Weekly Threat Digest: 13 to JULY 19, 2026

Weekly Threat Advisory
Download Now
Weekly Threat Digest — 13 to 19 July 2026 | HiveForce Labs

HiveForce Labs · Weekly Threat Digest

Weekly Threat Digest: SonicWall SMA1000's CVSS 10.0 Zero-Day Chain, Balbooa Forms Under Active Exploitation, and Six New Attacks

Covering 13 to 19 July 2026, this HiveForce Labs weekly threat digest is led by two actively exploited SonicWall SMA1000 zero-days — a critical server-side request forgery flaw, CVE-2026-15409 (CVSS 10.0), chained with a code injection bug, CVE-2026-15410 — and CVE-2026-56291, a critical unauthenticated file upload flaw in the Balbooa Forms Joomla extension exploited as a zero-day (see badges and panel below for the full figures).

ATTACKS EXECUTED: 6 VULNERABILITIES EXPLOITED: 10 ADVERSARIES IN ACTION: 0 CVE-2026-15409 · ZERO-DAY · CVSS 10.0 PUBLISHED: JULY 20, 2026

Publication

July 20, 2026

Coverage Window

13–19 July 2026

Attacks Executed

6

Vulns Exploited

10

Adversaries

0

Vulns This Week

2,711

Total Published

478.7K

Lead Vulnerability

CVE-2026-15409 (CVSS 10.0)

Source

HiveForce Labs

Summary

HiveForce Labs has reported a sharp rise in cybersecurity threats this week, tracking six major attacks and ten actively exploited vulnerabilities amid a concerning escalation in malicious activity worldwide.

SonicWall warned of two actively exploited zero-days in its SMA1000 remote access appliances, where a critical server-side request forgery flaw, CVE-2026-15409 (CVSS 10.0), chains with a code injection bug, CVE-2026-15410, to hand unauthenticated attackers full root control of the device. Meanwhile, CVE-2026-56291, a critical unauthenticated file upload flaw in the Balbooa Forms Joomla extension, was exploited as a zero-day in the wild, allowing anonymous attackers to achieve remote code execution in a single request (Section 07).

Elsewhere, the modular malware-for-hire TELEPUZ spread through ClickFix clipboard-hijacking lures delivered via a Vidar-based infection chain, and CrashStealer, a macOS information stealer, abused a signed, Apple-notarized dropper to slip past Gatekeeper and harvest keychain secrets, browser credentials, and cryptocurrency wallets. INC Ransomware has matured into one of 2026's most active operations, claiming more than 800 victims since 2023 by exploiting unpatched edge appliances, while the newly documented Spirals ransomware went from an ASP.NET web shell foothold to network-wide encryption in under 24 hours (Section 06). Together, these incidents underscore a growing trend of rapid zero-day weaponization paired with deceptive social engineering, reinforcing the need for timely patching, continuous monitoring, and layered security defenses.


High Level Statistics

Six attacks, ten exploited vulnerabilities and zero adversaries in action from the 13–19 July 2026 window, for quick reference.

Attacks Executed (6)

GigaWiper, CrashStealer, LabubaRAT, TELEPUZ, INC Ransomware, Spirals

Vulnerabilities Exploited (10)

CVE-2026-56291, CVE-2026-56164, CVE-2026-56155, CVE-2026-50661, CVE-2026-15409, CVE-2026-15410, CVE-2023-3519, CVE-2023-48788, CVE-2024-57727, CVE-2025-5777

Adversaries in Action (0)

No threat actor activity was observed or reported during this window (Section 08).


Insights

Six storylines stand out this week, spanning a maximum-severity SonicWall zero-day chain, a destructive backdoor, and rapid ransomware deployment.

CVE-2026-15409: A CVSS 10.0 SSRF Chained to Root on SonicWall SMA1000

A CVSS 10.0 server-side request forgery flaw in SonicWall SMA1000 chains with a code injection flaw, CVE-2026-15410, giving unauthenticated attackers root (full profile in Sections 06 and 07).

