chg: [ransomware] groups updated

This commit is contained in:
Alexandre Dulaunoy 2025-08-01 10:30:26 +02:00
parent d36bf825dd
commit 4b4d459fbf
Signed by: adulau
GPG key ID: 09E2CD4944E6CBCD

View file

@ -14467,7 +14467,11 @@
"links": [
"http://xfr3txoorcyy7tikjgj5dk3rvo3vsrpyaxnclyohkbfp3h277ap4tiad.onion",
"http://aoacugmutagkwctu.onion/",
"https://mazedecrypt.top/"
"https://mazedecrypt.top/",
"http://dnspexdevfbct2agyu3oxrmhm4ggf4ec6iwpnlb3kwb2rigrtuz3sayd.onion/",
"http://xjypo5vzgmo7jca6b322dnqbsdnp3amd24ybx26x5nxbusccjkm4pwid.onion/",
"http://Newsmaze.top",
"http://mazenews.top"
],
"refs": [
"https://malpedia.caad.fkie.fraunhofer.de/details/win.maze",
@ -15344,6 +15348,10 @@
{
"description": "The threat group behind this malware seems to operate by hacking into companies, stealing sensitive data, and then running Egregor to encrypt all the files. According to the ransom note, if the ransom is not paid by the company within 3 days, and aside from leaking part of the stolen data, they will distribute via mass media where the company's partners and clients will know that the company was attacked.",
"meta": {
"links": [
"http://egregoranrmzapcv.onion/",
"http://egregornews.com"
],
"ransomnotes-filenames": [
"RECOVER-FILES.txt"
],
@ -15355,7 +15363,8 @@
"https://www.appgate.com/news-press/appgate-labs-analyzes-new-family-of-ransomware-egregor",
"https://www.bleepingcomputer.com/news/security/crytek-hit-by-egregor-ransomware-ubisoft-data-leaked/",
"https://cybersecuritynews.com/egregor-ransomware/",
"https://securityboulevard.com/2020/10/egregor-sekhmets-cousin/"
"https://securityboulevard.com/2020/10/egregor-sekhmets-cousin/",
"https://www.ransomlook.io/group/egregor"
]
},
"related": [
@ -16054,7 +16063,8 @@
"http://darksidc3iux462n6yunevoag52ntvwp6wulaz3zirkmh4cnz6hhj7id.onion",
"http://supp24yy6a66hwszu2piygicgwzdtbwftb76htfj7vnip3getgqnzxid.onion/",
"http://supp24maprinktc7uizgfyqhisx7lkszb6ogh6lwdzpac23w3mh4tvyd.onion",
"http://dark24zz36xm4y2phwe7yvnkkkkhxionhfrwp67awpb3r3bdcneivoqd.onion/"
"http://dark24zz36xm4y2phwe7yvnkkkkhxionhfrwp67awpb3r3bdcneivoqd.onion/",
"http://darksidedxcftmqa.onion/"
],
"refs": [
"https://www.digitalshadows.com/blog-and-research/darkside-the-new-ransomware-group-behind-highly-targeted-attacks/",
@ -16450,6 +16460,10 @@
{
"description": "Ransom.Sekhmet not only encrypts a victims files, but also threatens to publish them.",
"meta": {
"links": [
"http://sekhmetleaks.top/",
"http://rlmuybcg5h5gaatr.onion/"
],
"ransomnotes-filenames": [
"RECOVER-FILES.txt"
],
@ -16460,7 +16474,8 @@
"https://www.bleepingcomputer.com/news/security/maze-ransomware-is-shutting-down-its-cybercrime-operation/",
"https://www.zdnet.com/article/as-maze-ransomware-group-retires-clients-turn-to-sekhmet-ransomware-spin-off-egregor/",
"https://blog.malwarebytes.com/detections/ransom-sekhmet/",
"https://securityboulevard.com/2020/10/egregor-sekhmets-cousin/"
"https://securityboulevard.com/2020/10/egregor-sekhmets-cousin/",
"https://www.ransomlook.io/group/sekhmet"
]
},
"related": [
@ -16904,7 +16919,8 @@
"http://mu6se7h7qfwuqclr4cc6zy7qevod6gyk37aq5vwnayrtbx3qqycx2fyd.onion",
"http://eleav2eq3ioyiuevbyvqaz3vruwvpislphszo4cm7n56itbpnupxngyd.onion",
"http://2cyxmof76rxeqze5snxxooqmhzjtcploqswxoxmenfayphumdhrtrzqd.onion",
"http://rqqn25k3hgmfkh7ykjbmakjgidwweomr7cbpy6pfecpxs57r5iwzwtyd.onion"
"http://rqqn25k3hgmfkh7ykjbmakjgidwweomr7cbpy6pfecpxs57r5iwzwtyd.onion",
"http://idep6vd7ywl7uruhsutqjdnjawe33hct35523rrmf73kb46xrhfb5sid.onion/"
],
"refs": [
"https://www.ransomlook.io/group/blackout"
@ -23245,6 +23261,14 @@
},
{
"description": "ransomware",
"meta": {
"links": [
"http:// ransomyktqx2m3xg.onion/"
],
"refs": [
"https://www.ransomlook.io/group/inpivx"
]
},
"uuid": "6a4ac521-4731-4bc1-abf4-639b451018bc",
"value": "INPIVX"
},
@ -24808,7 +24832,14 @@
"http://hl66646wtlp2naoqnhattngigjp5palgqmbwixepcjyq5i534acgqyad.onion",
"https://snatch.press/",
"https://snatchteam.cc",
"https://snatchnews.top/"
"https://snatchnews.top/",
"http://snatch6rpvi7yy4t.onion/",
"http://snatch2q72f2wjff.onion/",
"http://snatchh5ssxiorrn.onion/",
"http://snatch6brk4nfczg.onion/",
"http://snatchwezarcr27t.onion/",
"http://snatch24uldhpwrm.onion/",
"http://mydatassuperhero.com/"
],
"refs": [
"https://t.me/snatch_news",
@ -25044,7 +25075,9 @@
{
"description": "ransomware",
"meta": {
"links": [],
"links": [
"http://g6gwcbiylnvrzj6txsypi72weymzdg6oov2qycu36ggfx3narejcqcid.onion/HNDPXubuzAllW18lBXjT6HU3QnyCtlClvWD8dfcnU6ZUa"
],
"refs": [
"https://www.ransomlook.io/group/thor"
]
@ -25878,7 +25911,8 @@
"http://contirecj4hbzmyzuydyzrvm2c65blmvhoj2cvf25zqj2dwrrqcq5oad.onion/",
"http://contirecj4hbzmyzuydyzrvm2c65blmvhoj2cvf25zqj2dwrrqcq5oad.onion",
"https://contirecovery.best",
"https://contirecovery.top"
"https://contirecovery.top",
"http:// htcltkjqoitnez5slo7fvhiou5lbno5bwczu7il2hmfpkowwdpj3q2yd.onion/"
],
"ransomnotes": [
"All of your files are currently encrypted by CONTI ransomware."
