################################################################ # ThreatFox IOCs: recent MD5 hashes - CSV format # # Last updated: 2025-08-21 14:59:58 UTC # # # # Terms Of Use: https://threatfox.abuse.ch/faq/#tos # # For questions please contact threatfox [at] abuse.ch # ################################################################ # # "first_seen_utc","ioc_id","ioc_value","ioc_type","threat_type","fk_malware","malware_alias","malware_printable","last_seen_utc","confidence_level","reference","tags","anonymous","reporter" "2025-08-21 14:59:58", "1572318", "5ab23ac79ede02166d6f5013d89738f9", "md5_hash", "payload", "win.xenorat", "None", "XenoRAT", "", "100", "https://www.netresec.com/?page=Blog&month=2025-08&post=Define-Protocol-from-Traffic-XenoRAT", "None", "0", "netresec" "2025-08-21 14:59:58", "1572317", "e0b465d3bd1ec5e95aee016951d55640", "md5_hash", "payload", "win.xenorat", "None", "XenoRAT", "", "100", "https://www.netresec.com/?page=Blog&month=2025-08&post=Define-Protocol-from-Traffic-XenoRAT", "None", "0", "netresec" "2025-08-20 16:16:59", "1571848", "dfd1b59e6825391fb8ca57543e2b35fd", "md5_hash", "payload", "win.xworm", "None", "XWorm", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:56", "1571845", "acb29c97ebee5f59080292255f22b272", "md5_hash", "payload", "win.gcleaner", "None", "GCleaner", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:50", "1571842", "27f6c5d50f3e16e88259a61f5b81f345", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:43", "1571839", "baf9949e853bc2a3479b10e6335e1bd2", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:42", "1571836", "00a4c8a014786f525c9192bfbbf6e514", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:41", "1571833", "2af5068f57164b15ab2da10f956f243c", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:40", "1571830", "8693d73ec0b1ba1619b74e8936842123", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:39", "1571827", "ada31b3b06c23a13f9e5d6f520b1b539", "md5_hash", "payload", "win.gcleaner", "None", "GCleaner", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:38", "1571824", "3789c90b217dca894cebe98b93d4a714", "md5_hash", "payload", "win.agent_tesla", "AgenTesla,AgentTesla,Negasteal", "Agent Tesla", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:37", "1571821", "eb774e7c8fbc7976cbae2afc2a55f9ea", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:36", "1571818", "3ce52c9fb07a095c7885e91f4924c0ea", "md5_hash", "payload", "win.remcos", "RemcosRAT,Remvio,Socmer", "Remcos", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:35", "1571815", "a7e62ba3653962e5571bed11db6ac4f8", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:34", "1571812", "6352f7e42c001ab0776afa150b942fbf", "md5_hash", "payload", "win.vipkeylogger", "None", "VIP Keylogger", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:33", "1571809", "53caeb10cf0f802ec7597cff67bc9a13", "md5_hash", "payload", "win.formbook", "win.xloader", "Formbook", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:32", "1571806", "5db9a032b31a74b6b64614424818899f", "md5_hash", "payload", "win.purpleink", "None", "purpleink", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:31", "1571803", "34876a9697f92cc1c159053d5a670e5d", "md5_hash", "payload", "win.xworm", "None", "XWorm", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:30", "1571800", "0bfa29caf0bf03aa51021cf0060b3b41", "md5_hash", "payload", "win.vipkeylogger", "None", "VIP