TLP: CLEAR

STIX/TAXII — Indicadores de Compromiso

Campaña InstallFix / Amatera Stealer

Fecha: 12 de marzo de 2026 Formato: STIX 2.1 TLP: CLEAR Referencia: IR-2026-0312-IOC

Resumen de Indicadores

220IOCs Totales
20Dominios
6Direcciones IP
2URLs
192Hashes SHA-256

1. Dominios Maliciosos

Dominios directamente asociados a la campaña InstallFix / Amatera Stealer

DominioTipoPrimera detecciónÚltima detecciónFuente
claude.update-version.comC2/Distribución06/03/202611/03/2026IBM X-Force, Feedly [A1]
update-version.comC2/Distribución11/03/202611/03/2026Feedly [B2]
claude-code-macos.comDistribución03/202603/2026IBM X-Force [A1]
claude-code-docs-site.pages.devDistribución03/202603/2026IBM X-Force [A1]
nnnnnnnnnnnnnnnnnnnnn.pages.devDistribución03/202603/2026IBM X-Force [A1]
saramoftah.comC2/Staging03/202603/2026IBM X-Force [A1]
overplanteasiest.topC2 (Amatera)27/05/202519/06/2025Feedly [B2]
amaprox.icuC2 (Amatera)19/06/202519/06/2025Feedly [B2]

Dominios asociados a ACR Stealer (predecesor de Amatera)

DominioTipoPrimera detecciónÚltima detecciónFuente
playtogga.comC2 (ACR)03/202603/2026Feedly [B2]
apposx.comC2 (ACR)30/01/202603/03/2026Feedly [B2]
theriygrt.comC2 (ACR)30/01/202603/03/2026Feedly [B2]
memory-scanner.ccC2 (ACR)01/01/202604/02/2026Feedly [B2]
indeanapolice.ccC2 (ACR)30/01/202630/01/2026Feedly [B2]
globalsnn3-new.ccC2 (ACR)30/01/202630/01/2026Feedly [B2]
globalsnn2-new.ccC2 (ACR)30/01/202630/01/2026Feedly [B2]
tyuropium.comC2 (ACR)30/01/202630/01/2026Feedly [B2]
dpaste.orgDDR (ACR)30/01/202630/01/2026Feedly [B2]
joinmc.linkDDR (ACR)30/01/202630/01/2026Feedly [B2]
pktriot.netC2 (ACR)30/01/202630/01/2026Feedly [B2]
portmap.ioC2 (ACR)30/01/202630/01/2026Feedly [B2]

2. Direcciones IP

IPTipoPrimera detecciónÚltima detecciónFuente
45.94.47.224C2 (Amatera)14/11/202510/03/2026Feedly [B2]
212.34.138.4C2 (Amatera)28/01/202628/01/2026Feedly [B2]
91.98.229.246C2 (Amatera)14/11/202517/11/2025Feedly [B2]
104.21.80.1CDN Masking19/06/202518/07/2025Feedly [B2]
157.180.40.106C2 (ACR)03/202603/2026Feedly [B2]
78.40.193.126C2 (ACR)05/02/202605/02/2026Feedly [B2]

3. URLs Maliciosas

URLTipoFuente
https://geotravelsgi.xyz/ujs/2ae977f4-db12-4876-9e4d-fc8d1778842dStagingFeedly [B2]
62.133.61.104/downloads/test.pdf.lnkDropperFeedly [B2]

4. Hashes de Archivos (SHA-256)

173 hashes asociados a muestras de Amatera Stealer y ACR Stealer. Utilice el campo de búsqueda para filtrar.