GigaWiper: Three Malware Families Stitched Into One Destructive Implant

GigaWiper stitches three older malware families into one Go-based implant, flipping from silent surveillance to disk wiping and fake ransomware on command (Section 06).

CrashStealer Slips Past Gatekeeper to Drain Keychains and Crypto Wallets

CrashStealer slips past Gatekeeper via a signed, Apple-notarized dropper, then fakes a password prompt to drain the keychain, 80+ crypto wallets, and 14 password managers (Section 06).

Microsoft's July Patch Tuesday: Largest Release Ever

Microsoft's July Patch Tuesday was its largest release ever: 622 fixes, 63 Critical, with SharePoint and DHCP zero-days already under active attack.

LabubaRAT: A Reusable NVIDIA-Themed Remote Access Framework

LabubaRAT poses as NVIDIA software and takes C2 config at startup instead of hardcoding it, one reusable binary built for Malware-as-a-Service (Section 06).

Spirals: Web Shell to Network-Wide Encryption in Under 24 Hours

Spirals went from web shell to network-wide encryption in under 24 hours, killing 23 backup and database services before the Rust payload fired (Section 06).

Threat Distribution

This week's six attacks span the following threat categories: Backdoor, Infostealer, RAT, Modular malware, and Ransomware.


Targeted Countries

Countries targeted this week, most to least, are listed below.

Most Targeted

North Korea, North Macedonia, Norway, Oman, Pakistan, Palau, Panama, Slovenia, Papua New Guinea, Malaysia, Suriname, Austria, Namibia, South Korea, Saudi Arabia, Bahamas, Afghanistan, Bahrain, Micronesia, Bangladesh, Slovakia, Barbados, Russia, Serbia, Solomon Islands

Also Targeted

Belgium, Togo, Belize, Lithuania, Benin, Marshall Islands, Bhutan, Montenegro, Bolivia, New Zealand, Bosnia and Herzegovina, Pakistan, Botswana, Poland, Albania, Saint Vincent and the Grenadines, Brunei, Sierra Leone, Bulgaria, South Sudan, Burkina Faso, Spain, Burundi, Turkey, Cabo Verde

Lower Incidence

Uruguay, Cambodia, Madagascar, Cameroon, Mali, Canada, Mauritius, Central African Republic, Monaco, Chad, Mozambique, Chile, Nepal, China, Niger, Colombia, Norway, Comoros, Palestine State, Congo (Congo-Brazzaville), Peru, Costa Rica, Qatar, Côte d'Ivoire

Least Targeted

Denmark, Switzerland, Djibouti, Thailand, Dominica, Trinidad and Tobago, Dominican Republic, Tuvalu, Ecuador, United Kingdom, Egypt, Australia, El Salvador, Luxembourg, Malawi, Eritrea, Maldives, Estonia, Malta, Mauritania, Ethiopia


Targeted Industries

Industries reported as targeted this week span: Legal, Manufacturing, Business Services, Healthcare, Financial, Charitable Orgs, Retail, Government, Transportation, Education, Energy, Defense, Aerospace, Hospitality, Telecommunications, Media, Insurance, Technology, Real Estate, Religion, Associations, Aviation, Food Services, Agriculture, and Pharmaceutical.


Top MITRE ATT&CK TTPs

The top TTPs observed this week span execution, command-and-control, defense evasion, discovery, persistence, and exfiltration.

