// Investigation
Threat intelligence
Indicators are matched against the whole event window on every sweep, so intel added today surfaces telemetry already stored. Indicators at 60% confidence or above raise alerts; below that they enrich without adding to the queue.
6indicators6active0with sightings5feeds
Indicator feed
0 total sightings recorded across all indicators.
| On | Type | Indicator | Severity | Confidence | Context | Sightings | Last seen | Action |
|---|---|---|---|---|---|---|---|---|
| IP address | 185.100.200.50 | Critical | 95% | Source of the interactive logon in the jsmith takeover.Internal IR · takeover chain · Analyst | 0 | never | ||
| IP address | 45.137.21.9 | High | 80% | Reported command-and-control node, active in the last 30 days.Abuse.ch feed · Analyst | 0 | never | ||
| Domain | cdn-update-delivery.net | High | 75% | Payload staging domain masquerading as a content delivery host.Abuse.ch feed · Analyst | 0 | never | ||
| File hash | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | High | 70% | Loader observed alongside encoded PowerShell staging.Vendor advisory 2026-08 · Analyst | 0 | never | ||
| Domain | paste-share-quick.io | Medium | 45% | Paste site used for exfiltration in unrelated campaigns.OSINT · analyst submission · Analyst | 0 | never | ||
| User agent | python-requests/2.31 | Low | 30% | Scripted client. Common in automation as well as tooling, so it enriches rather than alerts.Internal baseline · Analyst | 0 | never |