0
Total Victims
2020-09-01
First Seen
2023-09-24
Last Seen
17
Known TTPs
7.3d
Avg Delay
0
Negotiations
ONION URLS
dllfp5vkfarmt4vxxescvvasdu4kfeugu65fldokudu76vv6uyl2yzsm.onion
TOOLS
AnyDesk QBot Brute Ratel
FILE EXTENSIONS
.dead
ACTIVITY TIMELINE
TOP SECTORS
TOP COUNTRIES
ACTIVITY HEATMAP
Date Victim Name Country Sector Status
No victims recorded
Technique ID Technique Name Tactic
T1560.001 Archive via Utility Collection
T1219 Remote Access Software Command and Control
T1572 Protocol Tunneling Command and Control
T1036.005 Match Legitimate Name or Location Defense Evasion
T1070.004 File Deletion Defense Evasion
T1082 System Information Discovery Discovery
T1087 Account Discovery Discovery
T1053.005 Scheduled Task Execution
T1059.003 Windows Command Shell Execution
T1204.001 Malicious Link Execution
T1041 Exfiltration Over C2 Channel Exfiltration
T1490 Inhibit System Recovery Impact
T1078 Valid Accounts Initial Access
T1133 External Remote Services Initial Access
T1021.001 Remote Desktop Protocol Lateral Movement
T1570 Lateral Tool Transfer Lateral Movement
T1098 Account Manipulation Persistence

No YARA rules

TypeValueDescriptionCopy
tox C3C661E8CCBE079DF344DC5A44F5918EBB9AEF0B9BA1E276464F2D3E73902B3846B202CD1C7F Infrastructure linked to Fracture
tox CC90DDDBEECCDD010339A7CFD6D9FCCA4E263B2CECFCDED153CBA67AC7DF5214EC6A809CBCAB Associated with Fracture ransomware
ip 150.26.98.61 C2 server IP - Fracture campaign
ip 220.67.245.214 C2 server IP observed in Fracture attacks
tox CBBA05F63C9E9BBB3117E5A7EE1D3608ECD3F1CB9AE6D4D9A2BBACE8EF1BA7DD0A07DE2C3992 Infrastructure linked to Fracture
sha1 da96ad4d0e1e17904a468ff8e935a5c93db87f2f Associated with Fracture ransomware
tox 410916B31F0AE025E9DD74A0A59DF9624BFFBE0D1DFC1C9FCD86FBEEA92C4BA3866A7BBEDEB0 Tox messenger ID - Fracture campaign
tox 74ADEA1ED4C6BD8AB4CF4331B008FDC2E7643D506B3DC51C0AEC029F4EABA7FE73FADADB0CB6 Associated with Fracture ransomware
email help262@airmail.cc Contact email observed in Fracture attacks
btc bc1qxezag2vqkry8d8t3k6eb2u3q5kr0l8z6beg4qb Infrastructure linked to Fracture
ip 27.8.255.101 Infrastructure linked to Fracture
btc bc1qk9natsfbxrtzji57pbxnnk1ia8ipc4xd8d9g5t Associated with Fracture ransomware
ip 201.60.9.229 Associated with Fracture ransomware
btc bc1q0z3plhd1xbkir588iyrmel1t94d4h82ymr7yk1 Bitcoin ransom address observed in Fracture attacks

No ransom notes