REDSHARK

Cyber Threat Intelligence Platform
2026-09-27 08:16:07 (GMT+8)Live Intel
Risk Posture
Elevated
Live Feed
CRITICALCVE-2026-85102cveOTX—
CRITICALhttp://192.162.199.149/uploads/d0f13ab7f8f848caa7df8c464d67912e.exeurlThreatFox—
CRITICALCVE-2026-85103cveOTX—
CRITICALhttp://62.197.62.195:60001/sshdurlThreatFox—
CRITICALCVE-2026-84869cveOTX—
CRITICALhttps://magistvapk.com.ar/file/magis-celular_vlatest_2.apkurlThreatFox—
CRITICALCVE-2026-76461cveOTX—
HIGHhttp://quiunch.click:6271/profilesurlThreatFox—
CRITICAL107.175.82.242ipOTXUnited States
CRITICAL39.96.203.222ipThreatFoxChina
CRITICAL193.178.159.128ipOTXFrance
CRITICAL45.131.3.38ipThreatFoxTurkey
CRITICAL06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90hashOTX—
CRITICAL64.188.59.224ipThreatFoxThe Netherlands
CRITICAL38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878hashOTX—
CRITICALhttp://107.161.168.217/?h=107.161.168.217&p=80&t=tcp&a=w32&stage=trueurlThreatFox—
MEDIUMbsc-dataseed1.ninicoin.iodomainOTX—
HIGHhttps://randombrosdatamines.pages.dev/Random.Project.exeurlThreatFox—
MEDIUMbsc-dataseed4.ninicoin.iodomainOTX—
CRITICAL7f2877c0400dcaf354e7de2848461abd959ad5d56f86d0e69fa7644ffa1287dahashThreatFox—
MEDIUMbsc-dataseed3.defibit.iodomainOTX—
CRITICALc458e443759ea633cde8929b4337726136675141d82251158f973f54008e20achashThreatFox—
MEDIUMbsc-dataseed4.defibit.iodomainOTX—
CRITICAL8630ccb0f78e12c7f7a283d49a34ff465c44ec994c874219d5c03bc7caf71abehashThreatFox—
MEDIUMbsc-dataseed3.ninicoin.iodomainOTX—
CRITICALa1d2d5253ae69788c0ab3ec33ca2cb49fac28a40dcb3526d5ee494877520ce10hashThreatFox—
MEDIUMbsc-dataseed2.ninicoin.iodomainOTX—
CRITICAL4b56b9f267d6dec2aeeb1b93af1acad6332e2fe3a484965bffce5b1fdc8b208ehashThreatFox—
MEDIUMbsc-dataseed2.defibit.iodomainOTX—
CRITICAL42b709ef46d6a65ebc390a70db367d3958652a519496d07b62eed461ecf22e69hashThreatFox—
CRITICALCVE-2026-85102cveOTX—
CRITICALhttp://192.162.199.149/uploads/d0f13ab7f8f848caa7df8c464d67912e.exeurlThreatFox—
CRITICALCVE-2026-85103cveOTX—
CRITICALhttp://62.197.62.195:60001/sshdurlThreatFox—
CRITICALCVE-2026-84869cveOTX—
CRITICALhttps://magistvapk.com.ar/file/magis-celular_vlatest_2.apkurlThreatFox—
CRITICALCVE-2026-76461cveOTX—
HIGHhttp://quiunch.click:6271/profilesurlThreatFox—
CRITICAL107.175.82.242ipOTXUnited States
CRITICAL39.96.203.222ipThreatFoxChina
CRITICAL193.178.159.128ipOTXFrance
CRITICAL45.131.3.38ipThreatFoxTurkey
CRITICAL06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90hashOTX—
CRITICAL64.188.59.224ipThreatFoxThe Netherlands
CRITICAL38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878hashOTX—
CRITICALhttp://107.161.168.217/?h=107.161.168.217&p=80&t=tcp&a=w32&stage=trueurlThreatFox—
MEDIUMbsc-dataseed1.ninicoin.iodomainOTX—
HIGHhttps://randombrosdatamines.pages.dev/Random.Project.exeurlThreatFox—
MEDIUMbsc-dataseed4.ninicoin.iodomainOTX—
CRITICAL7f2877c0400dcaf354e7de2848461abd959ad5d56f86d0e69fa7644ffa1287dahashThreatFox—
MEDIUMbsc-dataseed3.defibit.iodomainOTX—
CRITICALc458e443759ea633cde8929b4337726136675141d82251158f973f54008e20achashThreatFox—
MEDIUMbsc-dataseed4.defibit.iodomainOTX—
CRITICAL8630ccb0f78e12c7f7a283d49a34ff465c44ec994c874219d5c03bc7caf71abehashThreatFox—
MEDIUMbsc-dataseed3.ninicoin.iodomainOTX—
CRITICALa1d2d5253ae69788c0ab3ec33ca2cb49fac28a40dcb3526d5ee494877520ce10hashThreatFox—
MEDIUMbsc-dataseed2.ninicoin.iodomainOTX—
CRITICAL4b56b9f267d6dec2aeeb1b93af1acad6332e2fe3a484965bffce5b1fdc8b208ehashThreatFox—
MEDIUMbsc-dataseed2.defibit.iodomainOTX—
CRITICAL42b709ef46d6a65ebc390a70db367d3958652a519496d07b62eed461ecf22e69hashThreatFox—
Critical
69
High
52
Medium
70
Low
0
Total Active IOCs
191

