Indicators of compromise
237 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| md5 | 5c92d3b8734b4f498752f735a1ca0987 | n installer payload main-v2 hxxps://granderevolucao[.]store/5c92d3b8734b4f498752f735a1ca0987/{campaignId} .NET PE Injector sub-module hxxps://archive[.] | The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions Elastic Security Labs | · 1d ago |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | We've got one word for it, and it's usually the wrong one Cisco Talos | · 5d ago |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | We've got one word for it, and it's usually the wrong one Cisco Talos | · 5d ago |
| md5 | 9a47c4d379998ade2f8f99e23a630c06 | a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputat | We've got one word for it, and it's usually the wrong one Cisco Talos | · 5d ago |
| md5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat | We've got one word for it, and it's usually the wrong one Cisco Talos | · 5d ago |
| md5 | f3e82419a43220a7a222fc01b7607adc | 8fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 MD5: f3e82419a43220a7a222fc01b7607adc Talos Rep: https://talosintelligence.com/talos_file_reputat | We've got one word for it, and it's usually the wrong one Cisco Talos | · 5d ago |
| md5 | 0e39e8d7b641bcda4376ebbfeff7b12e | cluded in the malicious ISO File name / MD5 %TEMP%\find.vbs 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays the fake “license not found” message E | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | 15eca4a3f7350423cf4db0b4c30d1968 | 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3 | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | 1ec9eff863dc4418d1498bc3d904899d | haos ransomware File name / MD5 %TEMP%\YandexPackLoader.exe 1ec9eff863dc4418d1498bc3d904899d Browser installer included in the malicious ISO File name / | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | 2a0834560ed3770fc33d7a42f8229722 | %\rockstargamescrashfixer.exe , %TEMP%\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651 | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | 2a385fe7bed9899d77d05cb8e302d557 | a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associated launchers IP addresses 35.157.1 | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | 57b9c56ef97a7ada98257b23577bf5e3 | TEMP%\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3 | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | 60a0f58001ea7be538cd42b651924cc7 | 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | 6b49f24d5d5b49127476bc385565f8b0 | ecutable File name / MD5 %TEMP%\checkinternetconnection.bat 6b49f24d5d5b49127476bc385565f8b0 Batch file used to confirm internet connectivity File names | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | 8da3fe3664d81226b0fb2a50a0537d4f | at , C:\Users\Default\Local Settings\[RANDOM FILE NAME].exe 8da3fe3664d81226b0fb2a50a0537d4f DCRAT installer components and binary Hosts-file entries 0. | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | a15e280a3fd65dfaa243bbe2dbf45e97 | ype Indicator Description File name / MD5 Gta6installer.exe a15e280a3fd65dfaa243bbe2dbf45e97 Initial fake installation executable File name / MD5 %TEMP% | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | b9648ec8cc806e7661aabcfc91dc836c | %TEMP%\gta6.exe , %USERPROFILE%\AppData\Roaming\svchost.exe b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries File name read_it.txt Note droppe | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | dfdf5e5b78d2ec764c0e5641cf9a0d26 | -control infrastructure File name / MD5 %TEMP%\adminapp.exe dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.] | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | ea991bc9334b36a6b958f564ee716776 | 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associate | Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware Cyber Security News | · 5d ago |
| md5 | 15eca4a3f7350423cf4db0b4c30d1968 | 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3 | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 5d ago |
| md5 | 2a0834560ed3770fc33d7a42f8229722 | ckstargamescrashfixer.exe %TEMP%\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651 | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 5d ago |
| md5 | 2a385fe7bed9899d77d05cb8e302d557 | a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers Note: IP addresses | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 5d ago |
