Indicators of compromise
4,250 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| ipv4 | 7.2.11.1 | .9.1-3.sh.REL.tar 7.2 Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar 7.4 Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4. | U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog Security Affairs | · Jul 30, 2026 |
| ipv4 | 7.4.7.1 | 11.1-4.sh.REL.tar 7.4 Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar 7.6 Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6. | U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog Security Affairs | · Jul 30, 2026 |
| ipv4 | 7.6.5.1 | .7.1-3.sh.REL.tar 7.6 Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar 7.7 Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7. | U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog Security Affairs | · Jul 30, 2026 |
| ipv4 | 7.7.12.1 | .5.1-2.sh.REL.tar 7.7 Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar 10.0 Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0 | U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog Security Affairs | · Jul 30, 2026 |
| md5 | 18f61c6d686cffd131c9fd3f3437064b | AD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 25480dad40152ef3d0c6d38eecc9bd9b | FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F34 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 34a7f28e0bb69b0d49bacc88bdf20ac1 | D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe 34A7F28E0BB69B0D49BACC88BDF20AC1 run.exe, run2.exe, genie.exe 5D62C1349B8981C396C9A23F4F8F05 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 34b8828635f88078735799a3c1ac8e28 | 4F8F053C genie_encrypt.exe A8842616C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB3 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 3a4479b51890373bfc4a011ef41fe376 | D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F069660166D61FD74F911 GenieLocker for Linux and | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 58c0dda52b8f069660166d61fd74f911 | 7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F069660166D61FD74F911 GenieLocker for Linux and ESXi 9201E35E2993612612919A3C7130 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 5d62c1349b8981c396c9a23f4f8f053c | Trojan for Windows The Windows version of GenieLocker (MD5: 5d62c1349b8981c396c9a23f4f8f053c) is primarily written in C, but compiled with the C++ libra | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 780c8f4c6f077da4da96582987920362 | 0C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 7dad78584795aa5c160520cc6accf260 | E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6ACCF260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 824ca1e906cc073ee5b0f3519df69a8f | 50DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EECC9BD9B 7DAD78584795AA5C160520CC6A | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 9201e35e2993612612919a3c71302cab | ounterpart, the Linux and ESXi version of GenieLocker (MD5: 9201e35e2993612612919a3c71302cab) is simpler: there is no secret argument, anti‑debugging te | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 9969a8221312dba70dd5cbddf83a146c | F260 18F61C6D686CFFD131C9FD3F3437064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | 9cd514ff2809ce0b993e3b8649e82a94 | C3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906CC073EE5B0F3519DF69A8F 25480DAD40152EF3D0C6D38EEC | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | a50eaaf514f4f84e61ca2455a8789753 | ntact: [email protected] . GenieLocker for Windows A50EAAF514F4F84E61CA2455A8789753 kftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | a8842616c9057d5cf6e1fe1fa8c3c160 | enie.exe 5D62C1349B8981C396C9A23F4F8F053C genie_encrypt.exe A8842616C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | b893eafed0659f70d4ac250f09073723 | 221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373B | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | c68b6862725777651085650db34947fc | 8635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF2809CE0B993E3B8649E82A94 824CA1E906C | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | d3e06eb34d8eee7ef92cac3ad0a20ff5 | 16C9057D5CF6E1FE1FA8C3C160 34B8828635F88078735799A3C1AC8E28 D3E06EB34D8EEE7EF92CAC3AD0A20FF5 C68B6862725777651085650DB34947FC consultant.exe 9CD514FF280 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | d661cf666b9acbab7cfeae1127a261a9 | 6E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127A261A9 genie.exe 3A4479B51890373BFC4A011EF41FE376 58C0DDA52B8F0696 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | d87d0b01d95acc936b7dc47b8f41937a | B50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F41937A run.exe, genie_encrypt.exe 34A7F28E0BB69B0D49BACC88BDF20AC1 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | de3cfbb50f66079bfee20a6f64e59433 | 6F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987920362 D87D0B01D95ACC936B7DC47B8F | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | f08f476f26b01d142ca73923de65fc0c | 50EAAF514F4F84E61CA2455A8789753 kftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | f7b9e36e94163a9a303160945f99267a | 064B tempo.exe, kernel.exe 9969A8221312DBA70DD5CBDDF83A146C F7B9E36E94163A9A303160945F99267A B893EAFED0659F70D4AC250F09073723 D661CF666B9ACBAB7CFEAE1127 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| md5 | fd46a80c2f45577263328984edf7f4dc | ftd.exe, genie_encrypt.exe F08F476F26B01D142CA73923DE65FC0C FD46A80C2F45577263328984EDF7F4DC DE3CFBB50F66079BFEE20A6F64E59433 780C8F4C6F077DA4DA96582987 | New GenieLocker ransomware for Windows, ESXi, and Linux Kaspersky Securelist | · Jul 30, 2026 |