#Hash SHA-256Fuente
104c30011603048f69ad9ecf57ce580c1ebd20fb49a80b259e9628eaec79179a8IBM X-Force / VirusTotal [A1/B1]
205db76843f81795f9a736cb2609197d5f018978b33277f420fd17c166caddb93IBM X-Force / VirusTotal [A1/B1]
308bf6ddf7d0313477a51787d82ca3b66c102a93fcabdf53c891aa1ed331ea4a9IBM X-Force / VirusTotal [A1/B1]
40967e0e1f15ddfb9b3d7451832dd3a653177679b0b56a7c19aea8e5fd82bd420IBM X-Force / VirusTotal [A1/B1]
5096aabe166d4cec286d31042107c793431ce7ae75d208c7f7afbe822361ce329IBM X-Force / VirusTotal [A1/B1]
60df602fe581b9f252c21da7c6efc8c7bf1b9c7e83029e4b64ee1d3de6c771544IBM X-Force / VirusTotal [A1/B1]
7127a367df685ce3b04eed27ce58e148fba7c1b2273e280c531c0b3a2955dd2e6IBM X-Force / VirusTotal [A1/B1]
8133d56d17ba934898306f4ad442ee679f9e161e0237c968ff37f2abc487d3f0dIBM X-Force / VirusTotal [A1/B1]
9137c4590924df22317a90bdd9e1c9bec64def8905fe379e5f13beced9b2bb012IBM X-Force / VirusTotal [A1/B1]
1014daf77c40fa3c1ac8aef6071a818681412f36cf1565ef8cc9dc57085665476eIBM X-Force / VirusTotal [A1/B1]
1116dd58a3c2fc840fa00de80ea9dd0524ba2f02943ce049de2898598285cc9541IBM X-Force / VirusTotal [A1/B1]
1219e839202598018bab2825e24d9bdf9fad4d0ad93aada919fe13552d5a10d44bIBM X-Force / VirusTotal [A1/B1]
131ce829beec85e6633cc20abc1093395bfbd21e5235cec2ab2a447e8b14cc70d3IBM X-Force / VirusTotal [A1/B1]
141f2791dcde3845bff10d8b5612e8ee788a64d2f754a00707c85d37b0ffe6d2ccIBM X-Force / VirusTotal [A1/B1]
1522ef775bce102887a4965df0cd83d5863ff43393f2eab3fc65e6c3d2c0584cf0IBM X-Force / VirusTotal [A1/B1]
1624d94bdd8e8ce62a3ff0b704b75f01eac9345bab67086aad272dd3ac9a0c49a3IBM X-Force / VirusTotal [A1/B1]
17309e4e46e9aaf1376b7c46385269082412f3372a8071d0c4b8987bf498121874IBM X-Force / VirusTotal [A1/B1]
1831875081489b524d1cad448458de4732d13e0a570c762505765186834d66d9eaIBM X-Force / VirusTotal [A1/B1]
19318863986703d8e2bcff4a240f8d3e9f351b32741c1981e750e9546c42241bd5IBM X-Force / VirusTotal [A1/B1]
2033537764b8aa3b4c53e45181681fa67233411f56646dbad1aae45b391ba2b52bIBM X-Force / VirusTotal [A1/B1]
21360114ed2b6d6bc4c22c1a7918e58884013b733e3f3b3112b789ce0d8e77e03aIBM X-Force / VirusTotal [A1/B1]
223622330a5663d834856c72f1666ca3530319e82edc6b0db28b88360acebb64c4IBM X-Force / VirusTotal [A1/B1]
2336d2e6c50d2b153d1caae36199a6bf0d102cdb1ce1f79777bb60619ac67ba688IBM X-Force / VirusTotal [A1/B1]
243794a53a91357b30bf3329141171447d2e10e5e102db13a95838ec4669fee5d6IBM X-Force / VirusTotal [A1/B1]
2538589033da08fa0e259543a44d0eacc05606ec9350e3d86fee9ebaf9124992bbIBM X-Force / VirusTotal [A1/B1]
263ac830b1499c00d1433f19e833f68286f462b996ceec568ef69453aaee9b9c64IBM X-Force / VirusTotal [A1/B1]
273b562a133ca05f1921c230383726049fb1eb7f1af0ac49194b0c047c87f76719IBM X-Force / VirusTotal [A1/B1]
283c4da6c520bb4b7ed8606bacf4c2956a5f7e3a77c1e01607bb270ae7765608c9IBM X-Force / VirusTotal [A1/B1]
293d942864e59d5dd6a6b0e138aaf63bd31d5d21e10a9c3eef7c1eccd01900455dIBM X-Force / VirusTotal [A1/B1]
303f0d14ae0aee61e3342d12a0b84bfd240257b589cba4b5189f126cbe44777cedIBM X-Force / VirusTotal [A1/B1]
