IOC Radar
SHA256HighVerifiedSignal 82/100

69bf0bc46f51b33377c4f3d92caf876714f6bbbe99e7544487327920873f9820

Location
SpainSpain
First Seen
Mar 6, 2025
Last Seen
May 25, 2026
Mar 6
First Seen
484d ago
May 25
Last Seen
38d ago
5
Reports
source reports
82%
Confidence
high
Found in 5 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
SHA-256 Hash
SHA-256 file hash — primary identifier for malware samples.
MISP Category
Artifacts Dropped
Hash Algorithm
SHA256
Confidence
82%
Signal Score
82 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

47 techniques

Feed Intelligence Summary

5 reports82% confidence
5
Source reports
82%
Confidence score
Category tags
abuseaccount securityactive scanadobe readeradres urlakamaialienvault_ransomwareapk nazwaappleasciiascii textasiaauthority keybad reputationbin neutralbloat-abotnetbotnet activitybrute forcebypassca emitentcanadacertumcertum cacertum poziomcertum trustedcheckschinachromechrome cachecisacode injectioncommandcommand and controlcontactcontrolcredential harvestingcredential stuffingcrlcrlfcvesdata encryptiondata exfiltrationdata rtstringdata store exposureddosdigital signaturedistributed attacksdns attackdocelowa wersjadonutloaderdowiedz sidziennik zdarzeencryptionenterprise securityentityentryeuropeexecutable fileexploit scriptexploitation activityextortionfile-hashformatformat czcionkifrenchgithubgovernment websitesguidgwnahashhistorycznehrefyhttpsonlymodeidentifier ididentity & access exploitationindicatorinfostealeringress tool transferinjection activityissuer certumitalianja3sjapankazak defaultknowledge baseksigi wieczysteloaderloginmagia webmalicious softwaremalwaremalware signingmd5meduza stealermobile threatmozillanazwa certumnazwa hostanetpbm pamnetwork canetwork infonetwork trafficneutralnieruchomoci inorth americanumernumer seryjnyodciskopen fontopen threatoperating system securitypasswordpatch managementpdfpdf documentpdfkitpdfkit rubypdfspe filepeexepeexe cpeexe sha256performs dnsphishingplansplikpoczenie zpomoc dlapozycja akamaipricing blogprocess injectionprofil zaufanyprotocol-devipythonraidransomwareremote accessremote coderemote servicesrep domainresearchedrespondedrticon neutralseoseobility ohsocial engineeringsoftware integritysoftware vulnerabilitiesspainssdeepstartstealerstronastudiumsystem disruptiont1010t1012 queryt1018t1021t1027t1036t1041t1047t1055t1056t1057t1059.007t1070t1071t1071.001t1078t1082t1082 systemt1083t1095t1105t1140t1190t1203t1204.001t1204.002t1218t1486t1490t1496t1497t1499.002t1499.003t1518t1539t1547t1554.001t1554.003t1560t1562t1565t1566t1566.001t1566.002t1566.003t1566.004t1571t1573t1574tabna stronietabtretask schedulertekst unicodetexttext ctoolstor nodetrojantrojan malwaretrusted networkturkish defaulttworzy pliktworzy plikityp androidatyp plikuunicordevunited statesunizetourlsurls httpustaw dostpusugi dlavalidvalid fromvalid usagevhashvistavulnerability scanw32.bloat-awanewannacryweb crawlingweb exploitationwebkitwebkit bugwelcomewersjawhaszwhasz htmwhoiswin32 malwarewindows malwarewipeswpiswpis pamicixml externalxworm:yandexzakotwicz hrefyzmian plkontaktzwizane z

Activity Timeline

1 total obs
May 25May 25

Threat Activity Heatmap

· Peak: 2026-05-25
Less
More
Mon
Wed
Fri
Jun
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreHigh Risk
82
SIGNAL
Signal Score
82%
Confidence
5
Reports
First seenMar 6, 2025
Last seenMay 25, 2026
Verified IOC

