Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
| Favicon | Title | Type | Available | Last Visit | Server Info | FQDN | |
|---|---|---|---|---|---|---|---|
|
|
PLAY NEWS | No | 2026-06-08T22:13:43 |
mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion
|
|||
|
|
PLAY NEWS | No | 2026-06-08T22:13:55 |
k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion
|
|||
|
|
PLAY NEWS | No | 2026-07-28T01:07:39 | nginx |
j75o7xvvsm4lpsjhkjvb4wl2q6ajegvabe6oswthuaubbykk4xkzgpid.onion
|
| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |
|---|---|---|---|---|---|---|---|
|
AdFind
WKTools
|
|
EDRKill (echo_driver.sys + DBUtil 2.3)
GMER
IOBit
PowerTool
icardagt.exe (version.dll DLL sideload)
|
HandleKatz
Mimikatz
Nanodump
|
Cobalt Strike
WinPEAS
|
FRP
Plink
|
PsExec
|
WinSCP
|
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Stealth | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Impact | Resource Development | Defense Impairment |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Valid Accounts | Scheduled Task/Job: Scheduled Task | Valid Accounts: Domain Accounts | Valid Accounts: Domain Accounts | Obfuscated Files or Information | Obfuscated Files or Information: Command Obfuscation | OS Credential Dumping | System Network Configuration Discovery | Remote Services: Remote Desktop Protocol | Archive Collected Data | Data Transfer Size Limits | Ingress Tool Transfer | Data Encrypted for Impact | Develop Capabilities: Malware | Disable or Modify Tools |
| Valid Accounts: Domain Accounts | Command and Scripting Interpreter | Valid Accounts: Local Accounts | Valid Accounts: Local Accounts | Indicator Removal | Indicator Removal: File Deletion | OS Credential Dumping: LSASS Memory | Remote System Discovery | Remote Services: SMB/Windows Admin Shares | Archive Collected Data: Archive via Utility | Exfiltration Over Alternative Protocol | Remote Access Software | Service Stop | Obtain Capabilities: Tool | Disable or Modify Tools: Clear Windows Event Logs |
| Valid Accounts: Local Accounts | Command and Scripting Interpreter: PowerShell | External Remote Services | Indicator Removal: Clear Windows Event Logs | Valid Accounts: Domain Accounts | OS Credential Dumping: NTDS | Network Service Discovery | Lateral Tool Transfer | Inhibit System Recovery | ||||||
| External Remote Services | Command and Scripting Interpreter: Windows Command Shell | Domain or Tenant Policy Modification | Valid Accounts: Local Accounts | Unsecured Credentials | Process Discovery | Financial Theft | ||||||||
| Exploit Public-Facing Application | Domain or Tenant Policy Modification: Group Policy Modification | System Information Discovery | ||||||||||||
| Disable or Modify Tools | File and Directory Discovery | |||||||||||||
| Account Discovery: Domain Account | ||||||||||||||
| Software Discovery | ||||||||||||||
| Software Discovery: Security Software Discovery |
T1489
T1003.001
| Type | IOC |
|---|---|
Email
|
derdiarikucisv@gmx.de
|
Email
|
raniyumiamrm@gmx.de
|
Email
|
teilightomemaucd@gmx.com
|