313f4a9dd1e512ef05d6871676dc10094e8da5eaa4cb9df4fcbb61b27bca3dee89IBM X-Force / VirusTotal [A1/B1]
3240ba596be5c0c702a2ca4f156b7e3102cafe324e5191d25c25bdd12b521fe59bIBM X-Force / VirusTotal [A1/B1]
33421b2bb856c017b29788073ebcfce11a684555d9945a0377e4f8e27959b02ee1IBM X-Force / VirusTotal [A1/B1]
34429ab5f3d38e47a6aeda69cee14475745264bbad865aebfa7e0a1774feb9d44aIBM X-Force / VirusTotal [A1/B1]
3542c2f7ffab89d769906f4cb65bf9f30f61f13bc4dba128d57845f94bb9c8163fIBM X-Force / VirusTotal [A1/B1]
3642eabf1e8e5e5f2c2cbeaf47b277ba768d4c84b65b44f5db5d811c4347da59f8IBM X-Force / VirusTotal [A1/B1]
3743125fdc0fbdd0612b985f03298b7bd505f3f286ce2958d83e5d4bc5f46da870IBM X-Force / VirusTotal [A1/B1]
384341879fe90a6edb5c8e826e25c37cb8a7f49890781ffe2732b3bd963795a63cIBM X-Force / VirusTotal [A1/B1]
394475e6254c8c10e7a1ee231cafac459388de7e026bf8987dd11832b0b0fff30cIBM X-Force / VirusTotal [A1/B1]
4044e5b0bf7843024b86ae669ac96143fb84388ab03b0ae4887066cc3118d1cbe0IBM X-Force / VirusTotal [A1/B1]
4146bd2546646cc5f09ede431e971813f48b243c9d38af1eed5bcc97747908bfb5IBM X-Force / VirusTotal [A1/B1]
4247f04785b7414f2c9628fc544dc05c8da43b186ce3c9b3790d7af28bb2b2bcdeIBM X-Force / VirusTotal [A1/B1]
4348da3a8666a96374253c20e98608803a41a8057a318e458f2241b9e97ec13263IBM X-Force / VirusTotal [A1/B1]
4449e7a5329a19e32df5998efd8bb3b5eaeed28b13fe79218949693706f239305dIBM X-Force / VirusTotal [A1/B1]
454a0591336c7df9c61ed2656ac8d943cbc5b9a1375d83723e1cc9e3c71dd9a01cIBM X-Force / VirusTotal [A1/B1]
464a1b0e3635668e15ccadb554acd571109d8e5d3398deb39b0346aebcb6561d9bIBM X-Force / VirusTotal [A1/B1]
474afa12e92cb5cfa1ce31dc3679576b3dd70cb0c14c0fa5105c09612b6c515bf4IBM X-Force / VirusTotal [A1/B1]
4852faca2228eb5a3f2820e792279f338c5a0faffada1ce3b554873a128b234013IBM X-Force / VirusTotal [A1/B1]
4958e5b3002218fb778f2648c6096655aeab2a9b62973dbd7f7dc6a170edf522efIBM X-Force / VirusTotal [A1/B1]
505be1cde221d957444d8f4db59f50e0f14363ef4de69f0f46af460c592adb6100IBM X-Force / VirusTotal [A1/B1]
515f2e9a0da6938034fb0310f82d85afbe923df5963364b2b257ace0f9b33e51c4IBM X-Force / VirusTotal [A1/B1]
526040a2950f28f8d4ea16f8b9f73f95fca4043ec5356eeb14e1dcdd621ead06ccIBM X-Force / VirusTotal [A1/B1]
5360474d9dfcd8e77331b3f317441bb0c065d924b2dbb8b4dcc9ad917f4074a302IBM X-Force / VirusTotal [A1/B1]
5464bc219bca2e3a4426199b2cf54aba7df8ea53f8a0ed04364aae9a654e96efe1IBM X-Force / VirusTotal [A1/B1]
556678141627eeb3bbb72f2e48c0dcfc1f7bbe7c54f1a7787dcba7e780020e2167IBM X-Force / VirusTotal [A1/B1]
566840d20d78db83e0bd6f81e3c7cb5cda6577336ecbce38626e2299d79082ad5aIBM X-Force / VirusTotal [A1/B1]
576962de7de92116ea5eae20476f3490aa862091196d1eb00e216ff1a4960a3c10IBM X-Force / VirusTotal [A1/B1]
586c0fe0efb2bbfaa12c321e747a893ad0c9fa1e4e549a193a36a86bc2edb2c6d4IBM X-Force / VirusTotal [A1/B1]
596d0068de8bc140cfe20a79d0ce8f1feb5778c13f93e65938e0114d236291117eIBM X-Force / VirusTotal [A1/B1]
606d202bab1a6a981beb3d87936dbb2b526f4ef2d0c317194cccec8be324c05a48IBM X-Force / VirusTotal [A1/B1]
616e2ae6f112a0bb20a7b4907976b4279a8afb3778a6adb8b4b5db0228f257f49fIBM X-Force / VirusTotal [A1/B1]
