Skip to content
Latest
QScan and QTRouter Show Why Proxy Infrastructure Is an Espionage Force MultipliervCenter Exploitation Shows Patching Alone Is Not Incident ResponseEdge Infrastructure Convergence Shows Why Perimeter Devices Need Their Own Patch SLAsSigned ClickOnce Lures Show Why Hiring Workflows Need Endpoint GuardrailsShieldBreak Shows Why Endpoint Protection Needs Compensating ControlsAI-Enabled Malware Still Behaves Like MalwarePrivate APNs Are Becoming OT Attack PathsvCenter Exploitation Shows Why Control Planes Need ContainmentApollo Breach Shows Why Helpdesk Vishing Is a Cloud-Control ProblemBTR.sys Shows Why Trusted Security Drivers Need Behavioral MonitoringWeedHack Shows SEO Poisoning Is Malware Delivery InfrastructureAI Agent Incidents Need Task-Scoped Incident ResponseSDLC Supply-Chain Attacks Show Why Developer Tools Need Runtime ControlsRussian Auth-Flow Phishing Shows MFA Can Be Bypassed Without Exploits

Indicator of Compromise

be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c

SHA-256 hash Seen in 2 reports Watch this →

A SHA-256 file hash identifying a specific malicious sample. Match it against files on disk or in your EDR.

Included in the Hashes feed (live, machine-readable).

Related indicators

Indicators that appear alongside this one in the same reporting, often shared infrastructure or the same campaign.

104[.]194[.]159[.]150 31[.]57[.]243[.]154 38[.]146[.]28[.]75 m365-owa[.]com ms365-device[.]com ms365-live[.]com owa-ms365[.]com 107[.]189[.]18[.]7107[.]189[.]26[.]194125752ad7c20d715920a3b2fb0fdde660f07b3f2b053665cf38c2d6d9de86e1e196[.]251[.]107[.]1711d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3c1e3ee845fde739fcd3ca9ce62c7f142a7c501d11db4c4fb294d4939f12d0f91620e20b074967ed6f6e04d609ccec5ff7492665ef25f894c90c2ddc92fa47ac38213[.]145[.]86[.]11228f622028e690c943f7fa9aca426c07cab52b5aaba757ef8a3328609c0b3bec32c7f4165967d6f7737b3fef87959846920b57a5368b531ad1427c7214d4c41a238[.]146[.]28[.]132403b624e35777cbc07dbe66398b21bba70396a20b859c880732338ce1dd1f41f5b8d50c2e8cc3038b7c6e6dbf1219f6e814930a1e3c0053143a1191ae67f8ffc6f7090895c1c3dee30de6b3f098ca3a788dc198646e5293a8b1210430b0add97918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593a06a8fd1b6fa1924199a4540cf16d089217ce8f78c617739946f145fd1fc88c1bounce@chamber-ua[.]orgc5826032207d623a7f6caec8465af7364eccc355f9a48897da2a54f3e4420265ca3be5885afb3eb3bb19341e2653212200c568f3f900e0b2f04de9ba209aed25chamber-ua[.]org CVE-2026-21509 dosportal[.]appdrive[.]google[.]verify-drive[.]comfewfwfwfwfwf[.]infofinishoperations[.]comfinishoperations[.]orgfoc-share[.]comfoc-share[.]orgforeignrelations[.]usglobsec[.]netinternal-share[.]commail[.]kiis[.]co[.]ukmioisiskwowiwjowuwjwolab[.]club

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.