IOC Radar Logo
IOCRadar
IOC Radar Logo
IOCRadar

2bd426f6d6ce7583167e410047b9acd03bc8136e3d6617c5f0e38e210a9c98e1

Hash
18%
SIGNAL STRENGTHExtremely Noisy
FIRST SEEN2025-04-12 08:21:56
LAST SEEN2025-04-26 01:37:49
CATEGORY
honeypot
malware
sftp attack
malicious activity
port scan
ssh attack
brute force and port scanning activity
MITRE
T1565 - Data Manipulation
T1486 - Data Encrypted for Impact
T1071.001 - Web Protocol
T1595 - Active Scanning
T1499.002 - Endpoint DoS
T1499.003 - Network DoS
T1496 - Resource Hijacking
T1190 - Exploit Public-Facing Application
T1110.002 - Brute Force
T1550 - Use Alternate Authentication Material
TAGS
cowrie honeypot
ssh monitoring
file transfer
credential access
credential stuffing
process injection
remote services
distributed attacks
command and control
malicious software
Eye Icon
SOCRadar
AI Insight

The presence of SHA256 hash 2bd426f6d6ce7583167e410047b9acd03bc8136e3d6617c5f0e38e210a9c98e1 is a critical indicator of compromise (IOC) that warrants immediate attention. This hash, identified by AlienVault OTX feeds and linked to a Cowrie honeypot event observed in April 2025, suggests potential malicious activity associated with unauthorized access attempts and likely exploitation of vulnerabilities. The high score of 18.0 indicates a substantial threat level. Failure to address this IOC could lead to system compromise, data theft, or further malicious activity within the network. The observed association with honeypot data strongly suggests the possibility of attackers attempting to probe for and exploit known vulnerabilities, potentially aligning with reconnaissance or initial access phases of an attack campaign. This activity is concerning, especially if present in a production environment, as it signifies ongoing attempts to penetrate our security perimeter and gain unauthorized access.

Summary

Hash Type:
sha256
MD5:
-
SHA-1:
-
SHA-256:
-
Files:
-
File Type:
-

Top Classifications

Campaign:
-
Industry:
-
Country:
-
Region:
-
Threat Actors:
-
Malware:
-

Feed Sources

Feed Source
Count
Date
AlienVault OTX Feeds
179
2025-04-26

Threat Activity Timeline

Last 24 hours
Very Aggressive
Last 7 Days
Very Aggressive
Last Month
Very Aggressive
Last 3 Months
Very Aggressive
Extended Threat Intelligence
Free Trial

Stay ahead with proactive cyber threat warnings

Discover how SOCRadar's all-in-one platform can help protect your digital assets with extended threat intelligence, digital risk protection, and attack surface management.