Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Ransom Notes:

IOC

You haven't contacted us within three days, our leak plan has been made public on the dark web.
Your database and orders and files will be shared with the world.


Your sensitive data has been stolen by us.
If you don't contact us within three days, we will start leaking data on the dark web.
We stole all your file servers and databases while persisting on your network.
If you don't reply, we will use destructive software next time.

You need to download the tor browser to access the leak site.
tor browser download:
https://www.torproject.org/

leak site:
http://woqjumaahi662ka26jzxyx7fznbp4kg3bsjar4b52tqkxgm2pylcjlad.onion

You can contact us using tox.
https://tox.chat/

tox id:
4A4966259BE6EB1341A2A6A06EA25D747354257EA47F5FD4987A0760FFAEAB1E8E8955A0354F

Indicators of Compromise
Type IOC
onion url http://woqjumaahi662ka26jzxyx7fznbp4kg3bsjar4b52tqkxgm2pylcjlad.onion
tox id 4A4966259BE6EB1341A2A6A06EA25D747354257EA47F5FD4987A0760FFAEAB1E8E8955A0354F