| md5 | 57b9c56ef97a7ada98257b23577bf5e3 | rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3 | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 5d ago |
| md5 | 60a0f58001ea7be538cd42b651924cc7 | 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 5d ago |
| md5 | 6b49f24d5d5b49127476bc385565f8b0 | llation executable %TEMP%\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEM | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 5d ago |
| md5 | a15e280a3fd65dfaa243bbe2dbf45e97 | -clean media. IOCs Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\checkinternetconnect | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 5d ago |
| md5 | ea991bc9334b36a6b958f564ee716776 | 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associ | Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers GBHackers | · 5d ago |
| md5 | 9678f71ea4cccbc3d511dc8d7f24b113 | 25f44db68a MacSync sample hash reported by SEQRITE MD5 hash 9678f71ea4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6 | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 5d ago |
| md5 | de62a2f47d1c7dec2997f931a050a615 | h used for stolen-data uploads HTTP request header api-key: de62a2f47d1c7dec2997f931a050a615 API key observed in MacSync network requests HTTP User-Agen | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 5d ago |
| md5 | 9678f71ea4cccbc3d511dc8d7f24b113 | b68aeadc44eeb97c9aab11 Native Mach-O Stager Binary MD5 Hash 9678f71ea4cccbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5f | Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security. GBHackers | · 5d ago |
| md5 | 528cd4e69ecfa5191adbcf6ef28667bf | Infrastructure used to execute campaign activity File hash 528cd4e69ecfa5191adbcf6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 5d ago |
| md5 | 974decb9ff4c8f9ccb0937c96d513347 | sa_collect_small.exe — Rust LSA bootkey collector File hash 974decb9ff4c8f9ccb0937c96d513347 certipy.exe — Active Directory Certificate Services abuse t | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 5d ago |
| md5 | a6437ac3d6798090a218520985d36a3f | 687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d6798090a218520985d36a3f collect_custom.exe — Rust custom collection tool File hash | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 5d ago |
| md5 | ce870a91e8d27e8f663f0687abc60b04 | f6ef28667bf lsa_read.exe — Rust LSA secret reader File hash ce870a91e8d27e8f663f0687abc60b04 save_hives.exe — registry hive dumper File hash a6437ac3d67 | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 5d ago |
| md5 | fc92dfafa7aa741c5f2b9cbcf75d1d19 | collect_custom.exe — Rust custom collection tool File hash fc92dfafa7aa741c5f2b9cbcf75d1d19 lsa_collect_small.exe — Rust LSA bootkey collector File has | Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers GBHackers | · 5d ago |
| md5 | 0e39e8d7b641bcda4376ebbfeff7b12e | 18d1498bc3d904899d Yandex web browser %TEMP%\find.vbs MD5 : 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays a "license not found" message | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | 15eca4a3f7350423cf4db0b4c30d1968 | 6ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3 | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | 1ec9eff863dc4418d1498bc3d904899d | ansomware-encrypted files %TEMP%\YandexPackLoader.exe MD5 : 1ec9eff863dc4418d1498bc3d904899d Yandex web browser %TEMP%\find.vbs MD5 : 0e39e8d7b641bcda43 | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | 2a0834560ed3770fc33d7a42f8229722 | ckstargamescrashfixer.exe %TEMP%\rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651 | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | 2a385fe7bed9899d77d05cb8e302d557 | a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associated launchers 35.157.111[.]131 3 | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | 57b9c56ef97a7ada98257b23577bf5e3 | rockstarservices.exe MD5s: 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3 | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | 60a0f58001ea7be538cd42b651924cc7 | 560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | 6b49f24d5d5b49127476bc385565f8b0 | llation executable %TEMP%\checkinternetconnection.bat MD5 : 6b49f24d5d5b49127476bc385565f8b0 BAT file used to confirm a working internet connection %TEM | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | 8da3fe3664d81226b0fb2a50a0537d4f | :\Users\Default\Local Settings\[RANDOM FILE NAME].exe MD5 : 8da3fe3664d81226b0fb2a50a0537d4f Copy of DCRAT and associated installation files 0.0.0.0 app | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | a15e280a3fd65dfaa243bbe2dbf45e97 | Compromise (IOCs) Item Description Gta6installer.exe MD5 : a15e280a3fd65dfaa243bbe2dbf45e97 Initial installation executable %TEMP%\checkinternetconnect | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | b9648ec8cc806e7661aabcfc91dc836c | MP%\gta6.exe %USERPROFILE%\AppData\Roaming\svchost.exe MD5: b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries read_it.txt Ransomware note left | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | dfdf5e5b78d2ec764c0e5641cf9a0d26 | IP address that DCRAT connects to %TEMP%\adminapp.exe MD5 : dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary https://discord[.]com/ | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | ea991bc9334b36a6b958f564ee716776 | 8001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 Ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 Copies of NJRAT and associ | Grand Theft Auto VI hype leads to malware Huntress | · 6d ago |
| md5 | 528cd4e69ecfa5191adbcf6ef28667bf | ute the campaign 45.158.196.75 Used to execute the campaign 528cd4e69ecfa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0 | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 6d ago |
| md5 | 974decb9ff4c8f9ccb0937c96d513347 | f75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9ff4c8f9ccb0937c96d513347 (certipy.exe) ADCS Abuse Tool Administrator17 Adversary cre | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 6d ago |
| md5 | a6437ac3d6798090a218520985d36a3f | 27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 6d ago |
| md5 | ce870a91e8d27e8f663f0687abc60b04 | fa5191adbcf6ef28667bf (lsa_read.exe) Rust LSA secret reader ce870a91e8d27e8f663f0687abc60b04 (save_hives.exe) Registry Hive Dumper a6437ac3d6798090a2185 | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 6d ago |
| md5 | fc92dfafa7aa741c5f2b9cbcf75d1d19 | a218520985d36a3f (collect_custom.exe) Rust custom collector fc92dfafa7aa741c5f2b9cbcf75d1d19 (lsa_collect_small.exe) Rust LSA bootkey collector 974decb9 | Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF GreyNoise | · 6d ago |
| md5 | 581e2e2265d0c1509b3799c5a9039374 | encrypted payload we observed was generated on 2025-11-11 ( 581e2e2265d0c1509b3799c5a9039374 ). The AES key is not stored in the malware bundle itself. | JSCeal Hides Crypto Malware in V8 Bytecode Security Affairs | · 8d ago |
| md5 | 5568cd69c754b392121f1dbb8f900fda | r IPv4 (Tzulo VPN) 23.234.97[.]68 Intruder IPv4 (Tzulo VPN) 5568cd69c754b392121f1dbb8f900fda Malicious Cloudflare tunnel account tag Update: 8/6/26 @ 5: | Critical N-able N-central Vulnerability and Active Exploitation Huntress | · 9d ago |
| md5 | fced27f6d57702565353ecc11722533b | /cache/ss_<10hex>/sync_<10hex>.php web shell X-Cache-Token: fced27f6d57702565353ecc11722533b header the web shell requires, 404 without it 457cfa2fb7p5. | StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack Sansec (Magento / e-commerce security) | · 10d ago |
| md5 | c8c68e629bba773a10ac80012d10bf19 | tore File - ~/cache/haproxy-1000.cache File - /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 File - /var/lib/snapd/g580 File - /tmp/jasper-log SHA-256 - | New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News | · 11d ago |
| md5 | c8c68e629bba773a10ac80012d10bf19 | and saves them to an encrypted log file under /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 . Figure 2: hardcoded master passwords in userauth_passwd() | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 11d ago |
| md5 | ecd427ea8330a4ff73618483e00b9b41 | main – img.darklights.store – authenticating with api_token/ecd427ea8330a4ff73618483e00b9b41 and setting the User-token header to the victim ID to fetch | DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors Rapid7 Blog | · 11d ago |
| md5 | 7916c33688385525078bee504c90f359 | upport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.toml Registry keys: HKLM\Software\synapse\Config\S | Angry Birds: Toy Ghouls’ new toys Kaspersky Securelist | · 11d ago |
