ZeroHour

Indicators of compromise

4,235 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha256ab54af1dbe6a82488db161a7f57cd74f2dd282a9522587f18313b4e9835dc55827a21a95ea2a6136c264c6a6cc2f0910a24881118b6eabc2d6509dc8dd7 ab54af1dbe6a82488db161a7f57cd74f2dd282a9522587f18313b4e9835dc558 3cef0b5f069cc1d15d36aa83d54d2a7be79b29b02081b6592dd4714639aStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256ab9d8f1021f2a99c74aa66f8ddb52996ac2337da9de2676d090b87e19ce93033hell. SHA256 Family Callback Function Called By UUID Format ab9d8f1021f2a99c74aa66f8ddb52996ac2337da9de2676d090b87e19ce93033 ToneShell EnumSystemLocalesA ASCII cf61b7a9bdde2a39156d88f3Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256b382cc85eee95a620fc11370309ff76de9a3bcaefb645790434d8251a3b9fce1orm samples, we found a variant of the ToneShell backdoor ( b382cc85eee95a620fc11370309ff76de9a3bcaefb645790434d8251a3b9fce1 ) that had the same debug symbol path as the Bookworm loadeStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256b7e042d2accdf4a488c3cd46ccd95d6ad5b5a8be71b5d6d76b8046f17debaa18lated to PubLoad Using V6-winsp1-wuredir SHA256 Filename C2 b7e042d2accdf4a488c3cd46ccd95d6ad5b5a8be71b5d6d76b8046f17debaa18 analysis of the third meeting of ndsc.zip 123.253.32[.]15 4Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256bbf12ee2cd71dbcf2948adf64f354ad7c69d6b6ff0b78ea76b3df2d02b08ed0fdf154bb60fcf24d0ab5297d0c6beaca0f Leader.dll Leader.dll 0x0 bbf12ee2cd71dbcf2948adf64f354ad7c69d6b6ff0b78ea76b3df2d02b08ed0f dafdsafdsaa3 Resolver.dll 0x1 fa739724a4b6f7a766a2d7695d7daStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256cf61b7a9bdde2a39156d88f309f230a7d44e9feaf0359947e1f96e069eca4e86Compiled SHA256 Filename Debug Symbol Path C2 Dec. 23, 2021 cf61b7a9bdde2a39156d88f309f230a7d44e9feaf0359947e1f96e069eca4e86 anhlab.exe C:\Users\hack\Desktop\uuid\uu\Release\uu.pdb wwwStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256d7dbfb2b755418842fea4fca5628f0b36bbd128a71ddcd858b4b3c67ba78f516ac834672c1b544dd555c93600a637 fjdasljguafa KBLogger.dll 0x5 d7dbfb2b755418842fea4fca5628f0b36bbd128a71ddcd858b4b3c67ba78f516 Coder.dll Coder.dll 0xA 6804b10aefe8fdb2b33ecf3bc5a93f49413Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256da8ef50fe5e571d0143a758c7c66bb55653f1f2d04f16464fc857226441d79b2a725adc57d7b501f33e87230a8291cf8ad22d4d3a830293abcc0ac10d12 da8ef50fe5e571d0143a758c7c66bb55653f1f2d04f16464fc857226441d79b2 f0df09513dcf292264b3336269952c7e9ff685df8180a2035bee9f3143bStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256dcc349a1b624f6b949f181a7dd859a82715b4d3b6c37c7e5be1b729cd8e6f01f0820948d5d2ca4c192fac8b1ede91c2 yyrtytr.565 Network.dll 0xE dcc349a1b624f6b949f181a7dd859a82715b4d3b6c37c7e5be1b729cd8e6f01f feareade HTTP.dll 0x13 51bf329ba04a042789bad3b395092488a3d8Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256f0df09513dcf292264b3336269952c7e9ff685df8180a2035bee9f3143b3660950fe5e571d0143a758c7c66bb55653f1f2d04f16464fc857226441d79b2 f0df09513dcf292264b3336269952c7e9ff685df8180a2035bee9f3143b36609 Bookworm Modules SHA256 Module fa739724a4b6f7a766a2d7695d7dStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256f7b024196ac50bd0f7ed362a532e83edf154bb60fcf24d0ab5297d0c6beaca0frrent Module Name Related Bookworm Module Current Module ID f7b024196ac50bd0f7ed362a532e83edf154bb60fcf24d0ab5297d0c6beaca0f Leader.dll Leader.dll 0x0 bbf12ee2cd71dbcf2948adf64f354ad7cStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256fa739724a4b6f7a766a2d7695d7da7b33a6ac834672c1b544dd555c93600a637d6b6ff0b78ea76b3df2d02b08ed0f dafdsafdsaa3 Resolver.dll 0x1 fa739724a4b6f7a766a2d7695d7da7b33a6ac834672c1b544dd555c93600a637 fjdasljguafa KBLogger.dll 0x5 d7dbfb2b755418842fea4fca5628fStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256fb25a69ffc18b79ee664462e0717cf5e70820948d5d2ca4c192fac8b1ede91c2c6639eae65900cb2ea26911540a77d1f9b7acf6 AES.dll AES.dll 0xC fb25a69ffc18b79ee664462e0717cf5e70820948d5d2ca4c192fac8b1ede91c2 yyrtytr.565 Network.dll 0xE dcc349a1b624f6b949f181a7dd859a8Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256fbc67446daaa0a0264ed7a252ab42413d6a43c2e5ab43437c2b3272daec85e81DIS13n\Release\LTDIS13n.pdb www.fjke5oe[.]com Oct. 26, 2022 fbc67446daaa0a0264ed7a252ab42413d6a43c2e5ab43437c2b3272daec85e81 ltdis13n.dll C:\Users\hack\Documents\WhiteFile\LTDIS13n\RelStately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