Geospatial Threat Map

Global·Live

24H Incident Timeline

06131925
11:37
13:37
15:37
17:37
19:37
21:37
23:37
01:37
03:37
05:37
07:37
09:37
low
medium
high
critical

Executive AI Briefing

10:37

Malaysia Threat Posture — live indicators across the feed

RedShark aggregates indicators of compromise from multiple threat-intelligence feeds. The dominant attack vector observed is T1498 Network Denial of Service, with concentrated targeting of Kuala Lumpur and surrounding regions. Real attack severity and timing are mapped onto Malaysian ASN ranges to provide a localised SOC view; the most common indicator types observed are HASH, IP and DOMAIN.

Key Highlights
  • Top vector: T1498 Network Denial of Service
  • Most targeted region: Kuala Lumpur
  • Top sources: multiple threat-intelligence feeds
  • Hash + IP + Domain dominate the indicator mix

Recommended Actions

Stop unauthorised egress

Enforce DLP rules, monitor large outbound transfers, and disable unnecessary cloud storage / file-sharing endpoints.

MITRET1498

High severity surge

114 high-severity indicators observed. Escalate to Tier-2 review and expand IOC blocklists across firewalls and EDR.

SEVERITYHigh

Geographic concentration in Kuala Lumpur

80 indicators (16.9%) target Kuala Lumpur. Issue a regional CERT-MY advisory and brief local infrastructure operators.

REGIONKuala Lumpur

Update endpoint signatures

Distribute the 169 malicious hashes to AV / EDR vendors and run a retroactive sweep across endpoints.

CONTROLEndpoint

Diversify intelligence sources

Cross-validate signals across multiple threat-intelligence feeds. Avoid single-source bias when triaging high-severity IOCs.

COVERAGEMulti-source

Maintain proactive hardening

Enforce MFA, patch SLAs (critical ≤72h), least-privilege access, and weekly tabletop exercises against the top observed TTPs.

POSTUREBaseline

Rotate exposed credentials

Force credential resets for accounts in regions with a high volume of brute-force / valid-account indicators and audit recent VPN logins.

CONTROLIdentity

Apply network ACLs

Block source ranges feeding the top targeted IPs and rate-limit inbound traffic to Kuala Lumpur edge gateways.

