markcardiff.tech:/daily-intel/2026-08-31.html
Generated: 2026-08-31 08:00:27 UTC
P1: 0
P2: 1
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-31

Generated: 2026-08-31 08:00:27 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=0, P2=1, P3=31, P4=218.
  • Highest-priority item: RansomLook: Andover claimed by wallstreet (P2, source: RansomLook Recent Listings).
  • 1 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P2 RansomLook: Andover claimed by wallstreet — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: wallstreet. Claimed victim/listing: Andover. Description excerpt: The Town of Andover, Massachusetts, is a municipal government organization that provides public services, administration, community…

    Newly exploited vulnerabilities / CVE watch

  • None observed.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Andover claimed by wallstreet — Public RansomLook extortion-site listing claim. Group: wallstreet. Claimed victim/listing: Andover. Description excerpt: The Town of Andover, Massachusetts, is a municipal government organization that provides public…
  • P3 RansomLook: Westwing Group SE claimed by coinbase cartel — Public RansomLook extortion-site listing claim. Group: coinbase cartel. Claimed victim/listing: Westwing Group SE. Description excerpt: Furniture - $465.5 Million
  • P3 RansomLook: Directorate-General for Education claimed by panzer — Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Directorate-General for Education. Description excerpt: The Direção-Geral de Estatísticas da Educação e Ciência (DGEEC) is a…
  • P3 RansomLook: AFSARD claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: AFSARD. Description excerpt: Finance
  • P3 RansomLook: THQ Nordic claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: THQ Nordic.
  • P3 RansomLook: Erdem Hospital claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: Erdem Hospital.
  • P3 RansomLook: Hospital Clnico Universidad de Chile claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: Hospital Clnico Universidad de Chile.
  • P3 RansomLook: Crystalpharmatech claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Crystalpharmatech. Description excerpt: Business Services
  • P3 RansomLook: Absolute Consultancy Services claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Absolute Consultancy Services. Description excerpt: Business Services
  • P3 RansomLook: Black Cat Engineering Construction Wll claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Black Cat Engineering Construction Wll. Description excerpt: Civil Engineering Construction
  • P3 RansomLook: Company ID : mtfszhtggfdsg claimed by zawoo — Public RansomLook extortion-site listing claim. Group: zawoo. Claimed victim/listing: Company ID : mtfszhtggfdsg. Description excerpt: country: New Zealand | fileSize: 72009692411 | UNPUBLISHED
  • P3 RansomLook: Magnolia Dental claimed by orova — Public RansomLook extortion-site listing claim. Group: orova. Claimed victim/listing: Magnolia Dental. Description excerpt: Our practice is dedicated to providing exceptional dental services to Summerfield, FL, and the…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=.jar malware,hypixel,minecraft,trojan; url=https://taunahi.st/TaunahiLoader-26.2.jar
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=.jar malware,hypixel,minecraft,trojan; url=https://taunahi.st/TaunahiLoader-1.21.11-v4.2.5.jar
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://103.160.130.109:60664/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=adb,malware-download,shell-script; url=http://160.250.181.124/c8r3nv.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=SilverFox,ValleyRAT; url=https://download-sougou.com.cn/donwnload/sougouExpiorerr_Setup_x64_25537.zip
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=SilverFox,ValleyRAT; url=https://www.ryzhe.com/down88
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii; url=http://176.65.139.206/bins/w.sh
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=adb,malware-download,shell-script; url=http://160.250.181.124/b4k9zp.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=adb,malware-download,shell-script; url=http://160.250.181.124/a7m2qx.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=perl; url=http://147.182.224.216/zed
  • IOC highlights

    TypeValueContextSource
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=38
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=13 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=36 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.