ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash 7ccf7e8050c66eed69f35159042d8043032f8afe48ae1f51fce75ce2c51395f2.

Database Entry


IOC ID:1767068
IOC: 7ccf7e8050c66eed69f35159042d8043032f8afe48ae1f51fce75ce2c51395f2
IOC Type :sha256_hash
Threat Type :payload
Malware: BEARDSHELL
Confidence Level : Confidence level is high (95%)
Is compromised? : False
First seen:2026-03-15 16:31:27 UTC
Last seen:never
UUID:ea3a6cc1-2086-11f1-9af6-42010aa4000a
Reporter Lenard
Reward 5 credits from ThreatFox
Tags:APT28 BeardShell Covenant CVE-2026-21509 GRU NotDoor Sednit
Reference: https://www.trellix.com/blogs/research/apt28-operation-phantom-net-voxel/

Avatar
Lenard
APT28 BeardShell/COVENANT campaign. Includes RTF exploits (CVE-2026-21509), NotDoor VBA backdoor (VbaProject.OTM), weaponized docs.