CONTROLNetwork

Most Targeted IPs

MalaysiaLive MY
Target IPASNRegionIncidentsTop SeverityLast Hit
210.48.157.100AS17971 TM-SabahKota Kinabalu10critical2026-09-27 06:44
202.71.100.50AS17971 TM-SabahKota Kinabalu10critical2026-09-27 06:44
122.129.125.50AS24514 GovNetCyberjaya10critical2026-09-27 06:44
122.129.121.50AS24514 GovNetPutrajaya9critical2026-09-27 06:44
175.141.200.50AS4788 TM NetKuala Lumpur9critical2026-09-27 06:44
203.106.61.108AS4788 TM NetIpoh8critical2026-09-27 07:13
210.48.145.50AS17971 TM-SarawakMiri8critical2026-09-27 06:44
183.171.10.50AS10030 CelcomDigiShah Alam8critical2026-09-27 07:57
180.74.142.126AS4788 TM NetKuala Lumpur8critical2026-09-27 06:44
103.3.20.50AS10030 CelcomDigiKuala Lumpur8critical2026-09-27 07:05
27.125.224.50AS38466 U MobileKuala Lumpur8critical2026-09-27 06:44
202.168.69.152AS45410 Allo TechnologyCyberjaya7critical2026-09-27 06:44
49.236.198.50AS17971 TM-SabahSandakan7critical2026-09-27 06:43
202.185.188.41AS9930 AIMS GroupKuala Lumpur7high2026-09-27 06:44
180.74.238.133AS4788 TM NetKuala Terengganu6critical2026-09-27 06:43
124.195.130.50AS45960 YTL CommsKuala Lumpur6critical2026-09-27 06:44
211.25.111.50AS9930 TIME dotComSeremban6critical2026-09-27 06:44
183.78.10.5AS45960 YTL CommsCyberjaya6high09-24 22:09
122.0.30.50AS23678 MyKrisKuala Lumpur5critical2026-09-27 07:05
113.211.50.10AS9534 MaxisKuala Lumpur5critical2026-09-27 07:57

Top MITRE Attack Vectors

T1498Network Denial of Service
Impact
42
T1567Exfiltration Over Web Service
Exfiltration
37
T1566Phishing
Initial Access
36
T1059Command and Scripting Interpreter
Execution
34
T1071Application Layer Protocol
Command and Control
34
T1486Data Encrypted for Impact
Impact
31
T1110Brute Force
Credential Access
31
T1003OS Credential Dumping
Credential Access
31
T1499Endpoint Denial of Service
Impact
31
T1190Exploit Public-Facing Application
Initial Access
29

