Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
| Favicon | Title | Type | Available | Last Visit | Server Info | FQDN | |
|---|---|---|---|---|---|---|---|
|
|
Qilin | No | 2026-04-28T07:25:49 |
ozsxj4hwxub7gio347ac7tyqqozvfioty37skqilzo2oqfs4cw2mgtyd.onion
|
|||
|
|
DDOS Protection | No | 2026-04-28T07:28:21 |
kbsqoivihgdmwczmxkbovk7ss2dcynitwhhfu5yw725dboqo5kthfaad.onion
|
|||
|
|
Qilin blog | Yes | 2026-06-10T21:10:10 | Apache |
ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion
|
||
|
|
Sign In | No | 2026-04-28T07:30:53 |
ji57fr53anp7wb44tbbnp72qcgbhqywy4jmbncawdcrejj5amuvh3zqd.onion
|
| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |
|---|---|---|---|---|---|---|---|
|
Nmap
Nping
|
NetSupport
ScreenConnect
|
EDRSandBlast
PCHunter
PowerTool
Toshiba power management driver (BYOVD)
Updater for Carbon Black’s Cloud Sensor AV (upd.exe)
YDArk
Zemana Anti-Rootkit driver
|
Mimikatz
|
Cobalt Strike
Evilginx
Kali Linux
NetExec
SystemBC
Tofsee
|
Proxychains
|
PowerShell
PsExec
WinRM
fsutil
|
EasyUpload.io
MEGA
|
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Impact | Resource Development | Reconnaissance |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Valid Accounts | Command and Scripting Interpreter: PowerShell | Boot or Logon Initialization Scripts | Exploitation for Privilege Escalation | Obfuscated Files or Information | OS Credential Dumping: LSASS Memory | Query Registry | Remote Services | Archive Collected Data: Archive via Utility | Exfiltration Over Other Network Medium | Data Obfuscation | Data Encrypted for Impact | Develop Capabilities: Malware | Gather Victim Network Information: Network Topology |
| Exploit Public-Facing Application | Command and Scripting Interpreter: Unix Shell | Scheduled Task/Job | Masquerading: Invalid Code Signature | Network Sniffing | Network Service Discovery | Remote Services: Remote Desktop Protocol | Network Device Configuration Dump | Exfiltration Over Other Network Medium: Exfiltration Over Bluetooth | Data Obfuscation: Junk Data | Inhibit System Recovery | |||
| Phishing | System Services | Scheduled Task/Job: Scheduled Task | Access Token Manipulation: Parent PID Spoofing | Brute Force: Password Cracking | System Information Discovery | Remote Services: SMB/Windows Admin Shares | Exfiltration Over Alternative Protocol: Unencrypted Non-C2 Protocol | Application Layer Protocol: Web Protocols | Disk Wipe | ||||
| Phishing: Spearphishing via Service | System Services: Service Execution | Account Manipulation: SSH Authorized Keys | Exploitation for Defense Evasion | Credentials from Web Browsers | System Location Discovery | Remote Services: SSH | Exfiltration Over Web Service: Exfiltration to Cloud Storage | Protocol Tunneling | Disk Wipe: Disk Content Wipe | ||||
| Create Account | Execution Guardrails | Lateral Tool Transfer | |||||||||||
| Boot or Logon Autostart Execution | Virtualization/Sandbox Evasion: System Checks | ||||||||||||
| Subvert Trust Controls: Code Signing | |||||||||||||
| Disable or Modify Tools | |||||||||||||
| Impair Defenses: Disable or Modify System Firewall | |||||||||||||
| Hidden Artifacts | |||||||||||||
| Hidden Artifacts: Hidden Window |