























RedShark aggregates indicators of compromise from OTX (AlienVault), AbuseIPDB, ThreatFox (abuse.ch) and VirusTotal. The dominant attack vector observed is T1498 Network Denial of Service, with concentrated targeting of Kuala Lumpur and surrounding regions. Real attack severity and timing are mapped onto Malaysian ASN ranges (TM Net, Maxis, GovNet, TIME dotCom) to provide a localised SOC view; the most common indicator types observed are HASH, IP and DOMAIN.
Enforce DLP rules, monitor large outbound transfers, and disable unnecessary cloud storage / file-sharing endpoints.
114 high-severity indicators observed. Escalate to Tier-2 review and expand IOC blocklists across firewalls and EDR.
80 indicators (16.9%) target Kuala Lumpur. Issue a regional CERT-MY advisory and brief local infrastructure operators.
Distribute the 169 malicious hashes to AV / EDR vendors and run a retroactive sweep across endpoints.
Cross-validate signals from OTX, AbuseIPDB, ThreatFox and VirusTotal. Avoid single-source bias when triaging high-severity IOCs.
Enforce MFA, patch SLAs (critical ≤72h), least-privilege access, and weekly tabletop exercises against the top observed TTPs.
Force credential resets for accounts in regions with a high volume of brute-force / valid-account indicators and audit recent VPN logins.
Block source ranges feeding the top targeted IPs and rate-limit inbound traffic to Kuala Lumpur edge gateways.
| Target IP | ASN | Region | Incidents | Top Severity | Last Hit |
|---|---|---|---|---|---|
| 202.75.167.153 | AS4788 TM Net | Kuala Lumpur | 17 | critical | 2026-06-11 12:00 |
| 203.106.9.169 | AS24514 GovNet | Putrajaya | 12 | critical | 2026-06-11 12:11 |
| 203.106.190.172 | AS4788 TM Net | Kuala Lumpur | 12 | critical | 2026-06-11 11:55 |
| 175.137.158.188 | AS17971 TM-Sabah | Kota Kinabalu | 10 | critical | 2026-06-11 09:16 |
| 210.187.222.223 | AS4788 TM Net | Kuala Lumpur | 10 | critical | 2026-06-11 10:13 |
| 115.132.189.45 | AS17971 TM-Sabah | Kota Kinabalu | 10 | critical | 2026-06-11 11:30 |
| 180.74.189.57 | AS9534 Maxis | Johor Bahru | 9 | critical | 2026-06-11 11:27 |
| 218.111.235.41 | AS4788 TM Net | Kuantan | 9 | critical | 2026-06-11 11:30 |
| 203.106.185.1 | AS4788 TM Net | Kuala Lumpur | 9 | critical | 2026-06-11 09:00 |
| 180.74.142.126 | AS4788 TM Net | Kuala Lumpur | 9 | critical | 2026-06-11 11:28 |
| 113.210.134.1 | AS4788 TM Net | Kuantan | 8 | critical | 2026-06-11 09:44 |
| 121.121.185.32 | AS9930 TIME dotCom | Petaling Jaya | 8 | critical | 2026-06-11 12:00 |
| 218.111.63.253 | AS24514 GovNet | Cyberjaya | 8 | critical | 2026-06-11 12:00 |
| 115.132.95.192 | AS24514 GovNet | Putrajaya | 8 | critical | 2026-06-11 12:11 |
| 202.75.229.78 | AS9534 Maxis | Johor Bahru | 8 | critical | 2026-06-11 12:00 |
| 180.74.238.133 | AS4788 TM Net | Kuala Terengganu | 7 | critical | 2026-06-11 08:35 |
| 203.106.61.108 | AS4788 TM Net | Ipoh | 7 | critical | 2026-06-11 07:19 |
| 203.106.184.49 | AS17971 TM-Sabah | Sandakan | 7 | critical | 2026-06-11 09:43 |
| 121.121.46.244 | AS17971 TM-Sarawak | Miri | 7 | critical | 2026-06-11 10:52 |