@ -26320,7 +26354,13 @@
{
"description": "ransomware",
"meta": {
"date": "November 2020"
"date": "November 2020",
"links": [
"http://sifrecikx7s62cjv.onion/"
],
"refs": [
"https://www.ransomlook.io/group/sifrecikis"
]
},
"uuid": "4be906e7-b6db-453f-8f9b-a8d8d9b29f4b",
"value": "SifreCikis"
@ -27454,7 +27494,8 @@
"description": "Ransomware",
"meta": {
"links": [
"http://vbfqeh5nugm6r2u2qvghsdxm3fotf5wbxb5ltv6vw77vus5frdpuaiid.onion/"
"http://vbfqeh5nugm6r2u2qvghsdxm3fotf5wbxb5ltv6vw77vus5frdpuaiid.onion/",
"http://pandoraxyz.xyz/"
],
"refs": [
"https://twitter.com/malwrhunterteam/status/1501857263493001217",
@ -28190,7 +28231,8 @@
"http://inbukcc4xk67uzbgkzufdqq3q3ikhwtebqxza5zlfbtzwm2g6usxidqd.onion:81",
"http://p5quu5ujzzswxv4nxyuhgg3fjj2vy2a3zmtcowalkip2temdfadanlyd.onion/",
"http://tj3ty2q5jm5au3bmd2embtjscd3qjt7nfio2o7cr6moyy5kgil5pieqd.onion",
"http://kpfj3bmo77bwpy2f5zzwj4knatueuv7t3ldlpp4tlrmv2buiziw2tdyd.onion"
"http://kpfj3bmo77bwpy2f5zzwj4knatueuv7t3ldlpp4tlrmv2buiziw2tdyd.onion",
"http://ce6roic2ykdjunyzazsxmjpz5wsar4pflpoqzntyww5c2eskcp7dq4yd.onion/"
],
"ransomnotes": [
"BLACKBYTE \n\nAll your files have been encrypted, your confidential data has been stolen, in order to decrypt files and avoid leakage, you must follow our steps.\n\n1) Download and install TOR browser from this site: https://torproject.org/ \n\n2) Paste the URL in TOR browser and you will be redirected to our chat with all information that you need. \n\n3) If you won't contact with us within 4 days, your access to our chat will be removed and you wont be able to restore your system. \n\nYour URL: [LINK]\n\nYour Key: [KEY]",
@ -28918,7 +28960,8 @@
{
"meta": {
"links": [
"http://rwiajgajdr4kzlnrj5zwebbukpcbrjhupjmk6gufxv6tg7myx34iocad.onion/"
"http://rwiajgajdr4kzlnrj5zwebbukpcbrjhupjmk6gufxv6tg7myx34iocad.onion/",
"http://crkfkmrh4qzbddfrl2axnkvjp5tgwx73d7lq4oycsfxc7pfgbfhtfiid.onion/"
],
"refs": [
"https://www.ransomlook.io/group/cheers"
@ -29976,7 +30019,11 @@
"http://6d453sm6732jpr5gjs6zrjzysurnmrwi67624goptyly2xuz2kmjixad.onion",
"http://ftp://datashare:C}^SLA\"5Vl?vX#R4tg^}:hd3@185.196.10.52",
"http://ftp://dataShare:2bTWYKNn7aK7Rqp9mnv3@185.196.10.19",
"http://vn2untbh4etoqoc4rfsrzlautth7vm62swv7ohemsy4tgh3a4j5ykgyd.onion"
"http://vn2untbh4etoqoc4rfsrzlautth7vm62swv7ohemsy4tgh3a4j5ykgyd.onion",
"http://p2zg4yqlsflg77opdzcjiu3reyj3wx2owwez2tcyv3vemmz7wbyccyqd.onion/",
"http://ytdfc3dvgudgq4zyjwtipzbsu7arbiqvygfqdyqiygkvry2hy47oq2ad.onion",
"http://22odvea7bampzr7k2dztbqda67fpau6hcy7sgn2npucaz5gcjmmzrgqd.onion/",
"http://ji57fr53anp7wb44tbbnp72qcgbhqywy4jmbncawdcrejj5amuvh3zqd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/qilin"
@ -30017,7 +30064,8 @@
{
"meta": {
"links": [
"http://u67aylig7i6l657wxmp274eoilaowhp3boljowa6bli63rxyzfzsbtyd.onion/"
"http://u67aylig7i6l657wxmp274eoilaowhp3boljowa6bli63rxyzfzsbtyd.onion/",
"http://cartelraqonekult2cxbzzz2ukiff7v6cav3w373uuhenybgqulxm5id.onion/"
],
"refs": [
"https://www.ransomlook.io/group/ransomcartel"
@ -30303,7 +30351,8 @@
{
"meta": {
"links": [
"http://tdoe2fiiamwkiadhx2a4dfq56ztlqhzl2vckgwmjtoanfaya4kqvvvyd.onion"
"http://tdoe2fiiamwkiadhx2a4dfq56ztlqhzl2vckgwmjtoanfaya4kqvvvyd.onion",
