1
Total Victims
2022-08-01
First Seen
2026-03-05
Last Seen
19
Known TTPs
3.1d
Avg Delay
0
Negotiations
ONION URLS
xvl63cc5eswldvw5xjagmp2d2y24y4ioyak7f456dxcas5fe3oiyb55v.onion
TOOLS
nltest Chisel ADFind Mimikatz
FILE EXTENSIONS
.hack
ACTIVITY TIMELINE
TOP SECTORS
TOP COUNTRIES
ACTIVITY HEATMAP
Date Victim Name Country Sector Status
2026-03-05 First Consulting United States Legal Published
Technique ID Technique Name Tactic
T1005 Data from Local System Collection
T1039 Data from Network Shared Drive Collection
T1071.001 Web Protocols Command and Control
T1090 Proxy Command and Control
T1572 Protocol Tunneling Command and Control
T1110.003 Password Spraying Credential Access
T1036.005 Match Legitimate Name or Location Defense Evasion
T1218.011 Rundll32 Defense Evasion
T1069 Permission Groups Discovery Discovery
T1082 System Information Discovery Discovery
T1059.005 Visual Basic Execution
T1490 Inhibit System Recovery Impact
T1531 Account Access Removal Impact
T1078 Valid Accounts Initial Access
T1566.001 Spearphishing Attachment Initial Access
T1566.002 Spearphishing Link Initial Access
T1080 Taint Shared Content Lateral Movement
T1547.001 Registry Run Keys Persistence
T1547.009 Shortcut Modification Persistence

No YARA rules

TypeValueDescriptionCopy
sha1 906b6a5489e781389a1c77e1153417ee0ee36c72 Infrastructure linked to Caliburn
md5 a19ccb3959de5f27fd092278f8f996a9 Associated with Caliburn ransomware
tox EBEA4ECFFB9C8CB7B38EEF28E7FADA9BB1F163CD8E2BBBBD7AD09CFE0CCCB0D590E23C7AECAF Tox messenger ID - Caliburn campaign
tox 1ADBBC8CDAF0432BE83F09AD1A5CA04C5FBAFABBCCDD32DCBCD5FDD8EC56DBFDD82183BCC6CB Associated with Caliburn ransomware
btc bc1qshwwixyjo2co7ug1mbnehp4u3uh7bnsdrgqtm7 Bitcoin ransom address observed in Caliburn attacks
md5 8df2793ad9afcded077ccc1f4c017da9 Infrastructure linked to Caliburn
email recover253@protonmail.com Contact email - Caliburn campaign
sha1 fe3ba4083cfb5ff9c57e42f71a86c24730c98f3c Dropper hash - Caliburn campaign
tox CFA7C0D4C531E7FCBDCF7EFB34EEEF2D6F41BE0C2FAF98B7C5560F37AC47CB38DF9EF6F8DCEC Infrastructure linked to Caliburn
ip 88.135.244.151 Infrastructure linked to Caliburn
tox BBC3E81EC5393FE8EBC7A5DCC94AC20ECFFFC064EBD8E3C016A04423CC1E443CEB1ED9B33DBC Infrastructure linked to Caliburn
email contact170@airmail.cc Associated with Caliburn ransomware
md5 79c1ed246b210cd72fb5fac081c7bd9f Infrastructure linked to Caliburn

No ransom notes