeamPCP Traced Back to 2020 Cryptojacking Operation Infosecurity Magazine | · Aug 6, 2026 |
| domain | bitsender.top | tive ones. The main domain for Poison Claude, poison-claude.bitsender[.]top, ran behind Cloudflare’s CDN, hiding its originating IP a | Discounted Claude access bought on the gray market may expose every prompt you send Help Net Security | · Aug 6, 2026 |
| domain | claudeopus.shop | a phishing warning on the site, but had taken no action on claudeopus[.]shop even though that domain also runs behind Cloudflare. Ecom | Discounted Claude access bought on the gray market may expose every prompt you send Help Net Security | · Aug 6, 2026 |
| domain | qq.com | sed by Chinese internet users, and the top email domain was qq.com, which is a popular email service in China,” Okta wrote. Th | Discounted Claude access bought on the gray market may expose every prompt you send Help Net Security | · Aug 6, 2026 |
| ipv4 | 206.72.242.124 | shed three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and ch | U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog Security Affairs | · Aug 5, 2026 |
| ipv4 | 206.72.242.162 | dresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to block them and check logs for sig | U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog Security Affairs | · Aug 5, 2026 |
| ipv4 | 8.19.75.217 | ny also published three IP addresses linked to the attacks (8.19.75.217, 206.72.242.124, 206.72.242.162) and advised customers to b | U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog Security Affairs | · Aug 5, 2026 |
| domain | bkofamerica.com | id not point to Bank of America's legitimate domain, but to bkofamerica[.]com. The link in the message pointed, again, not to Bank of A | Fake Bank of America Phishing Scam Installs Remote Access Malware Infosecurity Magazine | · Aug 5, 2026 |
| domain | kleinschnitg.com | the message pointed, again, not to Bank of America, but to kleinschnitg[.]com, which then opened a page on sectioncompil[.]com from whi | Fake Bank of America Phishing Scam Installs Remote Access Malware Infosecurity Magazine | · Aug 5, 2026 |
| domain | sectioncompil.com | ica, but to kleinschnitg[.]com, which then opened a page on sectioncompil[.]com from which the malicious zip originated. The researchers | Fake Bank of America Phishing Scam Installs Remote Access Malware Infosecurity Magazine | · Aug 5, 2026 |
| domain | ealerts.bkofamerica.com | d account restrictions,” the email, sent from onlinebanking@ealerts[.]bkofamerica[.]com , tries to push them to follow the link without thinkin | Bank of America impersonators weaponize ScreenConnect, then make it hard to remove Help Net Security | · Aug 5, 2026 |
| domain | kleinschnitg.com | pages are easily identifiable: they are hosted on domains ( kleinschnitg[.]com , sectioncompil[.]com ) that look nothing thing like the | Bank of America impersonators weaponize ScreenConnect, then make it hard to remove Help Net Security | · Aug 5, 2026 |
| domain | sectioncompil.com | tifiable: they are hosted on domains ( kleinschnitg[.]com , sectioncompil[.]com ) that look nothing thing like the legitimate BoA domain. | Bank of America impersonators weaponize ScreenConnect, then make it hard to remove Help Net Security | · Aug 5, 2026 |
| domain | helprans.com | egistrar that accepts cryptocurrency payments. Domain Name: HELPRANS[.]COM Registry Domain ID: 3106477703_DOMAIN_COM-VRSN Registrar | INC Ransomware is Calling Victims - Pressure Tactics Post SonicWall Zero Security Affairs | · Aug 4, 2026 |
| domain | whois.ordertld.com | main ID: 3106477703_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.ordertld.com Registrar URL: http://www.ordertld.com Updated Date: 2026-0 | INC Ransomware is Calling Victims - Pressure Tactics Post SonicWall Zero Security Affairs | · Aug 4, 2026 |
| domain | braintree.net | t Package Delivers Skimmer — A malicious .NET package named Braintree.Net has been found to impersonate Braintree's legitimate Braint | ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More The Hacker News | · Aug 4, 2026 |
| domain | dweb.link | ention – we posted on this subject in 2023. The ipfs.io and dweb.link domains function as IPFS gateways. The principal risk assoc | Phishers are hijacking legitimate cloud infrastructure Kaspersky Securelist | · Aug 4, 2026 |
| domain | ipfs.io | nt close attention – we posted on this subject in 2023. The ipfs.io and dweb.link domains function as IPFS gateways. The princi | Phishers are hijacking legitimate cloud infrastructure Kaspersky Securelist | · Aug 4, 2026 |
| domain | tubely.com | igBasket set of "shoppers," a gaming set, and others). The “tubely[.]com” domain is not new, and neither is the behavior. Public f | “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI Cisco Talos | · Aug 4, 2026 |