T1059

Command and Scripting Interpreter

T1071

Application Layer Protocol

T1027

Obfuscated Files or Information

T1573

Encrypted Channel

T1082

System Information Discovery

T1071.001

T1071: Application Layer Protocol — Web Protocols

T1204

User Execution

T1105

Ingress Tool Transfer

T1518

Software Discovery

T1140

Deobfuscate/Decode Files or Information

T1070

Indicator Removal

T1190

Exploit Public-Facing Application

T1036

Masquerading

T1041

Exfiltration Over C2 Channel

T1057

Process Discovery

T1059.001

T1059: Command and Scripting Interpreter — PowerShell

T1547

Boot or Logon Autostart Execution

T1070.004

T1070: Indicator Removal — File Deletion

T1113

Screen Capture

T1078

Valid Accounts


Attacks Executed

Six attacks were executed this window (Section 02 has the full list) via destructive backdoors, information stealers, remote access frameworks, ClickFix social engineering, and edge-appliance exploitation; IOCs are in the Appendix.

GigaWiper — Backdoor

GigaWiper is a versatile implant that pairs strong command-and-control (C2) features with several destructive payloads, including disk wiping, fake ransomware, and system-level sabotage. It is an amalgamation of at least three standalone malware families stitched together as commands inside a single implant, plus new backdoor functionality on top. That backdoor lets attackers keep control of infected systems, run commands, deploy more tooling, and trigger any of its destructive options on demand, giving operators the flexibility to switch between quiet espionage and full-on wiping whenever they choose. GigaWiper targets Microsoft Windows and enables system compromise and command execution. No delivery method, CVE, or associated actor is recorded for GigaWiper.

CrashStealer — Infostealer

CrashStealer is a C++ macOS infostealer that disguises itself as Apple's crash-reporting framework to steal browser credentials, cryptocurrency wallets, and keychain data. Before sending anything out, CrashStealer encrypts the stolen files with AES-GCM, then exfiltrates them to a remote command-and-control server. CrashStealer targets macOS and enables data theft. No delivery method, CVE, or associated actor is recorded for CrashStealer.

LabubaRAT — RAT

LabubaRAT is a new remote access tool that poses as NVIDIA software to infect Windows computers. Rather than hardcoding its control server, LabubaRAT accepts configuration at startup, letting attackers reuse the same malware across targets. Once installed, it profiles the host to identify security tools and browsers before awaiting operator commands, indicating a reusable framework built for Malware-as-a-Service deployments. LabubaRAT targets Microsoft Windows and enables credential theft, data exfiltration, and persistent access. No delivery method, CVE, or associated actor is recorded for LabubaRAT.

TELEPUZ — Modular Malware

TELEPUZ is a modular malware that first surfaced through CLICKFIX-VIDAR attacks in April. Written in C, likely by hand, TELEPUZ is lightweight, modular, and reasonably well built, with sparse memory allocations, little middleware, and some features still under development — traits suggesting the project is run by a solo developer or a very small team who code for a living. To slow down reverse engineers, TELEPUZ interleaves its real code with "garbage instructions" that serve no functional purpose; some are even designed to produce side effects, like updating global variables or calling Windows APIs, so the compiler or disassembler won't strip them out as dead code. TELEPUZ is delivered via ClickFix, targets Chromium-based browsers (e.g., Chrome) and Mozilla Firefox, and enables system compromise and persistence. No CVE or associated actor is recorded for TELEPUZ.

INC Ransomware — Ransomware

INC is a Rust-based ransomware-as-a-service operation (aka GOLD IONIC) that has claimed 800+ victims since 2023 and ranks among 2026's most active groups, hitting legal, manufacturing, healthcare, technology, and construction targets predominantly in the US. Operators gain entry via unpatched edge appliances — notably CVE-2023-3519 and CVE-2023-48788 — or broker-supplied credentials, then use living-off-the-land binaries and a modified Veeam credential dumper to move laterally across Windows, Linux, and ESXi. Data is exfiltrated to attacker cloud storage before double-extortion encryption, with aggressive defense impairment via driver-dropping process killers and shadow-copy deletion. Pressure is applied through a Tor negotiation portal, a public leak site, wallpaper defacement, and ransom notes printed to networked printers. INC Ransomware is delivered by exploiting vulnerabilities, targets Citrix NetScaler ADC and NetScaler Gateway, Fortinet FortiClient EMS, and SimpleHelp Remote Support Software, and enables file encryption, data exfiltration, and double extortion.