626fae124d09e3eb213357175e59fded348b9f47fdb30a7a660f1e65771cb6eef7IBM X-Force / VirusTotal [A1/B1]
6372817b35ab376da800b5403fe3595676680dad41033a0f7107d0261a086f6eaeIBM X-Force / VirusTotal [A1/B1]
64742f5543ca17514b9a3b2fd7227f962cea17477050b03ebe8e07f1b1bdf1dea1IBM X-Force / VirusTotal [A1/B1]
6576a10b1097d80a92a99fb3fa313c290f236e1e69be703accd20c600bc164841cIBM X-Force / VirusTotal [A1/B1]
667c7aad09308047f103aa8d2d692707b5e2adf4ac219862ef1fbaf5e97854ee0fIBM X-Force / VirusTotal [A1/B1]
677e01ba0fd3dbc631f49c5b6a14fd954efde9bed0b00c7fa150665c6407c05b68IBM X-Force / VirusTotal [A1/B1]
687f83cf01abd97ca0fdac21991a6ddd45b57815ddd5bdc1a62e0f469550b6e9a5IBM X-Force / VirusTotal [A1/B1]
697f9700249874f38f183556f8028b2d59aaa20fa0cb03a427772507eb480ca103IBM X-Force / VirusTotal [A1/B1]
70809be9b70095f131db8a41629bd079424975668ef78fb75297d4e8251907d70cIBM X-Force / VirusTotal [A1/B1]
7180d289a581c8ef758ef16165b35a2294fa21b27c60dafe81bd706da962127f88IBM X-Force / VirusTotal [A1/B1]
7280f1c57294dadc4551a0a5d830dd508df0a491a7d4fc48c85e47ef795a97821dIBM X-Force / VirusTotal [A1/B1]
738110d62f3238365518dfaf9e673c5cae2ffee7dfdb8e6d48bfc2d211deab72c5IBM X-Force / VirusTotal [A1/B1]
7483b63027f77ccc7d1cdfd22ff160a20ff129ef660fb86af5839a675290c73181IBM X-Force / VirusTotal [A1/B1]
7584c35ac3554103162155a3c1fa2211a4ab703d9b1614b69a75248f300cf35eacIBM X-Force / VirusTotal [A1/B1]
76859834fba7aec413f91a24d7b72473f9a587e1e5e3ea15498050d26400228f4fIBM X-Force / VirusTotal [A1/B1]
77890950b1f00724110afa7ca2e5381fc49576bd20985444910e9c0c7cb6e770c6IBM X-Force / VirusTotal [A1/B1]
788975c1f6424eaff78d99c9e5dc69d63c0b3150146cef490e9935fe80d1fc8a04IBM X-Force / VirusTotal [A1/B1]
7989b32e6252d2b66e15f255f803d1e9936431f3ec05a343e36e0279c42bb2d2a9IBM X-Force / VirusTotal [A1/B1]
808a5e13b35745a2fd1de5567ee10e0493c437b59a6c8bd081f7543a71d3affe19IBM X-Force / VirusTotal [A1/B1]
818a5e9cbdc3fdf28bbf5d97559f6d6a6a76a89e25f2e6e6aa615ecf9d5fd1f2fbIBM X-Force / VirusTotal [A1/B1]
828bc815d40768f04720d1112b7d477e90c2f26611ae0488f2bb43502c008868e9IBM X-Force / VirusTotal [A1/B1]
838d3634a77504cb0eee0f0f853bebaeb501a8147e104eb0f381a93b497272e34fIBM X-Force / VirusTotal [A1/B1]
848d9044c428b2cad9b1ff7218d8a7d652964abb9a567468727808fd63ec9e60a8IBM X-Force / VirusTotal [A1/B1]
858da7cca815469604dd7e360c3567db5ff1354fe662a45392a3cbfdfcb5acb047IBM X-Force / VirusTotal [A1/B1]
868e7d408cc63726a0e53adb06749ab7a3115e11cac4e7befe72c7135d1e1278a8IBM X-Force / VirusTotal [A1/B1]
878f237a902bc62ad96dd5643275f4ad1ea64cb5dedbcc16d62db0e6de25cd9e5bIBM X-Force / VirusTotal [A1/B1]
888fc16b78b93594da17f958aecb690a8b39cdeabb63639887aa65a82038b0639cIBM X-Force / VirusTotal [A1/B1]
89903af605398c2582a90df8ca56fa6b780fd29d6892ec0e9dcaa7770d9e5329a0IBM X-Force / VirusTotal [A1/B1]
90904fa94df03c2933c589401f3905511461b10f7a21dcd68a8c4317693a9e6f79IBM X-Force / VirusTotal [A1/B1]
91917c89e14b81f4d2f76ae245974d5b6bc596cccee6be901ce8c5840e73ea1c63IBM X-Force / VirusTotal [A1/B1]
