markcardiff.tech:/daily-intel/2026-08-30.html
Generated: 2026-08-30 08:02:42 UTC
P1: 0
P2: 5
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-30

Generated: 2026-08-30 08:02:42 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=0, P2=5, P3=84, P4=161.
  • Highest-priority item: RansomLook: The University of Delhi (DU) claimed by dysphor1a (P2, source: RansomLook Recent Listings).
  • 1 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P2 RansomLook: The University of Delhi (DU) claimed by dysphor1a — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: The University of Delhi (DU). Description excerpt: Sector: Education Sector | Country: 🇮🇳 India | Records: Student records with PII, academic data, and identification…

  • P2 RansomLook: Indonesian Police Database claimed by dysphor1a — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: Indonesian Police Database. Description excerpt: Sector: Government / Law Enforcement | Country: Indonesia | Records: 52,000 officer records + 4,000 facial photos |…

  • P2 RansomLook: Netim Company claimed by dysphor1a — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: Netim Company. Description excerpt: Sector: Business / Domain Registrar | Country: 🇫🇷 France | Records: Source code, IPs, payment databases, customer PII — full…

  • P2 RansomLook: General Gruppo claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: General Gruppo. Description excerpt: generalgruppo.it rocketreach.co/general-gruppo-profile_b68428f5c6158b62 General Gruppo / General s.r.l. is a family-owned…

  • P2 RansomLook: cutlercapital claimed by lynx — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: lynx. Claimed victim/listing: cutlercapital. Description excerpt: Cutler Capital Management, LLC of Worcester, MA is an investment advisory firm r...

    Newly exploited vulnerabilities / CVE watch

  • None observed.
  • Ransomware and extortion trend notes

  • P2 RansomLook: The University of Delhi (DU) claimed by dysphor1a — Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: The University of Delhi (DU). Description excerpt: Sector: Education Sector | Country: 🇮🇳 India | Records: Student records with…
  • P2 RansomLook: Indonesian Police Database claimed by dysphor1a — Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: Indonesian Police Database. Description excerpt: Sector: Government / Law Enforcement | Country: Indonesia | Records: 52,000…
  • P2 RansomLook: Netim Company claimed by dysphor1a — Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: Netim Company. Description excerpt: Sector: Business / Domain Registrar | Country: 🇫🇷 France | Records: Source code, IPs, payment…
  • P2 RansomLook: General Gruppo claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: General Gruppo. Description excerpt: generalgruppo.it rocketreach.co/general-gruppo-profile_b68428f5c6158b62 General Gruppo /…
  • P2 RansomLook: cutlercapital claimed by lynx — Public RansomLook extortion-site listing claim. Group: lynx. Claimed victim/listing: cutlercapital. Description excerpt: Cutler Capital Management, LLC of Worcester, MA is an investment advisory firm r...
  • P3 RansomLook: LAPoco Architects claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: LAPoco Architects. Description excerpt: Architecture, Engineering & Design
  • P3 RansomLook: Magnolia Dental claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: Magnolia Dental. Description excerpt: Our practice is dedicated to providing exceptional dental services to Summerfield, FL, and the…
  • P3 RansomLook: Country Oaks Veterinary Clinic claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: Country Oaks Veterinary Clinic. Description excerpt: We were the first practice to become AAHA accredited in the area. Our…
  • P3 RansomLook: David King Architect claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: David King Architect. Description excerpt: We are an Architectural Firm and Design and prepare plans for almost any low rise…
  • P3 RansomLook: Woodside Ranch claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: Woodside Ranch. Description excerpt: Our motto is hard work and attention to detail. We are committed to giving young prospects the…
  • P3 RansomLook: Stoneybrook West Master Association, Inc claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: Stoneybrook West Master Association, Inc. Description excerpt: At Stoneybrook West, we plan regularly scheduled group physical…
  • P3 RansomLook: Stonecrest POA claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: Stonecrest POA. Description excerpt: Stonecrest POA, a United States-based property owners’ association.
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=185-100-157-222,sh,ua-wget; url=http://185.100.157.222/loader.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://112.225.112.61:47907/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://123.9.69.195:42280/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://39.71.13.220:39751/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=elf,iot,mirai,Mozi; url=http://39.89.242.234:38903/Mozi.m
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=elf,iot,mirai; url=http://168.222.254.23:889/agustin51
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot; url=http://190.123.46.208/bins.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_459f852b2ea61fd2.exe
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://61.220.155.123:36328/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,mirai; url=http://190.123.46.208/Okami.mips
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_7bce60f501d04523.exe
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_4c685dc091836067.msi
  • IOC highlights

    TypeValueContextSource
    ipv4`185.100.157.222`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=41
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: error: fetch failed for https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt: The read operation timed out
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=68 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=17 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: error: syntax error: line 1, column 0
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=30 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.