APTMembers
APT

Sandbox records IP lookup and requests for two server-hosted text files

A Windows executable’s sandbox report distinguishes an external-IP lookup from requests for two text-file paths on a separate server. It also records local executable output, but does not show what the server returned or link those requests to the written file.

Oct 4, 2026, 10:53 (UTC+9)Last seenOct 4, 2026Severity100ByCTX TeamActorTurlaIron HunterIOC31RegionsUS

A Windows executable’s sandbox report records requests to an external-IP lookup service and to two text-file paths on 178.16.54.109. The distinction matters: one destination has an identifiable address-discovery role, while the other is a concrete source of requested remote resources. What, exactly, did the program seek from that IP-hosted server—and does the report connect those requests to the executable files written locally?

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence