IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
CVEHighVerifiedSignal 81/100EPSS 82.0%

CVE-2025-55182

First Seen
Jun 2, 2026
Last Seen
Oct 10, 2026
Jun 2
First Seen
130d ago
Oct 10
Last Seen
today
207
Reports
source reports
87%
Confidence
high
Found in 207 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
CVE
Known vulnerability being actively exploited in the wild.
MISP Category
vulnerability
EPSS Score
82.01%
EPSS Percentile
99.2th
Confidence
87%
Signal Score
81 / 100
IDS Rule
No
CVE Intelligence
Exploit Probability82.01%
99.2th percentile of all CVEs

Feed Intelligence Summary

207 reports87% confidence
AU
Abuse.ch URLhaus
4477 IOCs in report
AU
Abuse.ch URLhaus
4833 IOCs in report
AU
Abuse.ch URLhaus
4590 IOCs in report
AU
Abuse.ch URLhaus
4475 IOCs in report
AU
Abuse.ch URLhaus
4469 IOCs in report
AU
Abuse.ch URLhaus
4583 IOCs in report
AU
Abuse.ch URLhaus
4471 IOCs in report
AU
Abuse.ch URLhaus
4590 IOCs in report
AU
Abuse.ch URLhaus
4473 IOCs in report
AU
Abuse.ch URLhaus
4479 IOCs in report

Activity Timeline

208 total obs
Oct 10Dec 3

Threat Activity Heatmap

· Peak: 2026-06-28
Less
More
Mon
Wed
Fri
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
·
·
Jul
·
·
·
Aug
·
·
·
·
Sep
·
·
·
24h
0
Dormant
7d
3
Moderate
30d
10
Elevated
3mo
14
Elevated
Threat ScoreHigh Risk
81
SIGNAL
Signal Score
87%
Confidence
207
Reports
First seenJun 2, 2026
Last seenOct 10, 2026
Verified IOC

VirusTotal

Not checked

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 4 months ago · Last seen today
Appeared in 207 threat reports from 10 sources
Associated with: Scattered Spider, BlackCat, UNC5174, Play, Akira, NoName057, Kimsuky, Royal, Conti, LockBit, Killnet, TA577, REvil, Gamaredon, APT38, APT28, APT33, APT41, APT35, Cl0p, DEV-0569, APT37, APT29, APT34, Salt Typhoon, FIN8, MuddyWater, UNC1549, Turla, Hive, APT31, TA412, Black Basta, Volt Typhoon, Ember Bear, DarkSide, Lazarus Group, Sandworm
Used by malware: Play, Hive, Pikabot, XMRig, Remcos, Akira, Rhysida, Bumblebee, LockBit, Stealc, TrickBot, Mirai, Vidar, XWorm, AsyncRAT, Medusa, Black Basta, QakBot, BlackCat, Conti, Royal, DarkSide, Mimikatz, Fscan, NetScan, META Stealer, Cobalt Strike, SocGholish, Rhadamanthys, Lumma, Mythic, Gh0st RAT, Ursnif, BazarLoader, AcidRain, INC Ransom, NotPetya, IcedID, Emotet, RedLine, PlugX, CaddyWiper, REvil, Brute Ratel, WhisperGate, Cl0p, HermeticWiper, NjRAT
1 user flagged this