16 indicators · scoped to malware families · back to OilRig
Live IOCs from URLhaus, ThreatFox, MalwareBazaar, and abuse.ch SSLBL for malware families this actor uses. All indicators are defanged for safe handling.
⚠
Indicators
16 of 16
url
hxxps://167.250.49.155/bin/x64/mimidrv.sys
family mimikatzsource urlhausfirst seen 2026-05-30T19:39:41Z