Indicators of compromise
29 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha1 | 072558bc1a539e9936584647df51fb1797c982b0 | mes writes: https://github.com/unrealircd/unrealircd/commit/072558bc1a539e9936584647df51fb1797c982b0. It's a great example of the shape of many LLM-reported (I' | Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations oss-security | · 2d ago |
| sha1 | 513a907b69edffc3cb77a494da395178d21ef9bd | mtp Second-stage payload download URL 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA-1 hash of /tmp/.z payload 2026-09-06 2026-09-08 64.207. | Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access GBHackers | · 4d ago |
| sha1 | 513a907b69edffc3cb77a494da395178d21ef9bd | mtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a494da395178d21ef9bd Account 0xterror , svc_[a-zA-Z0-9]{8} , Nxploited_[a-zA-Z0- | JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control Cyber Security News | · 4d ago |
| sha1 | 513a907b69edffc3cb77a494da395178d21ef9bd | 026-42018/CVE-2026-42016 exploitation 2026-09-07 2026-09-08 513a907b69edffc3cb77a494da395178d21ef9bd SHA1 of /tmp/.z payload 2026-09-06 2026-09-08 64.207.232[.] | Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Blog | · 5d ago |
| sha1 | 59508d071661ea70fa5fcbe6f9e2fb72506e57df | a4cccbc3d511dc8d7f24b113 MacSync sample MD5 hash SHA-1 hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df MacSync sample SHA-1 hash Code-signing identifier com.utils | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 5d ago |
| sha1 | d182eb7cba0ffa42d770d7b0d3499e49f24163a2 | ils.Launcher Ad-hoc-signed MacSync stager identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code directory hash associated with the sample Staged archi | Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware Cyber Security News | · 5d ago |
| sha1 | 59508d071661ea70fa5fcbe6f9e2fb72506e57df | cbc3d511dc8d7f24b113 Native Mach-O Stager Binary SHA-1 Hash 59508d071661ea70fa5fcbe6f9e2fb72506e57df Native Mach-O Stager Binary Code Signing ID com.utils.Launc | Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security. GBHackers | · 5d ago |
| sha1 | d182eb7cba0ffa42d770d7b0d3499e49f24163a2 | om.utils.Launcher Ad-hoc signature bundle identifier CDHash d182eb7cba0ffa42d770d7b0d3499e49f24163a2 Code Directory Hash Note: IP addresses and domains are inte | Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security. GBHackers | · 5d ago |
| sha1 | 286dd3ff41526b582ef48830de239dffbaa61f90 | Sep 05 Hi, https://github.com/util-linux/util-linux/commit/286dd3ff41526b582ef48830de239dffbaa61f90 Regards, Salvatore | Re: Vulnerability fixes in util-linux-2.42.3 oss-security | · 10d ago |
| sha1 | 03defdda9397e7536cf39951246483a0339ccd35 | c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-2 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · 29d ago |
| sha1 | 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 | 6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-0 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · 29d ago |
| sha1 | 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a | 502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-1 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · 29d ago |
| sha1 | ac3f20ddc2567af0b050c672ecd59dddab1fe55e | 947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-2 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · 29d ago |
| sha1 | 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 | ing file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbca | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · 29d ago |
| sha1 | 89a7861acb7983ad712ae9206131c96454a1b3d8 | ing file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a794bac4bf650b6ba537137504162520b67266449be979679 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · 29d ago |
| sha1 | d2c161ce52240b61d632607a2262890327d82502 | ing file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd9 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · 29d ago |
