Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
| Favicon | Title | Type | Available | Last Visit | Server Info | FQDN | |
|---|---|---|---|---|---|---|---|
|
|
Home | No | 2026-04-28T07:23:54 |
basemmnnqwxevlymli5bs36o5ynti55xojzvn246spahniugwkff2pad.onion
|
|||
|
|
This site has been seized | No | 2026-04-28T07:26:31 |
xb6q2aggycmlcrjtbjendcnnwpmmwbosqaugxsqb4nx6cmod3emy7sad.onion
|
|||
|
|
Home | No | 2026-04-28T07:22:08 |
92.118.36.204.
|
|||
|
|
This site has been seized | No | 2026-04-28T07:29:03 |
xfycpauc22t5jsmfjcaz2oydrrrfy75zuk6chr32664bsscq4fgyaaqd.onion
|
| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |
|---|---|---|---|---|---|---|---|
|
|
|
GMER
PCHunter
ProcessHacker
|
LaZagne
Mimikatz
NirSoft VNCPassView
NirSoft WebBrowserPassView
PasswordFox
ProcDump
|
|
|
PsExec
|
RClone
|
| Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Impact |
|---|---|---|---|---|---|---|---|---|
| Scheduled Task/Job | Scheduled Task/Job | Scheduled Task/Job | Obfuscated Files or Information | OS Credential Dumping | Process Discovery | Taint Shared Content | Data from Local System | Data Destruction |
| Command and Scripting Interpreter | Boot or Logon Autostart Execution | Token Impersonation/Theft | Software Packing | Input Capture | System Information Discovery | Input Capture | Data Encrypted for Impact | |
| Shared Modules | Registry Run Keys/Startup Folder | Boot or Logon Autostart Execution | Masquerading | File and Directory Discovery | Data Staged | Inhibit System Recovery | ||
| Registry Run Keys/Startup Files | File Deletion | Network Share Discovery | ||||||
| Modify Registry | Virtualization/Sandbox Evasion | |||||||
| Indirect Command Execution | Security Software Discovery | |||||||
| Virtualization/Sandbox Evasion | ||||||||
| Disable or Modify Tools | ||||||||
| Hidden Files and Directories |
| Type | IOC |
|---|---|
Email
|
8filesback@onionmail.org
|
Email
|
helpermail@onionmail.org
|
Email
|
recovery8files@onionmail.org
|
Email
|
solution247days@outlook.com
|
Email
|
wehavesolution@onionmail.org
|
telegram
|
https://t.me/eightbase
|