ZeroHour

Indicators of compromise

4,250 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
ipv482.114.160.98: 82.114.160.93 and 82.114.160.94. The device identified on 82.114.160.98 was still up at the time of this analysis. The re-emergenceYemeni War Emphasizes Importance of Internet Control in Statecraft and Conflict/yemen-internet
Recorded Future
· Jul 16, 2026
domainagent01.xeox.comThree entries it originally listed as malicious indicators, agent01.xeox.com , ws01.xeox.com , and 80.80.250.0/24 , are legitimate XEOXMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
The Hacker News
· Jul 15, 2026
domainasp.netromising an internet-facing IIS web server and uploading an ASP.NET web shell. Over the next three hours, they established persThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
The Hacker News
· Jul 15, 2026
domainextensions-hub.compdate, and uninstall, the extension pinged a second domain, extensions-hub[.]com, with the product, version, and browser. And a script thaGoogle and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
The Hacker News
· Jul 15, 2026
domaingeeked.wtfts were registered seconds apart, tied to a commit email at geeked[.]wtf and a Discord handle. Ninety of the 93 deployment hostnam148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
The Hacker News
· Jul 15, 2026
domaingov.brsed systems observed during the investigation were timon.ma.gov[.]br, loginam.sesp.es.gov[.]br (state public security), aplica20+ Hijacked Government Websites Became an Attack Channel
The Hacker News
· Jul 15, 2026
domaingsnc.euinstead. Group-IB traced this copy to an operator relay at gsnc[.]eu:67 , with the binary pulled from gsocket.io itself. The sNew ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
The Hacker News
· Jul 15, 2026
domaingsocket.ioperator relay at gsnc[.]eu:67 , with the binary pulled from gsocket.io itself. The stealer payloads sit on three compromised domaiNew ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
The Hacker News
· Jul 15, 2026
domainhunt.iofiltration. 3,900 threat servers mapped A new analysis from Hunt.io has uncovered more than 3,900 threat activities enabling seThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
The Hacker News
· Jul 15, 2026
domainipfs.iosystem-specific paths and executed. The downloader URL is "ipfs[.]io/ipfs/QmQobZSp1wRPrpSEQ56qnyq7ecZh5Bg5k1fnjt4SUwwHb9." TheCompromised AsyncAPI npm Packages Deliver Multi
The Hacker News
· Jul 15, 2026
domainlogfriend.comon utilize an operator panel accessible over the clearnet ("logfriend[.]com/login"), from where they can generate lures, set up campaForg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
The Hacker News
· Jul 15, 2026
domainlunaron.topaimed each browser at 30 connections to a Wisp endpoint on lunaron[.]top, itself a live proxy busy injecting malvertising. Wisp is148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
The Hacker News
· Jul 15, 2026
domainmoonsand.storehooks the app's Electron internals. Then it asks its C2 at moonsand[.]store . If the server sets a Wait flag, SeedHunter scans USB byOkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
The Hacker News
· Jul 15, 2026
domainpicis.netms since 2018, now running a Microsoft 365 AiTM platform on picis[.]net and monetizing access through a bulk mailer he wrote callMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
The Hacker News
· Jul 15, 2026
domainpipicka.xyztion with the remote server, including the server details ("pipicka[.]xyz") and the polling interval used by the implant. AlternatiLabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
The Hacker News
· Jul 15, 2026
domainromnor.cans alive on its own. Both phishing domains, picis[.]net and romnor[.]ca, were offline when The Hacker News checked ahead of publiMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
The Hacker News
· Jul 15, 2026
domainstanfordstudies.coms the encrypted list with your fingerprint, posts it to api.stanfordstudies[.]com, and wipes the local copy. The upload time is offset perGoogle and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
The Hacker News
· Jul 15, 2026
