Skip to content
Latest
Session Cookie Bypass Shows Why SSO Is Not the Whole Trust BoundaryWarlock Ransomware Shows SharePoint Is Still Critical Infrastructure RiskFortiMail Zero-Day Shows Email Security Appliances Need Incident ResponseDragonForce TURN and MQTT Backdoors Show Why Ransomware Defense Needs Egress VisibilityTA419 Shows AI Policy Is Now an Espionage Phishing TargetAI Is Turning Vulnerability Triage Into a Threat-Intel Problem2CLoader Shows Why Malware Loader Alerts Need Identity ResponseZimbra CVE-2026-73570 Shows Mail Servers Need Full Incident ReviewRMM Phishing Turns Trusted Admin Tools Into Persistent AccessApache MINA SSHD Auth Bypasses Show Why Embedded SSH Needs InventoryCustom GPT ClickFix Shows Why AI Trust Needs Browser-to-Shell ControlsNetScaler Zero-Days Show Why Edge Devices Need Incident Response, Not Just PatchingNeedyMantis Shows Why Post-Compromise Malware Needs Full Intrusion ReviewPython MaaS Infostealer Builder Shows Why Credential Theft Needs Behavior Controls

IOC Passport

be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c

SHA-256 hashArticle-derived observationCurrent reporting windowReported in 2 articlesWatch this →

A SHA-256 file identifier extracted from published reporting. Match it against files on disk or in your EDR, then verify its current feed status before acting.

This value remains inside its 730-day file-identifier reporting window. Current reporting status is separate from verified-feed admission. Archive-cleared or archived does not mean clean, inactive, benign, remediated, resolved, or safe, and this lifecycle does not change current verified-feed admission.

Current verified-feed status

Checking live guard…

Article reporting and current malicious-feed admission are evaluated separately.

First reported
Last reported
Article count
2
Admission policy
bulwark-exact-malicious-v2
Research lifecycle
Current

Related indicators

Observables that appear alongside this one in the same reporting. Co-occurrence can suggest shared infrastructure, but it does not establish common ownership, campaign identity, or actor attribution.

104[.]194[.]159[.]15031[.]57[.]243[.]15438[.]146[.]28[.]75m365-owa[.]comms365-device[.]comms365-live[.]comowa-ms365[.]com107[.]189[.]18[.]7107[.]189[.]26[.]194125752ad7c20d715920a3b2fb0fdde660f07b3f2b053665cf38c2d6d9de86e1e196[.]251[.]107[.]1711d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3c1e3ee845fde739fcd3ca9ce62c7f142a7c501d11db4c4fb294d4939f12d0f91620e20b074967ed6f6e04d609ccec5ff7492665ef25f894c90c2ddc92fa47ac38213[.]145[.]86[.]11228f622028e690c943f7fa9aca426c07cab52b5aaba757ef8a3328609c0b3bec32c7f4165967d6f7737b3fef87959846920b57a5368b531ad1427c7214d4c41a238[.]146[.]28[.]132403b624e35777cbc07dbe66398b21bba70396a20b859c880732338ce1dd1f41f5b8d50c2e8cc3038b7c6e6dbf1219f6e814930a1e3c0053143a1191ae67f8ffc6f7090895c1c3dee30de6b3f098ca3a788dc198646e5293a8b1210430b0add97918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593a06a8fd1b6fa1924199a4540cf16d089217ce8f78c617739946f145fd1fc88c1bounce@chamber-ua[.]orgc5826032207d623a7f6caec8465af7364eccc355f9a48897da2a54f3e4420265ca3be5885afb3eb3bb19341e2653212200c568f3f900e0b2f04de9ba209aed25chamber-ua[.]orgCVE-2026-21509dosportal[.]appdrive[.]google[.]verify-drive[.]comfewfwfwfwfwf[.]infofinishoperations[.]comfinishoperations[.]orgfoc-share[.]comfoc-share[.]orgforeignrelations[.]usglobsec[.]netinternal-share[.]commail[.]kiis[.]co[.]ukmioisiskwowiwjowuwjwolab[.]club

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.