IOC Radar
TLP:WHITE6 IOCs

China-Linked Group Deploys Custom ASPX and ASHX Web Shells

CP
Cyber Press
Published June 6, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTURE124.156.129.151hcgos.comashx.lhlsjcb.comCAPABILITYCobalt StrikeMetasploitPlugXVICTIMunknown
Adversary
Infrastructure(6)
Capability(3)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise6

TypeIndicatorConfidenceScoreFirst Seen
IP124.156.129.151
exploitintel-blogmalware
High
64
Jun 7, 26
Domainhcgos.com
intel-blogmalwarenetwork
High
63
Jun 7, 26
Domainashx.lhlsjcb.com
aptespionageintel-blog
High
68
Jun 7, 26
Domainc.hcgos.com
c2intel-blogmalware
High
63
Jun 7, 26
IP140.206.161.227
c2intel-blogmalware
High
58
Jun 7, 26
IP43.160.202.246
c2intel-blogmalware
High
64
Jun 7, 26

IOC Relationship Graph

IOC Relationship Graph6 total IOCs
IPDomain
IP3Domain3Malware3REPORTChina-Linked Group DeploysCobalt StrikeMetasploitPlugX
scroll to zoom · drag to pan · click IOC to open