Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
| Favicon | Title | Type | Available | Last Visit | Server Info | FQDN | |
|---|---|---|---|---|---|---|---|
|
|
INC Ransom | No | 2026-04-28T07:21:37 |
incblog7vmuq7rktic73r4ha4j757m3ptym37tyvifzp2roedyyzzxid.onion
|
|||
|
|
No | 2026-04-28T07:24:04 |
incbackrlasjesgpfu5brktfjknbqoahe2hhmqfhasc5fb56mtukn4yd.onion
|
||||
|
|
Error Response Page | No | 2026-04-28T07:26:27 |
incbackend.top
|
|||
|
|
INC Ransom | No | 2026-04-28T07:21:15 |
incapt.blog
|
|||
|
|
Error Response Page | No | 2026-04-28T07:28:31 |
incapt.su
|
|||
|
|
Disclosures | Yes | 2026-08-07T16:06:14 | nginx 1.27.5 |
incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion
|
||
|
|
Yes | 2026-08-07T16:05:40 | None — Express |
incbacg6bfwtrlzwdbqc55gsfl763s3twdtwhp27dzuik6s6rwdcityd.onion
|
| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |
|---|---|---|---|---|---|---|---|
|
AdFind
Advanced IP Scanner
SoftPerfect NetScan
|
AnyDesk
|
|
Mimikatz
|
|
Bitvise SSH Client
|
Finger
PsExec
|
7-Zip
BackBlaze
MEGA
RClone
Restic
WinRAR
s5cmd
|
| Vendor | Product | CVE | Source |
|---|---|---|---|
| SonicWall | SMA1000 | CVE-2026-15409 | — |
| SonicWall | SMA1000 | CVE-2026-15410 | — |
| Initial Access | Execution | Persistence | Privilege Escalation | Stealth | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Impact | Resource Development | Defense Impairment |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Valid Accounts | Windows Management Instrumentation | Valid Accounts | Valid Accounts | Masquerading: Match Legitimate Resource Name or Location | Network Service Discovery | Remote Services: Remote Desktop Protocol | Data Staged | Transfer Data to Cloud Account | Application Layer Protocol | Data Encrypted for Impact | Obtain Capabilities: Tool | Disable or Modify Tools |
| Exploit Public-Facing Application | Command and Scripting Interpreter: Windows Command Shell | Indicator Removal: File Deletion | System Network Connections Discovery | Lateral Tool Transfer | Archive Collected Data: Archive via Utility | Ingress Tool Transfer | Financial Theft | |||||
| Phishing | System Services: Service Execution | Valid Accounts | Permission Groups Discovery: Domain Groups | Remote Access Tools | ||||||||
| Account Discovery: Domain Account | ||||||||||||
| Network Share Discovery |
T1482
T1567.002