Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Ransom Notes:

IOC

Hi, Your hotel is hacked!

Your servers and files are locked and copied.

===================================

REMEMBER!

We also locked files in OneDrive.

And we did not change the extensions of files in OneDrive.

===================================



You cannot decrypt yourself without our key, even you're using third party software or from help of security companies.

Please do not waste your time.

Your files will be easily decrypted with pay. Never worry.



We're waiting here with UUID [snip]

Method * : nightspireteam.receiver@onionmail.org

Method 1 : Our qTox ID

3B61CFD6E12D789A439816E1DE08CFDA58D76EB0B26585AA34CDA617C41D5943CDD15DB0B7E6

Method 2 : Browse our Onion Site with Tor Browser

http://nspiremkiq44zcxjbgvab4mdedyh2pzj5kzbmvftcugq3mczx3dqogid.onion

http://a2lyiiaq4n74tlgz4fk3ft4akolapfrzk772dk24iq32cznjsmzpanqd.onion

We're waiting here with UUID [snip]

Indicators of Compromise
Type IOC
email nightspireteam.receiver@onionmail.org
onion url http://a2lyiiaq4n74tlgz4fk3ft4akolapfrzk772dk24iq32cznjsmzpanqd.onion
onion url http://nspiremkiq44zcxjbgvab4mdedyh2pzj5kzbmvftcugq3mczx3dqogid.onion
tox id 3B61CFD6E12D789A439816E1DE08CFDA58D76EB0B26585AA34CDA617C41D5943CDD15DB0B7E6