Indicators of compromise
4,235 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | ab54af1dbe6a82488db161a7f57cd74f2dd282a9522587f18313b4e9835dc558 | 27a21a95ea2a6136c264c6a6cc2f0910a24881118b6eabc2d6509dc8dd7 ab54af1dbe6a82488db161a7f57cd74f2dd282a9522587f18313b4e9835dc558 3cef0b5f069cc1d15d36aa83d54d2a7be79b29b02081b6592dd4714639a | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | ab9d8f1021f2a99c74aa66f8ddb52996ac2337da9de2676d090b87e19ce93033 | hell. SHA256 Family Callback Function Called By UUID Format ab9d8f1021f2a99c74aa66f8ddb52996ac2337da9de2676d090b87e19ce93033 ToneShell EnumSystemLocalesA ASCII cf61b7a9bdde2a39156d88f3 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b382cc85eee95a620fc11370309ff76de9a3bcaefb645790434d8251a3b9fce1 | orm samples, we found a variant of the ToneShell backdoor ( b382cc85eee95a620fc11370309ff76de9a3bcaefb645790434d8251a3b9fce1 ) that had the same debug symbol path as the Bookworm loade | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b7e042d2accdf4a488c3cd46ccd95d6ad5b5a8be71b5d6d76b8046f17debaa18 | lated to PubLoad Using V6-winsp1-wuredir SHA256 Filename C2 b7e042d2accdf4a488c3cd46ccd95d6ad5b5a8be71b5d6d76b8046f17debaa18 analysis of the third meeting of ndsc.zip 123.253.32[.]15 4 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | bbf12ee2cd71dbcf2948adf64f354ad7c69d6b6ff0b78ea76b3df2d02b08ed0f | df154bb60fcf24d0ab5297d0c6beaca0f Leader.dll Leader.dll 0x0 bbf12ee2cd71dbcf2948adf64f354ad7c69d6b6ff0b78ea76b3df2d02b08ed0f dafdsafdsaa3 Resolver.dll 0x1 fa739724a4b6f7a766a2d7695d7da | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | cf61b7a9bdde2a39156d88f309f230a7d44e9feaf0359947e1f96e069eca4e86 | Compiled SHA256 Filename Debug Symbol Path C2 Dec. 23, 2021 cf61b7a9bdde2a39156d88f309f230a7d44e9feaf0359947e1f96e069eca4e86 anhlab.exe C:\Users\hack\Desktop\uuid\uu\Release\uu.pdb www | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d7dbfb2b755418842fea4fca5628f0b36bbd128a71ddcd858b4b3c67ba78f516 | ac834672c1b544dd555c93600a637 fjdasljguafa KBLogger.dll 0x5 d7dbfb2b755418842fea4fca5628f0b36bbd128a71ddcd858b4b3c67ba78f516 Coder.dll Coder.dll 0xA 6804b10aefe8fdb2b33ecf3bc5a93f49413 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | da8ef50fe5e571d0143a758c7c66bb55653f1f2d04f16464fc857226441d79b2 | a725adc57d7b501f33e87230a8291cf8ad22d4d3a830293abcc0ac10d12 da8ef50fe5e571d0143a758c7c66bb55653f1f2d04f16464fc857226441d79b2 f0df09513dcf292264b3336269952c7e9ff685df8180a2035bee9f3143b | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | dcc349a1b624f6b949f181a7dd859a82715b4d3b6c37c7e5be1b729cd8e6f01f | 0820948d5d2ca4c192fac8b1ede91c2 yyrtytr.565 Network.dll 0xE dcc349a1b624f6b949f181a7dd859a82715b4d3b6c37c7e5be1b729cd8e6f01f feareade HTTP.dll 0x13 51bf329ba04a042789bad3b395092488a3d8 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | f0df09513dcf292264b3336269952c7e9ff685df8180a2035bee9f3143b36609 | 50fe5e571d0143a758c7c66bb55653f1f2d04f16464fc857226441d79b2 f0df09513dcf292264b3336269952c7e9ff685df8180a2035bee9f3143b36609 Bookworm Modules SHA256 Module fa739724a4b6f7a766a2d7695d7d | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | f7b024196ac50bd0f7ed362a532e83edf154bb60fcf24d0ab5297d0c6beaca0f | rrent Module Name Related Bookworm Module Current Module ID f7b024196ac50bd0f7ed362a532e83edf154bb60fcf24d0ab5297d0c6beaca0f Leader.dll Leader.dll 0x0 bbf12ee2cd71dbcf2948adf64f354ad7c | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fa739724a4b6f7a766a2d7695d7da7b33a6ac834672c1b544dd555c93600a637 | d6b6ff0b78ea76b3df2d02b08ed0f dafdsafdsaa3 Resolver.dll 0x1 fa739724a4b6f7a766a2d7695d7da7b33a6ac834672c1b544dd555c93600a637 fjdasljguafa KBLogger.dll 0x5 d7dbfb2b755418842fea4fca5628f | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fb25a69ffc18b79ee664462e0717cf5e70820948d5d2ca4c192fac8b1ede91c2 | c6639eae65900cb2ea26911540a77d1f9b7acf6 AES.dll AES.dll 0xC fb25a69ffc18b79ee664462e0717cf5e70820948d5d2ca4c192fac8b1ede91c2 yyrtytr.565 Network.dll 0xE dcc349a1b624f6b949f181a7dd859a8 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fbc67446daaa0a0264ed7a252ab42413d6a43c2e5ab43437c2b3272daec85e81 | DIS13n\Release\LTDIS13n.pdb www.fjke5oe[.]com Oct. 26, 2022 