Spirals — Ransomware

Spirals is a Rust-based ransomware family used in a double-extortion attack in June 2026. Attackers gained initial access via an ASP.NET web shell on an internet-facing IIS server and deployed the payload network-wide in under 24 hours, using PsExec to push it as bitsadmin.exe to impersonate a legitimate Windows utility. Files are encrypted with per-file AES-128 keys wrapped by an attacker-controlled ECDH P-256 public key, with intermittent encryption across jittered chunks applied to files over 5 MB for speed. Spirals targets Windows and enables file encryption, data exfiltration, and double extortion. No delivery method, CVE, or associated actor is recorded for Spirals.


Vulnerabilities Exploited

Ten vulnerabilities were exploited in the wild during the 13–19 July 2026 reporting window, all tracked as zero-day issues by HiveForce Labs. CVE-2026-56291 (Balbooa Forms), CVE-2026-56164 (Microsoft SharePoint), CVE-2026-56155 (Microsoft Active Directory Federation Services), CVE-2026-50661 (Windows BitLocker), CVE-2026-15409 and CVE-2026-15410 (SonicWall SMA1000) affect no currently recorded attack or ransomware in this digest but carry critical severity, while CVE-2023-3519, CVE-2023-48788, CVE-2024-57727, and CVE-2025-5777 chain into the INC Ransomware attack detailed in Section 06.

CVE IDNameAffected ProductAffected CPECWE IDAssociated TTPsAssociated ActorAssociated Attack/Ransomware
CVE-2026-56291
ZERO-DAY
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability Balbooa Forms (com_baforms) for Joomla: all versions up to and including 2.4.0 cpe:2.3:a:balbooa:forms:*:*:*:*:*:joomla\!:*:* CWE-434 T1190 Exploit Public-Facing Application, T1059 Command and Scripting Interpreter - -
CVE-2026-56164
ZERO-DAY
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016 cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
CWE-306 T1068 Exploitation for Privilege Escalation, T1190 Exploit Public-Facing Application - -
CVE-2026-56155
ZERO-DAY
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability Windows 10, Windows Server 2012, 2016, 2019, 2022, 2025 cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:*:*:*:*:*:*:*:*
CWE-1220 T1068 Exploitation for Privilege Escalation - -
CVE-2026-50661
ZERO-DAY
Windows BitLocker Security Feature Bypass Vulnerability Windows 10 – 11 26H1, Windows Server 2016, 2019, 2022, 2025 cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:*:*:*:*:*:*:*:*
CWE-693 T1211 Exploitation for Defense Evasion - -
CVE-2026-15409
ZERO-DAY
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability SonicWall SMA1000 Series 6210, 7210, 8200v 12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix); 12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix) cpe:2.3:a:sonicwall:sma1000:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*
CWE-918 T1190 Exploit Public-Facing Application, T1068 Exploitation for Privilege Escalation - -
CVE-2026-15410
ZERO-DAY
SonicWall SMA1000 Appliances Code Injection Vulnerability SonicWall SMA1000 Series 6210, 7210, 8200v 12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix); 12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix) cpe:2.3:a:sonicwall:sma1000:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma6210_firmware:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma7210_firmware:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:sma8200v:*:*:*:*:*:*:*
CWE-94 T1190 Exploit Public-Facing Application, T1059 Command and Scripting Interpreter - -
CVE-2023-3519
ZERO-DAY
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.13; 13.0 before 13.0-91.13; version 12.1 (end of life); 13.1-FIPS before 13.1-37.159; 12.1-FIPS before 12.1-55.297; 12.1-NDcPP before 12.1-55.297 cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
CWE-94 T1190 Exploit Public-Facing Application, T1505.003 Server Software Component: Web Shell, T1087.002 Account Discovery: Domain Account - INC Ransomware
CVE-2023-48788
ZERO-DAY
Fortinet FortiClient EMS SQL Injection Vulnerability FortiClientEMS 7.2.0 through 7.2.2; FortiClientEMS 7.0.1 through 7.0.10 cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:* CWE-89 T1190 Exploit Public-Facing Application, T1059 Command and Scripting Interpreter, T1219 Remote Access Software - INC Ransomware
CVE-2024-57727
ZERO-DAY
SimpleHelp Path Traversal Vulnerability SimpleHelp remote support software v5.5.7 and before cpe:2.3:a:simple-help:simplehelp:*:*:*:*:*:*:*:* CWE-22 T1190 Exploit Public-Facing Application, T1083 File and Directory Discovery, T1552.001 Unsecured Credentials: Credentials In Files - INC Ransomware
CVE-2025-5777
ZERO-DAY
Citrix NetScaler Gateway Out-of-Bounds Read Vulnerability (CitrixBleed 2) NetScaler ADC and NetScaler Gateway 14.1 before 14.1-43.56, 13.1 before 13.1-58.32; NetScaler ADC 13.1-FIPS and NDcPP before 13.1-37.235-FIPS and NDcPP; NetScaler ADC 12.1-FIPS before 12.1-55.328-FIPS cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
CWE-125 T1190 Exploit Public-Facing Application, T1539 Steal Web Session Cookie - INC Ransomware

