Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
TLP:WHITE13 IOCs
Cat’s Got Your Files: Lynx Ransomware
Threat Actors
Malware Families
Diamond Model
Adversary(1)
Infrastructure(4)
Capability(10)
Victim
Indicators of Compromise
Indicators of Compromise13
| Type | Indicator | Confidence | Score | First Seen |
|---|---|---|---|---|
| SHA1 | efe8b9ff7ff93780c9162959a4c1e5ecf6e840a4 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA256 | 517288e12c05a92e483e6d80b9136c19bc58c46851720680bb6d1b7016034c37 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| IP | 77.90.153.30 abuseaccessactive directory attack | High | 76 | Jun 12, 25 |
| Domain | temp.sh exfiltrationexploitintel-blog | High | 67 | Jun 3, 26 |
| MD5 | 3073af95dfc18361caebccd69d0021a2 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| Domain | delete.me aa24-131aabuseaccount | Medium | 68 | Mar 28, 25 |
| MD5 | 7532ff90145b8c59dc9440bf43dc87a5 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA256 | 07b36c1660deb223749a8ac151676d8924bc13aa59e6712a3c14a2df5237264a file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA256 | 6285d32a9491a0084da85a384a11e15e203badf67b1deed54155f02b7338b108 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA1 | 3e01df0155a539fe6d802ee9e9226d8c77fd96c9 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| MD5 | e2179046b86deca297ebf7398b95e438 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| IP | 195.211.190.189 abuseaccessactive directory attack | High | 76 | Feb 27, 25 |
| SHA1 | 2b4b11d3ecffd82ed44db652cdd65733224f8e34 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
IOC Relationship Graph
IOC Relationship Graph13 total IOCs
SHA1SHA256IPDomainMD5