s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-69de00aae91f11a6bf2fbe68 info

📛 Threat Title

Q1 2026 Malware Statistics Report for Windows Database Servers

Category: Larva-26002 Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

During the first quarter of 2026, Windows-based MS-SQL and MySQL database servers experienced consistent malicious attacks with a temporary decrease in February before rising again in March. The primary threat actor, Larva-26002, leveraged various utilities including BCP, curl, bitsadmin, and PowerShell to deploy a Go-based scanner called ICE Cloud, which contained Turkish language strings and C&C-based scanning capabilities. This tool attempted MS-SQL authentication using predefined credentials. Attack methods primarily consisted of brute force attacks, dictionary attacks, and exploitation of unpatched systems with misconfigured accounts stemming from inadequate account management practices. Pulse contains 12 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (13)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 51.89.88.99 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/51.89.88.99

IOC database

Type
ipv4
Value
51.89.88.99
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain hostroids.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/51.89.88.99

hash_md5 28847cb6859b8239f59cbf2b8f194770

IOC database

Type
hash_md5
Value
28847cb6859b8239f59cbf2b8f194770
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 5200410ec674184707b731b697154522

IOC database

Type
hash_md5
Value
5200410ec674184707b731b697154522
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 7fbbf16256c7c89d952fee47b70ea759

IOC database

Type
hash_md5
Value
7fbbf16256c7c89d952fee47b70ea759
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 89bf428b2d9214a66e2ea78623e8b5c9

IOC database

Type
hash_md5
Value
89bf428b2d9214a66e2ea78623e8b5c9
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 c031af92131cc5cef0be6fcb0804c2a84b976177

IOC database

Type
hash_sha1
Value
c031af92131cc5cef0be6fcb0804c2a84b976177
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 0a9f2e2ff98e9f19428da79680e80b77

IOC database

Type
hash_md5
Value
0a9f2e2ff98e9f19428da79680e80b77
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain hostroids.com 1 feed

IOC database

Type
domain
Value
hostroids.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 10b31700a4a5ee1b673aa2a070d2908536ca2d9d

IOC database

Type
hash_sha1
Value
10b31700a4a5ee1b673aa2a070d2908536ca2d9d
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 8d8c4b1f1f80b368340c6f4f45f35a49be794d45

IOC database

Type
hash_sha1
Value
8d8c4b1f1f80b368340c6f4f45f35a49be794d45
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 6130a96f19ab4e3af5dfaf16fef8d8c176d9cc508b0422032ef4c18a4b65ef19

IOC database

Type
hash_sha256
Value
6130a96f19ab4e3af5dfaf16fef8d8c176d9cc508b0422032ef4c18a4b65ef19
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 7ac9ea9f9d9a25c73d3267e7466cb0643f4e981bda36013ee9264feebe38b51c

IOC database

Type
hash_sha256
Value
7ac9ea9f9d9a25c73d3267e7466cb0643f4e981bda36013ee9264feebe38b51c
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 9084885412af5ae242082869ebb204bcc855db4216bda0b399d06097d193aab9

IOC database

Type
hash_sha256
Value
9084885412af5ae242082869ebb204bcc855db4216bda0b399d06097d193aab9
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • reference AlienVaulkt OTX
  • OTX pulse AlienVaulkt OTX

    During the first quarter of 2026, Windows-based MS-SQL and MySQL database servers experienced consistent malicious attacks with a temporary decrease in February before rising again in March. The primary threat actor, Larva-26002, leveraged various utilities including BCP, curl, bitsadmin, and PowerShell to deploy a Go-based scanner called ICE Cloud, which contained Turkish language strings and C&C-based scanning capabilities. This tool attempted MS-SQL authentication using predefined credentials

Remediations (8)

  • web:app.stationx.net

    Discover 60+ malware statistics for 2026 — malware volume, mobile threats, cryptojacking, detection rates, and AI evasion from 20+ sources.

  • web:asec.ahnlab.com

    this report summarizes the statistics of attacks targeting MS-SQL and MySQL servers installed on Windows and the malware used based on ASD logs for the first quarter of 2026 . Key statistics .

  • web:cloud.google.com

    Explore M-Trends 2026 report for frontline data on the latest cyber threats, including ransomware recovery denial and extreme persistence.

  • web:deepstrike.io

    Data-driven malware statistics for 2026 covering detections, malware categories, delivery vectors, sector exposure, and business impact with enterprise controls guidance.

  • web:securitricks.com

    Description During the first quarter of 2026 , Windows -based MS-SQL and MySQL database servers experienced consistent malicious attacks with a temporary decrease in February before rising again in March. The primary threat actor, Larva-26002, leveraged various utilities including BCP, curl, bitsadmin, and PowerShell to deploy a Go-based scanner called ICE Cloud, which contained Turkish language ...

  • web:worldmetrics.org

    Our in-depth market data report on Malware . Explore verified statistics and the latest research.

  • web:www.av-test.org

    Provides visualizations of malware statistics that have happened in the last year, 2 years, 5 years, and 10 year time period.

  • web:www.microsoft.com

    Report a security vulnerability or issue you have encountered with a Microsoft product or service. Access security best practices, documentation and guidance for protecting your environment. Access threat intelligence, analysis and mitigation guidance. Review security advisories and vulnerability disclosures to protect your organization ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…