■ LIVE INTEL
■ Sentinel APEX ■ Tools Hub ■ API Platform ■ API Docs ■ Corporate ■ Main Site ■ Blog Hub ▲ UPGRADE NOW
SENTINEL APEX ECOSYSTEM — LIVE

AI-Powered
Cyber Intelligence
For The Enterprise

Real-time CVE analysis, APT tracking, malware intelligence, and autonomous SOC capabilities. Trusted by security teams worldwide.

LIVE THREAT INTELLIGENCE FEED
VIEW FULL DASHBOARD ↗
SENTINEL APEX
AI Threat Intel Platform
THREAT API
Checking status...
LATEST CVE
Loading...
Live from Sentinel APEX API
AI SUMMARY
Loading...

[Vulnerability Exploitation] THREAT ADVISORY: Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs (+29 Correlated Events) (Score: 10.0/10)

CYBERDUDEBIVASH SENTINEL APEX

ID: CDB-APEX-1771097541 | v5.5 ENTERPRISE

CRITICAL

Threat Confidence

98%

Forensic Nodes

231 Unique

Status

ACTIVE TRIAGE

🌍 Global Threat Distribution

GLOBAL THREAT DISTRIBUTION

* Red pulses indicate active IoC origins triaged in this sweep.

Strategic Briefing

Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs

A previously undocumented threat actor has been attributed to attacks targeting Ukrainian organizations with malware known as CANFAIL. Google Threat Intelligence Group (GTIG) described the hacking group as possibly affiliated with Russian intelligence services. The threat actor is assessed to have t...

Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations

Several state-sponsored actors, hacktivist entities, and criminal groups from China, Iran, North Korea, and Russia have trained their sights on the defense industrial base (DIB) sector, according to findings from Google Threat Intelligence Group (GTIG). The tech giant's threat intelligence division ...

UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors

A previously unknown threat actor tracked as UAT-9921 has been observed leveraging a new modular framework called VoidLink in its campaigns targeting the technology and financial services sectors, according to findings from Cisco Talos. "This threat actor seems to have been active since 2019, althou...

Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History

Cybersecurity researchers have discovered a malicious Google Chrome extension that's designed to steal data associated with Meta Business Suite and Facebook Business Manager. The extension, named CL Suite by @CLMasters (ID: jkphinfhmfkckkcnifhjiplhfoiefffl), is marketed as a way to scrape Meta Busin...

npm’s Update to Harden Their Supply Chain, and Points to Consider

In December 2025, in response to the Sha1-Hulud incident, npm completed a major authentication overhaul intended to reduce supply-chain attacks. While the overhaul is a solid step forward, the changes don’t make npm projects immune from supply-chain attacks. npm is still susceptible to malware attac...

Over 300 Malicious Chrome Extensions Caught Leaking or Stealing User Data

With more than 37 million combined downloads, the extensions expose users to tracking and personal information theft.

The post Over 300 Malicious Chrome Extensions Caught Leaki...

In Other News: Google Looks at AI Abuse, Trump Pauses China Bans, Disney’s $2.7M Fine

Other noteworthy stories that might have slipped under the radar: vulnerabilities at 277 water systems, DoD employee acting as money mule, 200 airports exposed by flaw.

The post

Check Point Announces Trio of Acquisitions Amid Solid 2025 Earnings Beat

Check Point has acquired Israeli cybersecurity companies Cyata, Cyclops, and Rotate.

The post Check Point Announces Trio of Acquisitions Amid Solid 2025 Earnings Beat appear...

Dutch Carrier Odido Discloses Data Breach Impacting 6 Million

Hackers stole personal information such as names, addresses, and phone numbers from a customer contact system.

The post Dutch Carrier Odido Discloses Data Breach Impacting 6 Million ap...

BeyondTrust Vulnerability Targeted by Hackers Within 24 Hours of PoC Release

Exploitation attempts target CVE-2026-1731, a critical unauthenticated remote code execution flaw in BeyondTrust Remote Support.

The post BeyondTrust Vulnerability Targeted ...