"http://darktorhvabc652txfc575oendhykqcllb7bh7jhhsjduocdlyzdbmqd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/unknown"
@ -30374,7 +30423,8 @@
"http://ssq4zimieeanazkzc5ld4v5hdibi2nzwzdibfh5n5w4pw5mcik76lzyd.onion/",
"http://wmp2rvrkecyx72i3x7ejhyd3yr6fn5uqo7wfus7cz7qnwr6uzhcbrwad.onion",
"http://xu66gzit6zp22qvixpenlxu2ok7vzrpqvgkuupkiukpz47va47ewbwad.onion",
"http://tahnytazh47jpikpajm2so2jdsjrkx6gfcu4p7bu7u3vfarnpvshgeyd.onion/"
"http://tahnytazh47jpikpajm2so2jdsjrkx6gfcu4p7bu7u3vfarnpvshgeyd.onion/",
"http://ecdmr42a34qovoph557zotkfvth4fsz56twvwgiylstjup4r5bpc4oad.onion/"
],
"refs": [
"https://blog.talosintelligence.com/2021/08/vice-society-ransomware-printnightmare.html",
@ -31651,7 +31701,8 @@
"http://2yxf2ald2c67twt4663piypum2fu6yt4su453naxsdiilpd4m7pgu6qd.onion",
"http://wjdnuogx3mrnnutshrx7nbvjuwqfxnrb32rifaozygwdvs325s75keqd.onion",
"http://wxqhwn52dnzbrtqeywg35jfvzbpwkw7edlxxoil7ag44plraezw5z5id.onion",
"http://5bol522hpd3yknxfct2o35ilimxyo46licxxitjvajtvcedltfrj53qd.onion/"
"http://5bol522hpd3yknxfct2o35ilimxyo46licxxitjvajtvcedltfrj53qd.onion/",
"http://weg7sdx54bevnvuLapqu6bpzwztryeflq3s23trgbmnhkbpqz637f2yd.onion"
],
"refs": [
"https://www.ransomlook.io/group/black suit",
@ -32311,7 +32362,9 @@
"http://s7lmmhlt3iwnwirxvgjidl6omcblvw2rg75txjfduy73kx5brlmiulad.onion",
"http://medusakxxtp3uo7vusntvubnytaph4d3amxivbgg13hnhpk2nmus34yd.onion/227098164ef1fdb119ef537986bbdf24",
"http://hm2hlugduzuxiya5bgrsewfxmrzxbmslvg3t42zdzsorcn2nyfbrh6qd.onion/",
"http://7aqabivkwmpvjkyefonf3gpy5gsubopqni7kcirsrq3pflckxq5zz4id.onion/"
"http://7aqabivkwmpvjkyefonf3gpy5gsubopqni7kcirsrq3pflckxq5zz4id.onion/",
"http://762a33bcwneu3i6m7g4unj7xoyvl3nolnbeqhm4jfap6d7uczj43mrqd.onion",
"http://x4tqo27mrr5q5wobpuvw6rowmbclwe5h62etslydc6wnona73pmqwaid.onion"
],
"ransomnotes-filenames": [
"!!!READ_ME_MEDUSA!!!.txt"
@ -33853,7 +33906,8 @@
"http://xq5t7xwptmpoxzjkns7wfbbr43zxedm6ygbfsh6bp6lipvyhzkfopjyd.onion/",
"http://pdndkkg2hu4z36yhrbgtycxf52iodlh5os4argm2ooia4ypwgnvlzgqd.onion/",
"http://md7a4mzsppjuaw4zczoojpo7arqrlnmhlqoo35ttrc7l2lpeiblx2yqd.onion/",
"http://l4wvjhcng4klrah4gldyyvo3x5p5o4frzbvwdhzqa6vkg2chistqj3yd.onion/"
"http://l4wvjhcng4klrah4gldyyvo3x5p5o4frzbvwdhzqa6vkg2chistqj3yd.onion/",
"http://d26nwzgwylb3no3ar3rt3si3e3ujzndhp5wryxxlr76wba5snhap3tyd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/money message"
@ -33863,6 +33917,7 @@
"value": "money message"
},
{
"description": "",
"meta": {
"links": [
"https://handala.to/",
@ -33910,7 +33965,11 @@
"http://qrthxx5hkttfl3pk57eou6ddqi34pxsibxvndq7vt5pblqbaurkmxbqd.onion/",
"http://usu2gxoiijvnswhfymd6ucjjwhtgqby4c4ywzvnrtw4i6mpgppvzpsad.onion/",
"http://qk5nd25xdnygqrey7al2tb3xop5brk7kxua7xr2zrgftzked43bku4yd.onion/",
"http://p474ku5ehoex7mfsbdenppakbb4twvrnvggjzhp53xw4z5qq6glm4yad.onion/"
"http://p474ku5ehoex7mfsbdenppakbb4twvrnvggjzhp53xw4z5qq6glm4yad.onion/",
"http://vh2wkazjlflm6pvwtvw2fnztu3dcw4346lasvikzeg25yhx6bjvl5pqd.onion/",
"http://rngjexyyyl5mek5kg2lkxilqfef5nr6bpa4u24i5ei5hb3ydsh5drpid.onion/",
"http://tamvd5fdyvpekhaf2sdg5sum73ra2abc4h2iqihijpvw4hythnlmuhid.onion/",
"http://jolfnfw6lmcjsppgjfimhimqt2t7viybk67yc5zkxip6fxrcgo7mv4id.onion/"
],
"refs": [