9293996926637363d89936b9c878c11e0c5289c8aadecd07cbd7475e7caab83595IBM X-Force / VirusTotal [A1/B1]
939560b4aaff3989b986697e642528601e821f306b7b4161131b5bf5bdf83786d0IBM X-Force / VirusTotal [A1/B1]
94986b8a112ee72aff84800420d69524c35bfb2c307779d2b440d2c78734f2d130IBM X-Force / VirusTotal [A1/B1]
95993f59eea8a62974d98d56f6f5465d05b391b6d5272493951e7b59e37a87ed9aIBM X-Force / VirusTotal [A1/B1]
969a6222acd09d0f5c562df1e6cf9de913e6e19525ff2c299b3ccfefe5b442fe5cIBM X-Force / VirusTotal [A1/B1]
979cdc77b08aa5d2a1b7ff74d9adbbc6845c14764bb8c3017b51510cd1a46a0db9IBM X-Force / VirusTotal [A1/B1]
989f91c9f0839fb08719d3426ffc51a343c318482fec1a09c58e1ca304b945a333IBM X-Force / VirusTotal [A1/B1]
99a03d51cf173223b030a2efc043903a53c17307c81ba871455f700c799d80a081IBM X-Force / VirusTotal [A1/B1]
100a130899c3d7edb54817005b0e62da8512d674e706aa479c6c5885e221bd374e4IBM X-Force / VirusTotal [A1/B1]
101a214d286049720fb67ff97716d5695a5c7af9644aa9e1e91f85a291db6f0b074IBM X-Force / VirusTotal [A1/B1]
102a325ae77780855c5959c237db9cc5dfb215bda7605d8e0a03c25cb33a76003e7IBM X-Force / VirusTotal [A1/B1]
103a389ea8e6a5d25145dfeb476a6d79a4ac95c0d252775e0f38400368b70597c89IBM X-Force / VirusTotal [A1/B1]
104a54be7b1aefe64427a8a60ad27d2d6a2a2f862c3c3598f05593ef6c44d37a47cIBM X-Force / VirusTotal [A1/B1]
105a59b4a80e971c197c10fc8d37c2e7936618a59d25b0c3f3bc5fb8270043e778eIBM X-Force / VirusTotal [A1/B1]
106a6087401434c0ce8a2b141a1b87ee301d7945b7a8c51a3aee5cde72a19a632d6IBM X-Force / VirusTotal [A1/B1]
107a7987ec4361b890bc4248964b5b3cb79a3dcdb1e0044df5377a335bbee351857IBM X-Force / VirusTotal [A1/B1]
108a857af09fdfbceebcfdca6a0c8bb242bda95f1250f69225680e45c13487a568eIBM X-Force / VirusTotal [A1/B1]
109a8f5ad6064065fe0821daa6aef489b8ae3ac61b8dbe245af7dbfec19bcab05b4IBM X-Force / VirusTotal [A1/B1]
110acf12a0375d46897a69d730e32b3d8c14ca79f593db0d602fc398deb91430575IBM X-Force / VirusTotal [A1/B1]
111af421446784776aa11a0542445141d44e083ee683fff905b04dfdaf3e51ea479IBM X-Force / VirusTotal [A1/B1]
112b0c684a54ee747c2241eff998c3b2c4fdc6f17c3c74637c21bcbcbfdcde44e72IBM X-Force / VirusTotal [A1/B1]
113b407f05eae27d33fb5a71e5969c824732853248bb4905d8cca541d556e5decbaIBM X-Force / VirusTotal [A1/B1]
114b4363643a18007f3a1fd4e68269f87f6b78b0fb7390021df606901fd87c87aabIBM X-Force / VirusTotal [A1/B1]
115b5b8fa30d56490fc8385369ec7adcf3f1cc334b2204c910d7da43fdc06a4c08dIBM X-Force / VirusTotal [A1/B1]
116b999ccdeb2d043b645c9989ae4330f8abe039a6708bdbdfded750cc5f91a8e09IBM X-Force / VirusTotal [A1/B1]
117bb129862e059eb57df8d01311dfcae333d34f47a4a95f0f916c871b1aefb31f8IBM X-Force / VirusTotal [A1/B1]
118bbd76bcc6023e877ba553fe54cd072bed8ad483ce2fc778417600df0c05701a0IBM X-Force / VirusTotal [A1/B1]
119bfcd2440a0fc09819ee4034cab2a1f22a8d60a4b8812d65fd426ff5b7af1155dIBM X-Force / VirusTotal [A1/B1]
120c0709c02d27a88b78939bc422e738af70b1455580a5ef7f3169b2868ecdd584aIBM X-Force / VirusTotal [A1/B1]
121c251c36277cccfca55e7807c1720dd372012aff5ee6c6f27f58a9e1c1d753794IBM X-Force / VirusTotal [A1/B1]