sha256fdad627a21a95ea2a6136c264c6a6cc2f0910a24881118b6eabc2d6509dc8dd7da41cb509412ee230c6d7aac3d69361358b28c3a09ec851d3c0f3853326 fdad627a21a95ea2a6136c264c6a6cc2f0910a24881118b6eabc2d6509dc8dd7 ab54af1dbe6a82488db161a7f57cd74f2dd282a9522587f18313b4e9835Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
Palo Alto Unit 42
· Aug 17, 2026
domainadibas.topollowing list shows each domain followed by its IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergo"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainastrovoerta.topiuj[.]top - 46.173.219.161 suzemodels[.]top - 35.163.101.72 astrovoerta[.]top - 185.159.130.89 zofelaseo[.]top - 35.163.101.72 These do"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainfootarepu.topn followed by its IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 gunterg"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainguntergoner.topibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-te"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainibm-technoligi.toper[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polki"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainpolkiuj.topi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.161 suzemodel"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainsuzemodels.toplkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.161 suzemodels[.]top - 35.163.101.72 astrovoerta[.]top - 185.159.130.89 zofela"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainzofelaseo.topls[.]top - 35.163.101.72 astrovoerta[.]top - 185.159.130.89 zofelaseo[.]top - 35.163.101.72 These domain names were registered a day"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
ipv4185.159.130.896.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top -"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
ipv435.163.101.72219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 3"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
ipv435.165.251.242 guntergoner[.]top - 185.159.130.89 ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165."Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
ipv435.165.251.241.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.161 suzemodels[.]top - 35.163.10"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
ipv435.165.86.173IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163.101.72 guntergoner[.]top - 185.1"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
ipv446.173.219.161hows each domain followed by its IP address. adibas[.]top - 46.173.219.161 footarepu[.]top - 35.165.86.173 guntergoner[.]top - 35.163."Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
ipv462.109.29.26ibm-technoligi[.]top - 35.165.251.24 ibm-technoligi[.]top - 62.109.29.26 polkiuj[.]top - 35.165.251.241 polkiuj[.]top - 46.173.219.1"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware
Palo Alto Unit 42
· Aug 17, 2026
domainalita.kzugin.zip Examples for start of URLs generated by plugin.js: alita[.]kz/tmp/installation/language/cs-CZ/counter/ avtotur.com/librMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domainanilstone.ir/woorutu63408454 Links from the emails on Friday, April 14: anilstone[.]ir/libraries/joomla/string/wrapper/counter/1.htm AssociatedMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domainbel.tramples of fake Microsoft Microsoft Word Online pages: posof.bel[.]tr/counter/1.htm tramplinonline[.]ru/counter/1.htm mattsfotoMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domainboorsemsport.beom/libraries/fof/utils/ip/counter/ circus-stroy.ru/counter/ boorsemsport[.]be/templates/yoo_aurora/less/uikit/counter/ eurostandard[.]rMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domaineurostandard.roboorsemsport[.]be/templates/yoo_aurora/less/uikit/counter/ eurostandard[.]ro/pics/size1/counter/ forum-turism.org[.]ro/images/layout/cMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domainglochemindia.comsize1/counter/ forum-turism.org[.]ro/images/layout/counter/ glochemindia[.]com/modules/mod_roknavmenu/lib/librokmenu/counter/ sportbelijMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domainideliverys.coms from the emails on Wednesday, April 12: uspsaeyyuia158140.ideliverys[.]com/ioxoory254772 uspsbhusisoz75.ideliverys[.]com/aagupto83 uMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domainmaildeliverys.coms