"https://www.ransomlook.io/group/embargo"
@ -33974,7 +34033,8 @@
"http://panelqbinglxczi2gqkwderfvgq6bcv5cbjwxrksjtvr5xv7ozh5wqad.onion/Url=4094dd92-0f91-4699-8328-fdb7070a8230",
"http://panela3eefdzfzxzxcshfnbustdprtlhlbe3x2fqomdz7t33iqtzvjyd.onion/",
"http://26ubgm3vvrjawkdyfhvl2d2nhq77nu3zsagbih4yy2zgau5uv5ivfgyd.onion",
"http://zdkexsh2e7yihw5uhg5hpsgq3dois2m5je7lzfagij2y6iw5ptl35gyd.onion/"
"http://zdkexsh2e7yihw5uhg5hpsgq3dois2m5je7lzfagij2y6iw5ptl35gyd.onion/",
"http://4ozbomcjurd64vgeblkoqeqirvawi3dddswriw6qespscmequmqlshyd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/el dorado"
@ -34106,7 +34166,10 @@
"http://ncyg34lipi3w2u7yvxl3swr6wj6lsoeix3grrdsn6nmcv4r7vntanoid.onion/",
"http://bgpeqy3d5svuikeaueitix6zosg3pzekw77viulnucsiqsn4sjr65iyd.onion/",
"http://as7fbsjvifse52ek5qnptfgvkduvvnl56adb3jjgk6k3p7bisipvotyd.onion/",
"http://xangddavm54rgsju7iceahxztbqrcflzunffwbaswwhhftieygc4j3ad.onion/"
"http://xangddavm54rgsju7iceahxztbqrcflzunffwbaswwhhftieygc4j3ad.onion/",
"http://q226mkoikzgyu33jin7ox3qo6tea7yhlgz52p5lslpj73edtocsz4wqd.onion/",
"http://hdgfvxxkepllbvqvk7vrudgwq55tg4joo4xpajaa3nv5gzpake66bnid.onion/",
"http://jgkgqztfmwk53wlttsjo6i3nmwtzoch2oi2bocqzb4zmp6kfspuiaead.onion/"
],
"ransomnotes-filenames": [
"added_extension.README.txt",
@ -34211,7 +34274,9 @@
"http://wuyfbttjjzsmr5ghl5hoi75ytse3bwrqgk63c6guv3lhw7hwtxbgveid.onion/",
"http://bmfyfxl74qb6rsukgwymv7e22ua4uvhszsamqwx7jmj57qkamxwlhbid.onion/",
"http://yaoehn32c2s5pwsuzhaa4lsu2a4seycpwyvn5gfz3bn4i74t2jo3frad.onion/",
"http://5atqn4dwosjauijzj445mm7t6bqrcvzlzcylpmpnx243jxvlimyb6aid.onion/"
"http://5atqn4dwosjauijzj445mm7t6bqrcvzlzcylpmpnx243jxvlimyb6aid.onion/",
"http://ruzislhpcuvfzw3t2xfqu7gog3gs5j2u65ysaq3ybqkzri3hjddaqgad.onion/",
"http://leakshrlgof456tiw4ww5moiqlnrcork7q7r3cjgmsvex6zazpluhlad.onion/ec49pw6bi8xc2mk3j89kkiaa4ikdrf4wnq2nas4cseciagbw5pq63th7cqajky3c/"
],
"refs": [
"https://www.ransomlook.io/group/cicada3301"
@ -34444,6 +34509,7 @@
"value": "lynx"
},
{
"description": "",
"meta": {
"links": [
"http://nv4addu4insb7x6aagdv6r5gvxzczgfje7mmecsjonnrvsq7ulevvfid.onion",
@ -34574,7 +34640,10 @@
"http://zvdlza5tjyl33mbx4k7w7t25ve6e5c3ve3nmfwqlygl6ww6s4lmsu4ad.onion/",
"http://55gqddfwtzfcuxwgoz746tas2djoiai4lbjvc36kq55prehyvedee3qd.onion/",
"http://ybe6nbidsn6grrnhx5adksp2sd4cz7povuuszhmliir5p4th7inmexid.onion/",
"http://ws6uapok34o3uvn3v6nru574urlvlbn5u3pi2xzyg765vpv2fixcm4ad.onion"
"http://ws6uapok34o3uvn3v6nru574urlvlbn5u3pi2xzyg765vpv2fixcm4ad.onion",
"http://6lrsxvqscxtznb4fhux5u3vbslbanxjzxzgtokjtfwaitxe4pfgfebad.onion/",
"http://4fklgnaegkdpfgaa3rxr3x4xujq4yi6dcuumxikrquzar2m3meiqxwad.onion/",
"http://j56wqkcxzvuz25wzypoxua3fex5zfuc3emkhw4bemtiuikt46dwma6id.onion"
],
"refs": [
"https://www.ransomlook.io/group/nitrogen"
@ -34731,7 +34800,11 @@
"http://qccbb75hak6ze6rsm344rx73lh7rk6caha2hvleyopejhtgagxjyioqd.onion/",
"http://73jrahivyj7cydl3qeiauwm4fkz4f7e4d3deny6qt3cgtwxmkj2vmiyd.onion/",
"http://enfxn727mx4ue55zgbjkogn3lnb57e5ed7bcooodxsajzsp3dyo5xeyd.onion/",
"http://4tgkspsiob5zg7vwqmmbquymoj3sacpx4x4qixvgzukjfen4ck4s6mad.onion/"
"http://4tgkspsiob5zg7vwqmmbquymoj3sacpx4x4qixvgzukjfen4ck4s6mad.onion/",
