ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash 353bd65eca3e04761f823cffdda51fd0e098e23651a953fa353b3fd15bbba28d.

Database Entry


IOC ID:1795733
IOC: 353bd65eca3e04761f823cffdda51fd0e098e23651a953fa353b3fd15bbba28d
IOC Type :sha256_hash
Threat Type :payload
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-04-22 07:17:22 UTC
Last seen:2026-04-22 16:50:35 UTC
UUID:a04247d3-3dbd-11f1-8759-42010aa4000a
Reporter Lenny_3BO
Reward 5 credits from ThreatFox
Tags:ClickFix finger-tcp79 fingerfix win.fingerfix

Avatar
Lenny_3BO
proposed family win.fingerfix novel ClickFix finger/TCP79 delivery; chain cmd Run-dialog lure -> finger TCP79 -> python-embed sideload batch stage-2 -> Cyrillic-homoglyph b64 + XOR ctypes Python loader -> x86 PIC WinINet shellcode -> RC4-encrypted MSI on /v8 path; first-sighting; VT 0/94 on all pivots.