IOC Radar
SHA256MediumSignal 37/100

cdf7c97cfb494ade90886765606294db0b98a2576bc1d152bc8c4ec97672b687

First Seen
Jul 1, 2026
Last Seen
Jul 9, 2026
Jul 1
First Seen
37d ago
Jul 9
Last Seen
29d ago
2
Reports
source reports
48%
Confidence
medium
Found in 2 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
SHA-256 Hash
SHA-256 file hash — primary identifier for malware samples.
MISP Category
Artifacts Dropped
Hash Algorithm
SHA256
Confidence
48%
Signal Score
37 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

2 techniques

Feed Intelligence Summary

2 reports48% confidence

Activity Timeline

1 total obs
Jul 9Jul 9

Threat Activity Heatmap

· Peak: 2026-07-09
Less
More
Mon
Wed
Fri
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
·
·
Jul
·
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreLow Risk
37
SIGNAL
Signal Score
48%
Confidence
2
Reports
First seenJul 1, 2026
Last seenJul 9, 2026

VirusTotal

Not checked

WHOIS

description
The Clubfoot Wolf cyber threat group has been actively targeting Russian organizations, particularly those in the wholesale chemical sector, during May and June of 2026. The group uses phishing emails that are crafted to appear as legitimate requests for commercial proposals or invoices, masquerading as employees interested in purchasing products from the target companies. The emails contain ZIP archives with a malicious link (LNK) file and several decoy files that are intended to gain the recipient's trust and induce them to open the attachments.

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 month ago · Last seen 29 days ago
Appeared in 2 threat reports from 1 source