Kimwolf Botnet Lurking in Corporate, Govt. Networks

A new Internet-of-Things botnet called Kimwolf has spread to more than 2 million devices, forcing infected systems to participate in massive distributed denial-of-service (DDoS) attacks and to relay other malicious and abusive Internet traffic. Kimwolf's ability to scan the local networks of comprom...

Patch Tuesday, January 2026 Edition

Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. Eight of the vulnerabilities earned Microsoft's most-dire "critical" rating, and the company warns that attackers are already exploiting one of the bugs fixed today....

Who Benefited from the Aisuru and Kimwolf Botnets?

Our first story of 2026 revealed how a destructive new botnet called Kimwolf rapidly grew to infect more than two million devices by mass-compromising a vast number of unofficial Android TV streaming boxes. Today, we'll dig through digital clues left behind by the hackers, network operators, and cyb...

The Kimwolf Botnet is Stalking Your Local Network

The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. The vulnerability at issue has been exploited for months already, and it's time for a broader awareness of the threat. The short version is that everything you thought you knew about the...

Happy 16th Birthday, KrebsOnSecurity.com!

KrebsOnSecurity.com celebrates its 16th anniversary today! A huge "thank you" to all of our readers -- newcomers, long-timers and drive-by critics alike. Your engagement this past year here has been tremendous and truly a salve on a handful of dark days. Happily, comeuppance was a strong theme runni...

One threat actor responsible for 83% of recent Ivanti RCE attacks

Threat intelligence observations show that a single threat actor is responsible for most of the active exploitation of two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-21962 and CVE-2026-24061. [...]...

Snail mail letters target Trezor and Ledger users in crypto-theft attacks

Threat actors are sending physical letters pretending to be from Trezor and Ledger, makers of cryptocurrency hardware wallets, to trick users into submitting recovery phrases in crypto theft attacks. [...]...

Fake job recruiters hide malware in developer coding challenges

A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks. [...]...

Claude LLM artifacts abused to push Mac infostealers in ClickFix attack

Threat actors are abusing Claude artifacts and Google Ads in ClickFix campaigns that deliver infostealer malware to macOS users searching for specific queries. [...]...

Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches

South Korea has fined luxury fashion brands Louis Vuitton, Christian Dior Couture, and Tiffany $25 million for failing to implement adequate security measures, which facilitated unauthorized access and the exposure of data belonging to more than 5.5 million customers. [...]...

Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure

Summary

Note: This joint Cybersecurity Advisory is being published as an addition to the Cybersecurity and Infrastructure Security Agency (CISA) May 6, 2025, joint fact sheet

CISA Shares Lessons Learned from an Incident Response Engagement

Advisory at a Glance

Executive Summary CISA began incident response efforts at a U.S. federal civilian executive branch (FCEB) agency following the detection of potential malicious activity identified through security alerts generated by th...

Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System

Executive summary

People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks. While these actors focus ...

CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization

Summary

The Cybersecurity and Infrastructure Security Agency (CISA) and U.S. Coast Guard (USCG) are issuing this Cybersecurity Advisory to present findings from a recent CISA and USCG hunt engagement. The purpose of this advisory is to high...

#StopRansomware: Interlock

Summary

Note: This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include re...

CVE-2017-20187

** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file src/Magnesium/Message/Base.php. The manipulation of the argument email/name leads to ...

CVE-2017-7252

bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password....

CVE-2018-25092

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to addre...

CVE-2018-25093

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to address this issue. The na...

CVE-2020-28407

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall....

