0
Total Victims
2017-10-01
First Seen
2026-02-08
Last Seen
10
Known TTPs
28.9d
Avg Delay
0
Negotiations
ONION URLS
ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion
ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion
TOOLS
ConnectWise Cloudflare Tunnel Ligolo PowerShell Empire Rclone
FILE EXTENSIONS
.crypt
ACTIVITY TIMELINE
TOP SECTORS
TOP COUNTRIES
ACTIVITY HEATMAP
Date Victim Name Country Sector Status
No victims recorded
Technique ID Technique Name Tactic
T1005 Data from Local System Collection
T1110.003 Password Spraying Credential Access
T1218.011 Rundll32 Defense Evasion
T1562.004 Disable or Modify System Firewall Defense Evasion
T1018 Remote System Discovery Discovery
T1049 System Network Connections Discovery Discovery
T1059.001 PowerShell Execution
T1059.006 Python Execution
T1567.002 Exfiltration to Cloud Storage Exfiltration
T1566.002 Spearphishing Link Initial Access

No YARA rules

TypeValueDescriptionCopy
ip 75.235.81.129 Associated with JupiterLock ransomware
sha1 68cba7d1e258872e4612921c39ce5b643661c51a Associated with JupiterLock ransomware
sha1 f16e8884b997fbe2810ff486fdd0732dda015e11 Associated with JupiterLock ransomware
email decrypt317@firemail.cc Contact email - JupiterLock campaign
sha256 c32c96b3b1b20625736df19c50073403ac8426e7a5743d4c06c6deefdea304e2 Infrastructure linked to JupiterLock
sha1 b7d3100232c43dd9a7a10810869828dafcccf82e Associated with JupiterLock ransomware
btc bc1q8iu4mjp3494nzjgmje5tko48dy9isrly907iqg Associated with JupiterLock ransomware
email info686@keemail.me Contact email - JupiterLock campaign
sha256 775c8eaeb94128ca357f62e0606eaffdaed16d64474fbe789f178e5248587b34 Ransomware binary hash - JupiterLock campaign
ip 126.73.153.159 Associated with JupiterLock ransomware
tox 160B974AAC908CC8AEFAADD7DD6AFE217D3E4A34F7CF5EF97CA00D577C1AADDE06F78C2CF32A Associated with JupiterLock ransomware
btc bc1q0iebdlj8p5n2crtf5pspo0mml16fgm0vx0kqwx Bitcoin ransom address observed in JupiterLock attacks
md5 185a8e7335ae024b2ad23794ce5b52df Malware sample hash - JupiterLock campaign

No ransom notes