| domain | socket.io | rol server through a public blockchain transaction, opens a Socket.IO remote access channel, and stages a Python credential steal | Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js The Hacker News | · Aug 4, 2026 |
| domain | ip-api.com | a blockchain SmartLoader starts by sending a GET request to ip-api.com to collect the victim’s IP address, country, city, time zon | AI developers targeted via trojanized GitHub repositories Help Net Security | · Aug 4, 2026 |
| ipv4 | 104.243.35.63 | match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to originate from p | Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE The Hacker News | · Aug 3, 2026 |
| ipv4 | 216.152.148.54 | compromise (IoCs), all of which match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion ema | Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE The Hacker News | · Aug 3, 2026 |
| ipv4 | 216.152.151.204 | s), all of which match those shared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to or | Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE The Hacker News | · Aug 3, 2026 |
| ipv4 | 5.180.41.35 | hared by PTC - 216.152.148.54 216.152.151.204 104.243.35.63 5.180.41.35 The extortion emails appear to originate from previously co | Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE The Hacker News | · Aug 3, 2026 |
| domain | content.powerapps.com | and the breach notice page references assets on Microsoft’s content.powerapps.com domain, which corroborates the platform connection. That sa | PNLD Confirms Data Breach Affecting UK Police and Justice Staff Security Affairs | · Aug 3, 2026 |
| domain | us.zoom.06webin.us | investor/partnership call." The entire domain scheme being 'us.zoom.06webin.us' and such makes it really easy for someone to fall for thei | BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery The Hacker News | · Aug 1, 2026 |
| ipv4 | 6.1.7.10 | h 8.0.5, and Rails 8.1.0 through 8.1.3. Rails 6.0.0 through 6.1.7.10 releases are affected only when Active Storage is configure | Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads The Hacker News | · Jul 31, 2026 |
| ipv4 | 7.2.3.1 | tt Security list the affected ranges as Rails 7.0.0 through 7.2.3.1, Rails 8.0.0 through 8.0.5, and Rails 8.1.0 through 8.1.3. | Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads The Hacker News | · Jul 31, 2026 |
| ipv4 | 7.2.3.2 | no backport, so affected applications must upgrade to Rails 7.2.3.2 or later. Operators should upgrade to Rails 7.2.3.2, 8.0.5. | Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads The Hacker News | · Jul 31, 2026 |
| ipv4 | 8.0.5.1 | .2.3.2 or later. Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the applica | Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads The Hacker News | · Jul 31, 2026 |
| ipv4 | 8.1.3.1 | ter. Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the application process | Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads The Hacker News | · Jul 31, 2026 |
| domain | dns.multitoconference.com | hen creates a stream socket using a hard‑coded C2 address ( dns[.]multitoconference[.]com ) and port 443. It gathers the following information fr | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| domain | dns.ssentialserv.xyz | e, the attacker at first checked connectivity to the domain dns[.]ssentialserv[.]xyz as shown below. At the time of our research, the domain | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 082d49ef9f14e6811d68c7e0e82e5069 | IntSvc , which loads the loader DLL named oleasapi.dll (MD5 082d49ef9f14e6811d68c7e0e82e5069 ). The ServiceMain parameter in the service’s registry entr | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 2a571f6cee42a17d873f4c942649813f | ogger located at C:\Users\Public\Pictures\AnyDesk.exe (MD5: 2a571f6cee42a17d873f4c942649813f ). They then created a scheduled task named AnyDesk to run | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 32a5985543433a4f60da2fafd873b927 | tsdump Attackers ran a malicious file named Adobe.exe (MD5 32a5985543433a4f60da2fafd873b927 ), which is a portable‑executable version of Impacket’s sec | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 37dc84e4bcad92fa28f1e7778d088283 | rd Decryptor tool C:\users\[username]\libraries\64.exe (MD5 37dc84e4bcad92fa28f1e7778d088283 ) is used to extract passwords from browsers. The tool offe | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 45cf5916fab4272a1313c26e67aa9220 | executing the script located at C:\windows\temp\in.bat (MD5 45cf5916fab4272a1313c26e67aa9220, 4e6d5c4770d5a822d7fcce6a74f7ad73). After querying the task | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 