VirusTotal

Not checked

WHOIS

description
ASCII text, with no line terminators
references
Conversely, Port 443 remains accessible, serving a WordPress-based interface backed by a freshly issued Google Trust Services certificate (Feb 4, 2026). This asymmetric configuration ensures that the structurally invalid X.509 "Broken Seal" is only delivered via encrypted channels, while the gated Port 80 tier prevents the discovery of the underlying Zeppelin/Bloat-A redirection logic by non-human-interacted sessions., Imphash: 9698f46495ce9401c8bcaf9a2afe1598 | Imports (additional): GdipSetSmoothingMode, I_UuidCreate, RpcStringFreeW, UuidCreate, UuidToStringW, InternetCheckConnectionW | Resource: RT_MANIFEST (1, ENGLISH US, SHA-256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df, XML, entropy 4.91), Observed hosting and routing telemetry indicates the delivery infrastructure is operating through AS209242 (Cloudflare London LLC), suggesting the actor is leveraging Cloudflare’s transit layer for resilience and to reduce direct exposure of origin infrastructure., Research into the gogetlife.co telemetry confirms a dual-port obfuscation strategy designed to bypass multi-layer security indexing. Forensic HTTP scans identify a Port 80 "Fail-Closed" state, where standard web traffic is gated by a Cloudflare-managed 403 Forbidden challenge, effectively neutralizing automated crawlers. Conversely, Port 443 remains accessible, serving a WordPress-based interface backed by a freshly issued Google Trust Services certificate (Feb 4, 2026). This asymmetric configuration ensure, Compilation / Toolchain Compiler: Microsoft Visual C++ 2017 Linker: Microsoft Linker 14.16.27032 IDE: Visual Studio 2017 (15.9) Classification: PEBIN TrID: Win64 EXE (32.2%) / Win32 DLL (20.1%) / Win16 NE (15.4%) PE Section Entropy (Suspicion): .data 7.36 → high (suggests packing/encryption), .reloc 6.66 → possible runtime modification, .text 6.01, .rdata 5.88, .rsrc 4.72 Imports (Capabilities): CreateRemoteThread, CreateThread, ExitProcess, Broken Seal exploitation: The invalid X.509 seal appears engineered to exploit verification logic gaps, forcing fail-open behavior and allowing SEG bypass under certain configurations. Human-gated delivery posture: Cloudflare 403 challenges suggest the actor enforces human interaction before payload delivery, reducing automated discovery and sandbox analysis. Industrialized infrastructure: Correlation across thousands of domains and URLs indicates a highly automated, rotating delivery ecosystem., MITRE ATT&CK: Process Hollowing (T1055.012): Documentation on the RunPE injection method used by the payload to achieve a fileless state in RWX memory. RFC 5652 - Cryptographic Message Syntax (CMS): This standard defines the structure of the digital signatures that this campaign's "Broken Seal" exploit bypasses., As of Feb 13 (early AM) — Indicators of Compromise: 17K | Types: Email (30), FileHash-SHA256 (2,146), URL (8,070), Hostname (2,755), Domain (3,528), Other (1,110) | Geo: US (233), Canada (15), China (10), Japan (2), Spain (2), Other (13), Verification failure observed in automated verification handlers during sandbox replay., The payload (SHA256: dfff54...4af) achieves a fileless execution state via Process Hollowing (RunPE), injecting into RWX memory regions of legitimate system processes to evade disk-based EDR telemetry. Anti-analysis controls—including Bochs artifact checks, geofencing logic, and direct CPU clock interrogation—are implemented to validate a high-interaction user environment prior to execution., Multiple antivirus engines flagged the sample with generic heuristic names (e.g., Trojan:Win32/Vigorf.A, Win32:Malware-gen, Trojan.Generic), consistent with multi-engine heuristic detection on VirusTotal., Malicious sample (SHA256: fa8e2ddfe42e77a9771a7c4d6421c7a808cf4508f8cd6dc6f4cf8bd4e2ae7f8f) detected as TrojanDownloader:Win32/Tugspay.A with YARA hits for Win32_PUA_Domaiq, aPLib, PECompact_2xx and IDS alerts including TLS Handshake Failure + 403 Forbidden, contacting 36 domains (e.g., api.123mediaplayer.com, static.sslsecure1.com) and IPs such as 104.18.23.19 and 193.166.255.171., SHA256 3d10374b55a18a2dd90d35d28472600496c680a7efab4e772595f735cb062343 identified as Win.Malware.Vtflooder-9783271-0 / Trojan:Win32/Vflooder.B with UPX/Nrv2x packing YARA hits, IDS detections for Win32/Vflooder.B check-in and DOS behavior, and network C2 indicators including 172.66.0.227 and 34.54.88.138., SHA-256: fc1fedce1419d4e2009828aad8644deca78b4eeed176e5b009797e0eb0d7d3ff — Detected as Win.Malware.Vtflooder / Trojan:Win32/Vflooder; UPX-packed PE32 executable, with 812 IDS hits (including C2 checkin + HTTP EXE upload)., nationalgrid.com — Whitelisted domain (US, AS13335 Cloudflare) with 500+ passive DNS entries, 692 URLs, 195 subdomains, and 2 malicious files hosted on IP 104.17.1.192, which is concerning given the infrastructure and trust level., eversource.com (IP: 159.108.5.46, ASN: AS2024) has 2 flagged malicious files within its infrastructure, despite being whitelisted. The domain hosts 95 subdomains and maintains an active SPF record, indicating potential security risks under an otherwise trusted facade., Whitelisted IP Address 204.79.197.212 Location United States ASN AS8068 microsoft corporation Nameservers ns4-205.azure-dns.info. , ns1-205.azure-dns.com. More WHOIS Registrar: MarkMonitor, Inc., Creation Date: Mar 26, 1996 Related Pulses OTX User-Created Pulses (50) Related Tags 2025 Related Tags 4328 , 5943 , 80211 , #supportsitewebsiteabuse #rootcertificatefailure #cryptographicf , The dynamics of the mudoSOSIntersectalign with sophisticated adv More Indicator Facts 982 malicious files communicat, The AlienVault OTX report for flypdx.com documents 11 related tags, including ids detections and av detections, across 4 active AWS IP addresses (3.175.34.30–.106). These indicators confirm the airport's network has been flagged for unauthorized activity, specifically pointing to a bridge between their web infrastructure and internal passenger tracking. The display of PII on aviation hardware during my June flight matches a known data-bleeding pattern where Personally Identifiable Information (PII) leaks fr, https://app.any.run/tasks/be80a912-0d8e-433d-96bf-56fc1a8960ce?p=69dcf7f097c325be6ef9f1db, https://app.any.run/tasks/73105d2c-c840-4a76-b613-1bc68ba03991, https://app.any.run/tasks/db089766-63b3-41ab-a8e5-cc871b747e83, https://app.any.run/tasks/2a75242b-2060-41e5-9f93-3ae80684abdf, DonutLoader , Loader , Meduza Stealer , Stealer , XWorm:, https://mp.weixin.qq.com/s?__biz=MzI5NjA0NjI5MQ==&mid=2650186156&idx=1&sn=95bccdf47207d54411cc9fbb18b80c56&poc_token=HCJl2GmjxwVz-KgEpd2gv-zqsqu0QxPVQ76GKbWz, https://otx.alienvault.com/pulse/61ccc1c17e4140c6b5283acd, https://www.virustotal.com/graph/embed/g5e7363b624d2432f8ca7d2b330d546dafe002d6db6d44d6f9e77ae5a923aaca6, https://www.virustotal.com/graph/embed/g07f9bc06092d47888e8e47bc2548bc47a17abe8d304e4be0a437e901e81b41be, https://www.virustotal.com/graph/embed/gf624d741d9dd41548de12d4d09b2b50d6657f39f87cd4e97bce041fa3beadba8, https://www.virustotal.com/graph/embed/gdc3b6ebf6220489c9acd20673f740b20938816d7ed824407b68449e2b6b53c51

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 1 year ago · Last seen 1 month ago
Appeared in 5 threat reports