IOC Radar
TLP:WHITE54 IOCs

A VBScript campaign distributed through WhatsApp deploying RMM software

SE
Securelist
Published June 22, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREshaaslong.one202.61.160.201caiwuascw.s3.us-east-…CAPABILITYGh0st RATVICTIMunknown
Adversary
Infrastructure(6)
Capability(1)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise54

TypeIndicatorConfidenceScoreFirst Seen
MD51a3cc75466ffb1971482f7abf7aabc3f
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD531037a42ca048e06e69a78f55bc2eff5
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD53b1aba44dd3d9b6339b6f56e2f42034b
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD56359e6236471cbe434d0ef4c42b7f879
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
Domainshaaslong.one
exploitintel-blogmalware
High
58
Jun 23, 26
MD568c16c46f8afb9e00bbaba0207fb0a46
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD566705384a7ad81d14c34fc6c054a0ecf
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD57f81c1bc8cfd588e8998968e2621456e
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD574fd9f91fc93b6288b4fc253ea5b3e20
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD52c6f05f1f309d89b2236e6c8b59c88f9
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD58c6d9fc389ad3f20ccbc71d77eb39bfa
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD5ddaffe9849f7f3c79f8804adb9a6b3d5
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD51c47c63e5ed25060d95359c57c77b107
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD58c3322009b8982663c0cbecd9492e7eb
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD505d188f071d097f5b6bd8138749b4b14
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
IP202.61.160.201
c2intel-blogmalware
High
58
Jun 23, 26
MD55b6bbcc06cf08cc99e1afeda486d42fb
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
Domaincaiwuascw.s3.us-east-005.backblazeb2.com
exploitintel-blogmalware
High
58
Jun 23, 26
IP202.61.160.208
intel-blogmalwarenetwork
High
58
Jun 23, 26
MD5d43fdaa1f0ee09d7e5f0f94ee9df7b6c
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
Domaintemu.baskwms.top
exploitintel-blogmalware
High
58
Jun 23, 26
MD5dad708e050632a4280cabf98ac1376b7
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD563ac85195b73753333316a889cf5880f
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD5df4fa0369eaca5cec348be293890d4af
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD579ecd61b09b0f2d54b34586c916c4ec9
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
Domainqse.shoppes.help
exploitintel-blogmalware
High
58
Jun 23, 26
MD5b7cd06c71465038b658a6dc1f273a507
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
IP202.61.160.137
aptc2espionage
High
58
Jun 23, 26
Domainbaoxis.cc
exploitintel-blogmalware
High
58
Jun 23, 26
MD59f13c7b8ba391b2f597874e54d310648
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD5d06333c360b51456f427e616c3c5f8bd
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
Domainfacaia.s3.us-east-005.backblazeb2.com
exploitintel-blogmalware
High
58
Jun 23, 26
MD54f0593e8e0e8fac49429e9b45ebf7fa1
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD57403cbcc5a9c32384d431856dc48fcc9
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD51d94fbe9cab21278cc3f104bea334d08
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD5c7f38cbb99c8b74fa0465293feeba700
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD5993f4c0cadbc769a4b0ed62a918db58d
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD55002eca748205d544618e3bd2dedc223
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
IP202.61.160.160
c2intel-blogmalware
High
58
Jun 23, 26
MD566442f2457eca8f47385b1fb2c6fcab8
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD56fb6a55424adfb61e31f06aef33273e5
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD5d01cad98dd0d01b75e04e784953c5e2b
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD50ba93109757776a44de9d8c88baa4963
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD54044e4b6471c9de7b0a4ba37d9d9df9a
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD59d9ac85765e4a818a3ccabe2cf4fef82
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD56c39900d77dcba158e1d27c7619cb06d
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD520209b3a32769afc6a75694b8d8839dd
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
Domaininvoice.msopsa.top
exploitintel-blogmalware
High
58
Jun 23, 26
MD57f16449cd0c4862d1eadf8a5742bf09a
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
IP38.55.151.63
aptc2espionage
High
74
Jun 21, 26
MD5f90ed4b2d0b67114aa89ddfed658e5c0
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
IP202.61.160.202
c2intel-blogmalware
High
58
Jun 23, 26
MD57849061c536a3efb05a56d504694e7e7
exploitfile-hashintel-blog
Medium
53
Jun 23, 26
MD502bb20455cc592a69c080abac770ce90
exploitfile-hashintel-blog
Medium
53
Jun 23, 26

IOC Relationship Graph

IOC Relationship Graph54 total IOCs
MD5DomainIP
MD541Domain7IP6Malware1REPORTA VBScript campaign distriGh0st RAT
scroll to zoom · drag to pan · click IOC to open