4e6d5c4770d5a822d7fcce6a74f7ad73 | \windows\temp\in.bat (MD5 45cf5916fab4272a1313c26e67aa9220, 4e6d5c4770d5a822d7fcce6a74f7ad73). After querying the task’s status, the attacker triggers i | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 5e26df131ff0a679a0a2699b723b46e3 | ther C:\Users\[username]\1.bat or C:\ProgramData\1.bat (MD5 5e26df131ff0a679a0a2699b723b46e3). The task’s status is first queried, then it is executed, | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 6ecf84fb18f6747ed08d7598364d853a | tch script located at C:\Users\<username>\Videos\1.bat (MD5 6ecf84fb18f6747ed08d7598364d853a ). Prior to executing the task, the actor queries its statu | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | b874123a80fc4f40e06872b9cb54ebc6 | the batch script C:\Users\[username]\Desktop\auto.bat (MD5 b874123a80fc4f40e06872b9cb54ebc6 ). The script created a service named Cusrxsrv , which load | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | cf903e4a1629aa0582fd0363b5786676 | services. The executable is dropped to %TEMP%\fc.exe (MD5: cf903e4a1629aa0582fd0363b5786676) and writes its output to %TEMP%\result.txt . Using Fscan, | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| domain | hunt.io | , uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and independent journalist NetAskari started wi | Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App Security Affairs | · Jul 30, 2026 |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| md5 | 7bdbd180c081fa63ca94f9c22c457376 | 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| md5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| md5 | ded73d04bb3e3525226de64c38a332e3 | 6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 MD5: ded73d04bb3e3525226de64c38a332e3 Talos Rep: https://talosintelligence.com/talos_file_reputat | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| sha256 | 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 | : f_000177.exe Detection Name: W32.Trojan.29jq.1201 SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://ta | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| sha256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | .exe Detection Name: Win.Dropper.Miner::95.sbx.tg** SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| sha256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| sha256 | a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 | VID001.exe Detection Name: Win.Worm.Coinminer::1201 SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://ta | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| sha256 | fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 | -QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 MD5: ded73d04bb3e3525226de64c38a332e3 Talos Rep: https://ta | You were onto something with “It’s the Climb,” Miley Cisco Talos | · Jul 30, 2026 |
| domain | rg-telemetry.sbs | figuration responsible for fetching the actual C2 servers: "rg-telemetry[.]sbs/api" and "th-updates[.]sbs/analytics." "Each contract was | DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto The Hacker News | · Jul 30, 2026 |
| domain | th-updates.sbs | tching the actual C2 servers: "rg-telemetry[.]sbs/api" and "th-updates[.]sbs/analytics." "Each contract was created by a throwaway wal | DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto The Hacker News | · Jul 30, 2026 |
| domain | fwgcloud.com | evices. AI DIGITAL HUMANS The domain for the Fengwo Group — fwgcloud[.]com — claims the company is “redefining the boundaries of hum | Read This Before You Buy That TV Streaming Stick Krebs on Security | · Jul 30, 2026 |
| domain | cubepilot.org | nknown threat actors are said to have gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercep | ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories The Hacker News | · Jul 30, 2026 |
| domain | jshosting.me | same reverse-tunnelling address 176.65.128[.]26. The domain jshosting[.]me was used to distribute exploit scripts in both sets of at | Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts The Hacker News | · Jul 30, 2026 |
| ipv4 | 1.1.4.4 | Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as t | Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts The Hacker News | · Jul 30, 2026 |
| ipv4 | 1.1.4.6 | rity Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed release | Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts The Hacker News | · Jul 30, 2026 |
| ipv4 | 7.0.9.1 | ease Hot Fix Name 7.0 Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar 7.2 Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2. | U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog Security Affairs | · Jul 30, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.