| 180.74.33.32 | AS9930 TIME dotCom | Seremban | 6 | critical | 2026-06-11 08:34 |
| Indicator | Type | Severity | IOC Source | Source IP (Attacker) | Target IP (Malaysia) | Target Region | First Seen | Conf. |
|---|---|---|---|---|---|---|---|---|
| infra-telemetry.com | domain | medium | OTX | — | 175.137.158.188 | Kota Kinabalu | 05-12 08:51 | 62 |
| cloudservbr.com | domain | medium | OTX | — | 180.74.189.57 | Johor Bahru | 05-12 08:51 | 62 |
| a5c00451eb50fbafd0440d629fe153ed3e833d9df10d9932a273628438b8088d | hash | medium | OTX | — | 180.74.238.133 | Kuala Terengganu | 05-12 08:51 | 62 |
| 46b3efe9877f9d3e4fc4b9547ec213e75938397fdc30828857155238335973e7 | hash | medium | OTX | — | 218.111.235.41 | Kuantan | 05-12 08:51 | 62 |
| 1c37a58df996dd62449a76e49dd700d9d5fc70739179a92f3a86b6bdf4e1d87e | hash | medium | OTX | — | 113.210.134.1 | Kuantan | 05-12 08:51 | 62 |
| 2dbf48e7da928f88d37d5f3560838987a277eafed85612ad841b4edfa59944f3 | hash | medium | OTX | — | 203.106.185.1 | Kuala Lumpur | 05-12 08:51 | 62 |
| 3b72ef13049bea56198134de13ee54bfb3b327a19dcec20e2d70719bd4379e63 | hash | medium | OTX | — | 210.187.222.223 | Kuala Lumpur | 05-12 08:51 | 62 |
| 5209edb0076bbb0d08bfeb24fcd1eed714aa1038fe4c30921059bd3c95f83b72 | hash | medium | OTX | — | 203.106.9.169 | Putrajaya | 05-12 08:51 | 62 |
| thetruthinfo.com | domain | medium | OTX | — | 202.75.167.153 | Kuala Lumpur | 06-11 07:23 | 62 |
| catalystglobalsolutions.com | domain | medium | OTX | — | 115.132.189.45 | Kota Kinabalu | 06-11 07:23 | 62 |
| centrikglobalconsulting.com | domain | medium | OTX | — | 210.187.222.223 | Kuala Lumpur | 06-11 07:23 | 62 |
| cydfconsulting.com | domain | medium | OTX | — | 202.75.167.153 | Kuala Lumpur | 06-11 07:23 | 62 |
| finnaclevesperconsulting.com | domain | medium | OTX | — | 203.106.61.108 | Ipoh | 06-11 07:23 | 62 |
| geoindopacific.com | domain | medium | OTX | — | 175.137.158.188 | Kota Kinabalu | 06-11 07:23 | 62 |
| gpf-ina.org | domain | medium | OTX | — | 121.121.185.32 | Petaling Jaya | 06-11 07:23 | 62 |
| gulfpeace.org | domain | medium | OTX | — | 203.106.185.1 | Kuala Lumpur | 06-11 07:23 | 62 |
| msget.run | domain | medium | OTX | — | 218.111.235.41 | Kuantan | 06-10 16:22 | 62 |
| d4ug.site | domain | medium | OTX | — | 180.74.142.126 | Kuala Lumpur | 06-10 16:22 | 62 |
| 91.199.163.124 | ip | medium | OTX | 91.199.163.124 | 203.106.61.108 | Ipoh | 06-10 11:58 | 62 |
| 3a6adbe0081b2488e0f137496e92591e0c29148154b2d99faadab9cc435b879b | hash | medium | OTX | — | 202.75.167.153 | Kuala Lumpur | 06-10 11:58 | 62 |
| 79f8da9f9fb4ac7c16d9c210f1f6ef418357a3e7bf602b1dd03a490596fa58c5 | hash | medium | OTX | — | 218.111.63.253 | Cyberjaya | 06-10 11:58 | 62 |
| fb56e66920c84ef9e51db0ea23144f5755daef97cbff8613b05ab56d0dc9d623 | hash | medium | OTX | — | 203.106.184.49 | Sandakan | 06-10 11:58 | 62 |
| fbce30a0c852972fdc24f1b6a7c270512a50ef1a7c6c88c88b92a2dcbdfdd023 | hash | medium | OTX | — | 180.74.238.133 | Kuala Terengganu | 06-10 11:58 | 62 |
| CVE-2024-55591 | cve | critical | OTX | — | 218.111.63.253 | Cyberjaya | 06-10 11:58 | 88 |
