IOC Radar
TLP:WHITE115 IOCs

Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

SE
Securelist
Published May 22, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREinvestika-club.com81.30.105.71tenkoff.orgCAPABILITYPsExecVICTIMunknown
Adversary
Infrastructure(6)
Capability(1)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise115

TypeIndicatorConfidenceScoreFirst Seen
MD525c8ed0511375dca57ef136ac3fa0cca
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domaininvestika-club.com
exploitintel-blogmalware
High
58
Jun 2, 26
IP81.30.105.71
exploitintel-blogmalware
High
58
Jun 2, 26
MD51a11b26dd0261ef27a112ce8b361c247
file-hashintel-blogmalware
Medium
53
Jun 2, 26
MD59eaae9491f6a50d6df0be393734a44cb
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5eba3bcdb19a7e256bf8e2cc5b9c1cca9
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domaintenkoff.org
exploitintel-blogmalware
High
58
Jun 2, 26
MD5867b634588c0fd6b26684d502c15ab03
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainfishingflytackle.com
exploitintel-blogmalware
High
58
Jun 2, 26
MD5493b901d1b33eb577db64aadd948f9ce
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainlandscapeuganda.com
exploitintel-blogmalware
High
58
Jun 2, 26
IP195.58.49.9
exploitintel-blogmalware
High
58
Jun 2, 26
MD55329f7bff9d0d5db28821b86c26d628f
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domaininternationalcommoditiesllc.com
exploitintel-blogmalware
High
58
Jun 2, 26
MD58158552950d2e13b075001ce0c52aa97
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainkufar.org
exploitintel-blogmalware
High
58
Jun 2, 26
MD51d401d6e6fc0b00aaa2c65a0ac0cfd6b
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5b6aae073e7bfebf4d643c2bbeb5c02e1
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD536120f5e9411bcbac7104ef3fa964ed2
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5f56b31a4b47ad3365b18a7e922fba1a8
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
CVECVE-2018-0802
exploitintel-blogmalware
Medium
51
Jun 2, 26
MD52b4ba4facf8c299749771a3a4369782e
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD550568b1f9335a7e3ba4e5df035a8fb86
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD55000a353399500bc78381dc95b6ed2dc
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD57242ac065b50bcde9308756b49dbadcb
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
IP46.17.45.49
exploitintel-blogmalware
High
58
Jun 2, 26
MD5116f59e70a9df97f4adaea71eecb1e9a
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5344ca9ea07cd4ac90ef27f8890d4ec05
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domaingoverru.com
exploitintel-blogmalware
High
58
Jun 2, 26
MD5fb0f8027acf1b1e47e07a63d8812ed50
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5bc3739dec8cd8f54f3f60a85f3ed600e
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD51b39e86eb772a0e40060b672b7f574f1
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD57a95360b7e0eb5b107a3d231abbc541a
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainallgoodsdirect.com.au
exploitintel-blogmalware
High
58
Jun 2, 26
Domaincloudguide.in
exploitintel-blogmalware
High
58
Jun 2, 26
Domainbigbang.me
exploitintel-blogmalware
High
58
Jun 2, 26
MD567d7e3aeeb673bf60c59361c12a4ed81
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
IP185.250.181.207
exploitintel-blogmalware
High
58
Jun 2, 26
IP45.87.219.116
exploitintel-blogmalware
High
58
Jun 2, 26
MD528ecf8fb6719e14231b94b4d37629b0e
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5f9c3bbe108566d1a6b070f9c5fb03160
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD540a562b8600f843b717bc5951b2e3c29
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
IP185.22.154.73
exploitintel-blogmalware
High
58
Jun 2, 26
Domainistochnik.org
exploitintel-blogmalware
High
58
Jun 2, 26
Domainalnakhlah.com.sa
exploitintel-blogmalware
High
58
Jun 2, 26
MD5f721a76deb28fd0b80d27fce6b8f5016
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainonedrivesupport.net
exploitintel-blogmalware
High
58
Jun 2, 26
MD5ba9ce06641067742f2afc9691faff1dc
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainfirsai.tipshub.net
exploitintel-blogmalware
High
58
Jun 2, 26
MD563b6be9ae8d8024a40b200cccb438f1d
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD569121c36eb8bf77962dca825fcffd873
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD583edde9f7eeefac0363413972f35572b
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD538fa4306fa4406ba31cf171af4d36e34
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD50577db70844e88b32b954906e2f20798
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5369b75bdcded16469ede7ab8bedcfae1
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
IP194.102.104.207
exploitintel-blogmalware
High
58
Jun 2, 26
