markcardiff.tech:/daily-intel/2026-08-17.html
Generated: 2026-08-17 08:00:15 UTC
P1: 0
P2: 5
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-17

Generated: 2026-08-17 08:00:15 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=0, P2=5, P3=36, P4=209.
  • Highest-priority item: URLhaus: malware_download URL observed (offline) (P2, source: URLhaus Recent URLs).
  • 11 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P2 URLhaus: malware_download URL observed (offline) — URLhaus Recent URLs; score 60; technologies: none explicitly matched.
  • - Public URLhaus recent URL. Threat=malware_download; tags=botnet,bruteforce,iran,mirai,ssh; url=http://31.77.227.119/cat.sh

  • P2 URLhaus: malware_download URL observed (offline) — URLhaus Recent URLs; score 60; technologies: none explicitly matched.
  • - Public URLhaus recent URL. Threat=malware_download; tags=botnet,bruteforce,iran,mirai,ssh; url=http://31.77.227.119/iran.armv7l

  • P2 RansomLook: Albania's official national teacher training portal. claimed by emperador — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: Albania's official national teacher training portal.. Description excerpt: Albania’s official national teacher training portal provides centralized professional…

  • P2 RansomLook: Albania's Official National Teacher Training Portal claimed by emperador — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: Albania's Official National Teacher Training Portal. Description excerpt: Albania’s official national teacher training portal provides centralized professional…

  • P2 RansomLook: Moscord claimed by eclipse — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: eclipse. Claimed victim/listing: Moscord. Description excerpt: Moscord is a digital marketplace that connects buyers and sellers in the maritime industry, offering a platform for various suppliers to…

    Newly exploited vulnerabilities / CVE watch

  • P3 CVE-2026-65769: CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-57104: CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-65767: CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Albania's official national teacher training portal. claimed by emperador — Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: Albania's official national teacher training portal.. Description excerpt: Albania’s official national teacher training portal…
  • P2 RansomLook: Albania's Official National Teacher Training Portal claimed by emperador — Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: Albania's Official National Teacher Training Portal. Description excerpt: Albania’s official national teacher training portal…
  • P2 RansomLook: Moscord claimed by eclipse — Public RansomLook extortion-site listing claim. Group: eclipse. Claimed victim/listing: Moscord. Description excerpt: Moscord is a digital marketplace that connects buyers and sellers in the maritime industry, offering…
  • P3 RansomLook: Moores 🇬🇧 claimed by bravox — Public RansomLook extortion-site listing claim. Group: bravox. Claimed victim/listing: Moores 🇬🇧. Description excerpt: Kitchen solutions provider for housing developers.
  • P3 RansomLook: Coface claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Coface. Description excerpt: Insurance
  • P3 RansomLook: Spoonful of Comfort claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Spoonful of Comfort. Description excerpt: Grocery Retail
  • P3 RansomLook: Teikoku USA claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Teikoku USA. Description excerpt: Manufacturing
  • P3 RansomLook: AGUNSA claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: AGUNSA. Description excerpt: Freight & Logistics Services
  • P3 RansomLook: Dynatrace claimed by xpl0itrs — Public RansomLook extortion-site listing claim. Group: xpl0itrs. Claimed victim/listing: Dynatrace. Description excerpt: AI observability platform
  • P3 RansomLook: Oz Hair & Beauty claimed by xpl0itrs — Public RansomLook extortion-site listing claim. Group: xpl0itrs. Claimed victim/listing: Oz Hair & Beauty. Description excerpt: Hair and beauty products
  • P3 RansomLook: ******* claimed by xpl0itrs — Public RansomLook extortion-site listing claim. Group: xpl0itrs. Claimed victim/listing: *******. Description excerpt: School management software
  • P3 RansomLook: RapidFort claimed by xpl0itrs — Public RansomLook extortion-site listing claim. Group: xpl0itrs. Claimed victim/listing: RapidFort. Description excerpt: Software supply chain security
  • Malware / infrastructure / abuse feed highlights

  • P2 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnet,bruteforce,iran,mirai,ssh; url=http://31.77.227.119/cat.sh
  • P2 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnet,bruteforce,iran,mirai,ssh; url=http://31.77.227.119/iran.armv7l
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=android,armv7l,botnet,maleware,mirai; url=http://31.77.227.115/meower.so
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=android,armv7l,botnet,maleware,mirai; url=http://31.77.227.115/Services.apk
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=android,armv7l,botnet,maleware,mirai; url=http://31.77.227.115/meower.arm7
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix; url=https://smsechodata.cc/run.bat
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,Mozi; url=http://42.233.30.71:57935/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix,exe; url=https://share.dovgertz.com/api/shares/AAWs5FQ3/files/322f1f5b-e04e-48f7-bf8e-91ad1bfeb2b4
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://117.131.92.150:58096/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://219.156.112.14:60974/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://42.238.236.39:56045/i
  • IOC highlights

    TypeValueContextSource
    ipv4`31.77.227.119`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    cve`CVE-2026-65769`CVE-2026-65769 Microsoft Teams iOS Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-57104`CVE-2026-57104 Azure Storage Explorer Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65767`CVE-2026-65767 Microsoft Teams for Android Spoofing VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`31.77.227.115`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    hash`dbe106197da13620f53ed5f2481b1970`RansomLook: actua.fr claimed by lockbit5RansomLook Recent Listings
    hash`7c703831ffe8b0b9761a08710d0af29d`RansomLook: dupouy-associes.fr claimed by lockbit5RansomLook Recent Listings
    hash`9a49a287d3e0d4a993de4fa5bd968a44`RansomLook: agricolagalbusera.it claimed by lockbit5RansomLook Recent Listings
    hash`29cde1b97f982e6e9517920e9b8ca365`RansomLook: tecosim.com claimed by lockbit5RansomLook Recent Listings
    hash`56802155da7ca00b8af929049da5fcf1`RansomLook: vgrn.de claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=34
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=15 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=2 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=120 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.