from the emails on Thursday, April 13: aexhnneq102342usps.maildeliverys[.]com/kovcemaw707572 bdguz0371usps.maildeliverys[.]com/usvyneyeMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domainmattsfotoalbum.de: 1,537 bytes File description: Contents of plugin.zip from mattsfotoalbum[.]de on April 13th SHA256 hash: 40e8dc147f189baf4660d5db8e0cd1Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domainonline.ruytes File description: Contents of plugin.zip from tramplin.online[.]ru on April 13th SHA256 hash: a1670db6204f7666ad246cc11736b0Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domainorg.rocounter/ eurostandard[.]ro/pics/size1/counter/ forum-turism.org[.]ro/images/layout/counter/ glochemindia[.]com/modules/mod_rokMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domainsportbelijning.bemindia[.]com/modules/mod_roknavmenu/lib/librokmenu/counter/ sportbelijning[.]be/libraries/joomla/application/web/counter/Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domaintramplinonline.rut Microsoft Word Online pages: posof.bel[.]tr/counter/1.htm tramplinonline[.]ru/counter/1.htm mattsfotoalbum[.]de/cache/counter/1.htm aniMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
sha2563b5b19ebe8d8b6c7e5b2ffd2cc194fad1ae6c9eade7646f48c595bd154f4b1e1f plugin.zip from anilstone[.]ir on April 14th SHA256 hash: 3b5b19ebe8d8b6c7e5b2ffd2cc194fad1ae6c9eade7646f48c595bd154f4b1e1 File name: exe1.exe File size: 85,504 bytes File descriptioMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
sha25640e8dc147f189baf4660d5db8e0cd1c647c7f167f7176c5d8ee03b6cac26fed2gin.zip from mattsfotoalbum[.]de on April 13th SHA256 hash: 40e8dc147f189baf4660d5db8e0cd1c647c7f167f7176c5d8ee03b6cac26fed2 File name: plugin.js File size: 1,382 bytes File descriptioMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
sha25641f171eb916d555dc7771ce71013572c498b8d620d2f72872c4b2f3b50c7ccb1malware retrieved by plugin.js on April 13th) SHA256 hash: 41f171eb916d555dc7771ce71013572c498b8d620d2f72872c4b2f3b50c7ccb1 File name: exe2.exe File size: 363,728 bytes File descriptiMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
sha25650117ce3fe5dba572cf23584dc7541a7cfd4026d4316e69d29cdf536873fdf20malware retrieved by plugin.js on April 13th) SHA256 hash: 50117ce3fe5dba572cf23584dc7541a7cfd4026d4316e69d29cdf536873fdf20 File name: exe1.exe File size: 91,136 bytes File descriptioMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
sha2565459be968e2296a759dcafa7107ef06d02331b5291c9f3056077bcf38ce37d9emalware retrieved by plugin.js on April 13th) SHA256 hash: 5459be968e2296a759dcafa7107ef06d02331b5291c9f3056077bcf38ce37d9e File name: exe3.exe File size: 117,561 bytes File descriptiMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
sha2568e210658f17a265f0c595b4f63ee7ba3db4c83f64c93f522e74e57e6fc547b11/wrapper/counter/1.htm Associated file hashes: SHA256 hash: 8e210658f17a265f0c595b4f63ee7ba3db4c83f64c93f522e74e57e6fc547b11 File name: plugin.exe File size: 149,346 bytes File descripMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
sha256a1670db6204f7666ad246cc11736b052713a4413663f5cbe6aec90ab299431a7in.zip from tramplin.online[.]ru on April 13th SHA256 hash: a1670db6204f7666ad246cc11736b052713a4413663f5cbe6aec90ab299431a7 File name: plugin.js File size: 1,537 bytes File descriptioMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
sha256b2dfa063fa605d942822cc84ef90419e26cfa0030444751fc2b87f1456b72e30malware retrieved by plugin.js on April 13th) SHA256 hash: b2dfa063fa605d942822cc84ef90419e26cfa0030444751fc2b87f1456b72e30 File name: exe2.exe File size: 363,922 bytes File descriptiMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
sha256b36a3a9e2b9129cbe7385c97fa24666d2d086f7bb8a3c9c4e019f14a41538be0omware from thru Google Docs URL on April 12th SHA256 hash: b36a3a9e2b9129cbe7385c97fa24666d2d086f7bb8a3c9c4e019f14a41538be0 File name: plugin.js File size: 1,369 bytes File descriptioMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
sha256ba1327106fa0bf82050cf1a1b9c0c119eb0ded63931af4127e5d541dfa2c6850malware retrieved by plugin.js on April 14th) SHA256 hash: ba1327106fa0bf82050cf1a1b9c0c119eb0ded63931af4127e5d541dfa2c6850 File name: exe3.exe File size: 221,974 bytes File descriptiMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