domaintorproject.org.122[.]124 C2 IP: 57.128.246[.]79 Tor infrastructure: check.torproject[.]org, archive.torproject[.]org On-host artifacts: a randomly nCompromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The Hacker News
· Jul 15, 2026
domainvipersfutbol.comnt build still reaches, among them woofbeginner[.]com and c.vipersfutbol[.]com, are the ones to block first. Anyone who has loaded one o148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
The Hacker News
· Jul 15, 2026
domainwerkbit.appized dropper that's distributed as a disk image file named "Werkbit.app." Because both the disk image and binary are notarized andCrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
The Hacker News
· Jul 15, 2026
domainwerkbit.ior checks. The disk image itself originates from the domain "werkbit[.]io," which was registered in June 2026. In an interesting twCrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
The Hacker News
· Jul 15, 2026
domainwoofbeginner.comnd script hosts the current build still reaches, among them woofbeginner[.]com and c.vipersfutbol[.]com, are the ones to block first. An148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
The Hacker News
· Jul 15, 2026
domainws01.xeox.comiginally listed as malicious indicators, agent01.xeox.com , ws01.xeox.com , and 80.80.250.0/24 , are legitimate XEOX vendor infrastruMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
The Hacker News
· Jul 15, 2026
sha256a41a523ef9517aab37ed6eea0ec881821bdcb7aefcb5c5f603adc7907f868c86cbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60 dist/intro.js: a41a523ef9517aab37ed6eea0ec881821bdcb7aefcb5c5f603adc7907f868c86 Linux payload: fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The Hacker News
· Jul 15, 2026
sha256a742de963f14a92d24ebcbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60added files and their decompressed payloads: dist/setup.js: a742de963f14a92d24ebcbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60 dist/intro.js: a41a523ef9517aab37ed6eea0ec881821bdcb7aefcb5Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The Hacker News
· Jul 15, 2026
sha256b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d05490347a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd Windows payload: b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903 macOS payload: c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b5Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The Hacker News
· Jul 15, 2026
sha256c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd25cedf741de0917c2096bbc9d24649eea7853d054903 macOS payload: c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd Network endpoints StepSecurity observed at runtime. The twoCompromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The Hacker News
· Jul 15, 2026
sha256fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd6eea0ec881821bdcb7aefcb5c5f603adc7907f868c86 Linux payload: fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd Windows payload: b7ca95d1b23c8e67416a25cedf741de0917c2096bbCompromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The Hacker News
· Jul 15, 2026
domainmoonsand.storeby the malware Then the malware communicates with the C2 ( moonsand[.]store ) over HTTPS, sending a Base64-encoded JSON request contaOkoBot framework infection chain
Kaspersky Securelist
· Jul 14, 2026
domainfiles.pythonhosted.orgDuring installation, the PyPI frontend redirects users to “files.pythonhosted.org”, where the actual files are stored. Download URLs are deriThe serpent’s tongue: Luring the Python out of its den
Cisco Talos
· Jul 14, 2026
