Today's Core Dump is brought to you by ThreatPerspective

Threat Intelligence

Widespread Data Theft Targets Salesforce Instances via Salesloft Drift


A collection of indicators of compromise (IOCs) is available in a Google Threat Intelligence (GTI) collection for registered users.


Indicator Value

Description

Salesforce-Multi-Org-Fetcher/1.0

Malicious User-Agent string

Salesforce-CLI/1.0

Malicious User-Agent string

python-requests/2.32.4

User-Agent string

Python/3.11 aiohttp/3.12.15

User-Agent string

208.68.36.90

DigitalOcean

44.215.108.109

Amazon Web Services

154.41.95.2

Tor exit node

176.65.149.100

Tor exit node

179.43.159.198

Tor exit node

185.130.47.58

Tor exit node

185.207.107.130

Tor exit node

185.220.101.133

Tor exit node

185.220.101.143

Tor exit node

185.220.101.164

Tor exit node

185.220.101.167

Tor exit node

185.220.101.169

Tor exit node

185.220.101.180

Tor exit node

185.220.101.185

Tor exit node

185.220.101.33

Tor exit node

192.42.116.179

Tor exit node

192.42.116.20

Tor exit node

194.15.36.117

Tor exit node

195.47.238.178

Tor exit node

195.47.238.83

Tor exit node













Published: 2025-08-26T14:00:00











© Segmentation Fault . All rights reserved.

Privacy | Terms of Use | Contact Us