fbc67446daaa0a0264ed7a252ab42413d6a43c2e5ab43437c2b3272daec85e81 ltdis13n.dll C:\Users\hack\Documents\WhiteFile\LTDIS13n\Rel | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fdad627a21a95ea2a6136c264c6a6cc2f0910a24881118b6eabc2d6509dc8dd7 | da41cb509412ee230c6d7aac3d69361358b28c3a09ec851d3c0f3853326 fdad627a21a95ea2a6136c264c6a6cc2f0910a24881118b6eabc2d6509dc8dd7 ab54af1dbe6a82488db161a7f57cd74f2dd282a9522587f18313b4e9835 | Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | adibas.top | ollowing list shows each domain followed by its IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergo | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | astrovoerta.top | iuj[.]top - 46.173.219.161 suzemodels[.]top - 35.163.101.72 astrovoerta[.]top - 185.159.130.89 zofelaseo[.]top - 35.163.101.72 These do | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | footarepu.top | n followed by its IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 gunterg | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | guntergoner.top | ibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-te | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ibm-technoligi.top | er[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polki | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | polkiuj.top | i[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.161 suzemodel | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | suzemodels.top | lkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.161 suzemodels[.]top - 35.163.101.72 astrovoerta[.]top - 185.159.130.89 zofela | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | zofelaseo.top | ls[.]top - 35.163.101.72 astrovoerta[.]top - 185.159.130.89 zofelaseo[.]top - 35.163.101.72 These domain names were registered a day | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 185.159.130.89 | 6.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 35.163.101.72 | 219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 3 | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 35.165.251.24 | 2 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165. | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 35.165.251.241 | .251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.161 suzemodels[.]top - 35.163.10 | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 35.165.86.173 | IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.1 | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 46.173.219.161 | hows each domain followed by its IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163. | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 62.109.29.26 | ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.1 | "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | alita.kz | ugin.zip Examples for start of URLs generated by plugin.js: alita[.]kz/tmp/installation/language/cs-CZ/counter/ avtotur.com/libr | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | anilstone.ir | /woorutu63408454 Links from the emails on Friday, April 14: anilstone[.]ir/libraries/joomla/string/wrapper/counter/1.htm Associated | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bel.tr | amples of fake Microsoft Microsoft Word Online pages: posof.bel[.]tr/counter/1.htm tramplinonline[.]ru/counter/1.htm mattsfoto | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | boorsemsport.be | om/libraries/fof/utils/ip/counter/ circus-stroy.ru/counter/ boorsemsport[.]be/templates/yoo_aurora/less/uikit/counter/ eurostandard[.]r | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | eurostandard.ro | boorsemsport[.]be/templates/yoo_aurora/less/uikit/counter/ eurostandard[.]ro/pics/size1/counter/ forum-turism.org[.]ro/images/layout/c | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | glochemindia.com | size1/counter/ forum-turism.org[.]ro/images/layout/counter/ glochemindia[.]com/modules/mod_roknavmenu/lib/librokmenu/counter/ sportbelij | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ideliverys.com | s from the emails on Wednesday, April 12: uspsaeyyuia158140.ideliverys[.]com/ioxoory254772 uspsbhusisoz75.ideliverys[.]com/aagupto83 u | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | maildeliverys.com | s from the emails on Thursday, April 