markcardiff.tech:/daily-intel/2026-08-02.html
Daily Cyber Threat Intel Brief — 2026-08-02
Generated: 2026-08-02 08:00:32 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=0, P2=0, P3=5, P4=245.
No P1/P2 items were identified in this run.
2 public IOC highlights selected for analyst awareness.
Priority technology watch items
None.
Newly exploited vulnerabilities / CVE watch
None observed.
Ransomware and extortion trend notes
P3 RansomLook: Philippine Savings Bank claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Philippine Savings Bank. Description excerpt: psbank.com.ph zoominfo.com/c/philippine-savings-bank/83461899 SBank is widely…
Malware / infrastructure / abuse feed highlights
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=apk ,mamont; url=https://svo-poiskrat.vercel.app/?download=1
P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,bash,sh,ua-wget; url=http://51.75.118.165/loader.sh
P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_27c28b4831967d60.exe
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://42.231.67.69:60846/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://42.231.67.69:60846/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://115.56.150.63:52973/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://105.186.248.213:50161/i
P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,Mozi; url=http://61.52.36.63:54993/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=54e64e,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_a0497afdd457f5f8.exe
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=elf,iot,mirai,Mozi; url=http://113.221.58.195:45339/Mozi.m
P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_60d2bd674d037b28.exe
IOC highlights
| Type | Value | Context | Source |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `51.75.118.165` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=0 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=34
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=0 fetched=25
NVD Recent CVEs: ok new=80 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=0 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: ok new=0 fetched=10
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=89 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.