Adversaries in Action

No threat actor activity was observed or reported during this week.


Recommendations

01
Prioritize the ten exploited vulnerabilities

This digest can be utilized as a drive to force security teams to prioritize the ten exploited vulnerabilities and block the indicators related to malware GigaWiper, CrashStealer, LabubaRAT, TELEPUZ, INC Ransomware, and Spirals.

02
Block indicators tied to the six attacks executed

Use the IOC appendix to block indicators for GigaWiper, CrashStealer, LabubaRAT, TELEPUZ, INC Ransomware, and Spirals across your environment.

03
Run a scan to discover impacted assets (Uni5 users)

This is an actionable threat digest for HivePro Uni5 customers, who can get comprehensive insights into their threat exposure and action it effortlessly over the HivePro Uni5 dashboard by running a scan to discover the assets impacted by the ten exploited vulnerabilities.

04
Test control efficacy with Breach and Attack Simulation (Uni5 users)

Uni5 customers can test the efficacy of their security controls by simulating the attacks related to malware GigaWiper, LabubaRAT, TELEPUZ, and INC Ransomware using Breach and Attack Simulation (BAS).


Threat Advisories

  • CVE-2026-56291: Balbooa Forms File Upload Flaw Actively Exploited
  • GigaWiper: The All-in-One Destruction Kit
  • Signed, Sealed, Stolen: CrashStealer Slips Past Gatekeeper
  • Microsoft Patch Tuesday July 2026 – Priority Fixes
  • LabubaRAT: A Rust-Based Remote Access Framework
  • SonicWall SMA1000 Zero-Days Under Active Exploitation
  • TELEPUZ: A Modular Malware-for-Hire Spreading Through ClickFix Tricks
  • INC Ransomware: Rust-Based RaaS Exploiting Public-Facing Edge Devices
  • Spirals: The Ransomware That Doesn't Wait

Appendix

Known Exploited Vulnerabilities (KEV) Software vulnerabilities for which there are public exploits or proof-of-concept (PoC) code available, and for which there is a high risk of potential harm to an organization's systems or data if left unaddressed. Celebrity Vulnerabilities Software vulnerabilities that have gained significant attention and have been branded with catchy names and logos due to their profound and multifaceted impact. These vulnerabilities provide threat actors with opportunities to breach sensitive systems, potentially resulting in unauthorized access and the compromise of critical information.
Indicators of Compromise (IOCs)

IOCs for the six attacks executed during the 13 to 19 July 2026 window are listed below; a comprehensive list is available on the Uni5Xposure platform.

