0
Total Victims
2023-04-01
First Seen
N/A
Last Seen
8
Known TTPs
22.6d
Avg Delay
0
Negotiations
ONION URLS
pa32ymaeu62yo5th5mraikgw5fcvznnsiiwti42carjliarodltmqcqd.onion
hkpomcx622gnqp2qhenv4ceyrhwvld3zwogr4mnkdeudq2txf55keoad.onion
raworldw32b2qxevn3gp63pvibgixr4v75z62etlptg3u3pmajwra4ad.onion
raworlddecssyq43oim3hxhc5oxvlbaxuj73xbz2pbbowso3l4kn27qd.onion
TOOLS
Cobalt Strike Chisel Ligolo ScreenConnect
FILE EXTENSIONS
.encrypted
ACTIVITY TIMELINE
TOP SECTORS
TOP COUNTRIES
ACTIVITY HEATMAP
Date Victim Name Country Sector Status
No victims recorded
Technique ID Technique Name Tactic
T1005 Data from Local System Collection
T1036.005 Match Legitimate Name or Location Defense Evasion
T1018 Remote System Discovery Discovery
T1041 Exfiltration Over C2 Channel Exfiltration
T1189 Drive-by Compromise Initial Access
T1021.002 SMB/Windows Admin Shares Lateral Movement
T1021.004 SSH Lateral Movement
T1098 Account Manipulation Persistence

No YARA rules

TypeValueDescriptionCopy
sha256 8a5bf759e61b05be4c075359b3e0857425b1fa54ea0397cd37243902b61ce8b8 Ransomware binary hash observed in RA Group attacks
email help274@cock.li Contact email - RA Group campaign
md5 82db0526c8405ba5c075258ee4eda320 Malware sample hash - RA Group campaign
sha1 7b4e708b1b290f1bf449587ceda3847d01056053 Associated with RA Group ransomware
tox 7FA4B6DFE5FACD1AA1357D8ED9BD6DDE0EB82F0CFE04D0C7C922FB06BA3A7FFDD757C71AEBBE Tox messenger ID - RA Group campaign
sha256 ad9c708ed717ad4ba48ddf9d4874aa272ee7c97a8d00fb9714270faed5fa671f Associated with RA Group ransomware
md5 686e5a1b2b608aa239a4b1d83cdbaaa8 Malware sample hash - RA Group campaign
sha256 1e24b72780e10da2153f3c8f18b9ab4f18c1e95e68f9890065cd1faac4126e16 Infrastructure linked to RA Group
md5 44ed68bdd86d5d57faa1feb4c41ffdc9 Infrastructure linked to RA Group
tox A55C9A656E60D8A0B2DFCC04D7CDC3914A7CFCB44D470DAD955D0CDBB3E6EDEDFFCFEE9B89EE Infrastructure linked to RA Group
sha1 66b0ce9316ba431a154dfa831c624eb255453445 Dropper hash - RA Group campaign
sha1 19ebe886deb484e3fa7b99c9dc4356c26b42954b Dropper hash - RA Group campaign

No ransom notes