domaincohezo.comd to the same campaign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the Developer Team ID tCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domaincohezo.ionterfaces tied to the same campaign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the DevelCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domaincordinex.ioaign have been identified at cohezo[.]io, cohezo[.]com, and cordinex[.]io. Jamf reported the Developer Team ID to Apple after confiCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domaincrashreporter.appce indicator on its own. The downloaded disk image contains CrashReporter.app, which carries the bundle identifier com.apple.crashreporteCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domainendpoint-api-v1.comcommand the dropper runs next, pulling a shell script from endpoint-api-v1[.]com. The script isn’t written to disk in readable form: it arCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domainwerkbit.appe ad-hoc-signed payload it installs.” When the victim opens Werkbit.app, it queries the GitHub API and fetches a file called sys.caCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domainwerkbit.ioGatekeeper on first launch without any warning. The domain werkbit[.]io, which serves the installer, was registered in late JuneCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
ipv4179.43.166.242eporting component. The Info.plist contains the C2 address, 179.43.166.242, hardcoded as an App Transport Security exception, visibleCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
urlhttp://endpoint-api-v1[t downloads the payload disk image over cleartext HTTP from hxxp://endpoint-api-v1[.]com/d/f1b24e/download , retrying up to three times, and saCrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Security Affairs
· Jul 14, 2026
domainwerkbit.ioirming its use in the campaign. The installer was hosted on werkbit[.]io, a domain registered in late June, close to the build datNew macOS malware steals passwords by posing as Apple's crash-reporting tool
Help Net Security
· Jul 14, 2026
domain7zip.comwith a trojanized 7-Zip installer hosted on a domain named "7zip[.]com," covertly recruiting compromised devices as proxy nodes.Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
The Hacker News
· Jul 12, 2026
domain7-zip.orgtly referenced domain names (e.g., "7zip[.]com" instead of "7-zip[.]org") to use them to their advantage. Further analysis of theFake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
The Hacker News
· Jul 12, 2026
domainiplogger.comto their advantage. Further analysis of the IPLogger URL ("iplogger[.]com/mnWD") embedded within the samples tied to the 7-Zip campFake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
The Hacker News
· Jul 12, 2026
domaingov.pkis the Complaint Management System ("cms.balochistanpolice.gov[.]pk"), which is used for registering, tracking, and resolvingHackers Weaponize Balochistan Police Portal in Multi
The Hacker News
· Jul 11, 2026
md5257bbbbe0a2598872278c87d801d06fdnews.com/article/greece-marfin-bank-deaths-firebomb-arrests-257bbbbe0a2598872278c87d801d06fd A highly concerning development out of Greece this week regFriday Squid Blogging: "Squidbleed" Vulnerability
Schneier on Security
· Jul 10, 2026
domaininjective.networkest to an external server ("testnet.archival.chain.grpc-web.injective[.]network") in a single beacon. StepSecurity noted the malicious reInjective Labs GitHub Compromise Pushes Wallet-Key
The Hacker News
· Jul 10, 2026
domainhunt.iospilled the group's phishing tools and logs, in a campaign Hunt.io called Operation Roundish . What to do now If you run any oExposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
The Hacker News
· Jul 10, 2026
domainxxooonline.eu.ccucture: 137.175.93[.]126, 43.108.17[.]80, and the domain xs.xxooonline[.]eu[.]cc. What makes WP-SHELLSTORM worth attention is not how adExposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
The Hacker News
· Jul 10, 2026
ipv42.9.99.5s here. Treat the Joomla JCE flaw (CVE-2026-48907, fixed in 2.9.99.5) as urgent too, since it is a maximum-severity and on CISA'Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
The Hacker News
· Jul 10, 2026
domaingithub.comted with the investigation of a single malicious Go module: github[.]com/kaleidora/dnsub-scanning-tool, which presented itself as222 GitHub Repositories Linked to Fake Go Package Malware Operation
Security Affairs
· Jul 10, 2026
domainmuckcoding.comed a hidden PowerShell command that downloaded content from muckcoding[.]com, saved it as api.db, decoded it using certutil, wrote the222 GitHub Repositories Linked to Fake Go Package Malware Operation
Security Affairs
· Jul 10, 2026
