PULSE NAME
eScan Antivirus Update Server Compromised to Distribute Multi Stage Malware
WHITE cryptocti 2026-01-30 Modified: 2026-03-01
10
IOCs
LOW VOLUME
Threat actors compromised eScan's update infrastructure, delivering multi-stage malware to both enterprise and consumer systems.
Indicators of Compromise (10)
All FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 36ef2ec9ada035c56644f677dab65946798575e1d8b14f1365f22d7c68269860 2026-01-30
FileHash-SHA256 386a16926aff225abc31f73e8e040ac0c53fb093e7daf3fbd6903c157d88958c 2026-01-30
FileHash-SHA256 674943387cc7e0fd18d0d6278e6e4f7a0f3059ee6ef94e0976fae6954ffd40dd 2026-01-30
FileHash-SHA256 bec369597633eac7cc27a698288e4ae8d12bdd9b01946e73a28e1423b17252b1 2026-01-30
URL http://codegiant.io/dd/dd/dd.git/download/main/middleware.ts 2026-01-30
URL http://vhs.delrosal.net/i 2026-01-30
domain codegiant.io 2026-01-30
hostname 504e1a42.host.njalla.net 2026-01-30
hostname blackice.sol-domain.org 2026-01-30
hostname vhs.delrosal.net 2026-01-30