Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
critical threatRansomwareMalware Family
Historical
Hive
Critical severity
4.0k
IOCs Tracked
—
First Seen
—
Last Seen
0
YARA Rules
Associated IOCs4,028 total · showing 50
IP50
91.202.233.2142026-09-15High
162.248.225.1652026-09-15High
109.73.193.2422026-09-15High
46.151.182.2052026-09-15High
221.207.101.1752026-09-15High
15.204.95.2282026-09-15High
67.219.102.2442026-09-15High
5.101.86.982026-07-04High
5.101.86.1052026-07-06High
178.16.54.2482026-06-23High
88.119.167.1432026-08-17High
84.21.189.2252026-06-20High
107.175.148.682026-07-09High
195.123.240.2362026-09-15High
139.159.203.442026-09-15High
137.184.163.272026-09-15High
8.152.2.862026-09-13High
158.247.194.1442026-08-19High
38.181.42.1602026-09-13High
18.118.196.2442026-07-02High
Related Reports30 shown
Inside the Hive
Group-IB
New Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM
Cyber PressSep 9, 2026
PrettyPrague PoC Claims Avast Antivirus Zero-Day Enables SYSTEM Privilege Escalation
Cyber PressSep 3, 2026
CVE-2026-81578: Exploited PaperCut Authentication Bypass Chains to Pre-Auth RCE
SOC PrimeSep 2, 2026
Microsoft’s August Security Update of High-Risk Vulnerability Notice for Multiple Products
NSFOCUS Security LabsAug 18, 2026
Play Ransomware Scores Just 13% Prevention as Evasion Techniques Bypass Security Controls
Cyber PressAug 10, 2026
Oracle SQL Injection Attack Escalates to SYSTEM-Level Windows Code Execution
Cyber PressAug 6, 2026
LegacyHive Abuses Windows Profile Loading to Hijack Administrator Registry Hives
Cyber PressJul 28, 2026
Spirals Attackers Disable Windows Defender and Kill Backup Services Before Encrypting Systems
Cyber PressJul 17, 2026
LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
Cyber PressJul 17, 2026
Leveraging cyber intelligence for threat detection
BI.ZONEJul 17, 2026
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
SecurelistJul 16, 2026
Inside Kimsuky’s CHM Tradecraft: Multi-Stage Execution and Selective Payload Delivery
Synaptic SystemsJun 29, 2026
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Abuse.ch URLhaus (5000 entries)
Abuse.ch URLhaus
Threat Profile
TypeRansomware
StatusHistorical
IOCs tracked4,028