| md5 | bfadbeee63a4f0bf19ec9deb8fa58f58 | t.Zapchast.abwo File names and MD5 hashes: cplsupport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 ) wtass.exe ( 7916C33688385525078BEE504C90F359 ) config.tom | Angry Birds: Toy Ghouls’ new toys Kaspersky Securelist | · 11d ago |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 12d ago |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 12d ago |
| md5 | 41444d7018601b599beac0c60ed1bf83 | dceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 MD5: 41444d7018601b599beac0c60ed1bf83 Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 12d ago |
| md5 | 61e046145ee5cf45aeb033cd71e8b07c | d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 MD5: 61e046145ee5cf45aeb033cd71e8b07c Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 12d ago |
| md5 | 7bdbd180c081fa63ca94f9c22c457376 | 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 12d ago |
| md5 | 9a47c4d379998ade2f8f99e23a630c06 | a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://talosintelligence.com/talos_file_reputat | The story behind the intelligence Cisco Talos | · 12d ago |
| md5 | 2ec37a7cc8daf20b10e1ad6221061ca5 | the malicious actor’s secure shell client hash fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5 showing an established session. Attempt number 6 shows a fa | Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd) SANS Internet Storm Center | · 12d ago |
| md5 | 3612f843a42db38f48f59d2a3597e19c | d75ee30 ” , uri =“/ ctrlt / DeviceUpgrade_1 ” , response =“ 3612f843a42db38f48f59d2a3597e19c ” , algorithm =“ MD5 ” , qop =“ auth ” , nc = 00000001 , cn | Home & Small Office Wireless Routers Exploited to Attack Gaming Servers Palo Alto Unit 42 | · 28d ago |
| md5 | 88645cefb1f9ede0e336e3569d75ee30 | “ dslf - config ” , realm =“ HuaweiHomeGateway ” , nonce =“ 88645cefb1f9ede0e336e3569d75ee30 ” , uri =“/ ctrlt / DeviceUpgrade_1 ” , response =“ 3612f84 | Home & Small Office Wireless Routers Exploited to Attack Gaming Servers Palo Alto Unit 42 | · 28d ago |
| md5 | f1c099d65bf94e009f5e65238caac468 | 18b34633f303949a0bb07282dedcd8e9dc Updated JenX Sample MD5: f1c099d65bf94e009f5e65238caac468 SHA256: 676813ee73d382c08765a75204be8bab6bea730ff0073de1076 | Home & Small Office Wireless Routers Exploited to Attack Gaming Servers Palo Alto Unit 42 | · 28d ago |
| md5 | fb93601f8d4e0228276edff1c6fe635d | tinuity. Indicators of Compromise Original JenX sample MD5: fb93601f8d4e0228276edff1c6fe635d SHA256: 04463cd1a961f7cd1b77fe6c9e9f5e18b34633f303949a0bb07 | Home & Small Office Wireless Routers Exploited to Attack Gaming Servers Palo Alto Unit 42 | · 28d ago |
| md5 | 79ad2084b057847ce2ec2e48fda64073 | 80154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2 MD5 79ad2084b057847ce2ec2e48fda64073 Compile Date 2017-12-22 11:54:03 UTC One of the first modif | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · 29d ago |
| md5 | dd1876848203d9e10abceec07282ff37 | d using AES-128 and the following static key (hex-encoded): DD1876848203D9E10ABCEEC07282FF37 Conclusion The Patchwork group continues to plague victims | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · 29d ago |
| md5 | e3e7e71a0b28b5e96cc492e636722f73 | cation with the C2 (note the additional forward slashes): //e3e7e71a0b28b5e96cc492e636722f73//4sVKAOvu3D//ABDYot0NxyG.php In the event data is uploaded | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · 29d ago |
| md5 | 6fa5bcedaf124cdaccfa5548eed7f4b0 | 4d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-14 07:20:11 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · 29d ago |
| md5 | 7c65565dcf5b40bd8358472d032bc8fb | 32e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-25 00:54:18 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · 29d ago |
| md5 | a5164c686c405734b7362bc6b02488cb | f9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-28 01:54:40 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · 29d ago |
| md5 | d5679158937ce288837efe62bc1d9693 | a473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-02 07:57:38 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · 29d ago |
| md5 | 7cc0b212d1b8ceb808c250495d83bae4 | remainder of the analysis, the following file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · 29d ago |
| md5 | 8d42c01180be7588a2a68ad96dd0cf85 | remainder of the analysis, the following file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a79 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · 29d ago |