Attack NameTypeValue
GigaWiperSHA256633d4cbd496b1094495da89a64f5e6c31a0f6d4d1488411db5b0cba1cfe42001
ce9ad5f6c12019f4aae5b189bd8ddf5bb09e75b06a0a587b25a855c65948c913
f622ed85ef31ad4ab973f4e74524866fe1bb44f0965ad2b2ad796cd657a05bfd
9706a192e2c1a1faaf0a521daf31c2af60ff4590e3f47bbb4abc227f42af0683
3c30deb6556a94cfb84ae51798f4aecfae8c7358e55fdb321c5f2376579631cd
GigaWiperIPv4185[.]182[.]193[.]21
212[.]8[.]248[.]104
CrashStealerSHA256a1966a6d6f54a025f30d55571d21d6537977ca73ffa734c13494b9c806cd7007
LabubaRATSHA256b7443b0ab48d2f5786d1b6f3a580f02621e9ae5a3877ee3a44e01df13d984328
TELEPUZSHA25658aec6e3835aaf20f7b4a7e308b36a19e7454673a6f71783871e9bcf6cae8eed
bf3b4e645a3c0c23f87c55971069014f7424ad14497371ee7567eff68ffaf343
ff791fe1532a2dc3b3c188a71bfd0177f973ef228e4d1dda1db6d3c4b0d62b3e
INC RansomwareSHA25631800380c359143ae82c4f9011eee653dd22443d03d6a499148203bbfc275502
ea721240c14e3d14f8d88e0020880448c6c602f1180a1e5dbe40871cfeedcc22
8d1a22c430252f29611766b8e4a82af0fba60d609246463466b384d6d4793df4
bf8c45e5aa9551a17eefbd1d179422c32b4309c47ee9a3f315bb80ed6d4f7efc
6bf155b269d452f3c3b62832b27bbebe4da436e228dbf521155b1d5989e3743f
1898d056463284d849801cbdea6a3dec6c9f568f01569912c3868a5eea9a5449
24f6c0ca39b2a5593086ff56d818ddfbde121f8e44d54faa762e510397dc9db7
dc9938f51150d13a69fc25f3f19052eacb1bf0a086fd5cf39762501fb3ddd7da
acce811c4fc2a6e3fddd4231e386f1648ca44f039d2d275316bc0a0fc96e0af4
90e46e89fec2108a1cb4850bb33e3563e92a14d04e1e613ac8c9311f152d294c
ff5da8f0330a4c581c37284c74aae2683c007dc6e406e1e2e6803e7bb398b77b
97aebda5482899fef84a24e456bff055acaa47e5ab4029f768d9e0c62a660ce2
1d10d8f5a420d0e4683b4cb40bcf0c984d1e7ea1f3b4442a00a525584632ac11
f6a01d0246ce31faf6938ea488086d4358505405a4ef5c5faa482e79e92cb347
d65120291dee76c694f8bea54841f7f68329b499b28f4aee5ea5c9369a7432cb
765508aa2ec6a1b73a76a23f4fa559d32355622748c91a46ed7b315eae2ee60a
d26bfb0147f60dc6500a9298d521ee67b49daaf4b8f8be54e7cc8fd86a597570
589d9480fbfec2d8e61638eb0b537183d0f9977411fd1d2c0f8eb611feebe880
7f37351979c249417cb180b4ede0ed17e5fe2a1f08add4d72606b589f8fdb245
5cc212f84d2bf3fbab165aaf09b16e00fcf2f1ccd880d24b14404c53dcdbf241
60aeb9f7bccf377ff02ed64783e66a62c0f976878d9729b067bc7e5b0b9da9d6
6cd349eda0fa6c8b274a0920852c68f8b727afea1fdbc69ad183cef05d9cf141
SpiralsSHA2560f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141