ZeroHour

Indicators of compromise

29 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha1072558bc1a539e9936584647df51fb1797c982b0mes writes: https://github.com/unrealircd/unrealircd/commit/072558bc1a539e9936584647df51fb1797c982b0. It's a great example of the shape of many LLM-reported (I'Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations
oss-security
· 2d ago
sha1513a907b69edffc3cb77a494da395178d21ef9bdmtp Second-stage payload download URL 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA-1 hash of /tmp/.z payload 2026-09-06 2026-09-08 64.207.Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
GBHackers
· 4d ago
sha1513a907b69edffc3cb77a494da395178d21ef9bdmtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a494da395178d21ef9bd Account 0xterror , svc_[a-zA-Z0-9]{8} , Nxploited_[a-zA-Z0-JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
Cyber Security News
· 4d ago
sha1513a907b69edffc3cb77a494da395178d21ef9bd026-42018/CVE-2026-42016 exploitation 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA1 of /tmp/.z payload 2026-09-06 2026-09-08 64.207.232[.]Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Blog
· 5d ago
sha159508d071661ea70fa5fcbe6f9e2fb72506e57dfa4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df MacSync sample SHA-1 hash Code-signing identifier com.utilsHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 5d ago
sha1d182eb7cba0ffa42d770d7b0d3499e49f24163a2ils.Launcher Ad-hoc-signed MacSync stager identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code directory hash associated with the sample Staged archiHackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Cyber Security News
· 5d ago
sha159508d071661ea70fa5fcbe6f9e2fb72506e57dfcbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df Native Mach-O Stager Binary Code Signing ID com.utils.LauncHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers
· 5d ago
sha1d182eb7cba0ffa42d770d7b0d3499e49f24163a2om.utils.Launcher Ad-hoc signature bundle identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code Directory Hash Note: IP addresses and domains are inteHackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
GBHackers
· 5d ago
sha1286dd3ff41526b582ef48830de239dffbaa61f90Sep 05 Hi, https://github.com/util-linux/util-linux/commit/286dd3ff41526b582ef48830de239dffbaa61f90 Regards, SalvatoreRe: Vulnerability fixes in util-linux-2.42.3
oss-security
· 10d ago
sha103defdda9397e7536cf39951246483a0339ccd35c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-2RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· 29d ago
sha10bdb44255e9472d80ee0197d0bfad7d8eb4a18e96239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-0RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· 29d ago
sha125ba920cb440b4a1c127c8eb0fb23ee783c9e01a502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-1RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· 29d ago
sha1ac3f20ddc2567af0b050c672ecd59dddab1fe55e947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-2RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
Palo Alto Unit 42
· 29d ago
sha1177837d0fa5bfd274abe79d80a01cfe2374b4cd9ing file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbcaMultiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· 29d ago
sha189a7861acb7983ad712ae9206131c96454a1b3d8ing file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a794bac4bf650b6ba537137504162520b67266449be979679Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· 29d ago
sha1d2c161ce52240b61d632607a2262890327d82502ing file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd9Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan
Palo Alto Unit 42
· 29d ago
sha1d04ce934561934f758d77dfa944bd6743dd82cff2 Bits binary MD5 : 76429f8515768f9f5def697e71071f51 SHA1 : d04ce934561934f758d77dfa944bd6743dd82cff SHA256: 7757517ae6b4d513a57826f9ab65bd070d99d25ac526cfae3e9New Malware 'Rover' Targets Indian Ambassador to Afghanistan
Palo Alto Unit 42
· 29d ago
sha141ee612602833345fc5bd2b98103811c12345678ique ID. "41EE612602833345FC5BD2B98103811C" + "12345678" = "41EE612602833345FC5BD2B98103811C12345678" Next, Smoke Loader generates two strings based on the firsAnalysis of Smoke Loader in New Tsunami Campaign
Palo Alto Unit 42
· 29d ago
sha13d161de48d3f4da0aefff685253404c8b0111563by the malware): MD5 0f1d3ed85fee2acc23a8a26e0dc12e0f SHA1 3d161de48d3f4da0aefff685253404c8b0111563 SHA256 fb94a5e30de7afd1d9072ccedd90a249374f687f16170e1986d6NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· 29d ago
sha167c05b3937d94136eda4a60a2d5fb685abc776a1d was identified: MD5 05d43d417a8f50e7b23246643fc7e03d SHA1 67c05b3937d94136eda4a60a2d5fb685abc776a1 SHA256 3fee068bf90ffbeb25549eb52be0456609b1decfe91cda1967ebNOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· 29d ago
sha1741dbdb20d1beeb8ff809291996c8b78585cb812lease\LoadDll.pdb MD5 a2fe5dcb08ae8b72e8bc98ddc0b918e7 SHA1 741dbdb20d1beeb8ff809291996c8b78585cb812 SHA256 0669c71740134323793429d10518576b42941f9eee0def6057edNOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· 29d ago
sha1d13fc918433c705b49db74c91f56ae6c0cb5cf8dowing properties: MD5 e02024f38dfb6290ce0d693539a285a9 SHA1 d13fc918433c705b49db74c91f56ae6c0cb5cf8d SHA256 66a0c294ee8f3507d723a376065798631906128ce79bd6dfd8f0NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Palo Alto Unit 42
· 29d ago
sha1e66e416f300c7efb90c383a7630c9cfe901ff9fdowing properties: MD5 a943e196b83c4acd9c5ce13e4c43b4f4 SHA1 e66e416f300c7efb90c383a7630c9cfe901ff9fd SHA256 cfe436c1f0ce5eb7ac61b32cd073cc4e4b21d5016ceef77575beThe Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· 29d ago
sha1f459f9cfbd10b136cafb19cbc233a4c8342ad984g sample is used: MD5 3e4015366126dcdbdcc8b5c508a6d25c SHA1 f459f9cfbd10b136cafb19cbc233a4c8342ad984 SHA256 aef92be267a05cbff83aec0f23d33dfe0c4cdc71f9a424f5a2e5The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia
Palo Alto Unit 42
· 29d ago
sha1ba6d10e36f41c4ebc85f6beb95afd2b7c92406adc3c689899dc4e75fdbdd0ab076ac457de7fb83645fb735a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes FExploring the Latest Mispadu Stealer Variant
Palo Alto Unit 42
· 29d ago
sha182cb695f463b93b9cc089253cd6b5e32dce46c350477 - main . zip Type = zip Physical Size = 2360 Comment = 82cb695f463b93b9cc089253cd6b5e32dce46c35 Date Time Attr Size Compressed Name ------------------- ---Fake CVE-2023
Palo Alto Unit 42
· 29d ago
sha13b4f44d8e3d9d5de35127b42dd449babe2d19fe5he main branches of both LuCI and uhttpd, using LuCI commit 3b4f44d8e3d9d5de35127b42dd449babe2d19fe5 from May 27 and uhttpd commit 7b1bec45826bd78c8afc993435bdcCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
The Hacker News
· Jul 28, 2026
sha17b1bec45826bd78c8afc993435bdc0f1df2fe3999d5de35127b42dd449babe2d19fe5 from May 27 and uhttpd commit 7b1bec45826bd78c8afc993435bdc0f1df2fe399 from June 13. It described three as pre-authentication pathCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
The Hacker News
· Jul 28, 2026
sha131c69b3e12936abca770d430066f379ec1d997ec235, the domain cdnorigin[.]net, and one agent sample, SHA1 31c69b3e12936abca770d430066f379ec1d997ec. The Hacker News covered a different operator working the sNew NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
The Hacker News
· Jul 17, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.