122c25f55c1b8c8df717a347733bd13b8fe544969cdbdb81eace3d41b737179cd64IBM X-Force / VirusTotal [A1/B1]
123c39cf50252f271b3a7fb96429606c7acb791457076a80fb6bd8fb7302eae08c2IBM X-Force / VirusTotal [A1/B1]
124c62e8f6718bd826dff060996de02cab86d78385b8c147b8c21289067842bfe20IBM X-Force / VirusTotal [A1/B1]
125c641fcafd2aa18b7613c042deb8160ec9519b4c6795d42848a1ea42d3c0ecaefIBM X-Force / VirusTotal [A1/B1]
126c94be154ff82f46d6cfd34bae05ba8ae2502fe49e4eee23851f7b1db406adb21IBM X-Force / VirusTotal [A1/B1]
127ccc9acd19fa263eae1f879c6404f2a73fd0bcb0092e25d3c44f63f0cf6d5779dIBM X-Force / VirusTotal [A1/B1]
128cd713042c74ca5cd390ae794aa61e745df5d8b43f24b67b58336756dff3612f2IBM X-Force / VirusTotal [A1/B1]
129cf4a556c2adaf3f3c38c2dffd663cccb21606b9cfe4760bf87d970569669975aIBM X-Force / VirusTotal [A1/B1]
130d22eea2a1ad481932a96c5f1fa5f420f7f3754bcda91f8b8b5ef179158241a4aIBM X-Force / VirusTotal [A1/B1]
131d2d99ee55ce67286247f7acc45c8cff8dbf58d018298f854a6f3e0d41c4320e0IBM X-Force / VirusTotal [A1/B1]
132d31f0db296f0b8588af3b8094772ec57f7c51ce95d1bdec0c7ddc45994c4669eIBM X-Force / VirusTotal [A1/B1]
133d656f7f2013255b19c2c17bbc6dcbf00c81ac61e6109bc5b439053d510e8c383IBM X-Force / VirusTotal [A1/B1]
134d83fe96db4f4f9ce7049af471e78fabd425cbbfc9bc1f5ee474b80c46bb08493IBM X-Force / VirusTotal [A1/B1]
135d8a855515e8bc62c09a90698218c9befb7a5dcc8967852cb05721432c6eaaf45IBM X-Force / VirusTotal [A1/B1]
136d8dbbcab910ae421f9194f25e6e9a3604205fd4d006980c710a023e26fb416a1IBM X-Force / VirusTotal [A1/B1]
137dcca439390582b45f9a0b3e30f59c8ca43aaee050d1a6db3de9e5286dad4b765IBM X-Force / VirusTotal [A1/B1]
138dd0d7e49323ffad1a9803f1299dffc5dd38ab96bc7e2ae6ba1509dc7944150e4IBM X-Force / VirusTotal [A1/B1]
139deab8293009b0660cd094d5596e4627d5811ec20ab8dc90253431d3afc7428afIBM X-Force / VirusTotal [A1/B1]
140e102e3fc64fd8e6e688dfab60761c3cbb3e5b7b9127000c5136a0063b28deadcIBM X-Force / VirusTotal [A1/B1]
141e2809f1d32105a31ef82ed30cc6d1dd6ed93b17a335dc9e0f66b295b6aee5e30IBM X-Force / VirusTotal [A1/B1]
142e43ebc41d3091fa5353d38504557b7b91757a3f1049105a034064d87f3b4e650Feedly [B2]
143e5a27de41e2a586b44f92622fc025be4d24c2c292ebcf24c11c4fe47364d5430Feedly [B2]
144e73497f7c3d311faa8af5c83aafdfd08fd2cf3631cf6df295b0241033e4a11b4Feedly [B2]
145e7cdf0c76ebbc46f9521d16cd8f3ee8ff55d5e6a20f50a8c9a02e20700aa3b38Feedly [B2]
146e9f38fe0e1e22b28f05c5079c9436946e0b20ba9f73d719b0dc782ed8f392a23Feedly [B2]
147eb11fbb9fdc5a0ffab884629c0c24042912ac85eedcc5becb72606ecfb603065Feedly [B2]
148eb20c5b57c3f8518ef554936d492d96f7ebbfda2e5210669fe0ed8a651ec1392Feedly [B2]
149ebb439fd5a48a86a3b1eecd66929f6692b7f6e7a4b48238a1340566171e49c70Feedly [B2]
150ec09d94ab15223852ae23c9e9245c880aada90e1de590feb34334ce28e7e8de9Feedly [B2]
151eefe961b5e4ee1bab6379431c0a0d831fd35df5bbfeb9f3d4109def041182852Feedly [B2]
152f49e6edb57d0b4f4dd37cf695ab54a35af2b016ab6bae2e555be22a7141cde55Feedly [B2]
153f4be3316d1283766d8479e1ae49b0f2b114ca5dd4fc076cb8d350636d4360da1Feedly [B2]
154f4d640102f791f45864d15702ea91c2f4acca45c424ee05f34a4112aa1a0dd87Feedly [B2]
