ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash 96ecc107aa645e36b5f939ebfcf9e61fc9ebc27616680fbd0fdeb41c7950d79a.

Database Entry


IOC ID:1836174
IOC: 96ecc107aa645e36b5f939ebfcf9e61fc9ebc27616680fbd0fdeb41c7950d79a
IOC Type :sha256_hash
Threat Type :payload
Malware: KV
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-06-23 06:51:54 UTC
Last seen:never
UUID:4aaa5e98-6e83-11f1-9258-42010aa4000a
Reporter Anonymous
Reward 5 credits from ThreatFox
Tags:botnet G1017 MIPS recon VoltTyphoon
Reference: https://github.com/yankywilson/jdy-tasking-decryption

Avatar
Anonymous
JDY reconnaissance botnet payloads/droppers (MIPS/MIPS64/MIPSEL, China-nexus, Volt Typhoon G1017). Tasking decryption recovered (base64 → AES-128-CBC → JSON). Decryptor + full RE: https://github.com/yankywilson/jdy-tasking-decryption