13: aexhnneq102342usps.maildeliverys[.]com/kovcemaw707572 bdguz0371usps.maildeliverys[.]com/usvyneye | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | mattsfotoalbum.de | : 1,537 bytes File description: Contents of plugin.zip from mattsfotoalbum[.]de on April 13th SHA256 hash: 40e8dc147f189baf4660d5db8e0cd1 | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | online.ru | ytes File description: Contents of plugin.zip from tramplin.online[.]ru on April 13th SHA256 hash: a1670db6204f7666ad246cc11736b0 | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | org.ro | counter/ eurostandard[.]ro/pics/size1/counter/ forum-turism.org[.]ro/images/layout/counter/ glochemindia[.]com/modules/mod_rok | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sportbelijning.be | mindia[.]com/modules/mod_roknavmenu/lib/librokmenu/counter/ sportbelijning[.]be/libraries/joomla/application/web/counter/ | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | tramplinonline.ru | t Microsoft Word Online pages: posof.bel[.]tr/counter/1.htm tramplinonline[.]ru/counter/1.htm mattsfotoalbum[.]de/cache/counter/1.htm ani | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 3b5b19ebe8d8b6c7e5b2ffd2cc194fad1ae6c9eade7646f48c595bd154f4b1e1 | f plugin.zip from anilstone[.]ir on April 14th SHA256 hash: 3b5b19ebe8d8b6c7e5b2ffd2cc194fad1ae6c9eade7646f48c595bd154f4b1e1 File name: exe1.exe File size: 85,504 bytes File descriptio | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 40e8dc147f189baf4660d5db8e0cd1c647c7f167f7176c5d8ee03b6cac26fed2 | gin.zip from mattsfotoalbum[.]de on April 13th SHA256 hash: 40e8dc147f189baf4660d5db8e0cd1c647c7f167f7176c5d8ee03b6cac26fed2 File name: plugin.js File size: 1,382 bytes File descriptio | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 41f171eb916d555dc7771ce71013572c498b8d620d2f72872c4b2f3b50c7ccb1 | malware retrieved by plugin.js on April 13th) SHA256 hash: 41f171eb916d555dc7771ce71013572c498b8d620d2f72872c4b2f3b50c7ccb1 File name: exe2.exe File size: 363,728 bytes File descripti | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 50117ce3fe5dba572cf23584dc7541a7cfd4026d4316e69d29cdf536873fdf20 | malware retrieved by plugin.js on April 13th) SHA256 hash: 50117ce3fe5dba572cf23584dc7541a7cfd4026d4316e69d29cdf536873fdf20 File name: exe1.exe File size: 91,136 bytes File descriptio | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 5459be968e2296a759dcafa7107ef06d02331b5291c9f3056077bcf38ce37d9e | malware retrieved by plugin.js on April 13th) SHA256 hash: 5459be968e2296a759dcafa7107ef06d02331b5291c9f3056077bcf38ce37d9e File name: exe3.exe File size: 117,561 bytes File descripti | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 8e210658f17a265f0c595b4f63ee7ba3db4c83f64c93f522e74e57e6fc547b11 | /wrapper/counter/1.htm Associated file hashes: SHA256 hash: 8e210658f17a265f0c595b4f63ee7ba3db4c83f64c93f522e74e57e6fc547b11 File name: plugin.exe File size: 149,346 bytes File descrip | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a1670db6204f7666ad246cc11736b052713a4413663f5cbe6aec90ab299431a7 | in.zip from tramplin.online[.]ru on April 13th SHA256 hash: a1670db6204f7666ad246cc11736b052713a4413663f5cbe6aec90ab299431a7 File name: plugin.js File size: 1,537 bytes File descriptio | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b2dfa063fa605d942822cc84ef90419e26cfa0030444751fc2b87f1456b72e30 | malware retrieved by plugin.js on April 13th) SHA256 hash: b2dfa063fa605d942822cc84ef90419e26cfa0030444751fc2b87f1456b72e30 File name: exe2.exe File size: 363,922 bytes File descripti | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b36a3a9e2b9129cbe7385c97fa24666d2d086f7bb8a3c9c4e019f14a41538be0 | omware from thru Google Docs URL on April 12th SHA256 hash: b36a3a9e2b9129cbe7385c97fa24666d2d086f7bb8a3c9c4e019f14a41538be0 File name: plugin.js File size: 1,369 bytes File descriptio | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | ba1327106fa0bf82050cf1a1b9c0c119eb0ded63931af4127e5d541dfa2c6850 | malware retrieved by plugin.js on April 14th) SHA256 hash: ba1327106fa0bf82050cf1a1b9c0c119eb0ded63931af4127e5d541dfa2c6850 File name: exe3.exe File size: 221,974 bytes File descripti | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d9189f6df89acf8e2f0d689ab73429cde37f974ed423f91d1bcabfe5dda700fa | malware retrieved by plugin.js on April 14th) SHA256 hash: d9189f6df89acf8e2f0d689ab73429cde37f974ed423f91d1bcabfe5dda700fa File name: exe2.exe File size: 366,249 bytes File descripti | Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | here.jninmobilaria.com | .101.8.169 Nuclear EK domains: lotos.castrumtelcom.com.br , here.jninmobilaria.com.ar Follow-up malware IP address: 46.148.20.32 Follow-up mal | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | js.cefora.com | malware IP address: 46.148.20.32 Follow-up malware domain: js.cefora.com.ar IP addresses from post-infection traffic caused by Locky | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | lotos.castrumtelcom.com.br | .np Nuclear EK IP address: 46.101.8.169 Nuclear EK domains: lotos.castrumtelcom.com.br , here.jninmobilaria.com.ar Follow-up malware IP address: 4 | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sed.poudelkamal.com | and 2016-03-16 Gate IP address: 91.195.12.177 Gate domain: sed.poudelkamal.com.np Nuclear EK IP address: 46.101.8.169 Nuclear EK domains: | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 149.202.109.205 | Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: Description: 2016-03-15 Nuclear | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 46.101.8.169 | Gate domain: sed.poudelkamal.com.np Nuclear EK IP address: 46.101.8.169 Nuclear EK domains: lotos.castrumtelcom.com.br , here.jninm | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 46.148.20.32 | r , here.jninmobilaria.com.ar Follow-up malware IP address: 46.148.20.32 Follow-up malware domain: js.cefora.com.ar IP addresses fro | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 51.254.181.122 | ses from post-infection traffic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malw | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 51.255.107.8 | nfection traffic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: De | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 78.40.108.39 | fic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: Description: 20 | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 91.195.12.177 | Date/time range: 2016-03-15 and 2016-03-16 Gate IP address: 91.195.12.177 Gate domain: sed.poudelkamal.com.np Nuclear EK IP address: | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 4228036684f4f519704a102cd9322ac9edb1bfb5b20558a7a6873818f0e6a7b4 | scription: 2016-03-16 Nuclear EK Flash exploit SHA256 hash: 4228036684f4f519704a102cd9322ac9edb1bfb5b20558a7a6873818f0e6a7b4 Description: 2016-03-15 Nuclear EK payload - Locky ransomwa | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 94bd74514cc9e579edf55dd1bac653ceca1837d930d109c6e701afe309b23310 | scription: 2016-03-15 Nuclear EK Flash exploit SHA256 hash: 94bd74514cc9e579edf55dd1bac653ceca1837d930d109c6e701afe309b23310 Description: 2016-03-16 Nuclear EK Flash exploit SHA256 has | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a9dac0a0389c463b063cb30f647b3d1610e6052570efe2dfb1fca749d8f039fc | ayload - file that downloaded Locky ransomware SHA256 hash: a9dac0a0389c463b063cb30f647b3d1610e6052570efe2dfb1fca749d8f039fc Description: Locky ransomware downloaded by Nuclear EK payl | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | cc2355cc6d265cd90b71282980abcf0a7f3dcb3a608a5c98e7697598696481af | re downloaded by Nuclear EK payload (soft.exe) SHA256 hash: cc2355cc6d265cd90b71282980abcf0a7f3dcb3a608a5c98e7697598696481af | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | faf4f689683f3347738ef0a8370a78d504b513d44f3a70f833c50de3d138c3b2 | 16-03-15 Nuclear EK payload - Locky ransomware SHA256 hash: faf4f689683f3347738ef0a8370a78d504b513d44f3a70f833c50de3d138c3b2 Description: 2016-03-16 Nuclear EK payload - file that down | Locky Ransomware Installed Through Nuclear EK Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ddns.net | leech pattern was pointing to No-IP.com domains (hopto.org, ddns.net, myftp.biz, serveftp.com, etc). These No-IP domains were ei | Campaign Evolution: Darkleech to Pseudo Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | hopto.org | e same Darkleech pattern was pointing to No-IP.com