OTX-69de00aae91f11a6bf2fbe68
info
📛 Threat Title
Q1 2026 Malware Statistics Report for Windows Database Servers
Description
During the first quarter of 2026, Windows-based MS-SQL and MySQL database servers experienced consistent malicious attacks with a temporary decrease in February before rising again in March. The primary threat actor, Larva-26002, leveraged various utilities including BCP, curl, bitsadmin, and PowerShell to deploy a Go-based scanner called ICE Cloud, which contained Turkish language strings and C&C-based scanning capabilities. This tool attempted MS-SQL authentication using predefined credentials. Attack methods primarily consisted of brute force attacks, dictionary attacks, and exploitation of unpatched systems with misconfigured accounts stemming from inadequate account management practices. Pulse contains 12 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (13)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
51.89.88.99
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/51.89.88.99
IOC database
- Type
- ipv4
- Value
51.89.88.99- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain hostroids.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/51.89.88.99
hash_md5
28847cb6859b8239f59cbf2b8f194770
IOC database
- Type
- hash_md5
- Value
28847cb6859b8239f59cbf2b8f194770- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
5200410ec674184707b731b697154522
IOC database
- Type
- hash_md5
- Value
5200410ec674184707b731b697154522- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
7fbbf16256c7c89d952fee47b70ea759
IOC database
- Type
- hash_md5
- Value
7fbbf16256c7c89d952fee47b70ea759- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
89bf428b2d9214a66e2ea78623e8b5c9
IOC database
- Type
- hash_md5
- Value
89bf428b2d9214a66e2ea78623e8b5c9- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
c031af92131cc5cef0be6fcb0804c2a84b976177
IOC database
- Type
- hash_sha1
- Value
c031af92131cc5cef0be6fcb0804c2a84b976177- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
0a9f2e2ff98e9f19428da79680e80b77
IOC database
- Type
- hash_md5
- Value
0a9f2e2ff98e9f19428da79680e80b77- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
hostroids.com
1 feed
IOC database
- Type
- domain
- Value
hostroids.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
10b31700a4a5ee1b673aa2a070d2908536ca2d9d
IOC database
- Type
- hash_sha1
- Value
10b31700a4a5ee1b673aa2a070d2908536ca2d9d- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
8d8c4b1f1f80b368340c6f4f45f35a49be794d45
IOC database
- Type
- hash_sha1
- Value
8d8c4b1f1f80b368340c6f4f45f35a49be794d45- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
6130a96f19ab4e3af5dfaf16fef8d8c176d9cc508b0422032ef4c18a4b65ef19
IOC database
- Type
- hash_sha256
- Value
6130a96f19ab4e3af5dfaf16fef8d8c176d9cc508b0422032ef4c18a4b65ef19- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
7ac9ea9f9d9a25c73d3267e7466cb0643f4e981bda36013ee9264feebe38b51c
IOC database
- Type
- hash_sha256
- Value
7ac9ea9f9d9a25c73d3267e7466cb0643f4e981bda36013ee9264feebe38b51c- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
9084885412af5ae242082869ebb204bcc855db4216bda0b399d06097d193aab9
IOC database
- Type
- hash_sha256
- Value
9084885412af5ae242082869ebb204bcc855db4216bda0b399d06097d193aab9- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- reference AlienVaulkt OTX
-
OTX pulse
AlienVaulkt OTX
During the first quarter of 2026, Windows-based MS-SQL and MySQL database servers experienced consistent malicious attacks with a temporary decrease in February before rising again in March. The primary threat actor, Larva-26002, leveraged various utilities including BCP, curl, bitsadmin, and PowerShell to deploy a Go-based scanner called ICE Cloud, which contained Turkish language strings and C&C-based scanning capabilities. This tool attempted MS-SQL authentication using predefined credentials
Remediations (8)
-
web:app.stationx.net
Discover 60+ malware statistics for 2026 — malware volume, mobile threats, cryptojacking, detection rates, and AI evasion from 20+ sources.
-
web:asec.ahnlab.com
this report summarizes the statistics of attacks targeting MS-SQL and MySQL servers installed on Windows and the malware used based on ASD logs for the first quarter of 2026 . Key statistics .
-
web:cloud.google.com
Explore M-Trends 2026 report for frontline data on the latest cyber threats, including ransomware recovery denial and extreme persistence.
-
web:deepstrike.io
Data-driven malware statistics for 2026 covering detections, malware categories, delivery vectors, sector exposure, and business impact with enterprise controls guidance.
-
web:securitricks.com
Description During the first quarter of 2026 , Windows -based MS-SQL and MySQL database servers experienced consistent malicious attacks with a temporary decrease in February before rising again in March. The primary threat actor, Larva-26002, leveraged various utilities including BCP, curl, bitsadmin, and PowerShell to deploy a Go-based scanner called ICE Cloud, which contained Turkish language ...
-
web:worldmetrics.org
Our in-depth market data report on Malware . Explore verified statistics and the latest research.
-
web:www.av-test.org
Provides visualizations of malware statistics that have happened in the last year, 2 years, 5 years, and 10 year time period.
-
web:www.microsoft.com
Report a security vulnerability or issue you have encountered with a Microsoft product or service. Access security best practices, documentation and guidance for protecting your environment. Access threat intelligence, analysis and mitigation guidance. Review security advisories and vulnerability disclosures to protect your organization ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.