domainrambler.rulow combined a threat actor-linked email address, ischhfd83@rambler[.]ru, with force-push automation, a schedule running every min222 GitHub Repositories Linked to Fake Go Package Malware Operation
Security Affairs
· Jul 10, 2026
sha25651cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807tion blob recovered from the dead-drop material has SHA-256 51cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807 .” The decrypted URL resolves to a GitHub release: a passwo222 GitHub Repositories Linked to Fake Go Package Malware Operation
Security Affairs
· Jul 10, 2026
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputatWinning 54% of the time
Cisco Talos
· Jul 9, 2026
md538de5b216c33833af710e88f7f64fc98bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputatWinning 54% of the time
Cisco Talos
· Jul 9, 2026
md59b512ba139304c247ddd3d2c4b9179fd9e8aa423684827b4375a35684c71c600f2dd9101f235e8ec633488 MD5: 9b512ba139304c247ddd3d2c4b9179fd Talos Rep: https://talosintelligence.com/talos_file_reputatWinning 54% of the time
Cisco Talos
· Jul 9, 2026
md5cc4d231df34e57f59eb970353c7d9de2a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://talosintelligence.com/talos_file_reputatWinning 54% of the time
Cisco Talos
· Jul 9, 2026
sha256621c6d42409e8aa423684827b4375a35684c71c600f2dd9101f235e8ec633488D001.exe Detection Name: Win.Worm.Coinminer::1201** SHA256: 621c6d42409e8aa423684827b4375a35684c71c600f2dd9101f235e8ec633488 MD5: 9b512ba139304c247ddd3d2c4b9179fd Talos Rep: https://taWinning 54% of the time
Cisco Talos
· Jul 9, 2026
sha2569896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7ffd.exe Detection Name: W32.HEUR:Attribute.28iy.1201 SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://taWinning 54% of the time
Cisco Talos
· Jul 9, 2026
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://taWinning 54% of the time
Cisco Talos
· Jul 9, 2026
sha256afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638-QAD.exe Detection Name: Win.Tool.Procpatcher::1201 SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2 Talos Rep: https://taWinning 54% of the time
Cisco Talos
· Jul 9, 2026
domaincamorreado.clickmd.exe > curl.exe to download a malicious MSI (v7.msi) from camorreado[.]click and execute it. The MSI is a multi-stage loader that downThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
The Hacker News
· Jul 9, 2026
domaingovtop.oneurgency and trick users into clicking on a malicious link ("govtop[.]one/incometax") embedded within PDF attachments. The bogus laSuspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
The Hacker News
· Jul 9, 2026
domainkkxqbh.topo take screenshots and exfiltrate data to a remote server ("kkxqbh[.]top"). Exactly who is behind the activity is unclear, but infSuspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
The Hacker News
· Jul 9, 2026
domainouewop.comRAT belonging to the AsyncRAT malware family connecting to ouewop[.]com on port 6351 It's worth noting that DCRat is one of the sSuspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
The Hacker News
· Jul 9, 2026
domain7zip.com2026: a fake version of the 7-Zip archive utility hosted at 7zip[.]com instead of the real site, 7-zip[.]org. The researchers unFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domain7-zip.orghive utility hosted at 7zip[.]com instead of the real site, 7-zip[.]org. The researchers uncovered a years-long operation they’reFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domainiplogger.comitimate visitor-tracking service. The specific URL, hxxps://iplogger[.]com/mnWD, appeared across multiple distinct payloads spanningFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domainproxyreviews.orgt appear to be independent proxy review websites, including proxyreviews[.]org, to drive traffic to its own storefronts. The review siteFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domainsmartproxy.comreal Smartproxy company. Decodo, which owns the legitimate smartproxy[.]com, publicly called out the domain squatter. The fake was goFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domainsmartproxy.orgillustrates how convincing the impersonation is. The domain smartproxy[.]org presents itself as a budget proxy service offering accessFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