sha256d9189f6df89acf8e2f0d689ab73429cde37f974ed423f91d1bcabfe5dda700famalware retrieved by plugin.js on April 14th) SHA256 hash: d9189f6df89acf8e2f0d689ab73429cde37f974ed423f91d1bcabfe5dda700fa File name: exe2.exe File size: 366,249 bytes File descriptiMole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics
Palo Alto Unit 42
· Aug 17, 2026
domainhere.jninmobilaria.com.101.8.169 Nuclear EK domains: lotos.castrumtelcom.com.br , here.jninmobilaria.com.ar Follow-up malware IP address: 46.148.20.32 Follow-up malLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
domainjs.cefora.commalware IP address: 46.148.20.32 Follow-up malware domain: js.cefora.com.ar IP addresses from post-infection traffic caused by LockyLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
domainlotos.castrumtelcom.com.br.np Nuclear EK IP address: 46.101.8.169 Nuclear EK domains: lotos.castrumtelcom.com.br , here.jninmobilaria.com.ar Follow-up malware IP address: 4Locky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
domainsed.poudelkamal.comand 2016-03-16 Gate IP address: 91.195.12.177 Gate domain: sed.poudelkamal.com.np Nuclear EK IP address: 46.101.8.169 Nuclear EK domains:Locky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
ipv4149.202.109.205Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: Description: 2016-03-15 NuclearLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
ipv446.101.8.169Gate domain: sed.poudelkamal.com.np Nuclear EK IP address: 46.101.8.169 Nuclear EK domains: lotos.castrumtelcom.com.br , here.jninmLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
ipv446.148.20.32r , here.jninmobilaria.com.ar Follow-up malware IP address: 46.148.20.32 Follow-up malware domain: js.cefora.com.ar IP addresses froLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
ipv451.254.181.122ses from post-infection traffic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malwLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
ipv451.255.107.8nfection traffic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: DeLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
ipv478.40.108.39fic caused by Locky ransomware: 51.254.181.122 51.255.107.8 78.40.108.39 149.202.109.205 Exploits and malware noted: Description: 20Locky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
ipv491.195.12.177Date/time range: 2016-03-15 and 2016-03-16 Gate IP address: 91.195.12.177 Gate domain: sed.poudelkamal.com.np Nuclear EK IP address:Locky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
sha2564228036684f4f519704a102cd9322ac9edb1bfb5b20558a7a6873818f0e6a7b4scription: 2016-03-16 Nuclear EK Flash exploit SHA256 hash: 4228036684f4f519704a102cd9322ac9edb1bfb5b20558a7a6873818f0e6a7b4 Description: 2016-03-15 Nuclear EK payload - Locky ransomwaLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
sha25694bd74514cc9e579edf55dd1bac653ceca1837d930d109c6e701afe309b23310scription: 2016-03-15 Nuclear EK Flash exploit SHA256 hash: 94bd74514cc9e579edf55dd1bac653ceca1837d930d109c6e701afe309b23310 Description: 2016-03-16 Nuclear EK Flash exploit SHA256 hasLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
sha256a9dac0a0389c463b063cb30f647b3d1610e6052570efe2dfb1fca749d8f039fcayload - file that downloaded Locky ransomware SHA256 hash: a9dac0a0389c463b063cb30f647b3d1610e6052570efe2dfb1fca749d8f039fc Description: Locky ransomware downloaded by Nuclear EK paylLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
sha256cc2355cc6d265cd90b71282980abcf0a7f3dcb3a608a5c98e7697598696481afre downloaded by Nuclear EK payload (soft.exe) SHA256 hash: cc2355cc6d265cd90b71282980abcf0a7f3dcb3a608a5c98e7697598696481afLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
sha256faf4f689683f3347738ef0a8370a78d504b513d44f3a70f833c50de3d138c3b216-03-15 Nuclear EK payload - Locky ransomware SHA256 hash: faf4f689683f3347738ef0a8370a78d504b513d44f3a70f833c50de3d138c3b2 Description: 2016-03-16 Nuclear EK payload - file that downLocky Ransomware Installed Through Nuclear EK
Palo Alto Unit 42
· Aug 17, 2026
domainddns.netleech pattern was pointing to No-IP.com domains (hopto.org, ddns.net, myftp.biz, serveftp.com, etc). These No-IP domains were eiCampaign Evolution: Darkleech to Pseudo
Palo Alto Unit 42
· Aug 17, 2026
domainhopto.orge same Darkleech pattern was pointing to No-IP.com domains (hopto.org, ddns.net, myftp.biz, serveftp.com, etc). These No-IP domaiCampaign Evolution: Darkleech to Pseudo