155f5729e4772ff54d9d467d8db254c220e7880a50a28820135294ec7d5df37a89cFeedly [B2]
156f59df0373050020d46cc36bdec28542e71136d7a7988f8b1576272c8f1f5afbbFeedly [B2]
157f7b08d7183bc1b1ec18a3f12496243a52f14a1535b776771b02cffe1760145c7Feedly [B2]
158f89e7b0c6408f89c73bfa7c6f97d28c7bca0c067bcea97a524c10a377e55ee50Feedly [B2]
159fa5d5774063fe032b9be993617435b57da556c4ce2cef267581acb493098b76bFeedly [B2]
160fcd37d51ca9d72e7a38df466a2495e7cc4478e820f0d6953fb617bfe31142449Feedly [B2]
161fe5b16ab3a33610667334967a1d4e314e4291305390fc893060efda132dc7bd9Feedly [B2]
162fe65744e7490a23a0dc2ee6914184fbbc0e0f9815a285928a5b803de59959c85Feedly [B2]
163120316ecaf06b76a564ce42e11f7074c52df6d79b85d3526c5b4e9f362d2f1c2Feedly [B2]
16459202cb766c3034c308728c2e5770a0d074faa110ea981aa88f570eb402540d2Feedly [B2]
165ad0bfefa643b395400d4c89181446dbfec57f263dda39555c2ef5e704a9e6eb6Feedly [B2]
166f82938352cebfe4338e0e3e763cfee88aa5dd6229ac36200ce0392619153f4cdFeedly [B2]
16764010a9fe4483155044ad76aecbd2cdafab0fc1399e4ae0c644bcce6acbf7f58Feedly [B2]
1682db0c548a91356a4f79bcad8d492342699a5842b36cd813485145df0c2957c08Feedly [B2]
16968f9e86795c5dd817dec72f776ea0162a8c4a9cef26b54843fac00c101158ba1Feedly [B2]
1702df520219dd0db59d75203dec58c8d0dcce55b4e947defb1df30fdce4af982daFeedly [B2]
1714867b739b7a4cb72fdd88c7716150e12183b98a07a752753ced440355a5ee193Feedly [B2]
17238cd4bb0d7e4b8bc5de10df2a2554939ae96642109567e103d779b6eb19c40aeFeedly [B2]
17312ab29ed1c3f60092c101e9c8451ff44fda6c9787c6e32e3956e9a645be5dceeFeedly [B2]
1740111ffb0dab4bdef8c8788e4ce6ad4fc071b9f7b1f3affb7ead8d5df9582f34fFeedly [B2]
175006f0054609064c00d3d217ee37f924b4cf8c4fabde362408cdec1446d719913Feedly [B2]
17600b84eae83e4cd6165255247026c702c2c88f5cea8a1032187c2b842dc54095dFeedly [B2]
177dc363b99506502dac735b4b5636dfeadc07fec6742140da0d89673110538e532Feedly [B2]
178f7131fc0267d5e0eae0b00ee05eb221351910114d1794c30997a5e45e24059efFeedly [B2]
179bbf45b03ba04ceab793e2a4dda578c9d4881ba26d1a39bc1257a7996f7c3dfacFeedly [B2]
180bc55d60466f7d1a03e4002759aa95cae2bd08cf9c0685f2f822ebcc8956569b2Feedly [B2]
1818721d3af5d2d01dc76d8102716dd6bc4271284a7682df46f10b6aacfd5b2cd48Feedly [B2]
1823e99b0f5eb750b818e55f23a6f1fcf8213e7ed3ac850529ade7e6fa6b7afe0e2Feedly [B2]
1832428bd931dde4d818437ff9e12197bdbb4a5c0548bc7c068bb732c7bc4847554Feedly [B2]
184e4a1b01b2a76ef02a2f6ea32275eeee4f44b867d2d5768bf89f870cbfacfa47eFeedly [B2]
1850cec3100b84f95dfb1e856390cf41809b653812fd4d51025517ba11b167442faFeedly [B2]
186b9ff92917225778b82c30587d5559628f0ab14c359bd2b6ae4981ff262480fc8Feedly [B2]
187ca6b92b816c98e3fca7b287cf665257a93f1a35cc768cae223ac31a97d1af203Feedly [B2]
188e01fa4ca545c8a4002b9afe3243f80027b76ef5fb81fd5d9e9d1dcaddfaca54bFeedly [B2]
189f213970c9bde24a7b774e16803b9df9be69e02f1795e777241ada5201ed72666Feedly [B2]
1904ad9fd2b5519c521765a80f3411f825adcd38409ba6cfefd595873c9c6db92c3Feedly [B2]
1919375878e6780ed937d68f58904d27257c5ec7af0fef24c6126a8e05eb2dbd4f3Feedly [B2]
192532c9bc2e30150bef61a050386509dd5f3c152688898f6be616393f10b9262d3Feedly [B2]

