← Back to Pulse Feed
PULSE DETAIL
The investigation into the EmEditor supply chain attack, highlighted in a report by Trend Micro, revolves around a rare type of cyber threat known as a watering hole attack, which specifically targets users of the EmEditor software. This tactic typically involves compromising websites frequented by the intended victims to serve malicious content or payloads.
During the analysis phase, passive DNS resolution techniques were employed to trace additional IPs associated with the attack. The initial examination did not reveal any further URLs directly related to the command and control (C2) server identified by Trend Micro, which was http://cachingdrive.com, particularly the URL path "/gate/init". However, the investigation led to the discovery of a different domain with the path "/gate/start/", linked to a suspicious URL: hxxp://nc7d8p7u8j3n4hgm.com/gate/start/efeb550a. This suggests a potential expansion of the attack's infrastructure or alternative entry points.
Indicators of Compromise (23)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| CVE | CVE-2026-21858 | — | 2026-02-16 | |
| FileHash-MD5 | 7db4d84e579f0aad131bf32d55abf267 | MD5 of ceb31976b8040cad5d5db3856466d198d3c0ea5bc904ae05c509b3b6de72e1c8 | 2026-02-16 | |
| FileHash-MD5 | b97d5024adab17ceffe134f9ea877bf5 | — | 2026-02-16 | |
| FileHash-MD5 | d3c0ea5bc904ae05c509b3b6de72e1c8 | — | 2026-02-16 | |
| FileHash-SHA1 | 4c873cb2b661b9356a32eae67a5bf76177be4b1c | SHA1 of ceb31976b8040cad5d5db3856466d198d3c0ea5bc904ae05c509b3b6de72e1c8 | 2026-02-16 | |
| FileHash-SHA256 | ceb31976b8040cad5d5db3856466d198d3c0ea5bc904ae05c509b3b6de72e1c8 | — | 2026-02-16 | |
| URL | http://nc7d8p7u8j3n4hgm.com/gate/start/efeb550a. | — | 2026-02-16 | |
| URL | http://validin.com/ | — | 2026-02-16 | |
| URL | https://keyactivate.cc:443/gate/start/e805d522 | — | 2026-02-16 | |
| URL | https://n8n.kraski-event.ru:443/gate/start/e805d522 | — | 2026-02-16 | |
| URL | https://nc7d8p7u8j3n4hgm.com/gate/init/efeb550a/ | — | 2026-02-16 | |
| domain | cachingdrive.com | — | 2026-02-16 | |
| domain | emeditorde.com | — | 2026-02-16 | |
| domain | emeditorgb.com | — | 2026-02-16 | |
| domain | emeditorjapan.com | — | 2026-02-16 | |
| domain | emeditorjp.com | — | 2026-02-16 | |
| domain | emeditorltd.com | — | 2026-02-16 | |
| domain | emedjp.com | — | 2026-02-16 | |
| domain | emedorg.com | — | 2026-02-16 | |
| domain | keyactivate.cc | — | 2026-02-16 | |
| domain | nc7d8p7u8j3n4hgm.com | — | 2026-02-16 | |
| domain | validin.com | — | 2026-02-16 | |
| hostname | n8n.kraski-event.ru | — | 2026-02-16 |