Tactical Forensics & Reputation

Indicator VT Verdict Origin Infrastructure
8.8.8.8
IPV4
0/93 Flags Ashburn, United States Google LLC
4b036cc9930bb42454172f888b8fde1087797fc0c9d31ab546748bd2496bd3e5
SHA256
2/76 Flags N/A N/A
fba4883bf4f73aa48a957d894051d78e0085ecc3170b1ff50e61ccec6aeee2cd
SHA256
0 detections N/A N/A
C20BABA26EBB596DE14B403B9F78DDC3C13CE9870EEA332476AC2C1DD582AA07
SHA256
0 detections N/A N/A
d0c1662ce239e4d288048c0e3324ec52962f6ddda77da0cb7af9c1d9c2f1e2eb
SHA256
20/76 Flags N/A N/A
18a507bf1c533aad8e6f2a2b023fbbcac02a477e8f05b095ee29b52b90d47421
SHA256
0 detections N/A N/A
1845a910dcde8c6e45ad2e0c48439e5ab8bbbeb731f2af11a1b7bbab3bfe0127
SHA256
54/76 Flags N/A N/A
7a43789216ce242524e321d2222fa50820a532e29175e0a2e685459a19e09069
SHA256
0/76 Flags N/A N/A
1a70f4eef11fbecb721b9bab1c9ff43a8c4cd7b2cafef08c033c77070c6fe069
SHA256
0/76 Flags N/A N/A
96babe53d6569ee3b4d8fc09c2a6557e49ebc2ed1b965abda0f7f51378557eb1
SHA256
0 detections N/A N/A
1d04e33009bcd017898b9e1387e40b5c04279c02ebc110f12e4a724ccdb9e4fb
SHA256
2/76 Flags N/A N/A
f2bbba1ea0f34b262f158ff31e00d39d89bbc471d04e8fca60a034cabe18e4f4
SHA256
33/76 Flags N/A N/A
a4069aa29628e64ea63b4fb3e29d16dcc368c5add304358a47097eedafbbb565
SHA256
0 detections N/A N/A
f51b3d054995803d04a754ea3ff7d31823fab654393e8054b227092580be43db
SHA256
0 detections N/A N/A
28c3c50d115d2b8ffc7ba0a8de9572fbe307907aaae3a486aabd8c0266e9426f
SHA256
40/76 Flags N/A N/A
2814b33ce81d2d2e528bb1ed4290d665569f112c9be54e65abca50c41314d462
SHA256
0 detections N/A N/A
e86bb8361c436be94b0901e5b39db9b6666134f23cce1e5581421c2981405cb1
SHA256
32/76 Flags N/A N/A
70EE22D394E107FBB807D86D187C216AD66B8537EDC67931559A8AEF18F6B5B3
SHA256
0 detections N/A N/A
a1abc3d11c16ae83b9a7cf62ebe6d144dfc5e19b579a99bad062a9d31cf30bfe
SHA256
0 detections N/A N/A
da692ea0b7f24e31696f8b4fe8a130dbbe3c7c15cea6bde24cccc1fb0a73ae9e
SHA256
0 detections N/A N/A
A4F0B68052E8DA9A80B70407A92400C6A5DEF19717E0240AC608612476E1137E
SHA256
47/76 Flags N/A N/A
94bf0aba5f9f32b9c35e8dfc70afd8a35621ed6ef084453dc1b10719ae72f8e2
SHA256
0 detections N/A N/A
c733d85f445004c9d6918f7c09a1e0d38a8f3b37ad825cd544b865dba36a1ba6
SHA256
0 detections N/A N/A
8eb7e3e8f3ee31d382359a8a232c984bdaa130584cad11683749026e5df1fdc3
SHA256
0/76 Flags N/A N/A
7b9e12e3561285181634ab32015eb653ab5e5cfa157dd16cdd327104b258c332
SHA256
0 detections N/A N/A
078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b
SHA256
2/76 Flags N/A N/A
64a0ab00d90682b1807c5d7da1a4ae67cde4c5757fc7d995d8f126f0ec8ae983
SHA256
