ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash 93791ebe5df8c415f10518f839ada39c88d6e93b1217f37b04ac96b9b112ed40.

Database Entry


IOC ID:1795732
IOC: 93791ebe5df8c415f10518f839ada39c88d6e93b1217f37b04ac96b9b112ed40
IOC Type :sha256_hash
Threat Type :payload
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-04-22 07:17:22 UTC
Last seen:2026-04-22 16:50:35 UTC
UUID:a02e5ff0-3dbd-11f1-8759-42010aa4000a
Reporter Lenny_3BO
Reward 5 credits from ThreatFox
Tags:ClickFix finger-tcp79 fingerfix win.fingerfix

Avatar
Lenny_3BO
proposed family win.fingerfix novel ClickFix finger/TCP79 delivery; chain cmd Run-dialog lure -> finger TCP79 -> python-embed sideload batch stage-2 -> Cyrillic-homoglyph b64 + XOR ctypes Python loader -> x86 PIC WinINet shellcode -> RC4-encrypted MSI on /v8 path; first-sighting; VT 0/94 on all pivots.