"http://hqzjmm4qg2q2utn2e3yqt5lsnrabjmi5m4o547v4jp3pi2hwp2tkunid.onion/",
"http://nfh5wuh4gvbai237npdu672xmx2di2lo7pcwu6th2a7kzgue2fnhhdad.onion/",
"http://5q3lywcjrujw3vao7cz3ruqd57ugfdcu3qiisklpqillvuidl5wiqlqd.onion/",
"http://zp6bziy6wljpkg6i3uxzzcxyajodxzoc7acf5egb2vhzzrot23y3mpyd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/sarcoma",
@ -34803,7 +34876,12 @@
"http://5hiynrduugrjbzxluostnxmitaer62obvfyrfxnqkdeog2ejpxhzuqid.onion/",
"http://zdn5uv663oiffbrloxalsdl4v3lg73elrnuso47rbuavu6bmhqvd2wqd.onion/",
"http://63dxcqyjooi55s2x25aqsvrykywmmaaoxj4kc23kdboyxyng2zqtkbyd.onion/",
"http://rqkmahiz55v6bgogfgyni5h7v4sq3bgayycpa6u4c7if7kpvrylcrmad.onion/"
"http://rqkmahiz55v6bgogfgyni5h7v4sq3bgayycpa6u4c7if7kpvrylcrmad.onion/",
"http://fe3klmmbb7upoybd45ayjkxebqxaxukleu2w56kgo67rcnrxlalrxdad.onion/",
"http://nz5rdh2alikmxiyojqx52yhzxdqfty3jwtvcybqajxrkbtsk36jy4aqd.onion/",
"http://u2qvcxl65guk4lxi2lyxq5zwlgnq7ojahihr4ipl7a3wcui6pvff7dyd.onion/",
"http://lbqgjosup47uopyrlvbylzixcp7l5rsrxcdv3y4vy23cczcftsr6imad.onion/",
"http://bt52afulf6zsk3xhzceam6ukipw2wrzpfsizlizdcootn5bc4ewzr7ad.onion/"
],
"refs": [
"https://www.ransomlook.io/group/interlock"
@ -35075,7 +35153,10 @@
{
"description": "",
"meta": {
"links": [],
"links": [
"http://beast6azu4f7fxjakiayhnssybibsgjnmy77a6duufqw5afjzfjhzuqd.onion/",
"http://ooie6tet7ggcmlgvtmyvok4s6vha6ecwczssbchbyxrg2r6v2m6zkkad.onion/"
],
"refs": [
"https://www.ransomlook.io/group/beast"
]
@ -35797,7 +35878,8 @@
{
"meta": {
"links": [
"http://chat5sqrnzqewampznybomgn4hf2m53tybkarxk4sfaktwt7oqpkcvyd.onion/"
"http://chat5sqrnzqewampznybomgn4hf2m53tybkarxk4sfaktwt7oqpkcvyd.onion/",
"http://sugarpanel.space/advauth_ffma"
],
"refs": [
"https://www.ransomlook.io/group/sugar"
@ -36038,7 +36120,19 @@
"http://t3uouzfvsaqurb2rzoe2mkpetp54d7lgtl45ply34v5lugsnzysmkhid.onion/",
"http://xbupelqsy7lubogl6kdtdqguxoleehbxnuuqm2dos6bbmdwablpqckad.onion/",
"http://mvr2bidstp52pkaybzccjueux4hqbkukuqiss6vhn72qwqruzc7awsid.onion/",
"http://vmnnrqf3gs3kl2kfnxatughwmnlyq6qxzyx24ylyh2w36vw3gqwqjpqd.onion/"
"http://vmnnrqf3gs3kl2kfnxatughwmnlyq6qxzyx24ylyh2w36vw3gqwqjpqd.onion/",
"http://ko3lwb6glib74kmol5ov5cphabwqmifb5lnjw4bvj75jpfigrfbn7gid.onion/",
"http://wkqvktnmr2slazl76opbkdli4ia6gznhxln2z5wny54hf4kzjwgqvxyd.onion/",
"http://cjhuttkivmtrf6itrmyoqnxw55isy3dh6u5ifc3fnhajp7lwn5deflid.onion/",
"http://3cxvgnwvbzzfm2abzxidi76uib53vsjudsavgzm4viaj26drkcdl6wad.onion/",
"http://ab2v4xzffr24pdmswqzrbg45pwsget4h7eyd4swxewuqbxmlwcju7lad.onion/",
"http://fk5c3gxraixjl3p7zacchn4jvew35vxo5xpedqf2qtlynsheqymampid.onion/",
"http://yjsknaecbmhvrsagrcwqelpojnbcllt6v27vxebxhnotd3wu67onc5qd.onion/",
"http://kxntyq6yyfomjoqqya6px7pgc6mbfcbaejryxhiwpntcnlr7hopqj3yd.onion/",
"http://2puszzzqvfv2eco7idbt2fznn2iwlsw27ns5xq3ad257mui2keakacqd.onion/",
"http://ebcbyeua65jtsnbsqsjahurkfj6yndhcwnnfxvwwg4yegb5h7fxjc5ad.onion/",
"http://2lqlecl4q4hkrb3rl5p27b4hptnz7lqaaux5uca3g6pylpqlhqyafvad.onion/",
"http://74fwiwaeqvtuf6uddankq5pzq637zpput3qxzq36fcxkhltq5plcxdqd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/kraken"
@ -36905,7 +36999,9 @@
"http://rnsmwareartse3m4hjsumjf222pnka6gad26cqxqmbjvevhbnym5p6ad.onion/",
"http://nidzkoszg57upoq7wcalm2xxeh4i6uumh36axsnqnj3i7lep5uhkehyd.onion/",
