PULSE NAME
OSINT Volley 2026-02-05 - Unknown malware/Unknown Stealer/Cobalt Strike
WHITE pduggusa 2026-02-05 Modified: 2026-03-07
114
IOCs
HIGH VOLUME
Automated OSINT sweep from ThreatFox. Top malware: Unknown malware(67), Unknown Stealer(28), Cobalt Strike(20), Remcos(18), Lumma Stealer(17). Source: abuse.ch ThreatFox API. SSL enriched: 23 IPs with HTTPS, 18 self-signed (C2 candidates). Pattern 54: sweep→volley automation.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Unknown malware Unknown Stealer Cobalt Strike Remcos Lumma Stealer
Indicators of Compromise (11 / 114 total)
All hostname domain URL FileHash-SHA256 FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 b992e880fce09d09bd2ed7a172c592a20e211f31a116911174f20ac98b818cb0 ThreatFox: Mekotio - payload 2026-02-05
FileHash-SHA256 b7342b03d7642c894ebad639b9b53fd851d7958298f454283c18748051946585 ThreatFox: Unknown malware - payload 2026-02-05
FileHash-SHA256 be859b4f4576ec09b69a2ef2d119939f7eb31de121aa01d38e1f0b2290f5a15e ThreatFox: Unknown malware - payload 2026-02-05
FileHash-SHA256 c91183175ce77360006f964841eb4048cf37cb82103f2573e262927be4c7607f ThreatFox: Unknown malware - payload 2026-02-05
FileHash-SHA256 baad1153e58c86aa1dc9346cdd06be53b5dd2a6cf76202536d6721c934008f8e ThreatFox: Unknown malware - payload 2026-02-05
FileHash-SHA256 969d2776df0674a1cca0f74c2fccbc43802b4f2b62ecccecc26ed538e9565eae ThreatFox: Unknown malware - payload 2026-02-05
FileHash-SHA256 5a17cfaea0cc3a82242fdd11b53140c0b56256d769b07c33757d61e0a0a6ec02 ThreatFox: Unknown malware - payload 2026-02-05
FileHash-SHA256 e792adf4dff54faca5b9f5b32c1a2df3a6a955e722f1be8df2451c03ed940e41 ThreatFox: Unknown malware - payload 2026-02-05
FileHash-SHA256 d213b5079462e737eb940ac46c59e386eb6ca7f8decc95a594b3d8f3b6940010 ThreatFox: Unknown malware - payload 2026-02-05
FileHash-SHA256 1ed863a32372160b3a25549aad25d48d5352d9b4f58d4339408c4eea69807f50 ThreatFox: Unknown malware - payload 2026-02-05
FileHash-SHA256 968756e62052f9af80934b599994addbab29f8dc2615c47cda512bae48771019 ThreatFox: Unknown malware - payload 2026-02-05