| domain | npmjs.store | n XOR cipher keyed to 01042025 . The network indicators are npmjs[.]store and 216[.]74[.]123[.]126 . Amazon's post cites the OSV re | Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet The Hacker News | · Jul 30, 2026 |
| domain | agrocenter-eurohem.ru | t where the scammers had created a fraudulent website ("www.agrocenter-eurohem[.]ru") that was a near-perfect virtual copy of the legitimate | Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments The Hacker News | · Jul 29, 2026 |
| domain | 110gongan.com | une 18 that the fake application was being distributed from 110gongan[.]com, associated with 207.56.30[.]188, and could steal payment | Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates The Hacker News | · Jul 29, 2026 |
| domain | login.trees4sale.net | node reports its status to a heartbeat collection server at login.trees4sale.net:9000, sending a JSON health report with connection count an | Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure Security Affairs | · Jul 28, 2026 |
| sha1 | 3b4f44d8e3d9d5de35127b42dd449babe2d19fe5 | he main branches of both LuCI and uhttpd, using LuCI commit 3b4f44d8e3d9d5de35127b42dd449babe2d19fe5 from May 27 and uhttpd commit 7b1bec45826bd78c8afc993435bdc | Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root The Hacker News | · Jul 28, 2026 |
| sha1 | 7b1bec45826bd78c8afc993435bdc0f1df2fe399 | 9d5de35127b42dd449babe2d19fe5 from May 27 and uhttpd commit 7b1bec45826bd78c8afc993435bdc0f1df2fe399 from June 13. It described three as pre-authentication path | Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root The Hacker News | · Jul 28, 2026 |
| domain | aecert.org | folio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[.]98[.]113 aecert[.]org realhealthshop[.]com tjconsultingservices[.]com thehealth | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | buisness-centeral-transportation.com | hshop[.]com tjconsultingservices[.]com thehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarez | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | business-deegital.azurewebsites.net | lobal-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.] | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | businessdeegital.azurewebsites.net | ness-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | business-deegital.com | businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsites[.]net businessdeegital[ | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | businessmixture.com | PAPI.dll Domains and IPs smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.] | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | business-startup.azurewebsites.net | althcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[.]azurewebsites[.]net | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | businessstartup.azurewebsites.net | ]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[.]azurewebsites[.]net | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | global-reds.com | Ps smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegi | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | healthcarezoom-centeral.azurewebsites.net | thehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcare | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | healthcarezoomcenteral.azurewebsites.net | rtation[.]com healthcarezoom-centeral[.]azurewebsites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsites | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | healthcarezoomcenteral.org | websites[.]net healthcarezoomcenteral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azure | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | maadinglobal.com | azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.]com Business-deegital[.]com business-deegital[.]azurewebsites | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | neexportfolio.azurewebsites.net | ]azurewebsites[.]net businessdeegital[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[. | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | neexportfolio.com | l[.]azurewebsites[.]net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[ | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | neexportfolio.eastus.cloudapp.azure.com | net neexportfolio[.]azurewebsites[.]net neexportfolio[.]com neexportfolio[.]eastus[.]cloudapp[.]azure[.]com 172[.]86[.]98[.]113 aecert[.]org realhealthshop[.]c | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | realhealthshop.com | GET request to the /edfcvfgbhnjmkqwasderfgg endpoint at the realhealthshop[.]com domain, and uses tjconsultingservices[.]com as a fallback | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | smartconnect.azurewebsites.net | 14A2FE01C7363ECC56F5D046162C – IPHLPAPI.dll Domains and IPs smartconnect[.]azurewebsites[.]net businessmixture[.]com global-reds[.]com maadinglobal[.] | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | thehealth-life.com | ecert[.]org realhealthshop[.]com tjconsultingservices[.]com thehealth-life[.]com buisness-centeral-transportation[.]com healthcarezoom-cen | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | tjconsultingservices.com | erfgg endpoint at the realhealthshop[.]com domain, and uses tjconsultingservices[.]com as a fallback C2. When a valid C2 response is received, t | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | toadreport.azurewebsites.net | centeral[.]azurewebsites[.]net healthcarezoomcenteral[.]org toadreport[.]azurewebsites[.]net business-startup[.]azurewebsites[.]net businessstartup[ | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | 42f847597109da2a220391bb09d00676 | e WebSocket tunneling tool 5FA15EF96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CC6F498 BridgeHead WebSocket tunne | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | 5fa15ef96808ea82f0a6176f0bb4b386 | DBED163679 – sspicli.dll ArcBridge WebSocket tunneling tool 5FA15EF96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33C | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | 6038d42af0affd1fb263f470c0956f6b | 606599C7272CFB33CC6F498 BridgeHead WebSocket tunneling tool 6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7 | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | a239e655709a2518dd0b7bdbed163679 | [email protected] . File hashes NightLedger backdoor A239E655709A2518DD0B7BDBED163679 – sspicli.dll ArcBridge WebSocket tunneling tool 5FA15EF968 | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | ae628efa305387b633dce82f9364875b | tunneling tool 6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthrea | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | afb1c1583606599c7272cfb33cc6f498 | F96808EA82F0A6176F0BB4B386 42F847597109DA2A220391BB09D00676 AFB1C1583606599C7272CFB33CC6F498 BridgeHead WebSocket tunneling tool 6038D42AF0AFFD1FB263F47 | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | c832ecd135781b11f59e3fffb3d2b6ac | ocess of threat hunting, we detected another variant ( MD5: C832ECD135781B11F59E3FFFB3D2B6AC ) that shares the same dynamic-resolve stub pattern. This v | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | c90f0efadbf322e5eb1c4103a38c30e6 | .dll F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll D09B14A2FE01C7363ECC56F5D046162C – IP | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | d09b14a2fe01c7363ecc56f5d046162c | .dll C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll D09B14A2FE01C7363ECC56F5D046162C – IPHLPAPI.dll Domains and IPs smartconnect[.]azurewebsites | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| md5 | f7d36cc5904a53252d2bb3d21615134f | 6B – unbcl.dll AE628EFA305387B633DCE82F9364875B – unbcl.dll F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll C90F0EFADBF322E5EB1C4103A38C30E6 – li | Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools Kaspersky Securelist | · Jul 28, 2026 |
| domain | hunt.io | l prompts for commands that could be considered dangerous," Hunt.io said. "Purpose-built scripts target MOF Hadoop infrastructu | ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More The Hacker News | · Jul 28, 2026 |
| ipv4 | 206.72.242.124 | iew the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, operators shoul | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 206.72.242.162 | determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, operators should preserve VCO | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 5.2.3.14 | llowing versions are affected - VCO 5.2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prio | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 6.1.3.4 | .2.x releases prior to 5.2.3.14 VCO 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prio | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 6.4.2.4 | 6.1.x releases prior to 6.1.3.4 VCO 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged tha | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 7.0.0.1 | 6.4.x releases prior to 6.4.2.4 VCO 7.0.x releases prior to 7.0.0.1 Arista acknowledged that the vulnerability was externally d | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 8.19.75.217 | them and review the logs to determine if they are present - 8.19.75.217 206.72.242.124 206.72.242.162 "If compromise is suspected, | Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw The Hacker News | · Jul 28, 2026 |
| ipv4 | 51.89.204.28 | ative networking functions, and the command server address, 51.89.204.28 on port 4444, is baked directly into the binary rather than | MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data Security Affairs | · Jul 27, 2026 |
| domain | 24carnforth2merseyside.sol | ]eth record encodes distribution-node IPv4 addresses, while 24carnforth2merseyside[.]sol supplies other infrastructure records. The DDoS sample as | Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Hacker News | · Jul 27, 2026 |