"http://oow7rehrxlzpy6vh3hezl2khstkpa6s7wx3iit74tr6xbjibupld5iad.onion/",
"http://cvbu44wmzzslykypqkk3utdvrrdenrf5knvyrshhcvosfxa2un4tqrid.onion/"
"http://cvbu44wmzzslykypqkk3utdvrrdenrf5knvyrshhcvosfxa2un4tqrid.onion/",
"http://vnoa7t4c3wr6himmurl4it3ctvgmm6munjknuztqlu4nbz34367vokyd.onion",
"https://lmsxwm6hrd5osuefl6uia3wwnxxnlav2ce4d4nkjvuonb3426pwdmcad.onion"
],
"refs": [
"https://www.ransomlook.io/group/run some wares"
@ -37176,7 +37272,9 @@
},
{
"meta": {
"links": [],
"links": [
"http://ymnbqd5gmtxc2wepkesq2ktr5qf4uga6wwrsbtktq7n5uvhqmbyaq4qd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/axxes"
]
@ -37657,7 +37755,12 @@
"links": [
"http://secponewsxgrlnirowclps2kllzaotaf5w2bsvktdnz4qhjr2jnwvvyd.onion/",
"https://secp0-news.net/",
"http://secponewsxgrlnirowclps2kllzaotaf5w2bsvktdnz4qhjr2jnwvvyd.onion/files/12b3429e1124122e/"
"http://secponewsxgrlnirowclps2kllzaotaf5w2bsvktdnz4qhjr2jnwvvyd.onion/files/12b3429e1124122e/",
"http://bhn2xz5jer2xeibxjzhgfp7qclttnbvkkvd4hvlmjbnz66jxq7yzn6ad.onion/",
"http://2a6w667vebiebciji7vm3vj43svegvozoqypttdgojzgdcbnfsu5wiid.onion/",
"https://secp0-support.net/",
"https://secp0-support.cfd/",
"https://secp0-news.ws/"
],
"refs": [
"https://www.ransomlook.io/group/secp0"
@ -38428,7 +38531,9 @@
"http://5g2e.l.time4vps.cloud/",
"http://mgeegnexyhhn5dpqewihjy33qyhng3gy66h3fogiwefl5hljhtmfznad.onion/",
"http://2hxbnjzuymvdca4buxlyu4eolz4mbbxw2cnpibbb2od7z77y76di7cad.onion/",
"http://satanlock2p4c3ad7gxmx3ur7wwdwlywebo2azv3vv5qlmjmole2zbyd.onion"
"http://satanlock2p4c3ad7gxmx3ur7wwdwlywebo2azv3vv5qlmjmole2zbyd.onion",
"http://tzhwmgguyxrg6q3tu4q3gvopcjynrhw6ryx2bdl5ghisdkyunfua5xyd.onion/",
"http://42fybwnnv2t6fykirmgxpwvvfidgnfmegrz4lpi3vskivfid7z7kqyqd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/satanlock"
@ -38525,7 +38630,8 @@
"links": [
"http://gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad.onion/",
"http://2bw7r32r5eshwk2h7uekj3lwzorxds2jyhyzqyilphid3r27x5hsf4yd.onion",
"http://jzbhtsuwysslrzi2n5is3gmzsyh6ayhm7jt3xowldhk7rej4dqqubxqd.onion/"
"http://jzbhtsuwysslrzi2n5is3gmzsyh6ayhm7jt3xowldhk7rej4dqqubxqd.onion/",
"http://vrlgjxbl6yroq26xkcjpafgmmxrlpawvr4agppna6apfxjxav2mq66ad.onion"
],
"refs": [
"https://www.ransomlook.io/group/gunra"
@ -38608,7 +38714,8 @@
"meta": {
"links": [
"http://twniiyed6mydtbe64i5mdl56nihl7atfaqtpww6gqyaiohgc75apzpad.onion/",
"http://w4d5aqmdxkcsc2xwcz7w7jo6wdmvmakgy3y6mfmdtzmyvxe77cjkfbad.onion/"
"http://w4d5aqmdxkcsc2xwcz7w7jo6wdmvmakgy3y6mfmdtzmyvxe77cjkfbad.onion/",
"https://share.jtor.xyz/torrents/"
],
"refs": [
"https://www.ransomlook.io/group/j group"
@ -38694,7 +38801,8 @@
"links": [
"http://vg6xwkmfyirv3l6qtqus7jykcuvgx6imegb73hqny2avxccnmqt5m2id.onion/",
"http://panelqbinglxczi2gqkwderfvgq6bcv5cbjwxrksjtvr5xv7ozh5wqad.onion/",
"http://gdbkvfe6g3whrzkdlbytksygk45zwgmnzh5i2xmqyo3mrpipysjagqyd.onion/"
"http://gdbkvfe6g3whrzkdlbytksygk45zwgmnzh5i2xmqyo3mrpipysjagqyd.onion/",
"http://7bmz2tc4p2jk23dcyehg37cd7veflk3fyhxrnbxz75vvno2azfy6qayd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/global"
@ -38720,7 +38828,9 @@
"description": "",
"meta": {
"links": [