MD52042eb5d52f0b535a1ce6b6f954c8c2b
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD50320dd389fdbab25d46792bd2817675e
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
IP185.53.179.136
exploitintel-blogmalware
High
58
Jun 2, 26
MD5b4e183627b7399006c1bc47b3711e419
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD55339d1a666f3e40fe756505cf1d87d4b
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domaintotallegacy.org
exploitintel-blogmalware
High
58
Jun 2, 26
MD5bbf1fa694122e07635deeac11ad712f8
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5ec076cd21c483a40156f4e40d08daded
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD50c514e137860f489e3801213460ef938
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD59bd788f285e32a05e6591d1eb36ebffc
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainznews.net
exploitintel-blogmalware
High
58
Jun 2, 26
Domainwizzifi.com
exploitintel-blogmalware
High
58
Jun 2, 26
IP194.87.196.163
exploitintel-blogmalware
High
58
Jun 2, 26
Domainlafortunaitalian.co.uk
exploitintel-blogmalware
High
58
Jun 2, 26
MD53c75cedb1196df5eab91f31411ed4b33
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5d5b38b252cf212a4a32763de36732d40
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainhumanitas.si
exploitintel-blogmalware
High
58
Jun 2, 26
MD5a75dbed984963b9ab21309c5b2f8fd9b
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5c0d1eaa15a2cefbab9735787575c8d8e
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainagenciakharis.com.br
exploitintel-blogmalware
High
58
Jun 2, 26
MD52aa1e9765ef6b00b94a9b6be0041436a
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD56aa586bcc45ca2e92a4f0ef47e086fa1
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5d3c8afd22baa306ff659db1fac28574a
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5c5702eb250f855c8c872fffb9bb656ed
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainmamurjor.com
exploitintel-blogmalware
High
58
Jun 2, 26
MD5f6f62456fb0fcc396fb654cbed339bc3
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
IP37.228.129.224
exploitintel-blogmalware
High
58
Jun 2, 26
Domainamerikastaj.com
exploitintel-blogmalware
High
58
Jun 2, 26
Domainspbnews.net
exploitintel-blogmalware
High
58
Jun 2, 26
MD542ac350bfbc5b4eb0fedba16c81919c7
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD56d7b2d1172bbdb7340972d844f6f0717
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
IP146.70.53.171
exploitintel-blogmalware
High
58
Jun 2, 26
MD5097ca205ad9e3b72018750280904718c
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
IP46.17.44.212
exploitintel-blogmalware
High
58
Jun 2, 26
IP5.181.21.75
exploitintel-blogmalware
High
58
Jun 2, 26
MD50857c84b62289a1a9f29e19244e9a499
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD59769f43b9de8d19e803263267fa6d62e
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5ed34f5a136fba4fdea976570faa33ed7
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5a632858f14b36f03d0f213f5f5d6bff2
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainultimatecore.net
exploitintel-blogmalware
High
58
Jun 2, 26
MD5579a9952d31cad801a3988dbe7914ce7
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
IP185.126.239.77
exploitintel-blogmalware
High
58
Jun 2, 26
IP45.15.65.134
exploitintel-blogmalware
High
58
Jun 2, 26
MD5216cb7f31d383c0dd892b284df05a495
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5f301aa3d62b5095eec4d8e34201a4769
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
IP46.17.44.125
exploitintel-blogmalware
High
58
Jun 2, 26
MD5f42085522ec2ebb16edcf814e7c330ad
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD53e6e9df00a764b348ec611ee8504aca0
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5cc751619bfec0dc4607c17112b9e3b2c
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD589572f0ed20791a5ac9fc4267d67ccb0
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainkommando.live
exploitintel-blogmalware
High
58
Jun 2, 26
IP46.17.45.56
exploitintel-blogmalware
High
58
Jun 2, 26
IP93.125.114.193
exploitintel-blogmalware
High
58
Jun 2, 26
MD57f776ad200287d6de14a29158c457179
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainpaleturquoise-dragonfly-364512.hostingersite.com
exploitintel-blogmalware
High
58
Jun 2, 26
IP93.125.114.57
exploitintel-blogmalware
High
58
Jun 2, 26
MD551f7f794ed43fb90d0f8ebbb5effe628
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD5b8c753dd254509fba5077ffd5067eab0
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
MD52cabb721681455dae1b6a26709def453
exploitfile-hashintel-blog
Medium
53
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph115 total IOCs
MD5DomainIPCVE
MD569Domain26IP19CVE1Malware1REPORTCloud Atlas activity in thPsExec
scroll to zoom · drag to pan · click IOC to open