ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash 60e7f9ef3d00c861fb8dbfc14b2d9a221e54fac9adb365b4c38475965be75542.

Database Entry


IOC ID:1795734
IOC: 60e7f9ef3d00c861fb8dbfc14b2d9a221e54fac9adb365b4c38475965be75542
IOC Type :sha256_hash
Threat Type :payload
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-04-22 07:17:21 UTC
Last seen:2026-04-22 16:50:35 UTC
UUID:a057abf2-3dbd-11f1-8759-42010aa4000a
Reporter Lenny_3BO
Reward 5 credits from ThreatFox
Tags:ClickFix finger-tcp79 fingerfix win.fingerfix

Avatar
Lenny_3BO
proposed family win.fingerfix novel ClickFix finger/TCP79 delivery; chain cmd Run-dialog lure -> finger TCP79 -> python-embed sideload batch stage-2 -> Cyrillic-homoglyph b64 + XOR ctypes Python loader -> x86 PIC WinINet shellcode -> RC4-encrypted MSI on /v8 path; first-sighting; VT 0/94 on all pivots.