Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
| Favicon | Title | Type | Available | Last Visit | Server Info | FQDN | |
|---|---|---|---|---|---|---|---|
|
|
Human Verify | No | 2026-04-28T07:25:01 |
medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion
|
|||
|
|
Medusa Chat | No | 2026-04-28T07:27:33 |
medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion
|
|||
|
|
Human Verify | No | 2026-08-05T17:35:08 |
xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion
|
|||
|
|
503 Service Temporarily Unavailable | No | 2026-04-28T07:30:05 |
dlmfciajg5s4vliyo5dhs5jyzhi2xr2fnkebul46lpf4xudtqiue4nid.onion
|
|||
|
|
Human Verify | No | 2026-04-28T07:31:23 |
kyfiw76eol6ph2mq7pi5e5tdvce37bicddhai62qhdc5ja6jdchz4qqd.onion
|
|||
|
|
Human Verify | No | 2026-04-28T07:32:37 |
s7lmmhlt3iwnwirxvgjidl6omcblvw2rg75txjfduy73kx5brlmiulad.onion
|
|||
|
|
No | 2026-04-28T07:34:25 |
45.9.148.39
|
||||
|
|
Human Verify | No | 2026-04-28T07:36:17 |
cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion
|
|||
|
|
No | 2026-04-28T07:36:58 |
hupxs7ps7md24kpz4lwsbra64abgxjx3pcc2wuca5ibawf2g5hlpfyqd.onion
|
| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |
|---|---|---|---|---|---|---|---|
|
Advanced IP Scanner
Navicat
PDQ Inventory
RoboCopy
SoftPerfect NetScan
|
AnyDesk
Atera
HCL BigFix
N-Able
PDQ Deploy
ScreenConnect
SimpleHelp
Splashtop
eHorus
|
EDRSandBlast
KillAV
ThrottleStop driver
|
Mimikatz
|
|
Cloudflared
FRP
Ligolo
PuTTY
RevSocks
|
BITSAdmin
Process Explorer
PsExec
|
RClone
|
| Vendor | Product | CVE | Source |
|---|---|---|---|
| SimpleHelp | SimpleHelp RMM | CVE-2024-57727 | arcticwolf.com |
| Initial Access | Execution | Persistence | Privilege Escalation | Stealth | Defense Evasion | Credential Access | Discovery | Lateral Movement | Exfiltration | Command and Control | Impact | Resource Development | Defense Impairment |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Valid Accounts | Windows Management Instrumentation | Modify Registry | Create or Modify System Process: Windows Service | Obfuscated Files or Information: Software Packing | Impair Defenses | OS Credential Dumping: LSASS Memory | System Network Configuration Discovery | Remote Services | Exfiltration Over C2 Channel | Application Layer Protocol: Web Protocols | Data Encrypted for Impact | Acquire Infrastructure: Web Services | Modify Registry |
| External Remote Services | Command and Scripting Interpreter | Create Account: Domain Account | Abuse Elevation Control Mechanism: Bypass User Account Control | Obfuscated Files or Information: Command Obfuscation | Disable or Modify Tools | OS Credential Dumping: NTDS | Remote System Discovery | Remote Services: Remote Desktop Protocol | Exfiltration Over Alternative Protocol | Proxy: Multi-hop Proxy | Service Stop | Establish Accounts: Social Media Accounts | Subvert Trust Controls: Code Signing |
| Exploit Public-Facing Application | Command and Scripting Interpreter: PowerShell | Server Software Component: Web Shell | Indicator Removal: Clear Command History | Safe Mode Boot | Brute Force | System Owner/User Discovery | Software Deployment Tools | Exfiltration Over Web Service | Ingress Tool Transfer | Inhibit System Recovery | Establish Accounts: Email Accounts | Disable or Modify Tools | |
| Phishing | Command and Scripting Interpreter: Windows Command Shell | Create or Modify System Process: Windows Service | Indicator Removal: File Deletion | Network Service Discovery | Lateral Tool Transfer | Exfiltration Over Web Service: Exfiltration to Cloud Storage | Remote Access Tools | System Shutdown/Reboot | Obtain Capabilities: Tool | Disable or Modify System Firewall | |||
| Software Deployment Tools | System Binary Proxy Execution: MMC | Process Discovery | Encrypted Channel: Asymmetric Cryptography | Financial Theft | Stage Capabilities: Upload Tool | Prevent Command History Logging | |||||||
| Native API | Hide Artifacts: Hidden Window | Permission Groups Discovery: Domain Groups | Acquire Access | ||||||||||
| Inter-Process Communication: Component Object Model | System Information Discovery | ||||||||||||
| System Services: Service Execution | File and Directory Discovery | ||||||||||||
| Account Discovery: Local Account | |||||||||||||
| Network Share Discovery | |||||||||||||
| Software Discovery: Security Software Discovery | |||||||||||||
| Device Driver Discovery |
T1489
T1572