domains (hopto.org, ddns.net, myftp.biz, serveftp.com, etc). These No-IP domai | Campaign Evolution: Darkleech to Pseudo Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | myftp.biz | ern was pointing to No-IP.com domains (hopto.org, ddns.net, myftp.biz, serveftp.com, etc). These No-IP domains were either gates | Campaign Evolution: Darkleech to Pseudo Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | no-ip.com | . By early 2014, the same Darkleech pattern was pointing to No-IP.com domains (hopto.org, ddns.net, myftp.biz, serveftp.com, etc) | Campaign Evolution: Darkleech to Pseudo Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | serveftp.com | nting to No-IP.com domains (hopto.org, ddns.net, myftp.biz, serveftp.com, etc). These No-IP domains were either gates to an EK, or t | Campaign Evolution: Darkleech to Pseudo Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 104.129.198.32 | r their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 194.165.16.202 | 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016- | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 194.165.16.203 | 6-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016- | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 194.165.16.204 | 8-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016- | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 31.184.192.188 | 9-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 31.184.193.168 | 9-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 31.184.193.187 | 9-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.110 | 3 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016- | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.12 | 1 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.13 | 2 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09- | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.32 | ly reappeared well after their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-1 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.33 | 15-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.34 | 16-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.43 | 8 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.68 | 2 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.72 | 4 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 85.93.0.81 | 3 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 8 | EITest Campaign Evolution: From Angler EK to Neutrino and Rig Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | aba98.com | 85.93.0[.]33 - mvcvideo[.]tk 2016-03-14: 85.93.0[.]33 - bab.aba98[.]com 2016-03-29: 85.93.0[.]34 - folesd[.]tk When we first noti | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bobibo.tk | 85.93.0[.]32 - feedero[.]tk 2016-01-25: 85.93.0[.]32 - www.bobibo[.]tk 2016-01-26: 85.93.0[.]32 - en.robertkuzma[.]com 2016-02-0 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | co.uk | st gate URL 2014-09-22: 148.251.56[.]156 - flv.79highstreet.co[.]uk 2014-10-02: 148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 19 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | dofned.tk | 2-03: 85.93.0[.]32 - vyetbr[.]tk 2016-02-10: 85.93.0[.]32 - dofned[.]tk 2016-02-15: 85.93.0[.]32 - zeboms[.]tk 2016-02-18: 85.93. | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | feedero.tk | 31.184.192[.]206 - vecexeze[.]tk 2016-01-19: 85.93.0[.]32 - feedero[.]tk 2016-01-25: 85.93.0[.]32 - www.bobibo[.]tk 2016-01-26: 85 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | fix-mo.tk | 6 - flv.79highstreet.co[.]uk 2014-10-02: 148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 194.15.126[.]7 - joans[.]ga 2015-11-10: 31.18 | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | folesd.tk | : 85.93.0[.]33 - bab.aba98[.]com 2016-03-29: 85.93.0[.]34 - folesd[.]tk When we first noticed the EITest gate in September 2014, | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | joans.ga | 148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 194.15.126[.]7 - joans[.]ga 2015-11-10: 31.184.192[.]206 - ymest[.]ml 2015-12-04: 31. | How the EITest Campaign's Path to Angler EK Evolved Over Time Palo Alto Unit 42 | · Aug 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.