"http://elqfbcx5nofwtqfookqml7ltx2g6q6tmddys6e25vgu3al2meim6cbqd.onion/"
"http://elqfbcx5nofwtqfookqml7ltx2g6q6tmddys6e25vgu3al2meim6cbqd.onion/",
"http://zfytizegsze6uiswodhbaalyy5rawaytv2nzyzdkt3susbewviqqh7yd.onion/",
"http://ocwjy4ynmpbbzhumh2ama2vl3bc77lf5auqf7nf4k45lbmzoep2rbyid.onion/"
],
"refs": [
"https://www.ransomlook.io/group/warlock"
@ -38770,7 +38880,264 @@
},
"uuid": "2e54a485-5e92-5fb3-98c9-c394154266c0",
"value": "kawa"
},
{
"description": "",
"meta": {
"links": [
"http://d4rkd2fybtclo44hss2dpqpw7gmofboxhruax2az3uejw7puxxbpkvqd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/d4rk4rmy"
]
},
"uuid": "3f714bee-965a-5327-b966-2d84c07039ec",
"value": "d4rk4rmy"
},
{
"description": "",
"meta": {
"links": [
"http://securo45z554mw7rgrt7wcgv5eenj2xmxyrsdj3fcjsvindu63s4bsid.onion/"
],
"refs": [
"https://www.ransomlook.io/group/qilin-securotrop"
]
},
"uuid": "bf2c358f-79c3-5d04-b095-ebc0dcb2d8a4",
"value": "qilin-securotrop"
},
{
"meta": {
"links": [
"http://ankexpn6vk3qc5ooyyj7ufi6nmyt44vxbjtbxxkq4bxo7xzghai7kiqd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/ank"
]
},
"uuid": "86f03c13-35fe-57a9-bbb3-d0c8bac0db80",
"value": "ank"
},
{
"description": "",
"meta": {
"links": [
"http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/99fb65e2253ca3b34b83"
],
"refs": [
"https://www.ransomlook.io/group/vulcan"
]
},
"uuid": "d296d069-4d78-507f-b372-bf19a9f459e4",
"value": "vulcan"
},
{
"description": " Payouts King Group. We are not RaaS. No affiliates are accepted. We use Tox messaging protocol.",
"meta": {
"links": [
"https://payoutsgn7cy6uliwevdqspncjpfxpmzgirwl2au65la7rfs5x3qnbqd.onion/",
"https://v2mw3spxqhggig5zjd6tjnfamwntrprreij3dq77jlq74dduyjafeead.onion/",
"http://c6nrwsloenpiat7zilh243nvhe7a3edsfm3ct3kpxhu2fv7z36ksjcad.onion/"
],
"refs": [
"https://www.ransomlook.io/group/payoutsking"
]
},
"uuid": "d7d8cb83-3b41-5eb0-b85a-339ef142bdb0",
"value": "payoutsking"
},
{
"meta": {
"links": [
"http://leaksbcwijsbkxcx76s24qi4ab4jn7rgtzzyiss7fzco6amhj6h365ad.onion/"
],
"refs": [
"https://www.ransomlook.io/group/elonmusknow"
]
},
"uuid": "10063902-ad7d-59b8-993e-701dc94d6711",
"value": "elonmusknow"
},
{
"meta": {
"links": [
"http://homelandjustice.ru"
],
"refs": [
"https://www.ransomlook.io/group/homeland"
]
},
"uuid": "f1c0e834-1c40-5196-9a7d-53a9d1bfccec",
"value": "homeland"
},
{
"description": "aka BaqiyatLock",
"meta": {
"links": [
"http://yywhylvqeqynzik6ibocb53o2nat7lmzn5ynjpar3stndzcgmy6dkgid.onion/"
],
"refs": [
"https://www.ransomlook.io/group/bqtlock"
]
},
"uuid": "b5f4ccde-34a7-5db1-9ceb-a4976c393ef6",
"value": "bqtlock"
},
{
"description": "",
"meta": {
"links": [
"http://sdjf982lkjsdvcjlksaf2kjhlksvvnktyoiasuc92lf.onion"
],
"refs": [
"https://www.ransomlook.io/group/blackhunt"
]
},
"uuid": "4572a0a1-c92b-58cb-b436-51b849fa8653",
"value": "blackhunt"
},
{
"meta": {
"links": [
"http://ohu6eschnuhxfg46wvco7j3e76oqymo4cowfepbi7h6z3vf6if6lj5yd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/himalayaa"
]
},
"uuid": "66a55f27-3ead-5144-8307-def8a1da4230",
"value": "himalayaa"
},
{
"description": "",
"meta": {
"links": [],
"refs": [
"https://www.ransomlook.io/group/cryptedpay"
]
},
"uuid": "1b8bace9-c4e4-50b5-9d09-c2015fa7a470",