| domain | burrberry.eth | at resolves C2 through the same domain. XLab found that the burrberry[.]eth record encodes distribution-node IPv4 addresses, while 24 | Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Hacker News | · Jul 27, 2026 |
| domain | m3rnbvs5d.eth | ator falling back to an Ethereum Name Service (ENS) domain, m3rnbvs5d[.]eth, for command-and-control (C2). XLab's Dysphoria timeline | Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Hacker News | · Jul 27, 2026 |
| domain | purelogicbox.org | d decompresses a clean Bun runtime from that second domain, purelogicbox[.]org in the published sample response. Base64 blobs in the con | Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable The Hacker News | · Jul 27, 2026 |
| domain | corychase.org | d policy, and directed users to a live PHP phishing page on corychase[.]org," the company said . "The landing page was not a Microsof | Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News | · Jul 27, 2026 |
| domain | github.io | dev[.]xyz") has uncovered a GitHub Pages domain ("berry4603.github[.]io") and a repository named "Bluedashltd" that contains the | Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News | · Jul 27, 2026 |
| domain | support.berrydev.xyz | low." Further analysis of the threat actor infrastructure ("support[.]berrydev[.]xyz") has uncovered a GitHub Pages domain ("berry4603.githu | Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News | · Jul 27, 2026 |
| domain | teamvem.com | t published last week. The bogus Teams page in question is "teamvem[.]com." The active download is used to deliver "supportdev.exe, | Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update The Hacker News | · Jul 27, 2026 |
| domain | hunt.io | words and interact with specific internal systems. Although Hunt.io found evidence that the attackers had already compromised m | Hackers used autonomous AI agent to spy on Thailand's finance ministry The Record | · Jul 27, 2026 |
| domain | hypersnet.com | lant written in C++ that contacts an external server ("cert.hypersnet[.]com"). ThreatLabz noted that it identified post-compromise ac | TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments The Hacker News | · Jul 27, 2026 |
| md5 | c99f29ac08454855b3d538960bb2f34f | ctive loader codenamed MIXEDKEY to decrypt the contents of "C99F29AC08454855B3D538960BB2F34F.PCPKEY" and execute it. Both TELESHIM and MIXEDKEY have bee | TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments The Hacker News | · Jul 27, 2026 |
| domain | chatgpt.com | of a phishing link that adheres to the following pattern: "chatgpt[.]com/agents/studio/new?template_name=[template name]&initial_a | ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link The Hacker News | · Jul 27, 2026 |
| ipv4 | 8.8.8.8 | people already have. Switching to a hardcoded resolver like 8.8.8.8 doesn’t save you, because the query still leaves the laptop | Hackers Hijack Hotel Wi Security Affairs | · Jul 26, 2026 |
| domain | claude.ai | s). How attackers hosted a fake Claude download page on the claude.ai domain A threat actor abused Anthropic’s Claude Artifacts f | Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached Help Net Security | · Jul 26, 2026 |
| ipv4 | 104.194.9.14 | .54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 21 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 104.243.35.131 | associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.2 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 104.243.35.63 | 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command-and-control address) Web shel | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 172.111.38.31 | icators of compromise (IoCs) associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104. | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 185.227.83.236 | .146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 209.222.98.44 | 5.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 216.152.148.54 | promise (IoCs) associated with the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 216.152.151.204 | 14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command-and-control add | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 38.60.157.212 | /24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (Attacker command | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 5.180.41.35 | - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 7 | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 74.50.76.146 | the activity - 172.111.38.31 216.152.148.54 104.243.35.131 74.50.76.146 5.180.41.35 104.243.35.0/24 104.194.9.14 209.222.98.44 185. | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
| ipv4 | 78.128.113.10 | 5 104.243.35.0/24 104.194.9.14 209.222.98.44 185.227.83.236 78.128.113.10 38.60.157.212 216.152.151.204 104.243.35.63 5.180.41.35 (At | CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The Hacker News | · Jul 25, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.