urlhttps://iplogger[r, a legitimate visitor-tracking service. The specific URL, hxxps://iplogger[.]com/mnWD, appeared across multiple distinct payloads spannFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Security Affairs
· Jul 9, 2026
domainaccenture.com121123_AtriasTalentAcademy”, hosted on a partially redacted accenture.com domain. The real danger isn’t the headline number: SSH andA Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breach
Security Affairs
· Jul 8, 2026
domaincalvexagroup.comLLC . The “contact” link on the website for Calvexa Group — calvexagroup[.]com — forwards visitors to irisc2[.]com. G2Exchange shows thaFelons, Fraudsters Flog Offensive Cybersecurity Startup
Krebs on Security
· Jul 8, 2026
domaing2exchange.com, and operational value.” The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based iFelons, Fraudsters Flog Offensive Cybersecurity Startup
Krebs on Security
· Jul 8, 2026
domainirisc2.com/industry experience.” The website linked in that profile — irisc2[.]com — says the company is hiring for a number of open positioFelons, Fraudsters Flog Offensive Cybersecurity Startup
Krebs on Security
· Jul 8, 2026
domainbancaporinternetbbmx.onlinethe phishing landing page One such redirect destination, "'bancaporinternetbbmx[.]online," contains a page-load Telegram notification script thatSCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
The Hacker News
· Jul 8, 2026
domainfakeupdate.netmediately launches Microsoft Edge in kiosk mode pointing to fakeupdate[.]net, a well-known pentesting/red team site that renders a fakSCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
The Hacker News
· Jul 8, 2026
domainbleacherreport.comGerman streaming guide service, and one that resembles the BleacherReport[.]com certificate. JustWatch itself has not been compromised, nNew Malicious Campaign Delivers Vidar Stealer and Monero Crypto Miner
Infosecurity Magazine
· Jul 8, 2026
domainaccenture.comtration from a private Azure DevOps repository hosted on an accenture.com -associated production URL. When contacted, an Accenture meAccenture acknowledges security incident following 35GB data theft claim
Help Net Security
· Jul 8, 2026
domainshapedplugin.comr's Easy Digital Downloads (EDD) infrastructure via account.shapedplugin[.]com. The free versions of the plugins on WordPress.org are noShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
The Hacker News
· Jul 7, 2026
sha2560352f3e338261d98895df4c7b7a76b296485b2290c72bce56603351d167d06016f3a8e913f526ec57eeec50e1306f7b34b037915b7a1cf2968cc46acc58 0352f3e338261d98895df4c7b7a76b296485b2290c72bce56603351d167d0601 52b871429833e1dee348263844efb531f6a3fcd321f88dc8a876caaee91UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha25603926e3da998f32ad898b640bd15cf145768f9e849e6f18d81350234254c424eea5339c73cb4a777a3e9f98bf3cb08da6622c9dd3b4cc9b083cb03d10a2 03926e3da998f32ad898b640bd15cf145768f9e849e6f18d81350234254c424e 16971f9706d70ac4925651c7c8719b9d77aff63e4c0a618129efc32c2c4UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha25608701ed7975bf4f5688c2724d27ab497764200ad6f4dc53d3cc03b170378ced0878e28284539419612616d964ab9224cbe27e57f42293d91d02d684e3db 08701ed7975bf4f5688c2724d27ab497764200ad6f4dc53d3cc03b170378ced0 604b53f87d6c070bf387e80c70a6df8d272fa3fc143148d41f13e59d52aUAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha2560a8555a71868749be8c905ed53296ce335af50a9262772b5e154ad3f9c35c2e449fa81a699a667cafdbd6d1f6e781edd686c947eb8ae27134f6dc2c43d7 0a8555a71868749be8c905ed53296ce335af50a9262772b5e154ad3f9c35c2e4 5dbfa033676b5caacfae902734ce462cd871181eefbe299250ca8ac7e13UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha2560a8cae96e25e85c612b0736fe886f9b124ad70ec425bc2ec1a8a4135b25436ba3f87d6c070bf387e80c70a6df8d272fa3fc143148d41f13e59d52ab1f13 0a8cae96e25e85c612b0736fe886f9b124ad70ec425bc2ec1a8a4135b25436ba 8459ff264a2c81c68a34c4ee6bc109d141ad28b96037d34ff112322a4c8UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha2560af4c52a1d13e4132a1843ce7727abcf0ddd4d1ca6a4b17cdf599ec3f355c241c61baa67ae2838a36c2e6ff0476a8f2117b96a7027b830c8cb46ce78efc 