Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business
Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |
---|---|---|---|---|---|---|---|
Advanced IP Scanner
Navicat
PDQ Inventory
RoboCopy
SoftPerfect NetScan
|
AnyDesk
Atera
eHorus
HCL BigFix
N-Able
PDQ Deploy
ScreenConnect
SimpleHelp
Splashtop
|
EDRSandBlast
KillAV
ThrottleStop driver
|
Mimikatz
|
|
Cloudflared
FRP
Ligolo
PuTTY
RevSocks
|
BITSAdmin
Process Explorer
PsExec
|
RClone
|
Vendor | Product | CVE | Source |
---|---|---|---|
SimpleHelp | SimpleHelp RMM | CVE-2024-57727 | arcticwolf.com |
Initial Access | Execution | Defense Evasion | Credential Access | Discovery | Lateral Movement | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|
Valid Accounts | Command and Scripting Interpreter | Impair Defenses | Brute Force | File and Directory Discovery | Remote Services | Ingress Tool Transfer | Exfiltration Over C2 Channel | Inhibit System Recovery |
Phishing | Windows Management Instrumentation | Disable or Modify Tools | Network Share Discovery | Exfiltration Over Web Service | Service Stop | |||
External Remote Services | Safe Mode Boot | Exfiltration Over Alternative Protocol | Data Encrypted for Impact |
No negotiation chats available.
Type | IOC |
---|---|
email
|
medusa.support@onionmail.org |
email
|
MedusaSupport@cock.li |
md5
|
983a20479a281a182d33b75c0945e447 |
md5
|
4fe99e5dc101170750d8ece6ea066155 |
md5
|
dc344328208c3481587d0aab1005fcdd |
md5
|
10911494fa52daee0279972f91fded01 |
md5
|
24ccd142ff83e8622f00f5443ea5cb2d |
md5
|
a6980e543efa40771ed1dcf84b29d732 |
md5
|
a162a5c5ab72b3783215f52b9edc3680 |
md5
|
600371ebab1e29429f06a5b1909056e5 |
md5
|
0067679c7033139bcbb273840494b324 |
md5
|
602d720f1184d2ad739568cbf6403331 |
md5
|
ec5b1a6de3564c26c4e0e804e6bc2ecb |
md5
|
f05b57cdc3420acc359efe9e4941c428 |
md5
|
0168a4daa9598e991e140057e59438f6 |
md5
|
6be23d5a1ff1e9cbe99fe7f7c49a5607 |
md5
|
92a20ba91b4d3b89b57aa95a120667ae |
md5
|
e874240a53fc353bc770f507445cc061 |
md5
|
eb46bc3e2ad88149176ef33c9fea087a |
md5
|
bdf6ac02664baea655b103d50bdfd6ec |
telegram
|
https://t.me/+yXOcSjVjI9tjM2E0 |
tox
|
4AE245548F2A225882951FB14E9BF87EE01A0C10AE159B99D1EA62620D91A372205227254A9F |
tox
|
061AA6BDE8F6DE6C92F0D6E077359BF6911FCAF80030E82B3A3DB65E63C8011343D34F956FEC |
tox
|
AEA72DFCF492037A6D15755A74645C7D8E674E342BACA9F9070A3FB74117EC3143FD6E29BEAC |