Palo Alto Unit 42
· Aug 17, 2026
domainmyftp.bizern was pointing to No-IP.com domains (hopto.org, ddns.net, myftp.biz, serveftp.com, etc). These No-IP domains were either gatesCampaign Evolution: Darkleech to Pseudo
Palo Alto Unit 42
· Aug 17, 2026
domainno-ip.com. By early 2014, the same Darkleech pattern was pointing to No-IP.com domains (hopto.org, ddns.net, myftp.biz, serveftp.com, etc)Campaign Evolution: Darkleech to Pseudo
Palo Alto Unit 42
· Aug 17, 2026
domainserveftp.comnting to No-IP.com domains (hopto.org, ddns.net, myftp.biz, serveftp.com, etc). These No-IP domains were either gates to an EK, or tCampaign Evolution: Darkleech to Pseudo
Palo Alto Unit 42
· Aug 17, 2026
ipv4104.129.198.32r their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv4194.165.16.2022016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv4194.165.16.2036-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv4194.165.16.2048-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv431.184.192.1889-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv431.184.193.1689-01: 194.165.16.203 2016-09-02: 194.165.16.204 2016-09-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv431.184.193.1879-08: 31.184.193.168 2016-09-14: 31.184.192.188 2016-09-19: 31.184.193.187EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.1103 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-01: 194.165.16.203 2016-EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.121 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30:EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.132 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 85.93.0.110 2016-08-30: 194.165.16.202 2016-09-EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.32ly reappeared well after their first seen date. 2015-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-1EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.3315-12-29: 85.93.0.32 2016-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.3416-02-03: 104.129.198.32 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.438 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 85.93.0.13 2016-08-25: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.682 2016-02-24: 85.93.0.33 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.724 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 85.93.0.12 2016-08-17: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
ipv485.93.0.813 2016-03-16: 85.93.0.34 2016-04-01: 85.93.0.68 2016-05-18: 85.93.0.81 2016-06-06: 85.93.0.72 2016-06-11: 85.93.0.43 2016-07-18: 8EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Palo Alto Unit 42
· Aug 17, 2026
domainaba98.com85.93.0[.]33 - mvcvideo[.]tk 2016-03-14: 85.93.0[.]33 - bab.aba98[.]com 2016-03-29: 85.93.0[.]34 - folesd[.]tk When we first notiHow the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainbobibo.tk85.93.0[.]32 - feedero[.]tk 2016-01-25: 85.93.0[.]32 - www.bobibo[.]tk 2016-01-26: 85.93.0[.]32 - en.robertkuzma[.]com 2016-02-0How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainco.ukst gate URL 2014-09-22: 148.251.56[.]156 - flv.79highstreet.co[.]uk 2014-10-02: 148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 19How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domaindofned.tk2-03: 85.93.0[.]32 - vyetbr[.]tk 2016-02-10: 85.93.0[.]32 - dofned[.]tk 2016-02-15: 85.93.0[.]32 - zeboms[.]tk 2016-02-18: 85.93.How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainfeedero.tk31.184.192[.]206 - vecexeze[.]tk 2016-01-19: 85.93.0[.]32 - feedero[.]tk 2016-01-25: 85.93.0[.]32 - www.bobibo[.]tk 2016-01-26: 85How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainfix-mo.tk6 - flv.79highstreet.co[.]uk 2014-10-02: 148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 194.15.126[.]7 - joans[.]ga 2015-11-10: 31.18How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainfolesd.tk: 85.93.0[.]33 - bab.aba98[.]com 2016-03-29: 85.93.0[.]34 - folesd[.]tk When we first noticed the EITest gate in September 2014,How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026
domainjoans.ga148.251.56[.]156 - fix-mo[.]tk 2015-06-08: 194.15.126[.]7 - joans[.]ga 2015-11-10: 31.184.192[.]206 - ymest[.]ml 2015-12-04: 31.How the EITest Campaign's Path to Angler EK Evolved Over Time
Palo Alto Unit 42
· Aug 17, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.