markcardiff.tech:/daily-intel/2026-08-16.html
Daily Cyber Threat Intel Brief — 2026-08-16
Generated: 2026-08-16 08:00:34 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=0, P2=0, P3=17, P4=233.
No P1/P2 items were identified in this run.
2 public IOC highlights selected for analyst awareness.
Priority technology watch items
None.
Newly exploited vulnerabilities / CVE watch
None observed.
Ransomware and extortion trend notes
P3 RansomLook: TOTVS claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: TOTVS.
P3 RansomLook: Colla Health claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: Colla Health.
P3 RansomLook: PayrHealth claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: PayrHealth.
P3 RansomLook: DXS International claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: DXS International.
P3 RansomLook: DodoPayments claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: DodoPayments.
P3 RansomLook: AAM:HOA Management claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: AAM:HOA Management.
P3 RansomLook: servmarmg.cl (Chile, Valparaíso) claimed by ms13-089 — Public RansomLook extortion-site listing claim. Group: ms13-089. Claimed victim/listing: servmarmg.cl (Chile, Valparaíso). Description excerpt: Empresa con más de 25 años de experiencia en el rubro marítimo, orientada a…
P3 RansomLook: Alpine Electronics Europe claimed by panzer — Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Alpine Electronics Europe. Description excerpt: Alpine Electronics Europe specializes in the distribution of automotive electronics…
P3 RansomLook: SEARS (Grupo Sanborns) claimed by space bears — Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: SEARS (Grupo Sanborns). Description excerpt: SEARS (Grupo Sanborns, S.A. de C.V.) is a leading Mexican retail company and a key…
P3 RansomLook: Lepi Enterprises claimed by securotrop — Public RansomLook extortion-site listing claim. Group: securotrop. Claimed victim/listing: Lepi Enterprises. Description excerpt: If the company does not contact us before 20/08/2026, the data will be published.
P3 RansomLook: VR Advogados claimed by barracuda — Public RansomLook extortion-site listing claim. Group: barracuda. Claimed victim/listing: VR Advogados. Description excerpt: [upcoming] VR Advogados, a Brazilian law firm, neglected its clients’ personal data, violating…
P3 RansomLook: www.amca.org.ar claimed by blackwater — Public RansomLook extortion-site listing claim. Group: blackwater. Claimed victim/listing: www.amca.org.ar. Description excerpt: system breach, data blocking
Malware / infrastructure / abuse feed highlights
P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=script; url=http://103.77.246.150/loader.sh
P3 New Evooo1Bot Linux botnet turns routers into traffic relay nodes — A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://42.59.204.16:37885/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://116.140.186.83:34139/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://218.91.14.121:32924/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://125.44.181.178:58549/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://218.91.14.121:32924/bin.sh
P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://221.202.206.125:41411/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://125.44.181.178:58549/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://114.227.49.3:38196/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://114.227.49.3:38196/bin.sh
IOC highlights
| Type | Value | Context | Source |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `103.77.246.150` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=0 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=34
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=0 fetched=25
NVD Recent CVEs: ok new=13 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=0 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: ok new=0 fetched=10
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=49 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.