| md5 | a1bdb1889d960e424920e57366662a59 | remainder of the analysis, the following file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef42 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · 29d ago |
| md5 | 76429f8515768f9f5def697e71071f51 | l 80386, for MS Windows Architecture : 32 Bits binary MD5 : 76429f8515768f9f5def697e71071f51 SHA1 : d04ce934561934f758d77dfa944bd6743dd82cff SHA256: 775 | New Malware 'Rover' Targets Indian Ambassador to Afghanistan Palo Alto Unit 42 | · 29d ago |
| md5 | b5aa366f452feb9f4dff3c72157ca1f9 | LuO7bIWjRO5gjPNq:JarSKu6yzoF8rpAqXYv3XOgQLfnpLuOu imphash : b5aa366f452feb9f4dff3c72157ca1f9 Date : 0x5637227B [Mon Nov 2 08:44:43 2015 UTC] Language : | New Malware 'Rover' Targets Indian Ambassador to Afghanistan Palo Alto Unit 42 | · 29d ago |
| md5 | 41ee612602833345fc5bd2b98103811c | hash value of the string, MD5("Test_PC0B0D040612345678") = 41EE612602833345FC5BD2B98103811C It then appends the volume serial to the hash value and get | Analysis of Smoke Loader in New Tsunami Campaign Palo Alto Unit 42 | · 29d ago |
| md5 | 05d43d417a8f50e7b23246643fc7e03d | After decryption, the following payload was identified: MD5 05d43d417a8f50e7b23246643fc7e03d SHA1 67c05b3937d94136eda4a60a2d5fb685abc776a1 SHA256 3fee06 | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · 29d ago |
| md5 | 0f1d3ed85fee2acc23a8a26e0dc12e0f | tion is provided after it is decrypted by the malware): MD5 0f1d3ed85fee2acc23a8a26e0dc12e0f SHA1 3d161de48d3f4da0aefff685253404c8b0111563 SHA256 fb94a5 | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · 29d ago |
| md5 | a2fe5dcb08ae8b72e8bc98ddc0b918e7 | oject(20180108)\Final1stspy\LoadDll\Release\LoadDll.pdb MD5 a2fe5dcb08ae8b72e8bc98ddc0b918e7 SHA1 741dbdb20d1beeb8ff809291996c8b78585cb812 SHA256 0669c7 | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · 29d ago |
| md5 | e02024f38dfb6290ce0d693539a285a9 | was identified. This file had the following properties: MD5 e02024f38dfb6290ce0d693539a285a9 SHA1 d13fc918433c705b49db74c91f56ae6c0cb5cf8d SHA256 66a0c2 | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · 29d ago |
| md5 | 3e4015366126dcdbdcc8b5c508a6d25c | s For the analysis below, the following sample is used: MD5 3e4015366126dcdbdcc8b5c508a6d25c SHA1 f459f9cfbd10b136cafb19cbc233a4c8342ad984 SHA256 aef92b | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · 29d ago |
| md5 | a943e196b83c4acd9c5ce13e4c43b4f4 | l The downloaded CAB file has the following properties: MD5 a943e196b83c4acd9c5ce13e4c43b4f4 SHA1 e66e416f300c7efb90c383a7630c9cfe901ff9fd SHA256 cfe436 | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · 29d ago |
| md5 | 0304674e9876530dfbea5a9b4fec7b98 | Server: affiliatecollective[.]club C2 Port: 443 Hash Value: 0304674e9876530dfbea5a9b4fec7b98 Additional C2 Servers: 0 GUID: '\xd6\x04hr\x9a\xedLN\xae\xe | Cardinal RAT Sins Again, Targets Israeli Fin Palo Alto Unit 42 | · 29d ago |
| md5 | 723df0296951abd2aeed01361cec6b0d | 5a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes File Type PE32+ executable (GUI) x86-6 | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · 29d ago |
| md5 | 2915b3f8b703eb744fc54c81f4a9c67f | d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| md5 | 38de5b216c33833af710e88f7f64fc98 | bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| md5 | 7bdbd180c081fa63ca94f9c22c457376 | 83227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| md5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | e6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a Talos Rep: https://talosintelligence.com/talos_file_reputat | Why metaphor may dictate your security strategy Cisco Talos | · Aug 6, 2026 |
| md5 | 082d49ef9f14e6811d68c7e0e82e5069 | IntSvc , which loads the loader DLL named oleasapi.dll (MD5 082d49ef9f14e6811d68c7e0e82e5069 ). The ServiceMain parameter in the service’s registry entr | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 2a571f6cee42a17d873f4c942649813f | ogger located at C:\Users\Public\Pictures\AnyDesk.exe (MD5: 2a571f6cee42a17d873f4c942649813f ). They then created a scheduled task named AnyDesk to run | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
| md5 | 32a5985543433a4f60da2fafd873b927 | tsdump Attackers ran a malicious file named Adobe.exe (MD5 32a5985543433a4f60da2fafd873b927 ), which is a portable‑executable version of Impacket’s sec | OctLurk and SilkLurk: new Backdoors in Central Asia Kaspersky Securelist | · Jul 31, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.