IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE13 IOCs

Cat’s Got Your Files: Lynx Ransomware

TD
The DFIR Report
Published December 17, 2025Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYAkiraINFRASTRUCTURE77.90.153.30temp.shdelete.meCAPABILITYAkiraBloodHoundBumblebeeVICTIMunknown
Adversary(1)
Infrastructure(4)
Capability(10)
Victim

Indicators of Compromise

Indicators of Compromise13

TypeIndicatorConfidenceScoreFirst Seen
SHA1efe8b9ff7ff93780c9162959a4c1e5ecf6e840a4
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA256517288e12c05a92e483e6d80b9136c19bc58c46851720680bb6d1b7016034c37
file-hashintel-blogmalware
Medium
53
Oct 9, 26
IP77.90.153.30
abuseaccessactive directory attack
High
76
Jun 12, 25
Domaintemp.sh
exfiltrationexploitintel-blog
High
67
Jun 3, 26
MD53073af95dfc18361caebccd69d0021a2
file-hashintel-blogmalware
Medium
53
Oct 9, 26
Domaindelete.me
aa24-131aabuseaccount
Medium
68
Mar 28, 25
MD57532ff90145b8c59dc9440bf43dc87a5
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA25607b36c1660deb223749a8ac151676d8924bc13aa59e6712a3c14a2df5237264a
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA2566285d32a9491a0084da85a384a11e15e203badf67b1deed54155f02b7338b108
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA13e01df0155a539fe6d802ee9e9226d8c77fd96c9
file-hashintel-blogmalware
Medium
53
Oct 9, 26
MD5e2179046b86deca297ebf7398b95e438
file-hashintel-blogmalware
Medium
53
Oct 9, 26
IP195.211.190.189
abuseaccessactive directory attack
High
76
Feb 27, 25
SHA12b4b11d3ecffd82ed44db652cdd65733224f8e34
file-hashintel-blogmalware
Medium
53
Oct 9, 26

IOC Relationship Graph

IOC Relationship Graph13 total IOCs
SHA1SHA256IPDomainMD5
SHA13SHA2563MD53IP2Domain2Actors1Malware5REPORTCat’s Got Your Files: LynxAkiraAkiraBloodHoundBumblebeeCobalt StrikeMETA Stealer
scroll to zoom · drag to pan · click IOC to open