5. STIX 2.1 Bundle

Bundle STIX 2.1 completo con todos los indicadores de compromiso, objetos de amenaza y relaciones. El botón inferior permite descargar el JSON para importarlo en plataformas TAXII/SIEM.

6. Clasificación de Fuentes (Admiralty Code)

FuenteFiabilidadCredibilidadCódigo
IBM X-ForceA – Completamente fiable1 – Confirmada por otras fuentesA1
Proofpoint Threat InsightA – Completamente fiable2 – Probablemente verdaderaA2
FortiGuard LabsA – Completamente fiable2 – Probablemente verdaderaA2
eSecurity PlanetB – Normalmente fiable2 – Probablemente verdaderaB2
SecurityOnline / Daily CyberSecurityB – Normalmente fiable2 – Probablemente verdaderaB2
CybersecurityNewsB – Normalmente fiable2 – Probablemente verdaderaB2
Feedly AIB – Normalmente fiable2 – Probablemente verdaderaB2
VirusTotalB – Normalmente fiable1 – Confirmada por otras fuentesB1
CVE Details / NVDA – Completamente fiable1 – Confirmada por otras fuentesA1
Sistema de Evaluación Admiralty (NATO): El código Admiralty es un sistema estándar utilizado por las comunidades de inteligencia de la OTAN y aliados para evaluar fuentes de información. Combina dos escalas independientes:

Fiabilidad de la fuente (A-F): A – Completamente fiable; B – Normalmente fiable; C – Bastante fiable; D – No suele ser fiable; E – No fiable; F – No se puede juzgar.

Credibilidad de la información (1-6): 1 – Confirmada por otras fuentes; 2 – Probablemente verdadera; 3 – Posiblemente verdadera; 4 – Dudosa; 5 – Improbable; 6 – No se puede juzgar.

7. Referencias

  1. IBM X-Force — InstallFix Report:
    https://exchange.xforce.ibmcloud.com/report/details/guid:f52c99c24f704788b8036f1ead587991
  2. SecurityOnline — The Vibe-Coding Trap:
    https://securityonline.info/the-vibe-coding-trap-fake-claude-code-installers-unleash-amatera-malware-via-search-ads/
  3. eSecurity Planet — Fake Claude Code Install Pages:
    https://www.esecurityplanet.com/artificial-intelligence/fake-claude-code-install-pages-spread-infostealer-malware/
  4. CybersecurityNews — Claude Code Vulnerabilities:
    https://cybersecuritynews.com/claude-code-vulnerabilities/
  5. Feedly Threat Intelligence — Seguimiento de InstallFix / Amatera Stealer / ACR Stealer
  6. VirusTotal — Análisis de muestras de malware
  7. CVE Details / NVD — CVE-2025-59536, CVE-2026-21852
  8. Proofpoint — Amatera Stealer: Rebranded ACR Stealer analysis
  9. FortiGuard Labs — SVG Phishing / Amatera Stealer campaign