Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
TLP:WHITE14 IOCs
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Threat Actors
Malware Families
Diamond Model
Adversary(1)
Infrastructure(6)
Capability(4)
Victim
Indicators of Compromise
Indicators of Compromise14
| Type | Indicator | Confidence | Score | First Seen |
|---|---|---|---|---|
| IP | 104.164.55.46 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
| IP | 192.42.116.52 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
| IP | 149.102.229.154 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
| IP | 37.19.210.12 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
| IP | 104.28.163.162 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
| IP | 192.42.116.50 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
| IP | 192.42.116.97 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
| IP | 64.190.76.14 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
| IP | 192.42.116.12 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
| MD5 | 0108656a3e1ade6ca4f21b084f5e1208 exploitfile-hashintel-blog | High | 56 | Sep 22, 26 |
| IP | 104.28.162.228 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
| IP | 192.42.116.56 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
| MD5 | bea5e267f24d7da59f6821bffdbff293 exploitfile-hashintel-blog | High | 56 | Sep 22, 26 |
| IP | 146.70.117.239 exploitintel-blogmalware | High | 58 | Sep 22, 26 |
IOC Relationship Graph
IOC Relationship Graph14 total IOCs
IPMD5