Recent Indicators of Compromise

IndicatorTypeSeverityIOC SourceSource IP (Attacker)Target IP (Malaysia)Target RegionFirst SeenConf.
api.cemg.xyzdomainhighOTX—202.185.188.41Kuala Lumpur08-28 02:25
78
CVE-2026-42271cvemediumOTX—180.74.238.133Kuala Terengganu08-27 22:16
62
CVE-2026-48710cvemediumOTX—203.106.61.108Ipoh08-27 22:16
62
CVE-2026-59822cvemediumOTX—210.48.157.100Kota Kinabalu08-27 22:16
62
http://185.62.1.8/mon/mon.zip'urlmediumOTX—210.48.145.50Miri08-27 22:16
62
crazyeltonproxy.topdomainmediumOTX—202.179.100.50Johor Bahru08-27 22:16
62
1710.rwlp.bedomainmediumOTX—183.171.10.50Shah Alam08-27 22:16
62
7e2e036fec2fe7ab4bbd43978d9296563894c92a112f5ac2f39957f12108e245hashmediumOTX—202.71.100.50Kota Kinabalu08-27 22:16
62
ae6c356f1f09260b859f84d994ef8423540a6c0bdf98510d86b85834283e4926hashmediumOTX—180.74.142.126Kuala Lumpur08-27 22:16
62
b77811db4d218c65670a6c9a5b33c30ff81c6d779e15d658643138771178a818hashmediumOTX—202.71.100.50Kota Kinabalu08-27 22:16
62
4309d107af6a23f4a7f841b9148258e1a280b972hashmediumOTX—103.3.20.50Kuala Lumpur08-27 22:16
62
681b57b6bf79ff0fdcfd19633586a6dcd3491651hashmediumOTX—180.74.142.126Kuala Lumpur08-27 22:16
62
www.ac-link.comdomainmediumOTX—122.129.125.50Cyberjaya08-27 22:16
62
www.findmyipaddr.comdomainmediumOTX—122.0.30.50Kuala Lumpur08-27 22:16
62
bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4hashmediumOTX—180.74.238.133Kuala Terengganu08-27 22:16
62
b9993a8ad0518849416798cf29668256ccb96598fc4423501ccab5312812653ahashmediumOTX—180.74.189.57Johor Bahru08-27 22:16
62
24b9ee242f21a73b55f7bb3297eafb33c60840907386b542ed79fc6b72365168hashmediumOTX—103.3.20.50Kuala Lumpur08-27 22:16
62
22bf76fe317ea6769bd38619bd440e42d119bd6bhashmediumOTX—124.195.130.50Kuala Lumpur08-27 22:16
62
c8cb3f6d5b90c46686d2bf531dc1a5786e27edc5hashmediumOTX—202.185.188.41Kuala Lumpur08-27 22:16
62
d602f4eeb914cf32782799376a8c5953hashmediumOTX—202.71.100.50Kota Kinabalu08-27 22:16
62
93d8cffab1171a115228808e526d9bd7fe935e4ehashmediumOTX—122.129.121.50Putrajaya08-27 22:16
62
d8a6b102c1715bd80393ce510931b1f6hashmediumOTX—103.3.20.50Kuala Lumpur08-27 22:16
62
apple-unlock.comdomainhighOTX—124.195.130.50Kuala Lumpur08-27 08:04
78
buscar-lphone.comdomainhighOTX—180.74.189.57Johor Bahru08-27 08:04
78
suporte-lcloud.comdomainhighOTX—113.211.50.10Kuala Lumpur08-27 08:04
78
com-maps.infodomainhighOTX—183.78.10.5Cyberjaya08-27 08:04
78
findmy-dispositivos.comdomainhighOTX—183.171.10.50Shah Alam08-27 08:04
78
id-ubicacion.comdomainhighOTX—123.136.96.50Subang Jaya08-27 08:04
78
findsupport.livedomainhighOTX—202.168.69.152Cyberjaya08-27 08:04
78
zu7pl.prodomainhighOTX—175.141.200.50Kuala Lumpur08-27 08:04
78
fileshareapp.orgdomainhighOTX—202.71.100.50Kota Kinabalu08-26 21:59
78
sharefolders.orgdomainhighOTX—124.195.130.50Kuala Lumpur08-26 21:59
78
formshare.clouddomainhighOTX—210.48.157.100Kota Kinabalu08-26 21:59
78
drive.google.sharefolders.orgdomainhighOTX—210.48.145.50Miri08-26 21:59
78
drive.google.formshare.clouddomainhighOTX—122.129.125.50Cyberjaya08-26 21:59
78
usercontent.onlinedomainhighOTX—49.236.198.50Sandakan08-26 21:59
78
drive.google.usercontent.onlinedomainhighOTX—180.74.189.57Johor Bahru08-26 21:59
78
fllefolder.comdomainhighOTX—210.48.157.100Kota Kinabalu08-26 21:59
78
CVE-2024-28000cvemediumOTX—113.23.200.50Subang Jaya08-26 17:18
62
fine-work-team.comdomainmediumOTX—27.125.224.50Kuala Lumpur08-26 17:18
62
timelevel12.comdomainmediumOTX—183.78.10.5Cyberjaya08-26 17:18
62
http://timelevel12.com/bigurlmediumOTX—103.3.20.50Kuala Lumpur08-26 17:18
62
snake.zooparkko.comdomainmediumOTX—49.236.198.50Sandakan08-26 17:18
62
CVE-2023-49105cvemediumOTX—180.74.238.133Kuala Terengganu08-26 17:18
62
10df3451915ea35bcb17efe121415f24182680e2d07fc09df07ee695072104c1hashmediumOTX—210.48.157.100Kota Kinabalu08-26 17:18
62
7447d0d0c34779d4c519823b39bf6ddc16d2b34a226b82ee69da6f5b4a77ad82hashmediumOTX—49.236.198.50Sandakan08-26 17:18
62
contabilidad.icudomainhighOTX—49.236.198.50Sandakan08-26 17:18
78
documentodigital.clouddomainhighOTX—183.171.10.50Shah Alam08-26 17:18
78
getpdfdigital.clouddomainhighOTX—202.185.188.41Kuala Lumpur08-26 17:18
78
soportedigital.clouddomainhighOTX—113.211.50.10Kuala Lumpur08-26 17:18
78