IOC Radar
TLP:WHITE21 IOCs

Oyster Malware Delivery via Teams Fake App

MA
MalasadaTech
Published September 28, 2025Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREwitherspoon-law.com85.239.53.66teams-install.icuCAPABILITYCobalt StrikeVICTIMunknown
Adversary
Infrastructure(6)
Capability(1)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise21

TypeIndicatorConfidenceScoreFirst Seen
Domainwitherspoon-law.com
intel-blogmalwarenetwork
High
58
Jun 2, 26
IP85.239.53.66
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainteams-install.icu
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainteams-install.run
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainteams-download.top
intel-blogmalwarenetwork
High
58
Jun 2, 26
IP51.222.96.108
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domaindaringdatadaredevils.com
intel-blogmalwarenetwork
High
58
Jun 2, 26
IP185.28.119.228
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domaintechwisenetwork.com
intel-blogmalwarenetwork
High
58
Jun 2, 26
SHA256291973f004fcaa78e053a33a99b2bb0b09cb80d9e972aa26d0b5715c75eef64a
file-hashintel-blogmalware
Medium
53
Jun 2, 26
Domaineastridge-infotech.com
intel-blogmalwarenetwork
High
58
Jun 2, 26
IP135.125.241.45
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainnickbush24.com
c2intel-blogmalware
High
58
Jun 2, 26
SHA256e59b6d89b90dd6dbbe3aa3ac163eea3d659e952bac6a6bf65b99e40157cb95f5
file-hashintel-blogmalware
Medium
53
Jun 2, 26
IP51.222.96.69
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainfunkyfirmware.com
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domaindatadrivendreamers.com
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainteams-download.buzz
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domaincybersavvynetwork.com
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainteams-install.top
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainteams-download.icu
intel-blogmalwarenetwork
High
58
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph21 total IOCs
DomainIPSHA256
Domain14IP5SHA2562Malware1REPORTOyster Malware Delivery viCobalt Strike
scroll to zoom · drag to pan · click IOC to open