top of page
Inside a Multi-Stage Windows Malware Campaign
C45-2026-01-21-5
Indicators of Compromise (IOC) List
Indicator of Compromise (IOC) | Date Published | IOC Type |
|---|---|---|
71069a5d2a80a047ca36ca82e630d353829726d4f03a74c7522b7700c5c2bb59 | 21/01/2026 | SHA-256 |
359fe8df31c903153667fbe93795929ad6172540b3ee7f9eff4bcc1da6d08478 | 21/01/2026 | SHA-256 |
e6ca6bab85ae1eff08a59b46b7905ae0568110da172dec8367f32779094bdd08 | 21/01/2026 | SHA-256 |
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender. These entries disable core antivirus and antispyware functionality | 21/01/2026 | Win_Registry |
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\
By targeting the current user hive | 21/01/2026 | Win_Registry |
7de56603a7b41fca9313231df6105dbb8148d3b0d80dfbc00e71e1d88f871915 | 21/01/2026 | SHA-256 |
HKCU\Software\Microsoft\Windows\CurrentVersion\Run | 21/01/2026 | Win_Registry |
263b5ba921e478215dc9e3a397157badab415fc775cfb4681821b7446c14fb1a | 21/01/2026 | SHA-256 |
45e942ba59f3876b263a03ed7e5d5b1b250e84a0a4b4093b3c13b5fca4e12b21 | 21/01/2026 | SHA-256 |
6222775b877b4be4f5407525d52c5889739b96c302e5a204ef369b4a51c6dab2 | 21/01/2026 | SHA-256 |
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Persistence
T1547.001
Boot or Logon Autostart Execution | 21/01/2026 | Win_Registry |
5443232a367a83ac2899b37c066dae3ec2010df292291db24ce3d744133218a6 | 21/01/2026 | SHA-256 |
3aa6ebb73390d304eef8fd897994906c05f3e967f8f6f6a7904c6156cf8819f9 | 21/01/2026 | SHA-256 |
7b8cf0ef390a7d6126c5e7bf835af5c5ce32c70c0d58ca4ddc9c238b2d3f059a | 21/01/2026 | SHA-256 |
1828614be6d9bdd92f7ee30e12c8aac8eba33a6df2c92995f9bf930c3f1b992b | 21/01/2026 | SHA-256 |
bottom of page