| 3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235 | hash | critical | OTX | — | 203.106.61.108 | Ipoh | 06-10 11:58 | 88 |
| 4200b46a93c6ab059e2b34ce200c4a5b | hash | critical | OTX | — | 113.210.134.1 | Kuantan | 06-10 11:58 | 88 |
| 42bcc743c71a9ea083c1c750a398110582796762 | hash | critical | OTX | — | 180.74.189.57 | Johor Bahru | 06-10 11:58 | 88 |
| tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion | domain | critical | OTX | — | 218.111.63.253 | Cyberjaya | 06-10 11:58 | 88 |
| http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ | url | critical | OTX | — | 203.106.190.172 | Kuala Lumpur | 06-10 11:58 | 88 |
| ead0d7a8ae0a6ffb7f0a5873fec4ff5e | hash | critical | OTX | — | 203.106.9.169 | Putrajaya | 06-10 11:58 | 88 |
| 39bd9c888d3e8110c127ba60cc727d2538bf7da2 | hash | critical | OTX | — | 203.106.190.172 | Kuala Lumpur | 06-10 11:58 | 88 |
| https://install.app-distribution.net/setup/ | url | medium | OTX | — | 121.121.46.244 | Miri | 05-11 11:49 | 62 |
| a37f6403fbf28fa0b48863287f4c5a5d | hash | medium | OTX | — | 115.132.95.192 | Putrajaya | 05-11 11:49 | 62 |
| http://91.92.242.30/1v07y9e1m6v7thl6 | url | medium | OTX | — | 175.137.158.188 | Kota Kinabalu | 05-11 11:49 | 62 |
| http://91.92.242.30/6wioz8285kcbax6v | url | medium | OTX | — | 121.121.185.32 | Petaling Jaya | 05-11 11:49 | 62 |
| velvet-parrot.com | domain | medium | OTX | — | 210.187.222.223 | Kuala Lumpur | 05-11 11:49 | 62 |
| a396ec79d8e33ca984c7ffc7ee4d7d2caa8412ee | hash | medium | OTX | — | 203.106.190.172 | Kuala Lumpur | 05-11 11:49 | 62 |
| f0a54f2b44e557854b0a5001c4e10185884af945814786f78b86539014f78a16 | hash | medium | OTX | — | 121.121.185.32 | Petaling Jaya | 05-11 11:49 | 62 |
| b488d8d0cb6ee18af9e5800b66ff1ed9 | hash | medium | OTX | — | 180.74.238.133 | Kuala Terengganu | 05-11 11:49 | 62 |
| valid.boostedengagement.de | domain | high | OTX | — | 203.106.190.172 | Kuala Lumpur | 06-10 10:57 | 78 |
| log.evergreenhostingoptions.de | domain | high | OTX | — | 203.106.9.169 | Putrajaya | 06-10 10:57 | 78 |
| http://log.evergreenhostingoptions.de/UO95w/ | url | high | OTX | — | 115.132.95.192 | Putrajaya | 06-10 10:57 | 78 |
| login.av7551.com | domain | high | OTX | — | 180.74.33.32 | Seremban | 06-10 10:57 | 78 |
| http://login.av7551.com/common/oauth2/v2.0/authorize | url | high | OTX | — | 203.106.185.1 | Kuala Lumpur | 06-10 10:57 | 78 |
| login.kgbpkh6syhgxptsgwkqc93ushhphua422xb7ma.2bd.net | domain | high | OTX | — | 218.111.235.41 | Kuantan | 06-10 10:57 | 78 |
| admhr.execsuccessmetrics.de | domain | high | OTX | — | 203.106.184.49 | Sandakan | 06-10 10:57 | 78 |
| http://admhr.execsuccessmetrics.de/HOngH/ | url | high | OTX | — | 121.121.185.32 | Petaling Jaya | 06-10 10:57 | 78 |
| 03bbc4fa1fd784276da135ab62fef85aaddea66e6eb176d7e59c3398f818b153 | hash | high | OTX | — | 115.132.189.45 | Kota Kinabalu | 06-09 20:11 | 78 |
| b149948bf55a3313d8d355de6d663b7d | hash | high | OTX | — | 121.121.46.244 | Miri | 06-09 20:11 | 78 |
| 8cc4649a0f87a927d999ec352a65d88a0335a3cf | hash | high | OTX | — | 210.187.222.223 | Kuala Lumpur | 06-09 20:11 | 78 |
Made with Emergent