IOC Radar
SHA256HighVerifiedSignal 61/100

bed33c3732307e19e9a702e7ff179180a7891b92cb879a5b758021eefc68a99b

Location
SingaporeSingapore
First Seen
Aug 30, 2024
Last Seen
Jul 11, 2026
Aug 30
First Seen
693d ago
Jul 11
Last Seen
14d ago
6
Reports
source reports
61%
Confidence
high
Found in 6 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
SHA-256 Hash
SHA-256 file hash — primary identifier for malware samples.
MISP Category
Artifacts Dropped
Hash Algorithm
SHA256
Confidence
61%
Signal Score
61 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

68 techniques

Feed Intelligence Summary

6 reports61% confidence
6
Source reports
61%
Confidence score
Category tags
abmglobalabuseactive scanaddress rangeafricaakiraallocation typeapnicapnic irtapnic routeas133618 descras133618 nameascii englishasiaau addressau orgau phoneaullie aullieaustaust scamaustraliabad reputationbotnetbotnet activitybrute forcecalls-wmichecks-bioschecks-memory-availablechecks-network-adapterschecks-user-inputcidrclickcodecommand and controlcompromised credentialscontinent occopycountry aucredential stuffingcrlf linecrypto cybercryptocurrencycus oletcyberdata encryptiondata exfiltrationdata store exposureddosdefencedetect-debug-environmentdistributed attacksdomaindos executabledreigdtrackeast concourseeewama eewamaegyptencrypt cnr10encryptionentity tpla7apexploitation activityextortionfile-hashfirmware updatefoggenericgeneric windosglobal scamhandlehashesidentity & access exploitationindicatorinitial accessinjection activityinspectraintelirttrellianaujaymurrayjayparkerkangol kangolkey identifierkey infolabel trellianlateral movementlimitedlir phonelong-sleepslookupmagic asciimalicious softwaremalwaremiraimobile threatmoroccoms windowsnamenc1 nc1networknetwork namenumberoceaniaoffsite backupoverlaypasspe32 packerpeexeperupost-compromiseprocess injectionpsalm6 psalm6ransomransomwareregistry apnicremote accessreportresearchedrootserversgwwsignedsingaporeskynetsouth americaspywaressl vpnstatussubject publicsystem disruptionsystem numbert1003t1003.001t1003.004t1018t1021t1021.001t1021.002t1027t1036t1036.005t1041t1046t1048t1048.003t1053t1053.001t1053.002t1053.005t1055t1056t1057t1059t1059.001t1059.003t1068t1070t1071t1071.001t1078t1078.002t1082t1095t1110t1110.001t1110.003t1133t1136t1136.001t1140t1190t1213t1213.002t1219t1482t1486t1490t1496t1497t1499.002t1499.003t1518t1543t1543.003t1547t1547.001t1555t1555.003t1555.004t1560t1560.001t1565t1566t1566.001t1567t1567.002t1570t1574t1574.002t2techtargettext textthis mapthreatthreat actorthreat grouptimetopclassdealstor nodetrid fileusage typev3 serialvpnvpn exploitationvps hosting ipvulnerability scanwhois serverwin32 exewindowsworkclubglobalx509v3 subjectzybot zybot

Activity Timeline

1 total obs
Jul 11Jul 11

Threat Activity Heatmap

· Peak: 2026-07-11
Less
More
Mon
Wed
Fri
Jul
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
·
·
Jul
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
61
SIGNAL
Signal Score
61%
Confidence
6
Reports
First seenAug 30, 2024
Last seenJul 11, 2026
Verified IOC

VirusTotal

Not checked

WHOIS

description
Since early August, there has been a significant increase in Fog and Akira ransomware intrusions targeting SonicWall SSL VPN users across various industries. The attacks appear opportunistic rather than targeting specific sectors. All affected devices lacked patches for CVE-2024-40766. Initial access involved VPN logins from VPS hosting IPs, with rapid progression to data encryption and exfiltration, often within hours. Shared infrastructure was observed across multiple intrusions. Defenders are advised to prioritize firmware updates, monitor for suspicious VPN logins, maintain secure offsite backups, and watch for post-compromise activities on endpoints.

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 1 year ago · Last seen 14 days ago
Appeared in 6 threat reports