48/76 Flags N/A N/A
8b448f47e36909f3a921b4ff803cf3a61985d8a10f0fe594b405b92ed0fc21f1
SHA256
0 detections N/A N/A
FAFCD5404A992850FFCFFEE46221F9B2FF716006AECB637B80E5CD5AA112D79C
SHA256
0 detections N/A N/A
44887125aa2df864226421ee694d51e5535d8c6f70e327e9bcb366e43fd892c1
SHA256
0 detections N/A N/A
a70af759e38219ca3a7f7645f3e103b13c9fb1db6d13b68f3d468b7987540ddf
SHA256
0 detections N/A N/A
d535bdc9970a3c6f7ebf0b229c695082a73eaeaf35a63cd8a0e7e6e3ceb22795
SHA256
0 detections N/A N/A
88f26f3721076f74996f8518469d98bf9be0eaee5b9eccc72867ebfc25ea4e83
SHA256
36/76 Flags N/A N/A
e4d6fe517cdf3790dfa51c62457f5acd8cb961ab1f083de37b15fd2fddeb9b8f
SHA256
0 detections N/A N/A
ff7ad2376ae01e4b3f1e1d7ae630f87b8262b5c11bc5d953e1ac34ffe81401b5
SHA256
0 detections N/A N/A
dfb5ba578b81f05593c047f2c822eeb03785aecffb1504dcb7f8357e898b5024
SHA256
0 detections N/A N/A
68A49D5A097E3850F3BB572BAF2B75A8E158DADB70BADDC205C2628A9B660E7A
SHA256
9/76 Flags N/A N/A
70bb799557da5ac4f18093decc60c96c13359e30f246683815a512d7f9824c8f
SHA256
0 detections N/A N/A
97931d2e2e449ac3691eb526f6f60e2f828de89074bdac07bd7dbdfd51af9fa0
SHA256
0/76 Flags N/A N/A
73a9a1e38ff40908bcc15df2954246883dadfb991f3c74f6c514b4cffdabde66
SHA256
0/76 Flags N/A N/A
C9F4C41C195B25675BFA860EB9B45945
MD5
40/76 Flags N/A N/A
de778443619f37e2224898a9a800fa78
MD5
0 detections N/A N/A
eba9ae70d1b22de67b0eba160a6762d8
MD5
0 detections N/A N/A
B7B3647E06F23B9E83D0B1CCE3E71642
MD5
0 detections N/A N/A
feda15d3509b210cb05eacc22485a78c
MD5
0 detections N/A N/A
33e692f435d6cf3c637ba54836c63373
MD5
33/76 Flags N/A N/A
20b70dac937377b6d0699a44721acd80
MD5
0 detections N/A N/A
0777EA1D01DAD6DC261A6B602205E2C8
MD5
0 detections N/A N/A
64e3a3458b3286caaac821c343d4b208
MD5
35/76 Flags N/A N/A
Stopransomware.gov
DOMAIN
0/93 Flags N/A N/A
WinSCP-6.3.5-Setup.exe
DOMAIN
0 detections N/A N/A
www.mcafee.com
DOMAIN
0/93 Flags N/A N/A
ScreenConnect.ClientService.exe
DOMAIN
0 detections N/A N/A
autoservice.dll
DOMAIN
0 detections N/A N/A
www.hhs.gov
DOMAIN
0/93 Flags N/A N/A
blogs.microsoft.com
DOMAIN
0/93 Flags N/A N/A
AA25-203A-interlock-stix.json
DOMAIN
0 detections N/A N/A
qrpce91.exe.asd
DOMAIN
0 detections N/A N/A
stopransomware.gov
DOMAIN
0/93 Flags N/A N/A
cleanup.dll
DOMAIN
0 detections N/A N/A
20Activity.jpg
DOMAIN
0 detections N/A N/A
KrebsOnSecurity.com
DOMAIN
0/93 Flags N/A N/A
Handx.ashx
DOMAIN
0 detections N/A N/A
20NVIC.pdf
DOMAIN
0 detections N/A N/A
www.energy.gov
DOMAIN
0/93 Flags N/A N/A
t.py
DOMAIN
0/93 Flags N/A N/A
iexplore.exe
