← Back to Pulse Feed
PULSE DETAIL
During threat hunting activities conducted on the ANY.RUN platform, the artifact was identified in public submissions of the interactive sandbox. The analysis of samples available in the public repository allowed correlating hashes and network behaviors with the already mapped C2 infrastructure (24.152.36.241), confirming that the GrabBot/Slinky campaign is active and being distributed in a real environment. The sandbox results complement the static analysis presented in this report, providing dynamic execution evidence.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (2 / 6 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 9b1264eb4ff5ee8f00b8b80341fb6917dc3d3148 | — | 2026-04-30 | |
| FileHash-SHA1 | f9fe23f24d45eae418c60819c523a83ddba4ca50 | — | 2026-04-30 |