Keylogger", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:29", "1571797", "a72fbedc6515423321246d11c82db58e", "md5_hash", "payload", "win.krakenkeylogger", "None", "KrakenKeylogger", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:28", "1571794", "9ac6847453af1e7ae25c2356e17ee0df", "md5_hash", "payload", "win.formbook", "win.xloader", "Formbook", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:25", "1571791", "fb5d864ea260cea1e75d825d88d4152b", "md5_hash", "payload", "win.xworm", "None", "XWorm", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:24", "1571788", "9d1ee858be90e34a8e70bdb8ad2c5e5a", "md5_hash", "payload", "win.amadey", "None", "Amadey", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:23", "1571785", "e0703500ff017c45a3364a473bce1bda", "md5_hash", "payload", "win.havoc", "Havokiz", "Havoc", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:22", "1571782", "fb9376eaf838223e5361854cdb9485cd", "md5_hash", "payload", "win.xworm", "None", "XWorm", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:21", "1571779", "77bb7e58c81684e5b380ea7a15bb8f6a", "md5_hash", "payload", "win.formbook", "win.xloader", "Formbook", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:20", "1571776", "558a5b1e7d522106befa31207e0d4f68", "md5_hash", "payload", "win.cobalt_strike", "Agentemis,BEACON,CobaltStrike,cobeacon", "Cobalt Strike", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:18", "1571773", "888f19d6a9aa7e7dbf0a0631a2846092", "md5_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:17", "1571770", "0ade37df44fc167eb53b80ef66bb02b9", "md5_hash", "payload", "win.gcleaner", "None", "GCleaner", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:14", "1571767", "90ae9ea4403cc0cf5c92af2d3d82c7e3", "md5_hash", "payload", "win.gcleaner", "None", "GCleaner", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:13", "1571764", "fc0bf0571f17febe7fa85a759e41fa56", "md5_hash", "payload", "win.xworm", "None", "XWorm", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:12", "1571761", "fc2fdd3092209746c6dd0a9cdbc946e1", "md5_hash", "payload", "win.xworm", "None", "XWorm", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:10", "1571758", "7917b4df9d64d168cbd3028a54769872", "md5_hash", "payload", "win.plugx", "Destroy RAT,Kaba,Korplug,Sogu,TIGERPLUG,RedDelta", "PlugX", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:08", "1571755", "2672f886b9c5cf4bfb39df3915a346ce", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:07", "1571752", "6f4151c124693d9dfd2092b7e01df0d4", "md5_hash", "payload", "win.amadey", "None", "Amadey", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:06", "1571749", "fcb7009ab298bb4b59a28bc958b30a6d", "md5_hash", "payload", "win.coinminer", "None", "Coinminer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:05", "1571746", "fcfcbeb5322cc1f2cc3d8abbeac06814", "md5_hash", "payload", "win.xworm", "None", "XWorm", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:03", "1571743", "9bf7a6fdb4e14147efae8a79767d6d86", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:02", "1571740", "1fd70a931d005b7b32c1df6107056762", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:16:01", "1571737", "fdb6f1e48ff8ec82a5d30d1aa2084078", "md5_hash", "payload", "win.amadey", "None", "Amadey", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:15:53", "1571734", "fd45dd72e29bd2b4c0728fe4880f92ab", "md5_hash", "payload", "win.xworm", "None", "XWorm", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:15:52", "1571731", "7c136e58cd9cbfa39193e4f60f019d3b", "md5_hash", "payload", "win.xworm", "None", "XWorm", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:15:50", "1571728", "264209bff659d152dd59800888ef00c3", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:15:49", "1571725", "a9452a306bef9139dc7d80fb222f01e7", "md5_hash", "payload", "win.gcleaner", "None", "GCleaner", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:15:47", "1571722", "cc36da35f070a8d624b1dee90fd38046", "md5_hash", "payload", "win.gcleaner", "None", "GCleaner", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:15:46", "1571719", "5f85b9eca6c9f0ddea551d99fa9dbc8d", "md5_hash", "payload", "win.redline_stealer", "RECORDSTEALER", "RedLine Stealer", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:15:45", "1571716", "2ec65ea39e10130c9ef1b4959cd8c1b6", "md5_hash", "payload", "win.stealc", "None", "Stealc", "", "95", "None", "None", "0", "Grim" "2025-08-20 16:15:43", "1571713", "f2642117458898700b711c42223cbf1f", "md5_hash", "payload", "win.luca_stealer", "None", "Luca Stealer", "", "95", "None", "None", "0", "Grim" # Number of entries: 48