DOMAIN
0 detections N/A N/A
Starship.exe
DOMAIN
0 detections N/A N/A
www.europol.europa.eu
DOMAIN
0/93 Flags N/A N/A
siet.py
DOMAIN
0/93 Flags N/A N/A
www.etsi.org
DOMAIN
0/93 Flags N/A N/A
Webex.exe
DOMAIN
0 detections N/A N/A
362.html
DOMAIN
0 detections N/A N/A
skw.gov.pl
DOMAIN
0/93 Flags N/A N/A
cas.docs.cisecurity.org
DOMAIN
0/93 Flags N/A N/A
bfv.bund.de
DOMAIN
0/93 Flags N/A N/A
linux-exploit-suggester2.pl
DOMAIN
1/93 Flags N/A N/A
www.idfa.org
DOMAIN
0/93 Flags N/A N/A
RingQ.exe
DOMAIN
0 detections N/A N/A
pages.nist.gov
DOMAIN
0/93 Flags N/A N/A
www.ic3.gov
DOMAIN
0/93 Flags N/A N/A
StorageExplorer.exe
DOMAIN
0 detections N/A N/A
www.cyber.gov.au
DOMAIN
0/93 Flags N/A N/A
www.epa.gov
DOMAIN
0/93 Flags N/A N/A
hhs.gov
DOMAIN
0/93 Flags N/A N/A
github.com
DOMAIN
0/93 Flags N/A N/A
SophosendpointAgent.exe
DOMAIN
0 detections N/A N/A
applicationHost.config
DOMAIN
0 detections N/A N/A
smtp.gc.ca
DOMAIN
0/93 Flags N/A N/A
NIST.SP
DOMAIN
0 detections N/A N/A
klg.dll
DOMAIN
0 detections N/A N/A
Autostart.exe
DOMAIN
0 detections N/A N/A
FortiClient.exe
DOMAIN
0 detections N/A N/A
cyber.gov.au
DOMAIN
0/93 Flags N/A N/A
www.nsa.gov
DOMAIN
0/93 Flags N/A N/A
agent.tar
DOMAIN
0 detections N/A N/A
map.tcl
DOMAIN
0 detections N/A N/A
ld-linux-x86-64.so
DOMAIN
0/93 Flags N/A N/A
220270-use-cisco-ios-xe-hardening-guide.html
DOMAIN
0 detections N/A N/A
webujgd.lnk
DOMAIN
0 detections N/A N/A
RingQ.rar
DOMAIN
0 detections N/A N/A
bnd.bund.de
DOMAIN
0/93 Flags N/A N/A
cisa.dhs.gov
DOMAIN
0/93 Flags N/A N/A
fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
DOMAIN
0 detections N/A N/A
assets.publishing.service.gov.uk
DOMAIN
0/93 Flags N/A N/A
sp800-63b.html
DOMAIN
0 detections N/A N/A
Sysmon.sys
DOMAIN
0 detections N/A N/A
tclproxy.tcl
DOMAIN
0 detections N/A N/A
main.go
DOMAIN
0 detections N/A N/A
t1.sh
DOMAIN
0/93 Flags N/A N/A
www.tripwire.com
DOMAIN
0/93 Flags N/A N/A
jar.jar
DOMAIN
0 detections N/A N/A
www.cisco.com
DOMAIN
0/93 Flags N/A N/A
clickfix-attacks-sector-alert-tlpclear.pdf
DOMAIN
0 detections N/A N/A
pack.jar
DOMAIN
0 detections N/A N/A
iox.rar
DOMAIN
0 detections N/A N/A
learn.microsoft.com
DOMAIN
0/93 Flags N/A N/A
www.isa.org
DOMAIN
0/93 Flags N/A N/A
resolv.conf
DOMAIN
0 detections N/A N/A
web.xml
DOMAIN
0 detections N/A N/A
13608-21.html
DOMAIN
0 detections N/A N/A
AA25-203A-interlock-stix.xml
DOMAIN
0 detections N/A N/A
nukib.gov.cz
DOMAIN
0/93 Flags N/A N/A
20DEVICES.PDF
DOMAIN
0 detections N/A N/A
conhost.exe
DOMAIN
0 detections N/A N/A
