IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE14 IOCs

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

MT
Microsoft Threat Intelligence
Published July 31, 2026Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYAPT29INFRASTRUCTURE38.146.28.7531.57.243.154https://213.145.86.11…CAPABILITYCobalt StrikeVICTIMunknown
Adversary(1)
Infrastructure(6)
Capability(1)
Victim

Indicators of Compromise

Indicators of Compromise14

TypeIndicatorConfidenceScoreFirst Seen
SHA256918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593
botnetfile-hashintel-blog
High
86
Aug 1, 26
IP38.146.28.75
aptespionageexploit
High
72
Jul 24, 26
IP31.57.243.154
aptespionageexploit
High
72
Jul 24, 26
URLhttps://213.145.86.112/cdn/chunks/polyfill-7e2b.min.js
intel-blogmalwarenetwork
High
58
Aug 1, 26
IP38.146.28.132
aptespionageintel-blog
High
69
Aug 1, 26
IP107.189.26.194
aptespionageintel-blog
High
69
Aug 1, 26
Domainowa-ms365.com
aptespionageintel-blog
High
72
Jul 24, 26
SHA256be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c
botnetfile-hashintel-blog
High
86
Aug 1, 26
IP104.194.159.150
aptespionageexploit
High
75
Jul 24, 26
Domainm365-owa.com
aptespionageintel-blog
High
72
Jul 24, 26
URLhttps://213.145.86.112/t/event
intel-blogmalwarenetwork
High
58
Aug 1, 26
Domainms365-live.com
aptespionageintel-blog
High
72
Jul 24, 26
URLhttps://213.145.86.112/t/pixel.gif
intel-blogmalwarenetwork
High
58
Aug 1, 26
Domainms365-device.com
aptespionageintel-blog
High
72
Jul 24, 26

IOC Relationship Graph

IOC Relationship Graph14 total IOCs
SHA256IPURLDomain
IP5Domain4URL3SHA2562Actors1Malware1REPORTCaptiveCrunch: Midnight BlAPT29Cobalt Strike
scroll to zoom · drag to pan · click IOC to open