0af4c52a1d13e4132a1843ce7727abcf0ddd4d1ca6a4b17cdf599ec3f355c241 d4861088161fc72b9922abf933b4ea664a807105ec1eab4a173253aa60bUAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha25613acadb3541e75af50e02d5be56c2238b93d8f154ce5514be1558e6ee59a14328dea8ed9aec4466e67a9d0aecf9e7026ff16a792d1d6f306e8b67d3f34c 13acadb3541e75af50e02d5be56c2238b93d8f154ce5514be1558e6ee59a1432UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha2561660536f448b8b9f086ce9ea3ce4e9deefc59a76711ea53ee6d8f08fc8c1bb99636eec376ad6c3ece2202b1722219955638e09b6f96d4cfc0598d3b1890 1660536f448b8b9f086ce9ea3ce4e9deefc59a76711ea53ee6d8f08fc8c1bb99 65feba2c971c214e71303ad2e0fbf62b45ebcaa784cbf3d0dab62786cb4UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha25616971f9706d70ac4925651c7c8719b9d77aff63e4c0a618129efc32c2c46b989e3da998f32ad898b640bd15cf145768f9e849e6f18d81350234254c424e 16971f9706d70ac4925651c7c8719b9d77aff63e4c0a618129efc32c2c46b989 6917c0f9eafefe42e33e791b75a7e503ff8b081bc10a98449e4076787dfUAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha2561b5649b479fd625de5c8120873644b5eb669cc89cd504582c18e0ae350fd8823ttp[:]//95.182.100[.]231:2222/ Malware indicators LEASHTEST 1b5649b479fd625de5c8120873644b5eb669cc89cd504582c18e0ae350fd8823 LONGLEASH 755fcee1337a252203002ecfdf673a08cfadeda8d738bef2dUAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha25620fcba222f74dd68aaeb1f0ad30cdf702a828ee164a182b30d05d600c35b72d9033676b5caacfae902734ce462cd871181eefbe299250ca8ac7e139719e 20fcba222f74dd68aaeb1f0ad30cdf702a828ee164a182b30d05d600c35b72d9 912adea5339c73cb4a777a3e9f98bf3cb08da6622c9dd3b4cc9b083cb03UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha25629686c933cec1e274467e2dae264625ae6f754824bb7f550bc9c3131f625562ca37a9943a267a8b2100fba2678353d6ec88844505ccbba659e586c7a105 29686c933cec1e274467e2dae264625ae6f754824bb7f550bc9c3131f625562c d973ad5a80c3d7468a9c392db4166857ed32b5d61cd6755766ba8922156UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha25629c7fccc6ef8cbfe4da9a169c7c74bacaea1fb515a1fddef91ab1b1522f76e4c1f273eeb576d39235d0a5c6f18f2574b132a1022598edfa38065783ab98 29c7fccc6ef8cbfe4da9a169c7c74bacaea1fb515a1fddef91ab1b1522f76e4c 425bf771c8c9f740b1ae9803dcb4fd45af4d6a6f171fcc72fc7d511095cUAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha2562e0e43776e2e1a37d882a1b2ebb7d337ee88950177e43831dae645a367824febe8ae98579bfb940290f60e59a502b3065345aaf765456387989c0488b20 2e0e43776e2e1a37d882a1b2ebb7d337ee88950177e43831dae645a367824feb b5969636eec376ad6c3ece2202b1722219955638e09b6f96d4cfc0598d3UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha2562ebc1b6cf543e2cb3f22d9a5b54b6676bb71dde98df7532f8791297734e44fdddfae488d9dfe260b32460a1d947fb5af58ceaf2fb0139bc08b4bb79a966 2ebc1b6cf543e2cb3f22d9a5b54b6676bb71dde98df7532f8791297734e44fdd 6dbd507ca7cecea861f9cf704b3c5c37f5bd5392886a8c2562088892b77UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha2563169a6dbcce684e2c5a2f166996b58ffa673df6e58b8edf2bdf3e66271c8c69ee9acd50f96d566e8d139f6490abf2bbf7a9293b876eeb4598fd2c37c515 3169a6dbcce684e2c5a2f166996b58ffa673df6e58b8edf2bdf3e66271c8c69e d871d76171504597bbda387689e12e7a5e354c360ff135f4df231cec68cUAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha256323c3a91be60ebc3e06e942bad04899a15911cea23269e43d07829164b2ce5d490571645c4641dcff2c07a4c3ab9acad06aa9607350a385729d8d6139f1 323c3a91be60ebc3e06e942bad04899a15911cea23269e43d07829164b2ce5d4 880425fee707e9f42e0b8d60119ed639b1ad506ea29877d126bdebce379UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha256324d95024fc8da5c92b5a1f4825aed5a2a91c9ca8fb6aa52abb332a4c9cf425729d9d0d4e45fc2b784a7fcfcf31dd48fd3bde30f8d956383d1 JARLEASH 324d95024fc8da5c92b5a1f4825aed5a2a91c9ca8fb6aa52abb332a4c9cf4257 bafba443170e54ef7fd431ce7f1b5e202719f3fd022e4ef70788904f574UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026
sha25633c10b77e1da9f0679023d55fb3057879d15609db9c1d46ee5c3ff1240a3d052b231c23d41234e55b1f7ed89f86234f785adbbe820959655d7b019d7df9 33c10b77e1da9f0679023d55fb3057879d15609db9c1d46ee5c3ff1240a3d052 5faea1650cac0f3ffd2dc1fb220182095a46e34158967d37c2a942e85e2UAT-7810 continues building ORB networks using new malware
Cisco Talos
· Jul 7, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.