www.cve.org
DOMAIN
0/93 Flags N/A N/A
myservices.cisa.gov
DOMAIN
0/93 Flags N/A N/A
AnyDesk.exe
DOMAIN
0 detections N/A N/A
blog.sekoia.io
DOMAIN
0/93 Flags N/A N/A
start.exe
DOMAIN
0 detections N/A N/A
RinqQ.exe
DOMAIN
0 detections N/A N/A
c.bat
DOMAIN
0 detections N/A N/A
best-practices-for-event-logging-and-threat-detection.pdf
DOMAIN
0 detections N/A N/A
putty.exe
DOMAIN
0 detections N/A N/A
20CTIME.pdf
DOMAIN
0 detections N/A N/A
20METHODOLOGY.PDF
DOMAIN
0 detections N/A N/A
niccs.cisa.gov
DOMAIN
0/93 Flags N/A N/A
autorun.log
DOMAIN
0 detections N/A N/A
blog.talosintelligence.com
DOMAIN
0/93 Flags N/A N/A
ncsc.govt.nz
DOMAIN
0/93 Flags N/A N/A
www.ofcom.org.uk
DOMAIN
0/93 Flags N/A N/A
hygiene-improvement-after-conducting-proactive-threat-hunt-508c.pdf
DOMAIN
0 detections N/A N/A
cyber.go.jp
DOMAIN
0/93 Flags N/A N/A
ASP.NET
DOMAIN
0/93 Flags N/A N/A
agentu.exe
DOMAIN
0 detections N/A N/A
cyber.nsa.gov
DOMAIN
0/93 Flags N/A N/A
media.defense.gov
DOMAIN
0/93 Flags N/A N/A
cyber.int
DOMAIN
0/93 Flags N/A N/A
ApplicationHost.config
DOMAIN
0 detections N/A N/A
tar.gz
DOMAIN
0 detections N/A N/A
20copy.pdf
DOMAIN
0 detections N/A N/A
TCLproxy.tcl
DOMAIN
0 detections N/A N/A
conhost.txt
DOMAIN
0 detections N/A N/A
attack.mitre.org
DOMAIN
0/93 Flags N/A N/A
www.uscg.mil
DOMAIN
0/93 Flags N/A N/A
Ivanti-Secure-Access-Client.exe
DOMAIN
0 detections N/A N/A
CSA-CISCO-SMART-INSTALL-PROTOCOL-MISUSE.PDF
DOMAIN
0 detections N/A N/A
Base.php
DOMAIN
0 detections N/A N/A
uscg.mil
DOMAIN
0/93 Flags N/A N/A
Rar.exe
DOMAIN
0 detections N/A N/A
d3fend.mitre.org
DOMAIN
0/93 Flags N/A N/A
us.af.mil
DOMAIN
0/93 Flags N/A N/A
GlobalProtect.exe
DOMAIN
0 detections N/A N/A
cwe.mitre.org
DOMAIN
0/93 Flags N/A N/A
www.fbi.gov
DOMAIN
0/93 Flags N/A N/A
cht.exe
DOMAIN
0 detections N/A N/A
1.txt
DOMAIN
0 detections N/A N/A
PuTTYPortable.zip
DOMAIN
0/93 Flags N/A N/A
aa.sh
DOMAIN
0/93 Flags N/A N/A
aa25-203a-stopransomware-interlock-072225.pdf
DOMAIN
0 detections N/A N/A
cyber.gc.ca
DOMAIN
0/93 Flags N/A N/A
nsarchive.gwu.edu
DOMAIN
0/93 Flags N/A N/A
aaa.zip
DOMAIN
0/93 Flags N/A N/A
mycap.pcap
DOMAIN
0 detections N/A N/A
www.bleepingcomputer.com
DOMAIN
0/93 Flags N/A N/A
Last.txt
DOMAIN
0 detections N/A N/A
ofcom.org.uk
DOMAIN
0/93 Flags N/A N/A
PuTTY.exe
DOMAIN
0 detections N/A N/A
puttyportable.exe
DOMAIN
0 detections N/A N/A
doi.org
DOMAIN
0/93 Flags N/A N/A
rundll32.exe
DOMAIN
0 detections N/A N/A
www.cisa.gov
DOMAIN
0/93 Flags N/A N/A
supo.fi
DOMAIN
0/93 Flags N/A N/A
SophosScaner.exe
DOMAIN
0 detections N/A N/A
bsi.bund.de
DOMAIN
0/93 Flags N/A N/A
report.ncsc.gov.uk
DOMAIN
0/93 Flags N/A N/A
mm.sh
DOMAIN
0/93 Flags N/A N/A
nsa.gov
DOMAIN
0/93 Flags N/A N/A
Cisco-Secure-Client.exe
DOMAIN
0 detections N/A N/A
Policies.cfm
DOMAIN
0 detections N/A N/A
95.html
DOMAIN
0 detections N/A N/A
1.pcap
DOMAIN
0 detections N/A N/A
sec.cloudapps.cisco.com
DOMAIN
0/93 Flags N/A N/A
web.config
DOMAIN
0 detections N/A N/A
guidance-mobile-communications-best-practices.pdf
DOMAIN
0 detections N/A N/A
www.ncsc.gov.uk
DOMAIN
0/93 Flags N/A N/A
www.legislation.gov.uk
DOMAIN
0/93 Flags N/A N/A
www.sicurezzanazionale.gov.it
DOMAIN
0/93 Flags N/A N/A
difxepi.dll
DOMAIN
0 detections N/A N/A
tac.pcap
DOMAIN
0 detections N/A N/A
www.cisecurity.org
DOMAIN
0/93 Flags N/A N/A
cisa.gov
DOMAIN
0/93 Flags N/A N/A
www.naruc.org
DOMAIN
0/93 Flags N/A N/A
AnyConnectVPN.exe
DOMAIN
0 detections N/A N/A
commands.log
DOMAIN
0 detections N/A N/A
aw.gov.pl
DOMAIN
0/93 Flags N/A N/A
csrc.nist.gov
DOMAIN
0/93 Flags N/A N/A
machine.config
DOMAIN
0 detections N/A N/A
www.darkreading.com
DOMAIN
0/93 Flags N/A N/A
www.cnss.gov
DOMAIN
0/93 Flags N/A N/A
agent.zip
DOMAIN
0/93 Flags N/A N/A
DC3.DCISE
DOMAIN
0 detections N/A N/A
tmp41.wasd
DOMAIN
0 detections N/A N/A
cisecurity.org
DOMAIN
0/93 Flags N/A N/A
conhost.dll
DOMAIN
0 detections N/A N/A
mail.cisa.dhs.gov
DOMAIN
0/93 Flags N/A N/A
Aisa.exe
DOMAIN
0 detections N/A N/A
www.securityweek.com
DOMAIN
0/93 Flags N/A N/A
PsExec.exe
DOMAIN
0 detections N/A N/A
processhacker-2.39-bin.zip
DOMAIN
0/93 Flags N/A N/A
CVE-2024-21887
CVE
N/A N/A N/A
CVE-2024-3400
CVE
N/A N/A N/A
CVE-2026-24061
CVE
N/A N/A N/A
CVE-2024-36401
CVE
N/A N/A N/A
CVE-2018-0171
CVE
N/A N/A N/A
CVE-2026-21962
CVE
N/A N/A N/A
CVE-2016-5195
CVE
N/A N/A N/A
CVE-2023-20273
CVE
N/A N/A N/A
CVE-2023-20198
CVE
N/A N/A N/A
CVE-2026-1731
CVE
N/A N/A N/A
CVE-2023-46805
CVE
N/A N/A N/A

🛡️ Defensive Guidance

  • Network: Block all listed IP indicators at perimeter firewalls/WAFs.
  • Endpoint: Hunt for file hashes across EDR (CrowdStrike/SentinelOne).
  • Identity: Monitor for unusual authentication attempts from identified Geo-Origins.

This report was autonomously generated by CyberDudeBivash Sentinel APEX.

© 2026 CyberDudeBivash Pvt Ltd | STIX ID: CDB-APEX-1771097541

POWERED BY SENTINEL APEX
Get Full Threat Intelligence Access
Live CVE feeds, APT tracking, malware analysis, AI summaries & enterprise SOC integration
▸▸ LATEST THREAT ADVISORIES
⎯⎯⎯ NAVIGATE INTELLIGENCE REPORTS ⎯⎯⎯