| sha1 | d04ce934561934f758d77dfa944bd6743dd82cff | 2 Bits binary MD5 : 76429f8515768f9f5def697e71071f51 SHA1 : d04ce934561934f758d77dfa944bd6743dd82cff SHA256: 7757517ae6b4d513a57826f9ab65bd070d99d25ac526cfae3e9 | New Malware 'Rover' Targets Indian Ambassador to Afghanistan Palo Alto Unit 42 | · 29d ago |
| sha1 | 41ee612602833345fc5bd2b98103811c12345678 | ique ID. "41EE612602833345FC5BD2B98103811C" + "12345678" = "41EE612602833345FC5BD2B98103811C12345678" Next, Smoke Loader generates two strings based on the firs | Analysis of Smoke Loader in New Tsunami Campaign Palo Alto Unit 42 | · 29d ago |
| sha1 | 3d161de48d3f4da0aefff685253404c8b0111563 | by the malware): MD5 0f1d3ed85fee2acc23a8a26e0dc12e0f SHA1 3d161de48d3f4da0aefff685253404c8b0111563 SHA256 fb94a5e30de7afd1d9072ccedd90a249374f687f16170e1986d6 | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · 29d ago |
| sha1 | 67c05b3937d94136eda4a60a2d5fb685abc776a1 | d was identified: MD5 05d43d417a8f50e7b23246643fc7e03d SHA1 67c05b3937d94136eda4a60a2d5fb685abc776a1 SHA256 3fee068bf90ffbeb25549eb52be0456609b1decfe91cda1967eb | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · 29d ago |
| sha1 | 741dbdb20d1beeb8ff809291996c8b78585cb812 | lease\LoadDll.pdb MD5 a2fe5dcb08ae8b72e8bc98ddc0b918e7 SHA1 741dbdb20d1beeb8ff809291996c8b78585cb812 SHA256 0669c71740134323793429d10518576b42941f9eee0def6057ed | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · 29d ago |
| sha1 | d13fc918433c705b49db74c91f56ae6c0cb5cf8d | owing properties: MD5 e02024f38dfb6290ce0d693539a285a9 SHA1 d13fc918433c705b49db74c91f56ae6c0cb5cf8d SHA256 66a0c294ee8f3507d723a376065798631906128ce79bd6dfd8f0 | NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT Palo Alto Unit 42 | · 29d ago |
| sha1 | e66e416f300c7efb90c383a7630c9cfe901ff9fd | owing properties: MD5 a943e196b83c4acd9c5ce13e4c43b4f4 SHA1 e66e416f300c7efb90c383a7630c9cfe901ff9fd SHA256 cfe436c1f0ce5eb7ac61b32cd073cc4e4b21d5016ceef77575be | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · 29d ago |
| sha1 | f459f9cfbd10b136cafb19cbc233a4c8342ad984 | g sample is used: MD5 3e4015366126dcdbdcc8b5c508a6d25c SHA1 f459f9cfbd10b136cafb19cbc233a4c8342ad984 SHA256 aef92be267a05cbff83aec0f23d33dfe0c4cdc71f9a424f5a2e5 | The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia Palo Alto Unit 42 | · 29d ago |
| sha1 | ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad | c3c689899dc4e75fdbdd0ab076ac457de7fb83645fb735a46ad4ea SHA1 ba6d10e36f41c4ebc85f6beb95afd2b7c92406ad MD5 723df0296951abd2aeed01361cec6b0d Size 4,298,240 bytes F | Exploring the Latest Mispadu Stealer Variant Palo Alto Unit 42 | · 29d ago |
| sha1 | 82cb695f463b93b9cc089253cd6b5e32dce46c35 | 0477 - main . zip Type = zip Physical Size = 2360 Comment = 82cb695f463b93b9cc089253cd6b5e32dce46c35 Date Time Attr Size Compressed Name ------------------- --- | Fake CVE-2023 Palo Alto Unit 42 | · 29d ago |
| sha1 | 3b4f44d8e3d9d5de35127b42dd449babe2d19fe5 | he main branches of both LuCI and uhttpd, using LuCI commit 3b4f44d8e3d9d5de35127b42dd449babe2d19fe5 from May 27 and uhttpd commit 7b1bec45826bd78c8afc993435bdc | Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root The Hacker News | · Jul 28, 2026 |
| sha1 | 7b1bec45826bd78c8afc993435bdc0f1df2fe399 | 9d5de35127b42dd449babe2d19fe5 from May 27 and uhttpd commit 7b1bec45826bd78c8afc993435bdc0f1df2fe399 from June 13. It described three as pre-authentication path | Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root The Hacker News | · Jul 28, 2026 |
| sha1 | 31c69b3e12936abca770d430066f379ec1d997ec | 235, the domain cdnorigin[.]net, and one agent sample, SHA1 31c69b3e12936abca770d430066f379ec1d997ec. The Hacker News covered a different operator working the s | New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens The Hacker News | · Jul 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.