Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
| Favicon | Title | Type | Available | Last Visit | Server Info | FQDN | |
|---|---|---|---|---|---|---|---|
|
|
Redirecting... | Yes | 2026-07-29T18:56:58 |
handala.to
|
|||
|
|
This Website Has Been Seized | Yes | 2026-07-29T18:58:03 | cloudflare |
handala-hack.to
|
||
|
|
No | 2026-04-29T09:35:24 |
vmjfieomxhnfjba57sd6jjws2ogvowjgxhhfglsikqvvrnrajbmpxqqd.onion
|
||||
|
|
Error Response Page | No | 2026-05-01T14:05:16 |
handala-team.to
|
|||
|
|
Security Verification | Yes | 2026-07-29T18:57:31 | TencentEdgeOne |
handala-hack.tw
|
| Initial Access | Execution | Persistence | Privilege Escalation | Stealth | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Impact | Resource Development | Reconnaissance | Defense Impairment |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Valid Accounts | Windows Management Instrumentation | Valid Accounts | Valid Accounts | Obfuscated Files or Information: Compression | OS Credential Dumping: LSASS Memory | System Information Discovery | Remote Services: Remote Desktop Protocol | Data from Local System | Exfiltration Over C2 Channel | Application Layer Protocol: Web Protocols | Data Destruction | Acquire Infrastructure: Domains | Gather Victim Identity Information | Domain or Tenant Policy Modification: Group Policy Modification |
| Valid Accounts: Domain Accounts | Command and Scripting Interpreter: PowerShell | Valid Accounts: Domain Accounts | Valid Accounts: Domain Accounts | Masquerading: Masquerade Task or Service | Brute Force | Account Discovery: Domain Account | Software Deployment Tools | Data Staged | Web Service | Data Encrypted for Impact | Acquire Infrastructure: Virtual Private Server | Active Scanning: Vulnerability Scanning | Disable or Modify System Firewall: Windows Host Firewall | |
| Valid Accounts: Cloud Accounts | Command and Scripting Interpreter: Python | Valid Accounts: Cloud Accounts | Valid Accounts: Cloud Accounts | Masquerading: Match Legitimate Resource Name or Location | Brute Force: Password Guessing | Screen Capture | Ingress Tool Transfer | Inhibit System Recovery | Acquire Infrastructure: Server | |||||
| External Remote Services | Software Deployment Tools | Account Manipulation | Account Manipulation | Valid Accounts | Brute Force: Credential Stuffing | Email Collection: Remote Email Collection | Remote Access Tools: Remote Desktop Software | Disk Wipe: Disk Content Wipe | Acquire Infrastructure: Web Services | |||||
| Exploit Public-Facing Application | User Execution: Malicious File | External Remote Services | Domain or Tenant Policy Modification: Group Policy Modification | Valid Accounts: Domain Accounts | Unsecured Credentials: Credentials in Registry | Automated Collection | Protocol Tunneling | Disk Wipe: Disk Structure Wipe | Establish Accounts: Social Media Accounts | |||||
| Trusted Relationship | Cloud Administration Command | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder | Valid Accounts: Cloud Accounts | Audio Capture | Financial Theft | Establish Accounts: Email Accounts | |||||||
| Phishing | Hide Artifacts: Hidden Window | Video Capture | Develop Capabilities: Malware | |||||||||||
| Selective Exclusion | Data from Information Repositories: Sharepoint | Obtain Capabilities: Malware | ||||||||||||
| Social Engineering: Impersonation | Archive Collected Data: Archive via Utility | Obtain Capabilities: Tool |
T1567.002