"value": "cryptedpay"
},
{
"meta": {
"links": [
"http://dfpc7yvle5kxmgg6sbcp5ytggy3oeob676bjgwcwhyr2pwcrmbvoilqd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/mindware"
]
},
"uuid": "7c892b54-9c6e-5f1c-bbd4-bae770a9538a",
"value": "mindware"
},
{
"description": "RansomedVC2 aka RebornVC aka RansomedVC (rebrand) under new leadership.",
"meta": {
"links": [
"https://ransomed.biz/",
"https://ransomed.vc/"
],
"refs": [
"https://www.ransomlook.io/group/ransomedvc2"
]
},
"uuid": "dd3517b0-82f3-579a-a037-6204a8113d42",
"value": "ransomedvc2"
},
{
"meta": {
"links": [
"http://ranionv3j2o7wrn3um6de33eccbchhg32mkgnnoi72enkpp7jc25h3ad.onion/"
],
"refs": [
"https://www.ransomlook.io/group/ranion"
]
},
"uuid": "3eb393c6-bc78-5039-a04a-928598876ff8",
"value": "ranion"
},
{
"meta": {
"links": [
"http://7k4yyskpz3rxq5nyokf6ztbpywzbjtdfanweup3skctcxopmt7tq7eid.onion/databases.html"
],
"refs": [
"https://www.ransomlook.io/group/cryp70n1c0d3"
]
},
"uuid": "fb63284e-b38e-5160-800d-4abce55e9115",
"value": "cryp70n1c0d3"
},
{
"description": "",
"meta": {
"links": [
"http://dounczge5jhw4iztnnpzp54kd4ot3tikhjsimurtcewqssgye6vvrhqd.onion/",
"http://faow6n2hkweyyalp67zvonafn2dzphw36cav653wamj724mwsmtfa5yd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/blackbyte-crux"
]
},
"uuid": "2865f56a-51d4-5d69-abfd-55232f020b28",
"value": "blackbyte-crux"
},
{
"description": "",
"meta": {
"links": [
"http://wugurgyscp5rxpihef5vl6b6m5ont3b6sezhl7boboso2enib2k3q6qd.onion/"
],
"refs": [
"https://www.ransomlook.io/group/devman2"
]
},
"uuid": "c16922f7-2daa-509f-b6ee-d51784c52e67",
"value": "devman2"
},
{
"description": "",
"meta": {
"links": [
"http://sinobi6ftrg27d6g4sjdt65malds6cfptlnjyw52rskakqjda6uvb7yd.onion/leaks",
"http://sinobi6rlec6f2bgn6rd72xo7hvds4a5ajiu2if4oub2sut7fg3gomqd.onion/leaks",
"http://sinobi6ywgmmvg2gj2yygkb2hxbimaxpqkyk27wti5zjwhfcldhackid.onion/leaks",
"http://sinobi7l3wet3uqn4cagjiessuomv75aw3bvgah4jpj43od7xndb7kad.onion/leaks",
"http://sinobi7sukclb3ygtorysbtrodgdbnrmgbhov45rwzipubbzhiu5jvqd.onion/leaks",
"http://sinobi23i75c3znmqqxxyuzqvhxnjsar7actgvc4nqeuhgcn5yvz3zqd.onion/leaks",
"http://sinobia6mw6ht2wcdjphessyzpy7ph2y4dyqbd74bgobgju4ybytmkqd.onion/leaks",
"http://sinobi7yuoppj76qnkwiobwfc2qve2xkv2ckvzyyjblwd7ucpptl62ad.onion/login",
"http://sinobi57mfegeov2naiufkidlkpze263jtbldokimfjqmk2mye6s4yqd.onion/login",
"http://sinobibdvzohujkliofkxiz3ueyedfh6bed21zjz2z6pafw5jeoptsid.onion/login",
"http://sinobibjqytwqxjw24zuerqcjyd3hoow6zia7z6kzvwawivamu7nqayd.onion/login",
"http://sinobicrh73ongfuxjajmlyyhalvkhlcgttxkxaxz3gvsgdcgf76uiqd.onion/login",
"http://sinobidxodgt4jsr3t1mf2rr4okjvvwfp5gh31rqxnowomcx62ssrhqd.onion/login",
"http://sinobiea4snfqtkc43paumapo40i7vxcy5vjzfoalunsnvzehozfhpyd.onion/login",
"http://blog.sinobi.us.org/leaks",
"http://chat.sinobi.us.org/",
"http://cdn.sinobi.us.org/"
],
"refs": [
"https://www.ransomlook.io/group/sinobi"
]
},
"uuid": "2a80eeca-bbb8-5b09-bebd-8d791d0f73c3",
"value": "sinobi"
},
{
"meta": {
"links": [
"http://sharpboyz.io/"
],
"refs": [
"https://www.ransomlook.io/group/sharpboys"
]
},
"uuid": "a94e8cb4-76c4-5d5e-871b-2a98860c910f",
"value": "sharpboys"
}
],
"version": 155
"version": 156
}