logo

Echoes of Stargazer Goblin: Analyzing Shared TTPs from an Open Directory

ID: 0bc74fe5-86b1-5ba0-9b38-796d186ce367

STIX ID: report--0bc74fe5-86b1-5ba0-9b38-796d186ce367

Feed Name: Hunt.io Blog

Threat Score
72/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report describes the discovery and analysis of an open directory (52.156.24.251) that hosted malicious HTML/HTA files, obfuscated VBScript, PowerShell scripts, donut-generated shellcode, and Sliver C2 components used to deliver and execute malware and perform data exfiltration; the authors document network and host IoCs and note similarities to Stargazer Goblin techniques but do not conclusively attribute the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.