Daily Cyber Threat Intel Brief — 2026-08-30
Generated: 2026-08-30 08:02:42 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=0, P2=5, P3=84, P4=161.
Highest-priority item: RansomLook: The University of Delhi (DU) claimed by dysphor1a (P2, source: RansomLook Recent Listings).
1 public IOC highlights selected for analyst awareness.
Priority technology watch items
P2 RansomLook: The University of Delhi (DU) claimed by dysphor1a — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: The University of Delhi (DU). Description excerpt: Sector: Education Sector | Country: 🇮🇳 India | Records: Student records with PII, academic data, and identification…
P2 RansomLook: Indonesian Police Database claimed by dysphor1a — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: Indonesian Police Database. Description excerpt: Sector: Government / Law Enforcement | Country: Indonesia | Records: 52,000 officer records + 4,000 facial photos |…
P2 RansomLook: Netim Company claimed by dysphor1a — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: Netim Company. Description excerpt: Sector: Business / Domain Registrar | Country: 🇫🇷 France | Records: Source code, IPs, payment databases, customer PII — full…
P2 RansomLook: General Gruppo claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: General Gruppo. Description excerpt: generalgruppo.it rocketreach.co/general-gruppo-profile_b68428f5c6158b62 General Gruppo / General s.r.l. is a family-owned…
P2 RansomLook: cutlercapital claimed by lynx — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: lynx. Claimed victim/listing: cutlercapital. Description excerpt: Cutler Capital Management, LLC of Worcester, MA is an investment advisory firm r...
Newly exploited vulnerabilities / CVE watch
None observed.
Ransomware and extortion trend notes
P2 RansomLook: The University of Delhi (DU) claimed by dysphor1a — Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: The University of Delhi (DU). Description excerpt: Sector: Education Sector | Country: 🇮🇳 India | Records: Student records with…
P2 RansomLook: Indonesian Police Database claimed by dysphor1a — Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: Indonesian Police Database. Description excerpt: Sector: Government / Law Enforcement | Country: Indonesia | Records: 52,000…
P2 RansomLook: Netim Company claimed by dysphor1a — Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: Netim Company. Description excerpt: Sector: Business / Domain Registrar | Country: 🇫🇷 France | Records: Source code, IPs, payment…
P2 RansomLook: General Gruppo claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: General Gruppo. Description excerpt: generalgruppo.it rocketreach.co/general-gruppo-profile_b68428f5c6158b62 General Gruppo /…
P2 RansomLook: cutlercapital claimed by lynx — Public RansomLook extortion-site listing claim. Group: lynx. Claimed victim/listing: cutlercapital. Description excerpt: Cutler Capital Management, LLC of Worcester, MA is an investment advisory firm r...
P3 RansomLook: LAPoco Architects claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: LAPoco Architects. Description excerpt: Architecture, Engineering & Design
P3 RansomLook: Magnolia Dental claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: Magnolia Dental. Description excerpt: Our practice is dedicated to providing exceptional dental services to Summerfield, FL, and the…
P3 RansomLook: Country Oaks Veterinary Clinic claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: Country Oaks Veterinary Clinic. Description excerpt: We were the first practice to become AAHA accredited in the area. Our…
P3 RansomLook: David King Architect claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: David King Architect. Description excerpt: We are an Architectural Firm and Design and prepare plans for almost any low rise…
P3 RansomLook: Woodside Ranch claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: Woodside Ranch. Description excerpt: Our motto is hard work and attention to detail. We are committed to giving young prospects the…
P3 RansomLook: Stoneybrook West Master Association, Inc claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: Stoneybrook West Master Association, Inc. Description excerpt: At Stoneybrook West, we plan regularly scheduled group physical…
P3 RansomLook: Stonecrest POA claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: Stonecrest POA. Description excerpt: Stonecrest POA, a United States-based property owners’ association.
Malware / infrastructure / abuse feed highlights
P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=185-100-157-222,sh,ua-wget; url=http://185.100.157.222/loader.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://112.225.112.61:47907/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://123.9.69.195:42280/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://39.71.13.220:39751/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=elf,iot,mirai,Mozi; url=http://39.89.242.234:38903/Mozi.m
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=elf,iot,mirai; url=http://168.222.254.23:889/agustin51
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot; url=http://190.123.46.208/bins.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_459f852b2ea61fd2.exe
P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://61.220.155.123:36328/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,mirai; url=http://190.123.46.208/Okami.mips
P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_7bce60f501d04523.exe
P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_4c685dc091836067.msi
IOC highlights
| Type | Value | Context | Source |
| ipv4 | `185.100.157.222` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=0 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=41
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: error: fetch failed for https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt: The read operation timed out
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=0 fetched=25
NVD Recent CVEs: ok new=68 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=17 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: error: syntax error: line 1, column 0
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=30 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.