IOC Radar
TLP:WHITE21 IOCs

JOMANGY: INJ3CTOR3’s Self-Healing FreePBX Toll Fraud Campaign

CY
Cyble
Published May 21, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTURE169.150.218.33http://45.95.147.178/…169.150.218.37CAPABILITYCobalt StrikeVICTIMunknown
Adversary
Infrastructure(6)
Capability(1)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise21

TypeIndicatorConfidenceScoreFirst Seen
MD5cf710203400b8c466e6dfcafcf36a411
file-hashintel-blogmalware
High
61
Jun 2, 26
IP169.150.218.33
intel-blogmalwarenetwork
High
68
Jun 2, 26
URLhttp://45.95.147.178/z/post/noroot.php
intel-blogmalwarenetwork
High
68
Jun 2, 26
MD5e1ebf9066a951be519a24140711839ea
exploitfile-hashintel-blog
High
61
Jun 2, 26
MD5bfcedbc1831779921a0ee2cfaee004f2
file-hashintel-blogmalware
High
61
Jun 2, 26
IP169.150.218.37
intel-blogmalwarenetwork
High
68
Jun 2, 26
IP45.234.176.202
intel-blogmalwarenetwork
High
68
Jun 2, 26
IP146.70.129.114
intel-blogmalwarenetwork
High
68
Jun 2, 26
URLhttp://45.95.147.178/x
intel-blogmalwarenetwork
High
68
Jun 2, 26
MD5ec4ca4db5ec0b782e51224fa7082ac06
file-hashintel-blogmalware
High
61
Jun 2, 26
URLhttp://45.95.147.178/
intel-blogmalwarenetwork
High
68
Jun 2, 26
CVECVE-2025-57819
exploitintel-blogloader
High
59
Jun 2, 26
URLhttp://45.95.147.178/k.php
intel-blogmalwarenetwork
High
68
Jun 2, 26
MD5b92c65af386ed772972b43cab0d55a4a
file-hashintel-blogmalware
High
61
Jun 2, 26
CVECVE-2019-19006
exploitintel-blogmalware
High
59
Jun 2, 26
CVECVE-2021-45461
exploitintel-blogmalware
High
59
Jun 2, 26
MD5a8b65af6c142736ccf80420e44df240f
file-hashintel-blogmalware
High
61
Jun 2, 26
IP160.119.76.250
aptespionageintel-blog
High
68
Jun 2, 26
CVECVE-2025-64328
exploitintel-blogmalware
High
59
Jun 2, 26
SHA16ea9c6d2d932532a4cd44c7974fb1a0a87dbfcf9
file-hashintel-blogmalware
High
61
Jun 2, 26
URLhttp://45.95.147.178/z/post/root.php
intel-blogmalwarenetwork
High
68
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph21 total IOCs
MD5IPURLCVESHA1
MD56IP5URL5CVE4SHA11Malware1REPORTJOMANGY: INJ3CTOR3’s Self-Cobalt Strike
scroll to zoom · drag to pan · click IOC to open