diff --git a/clusters/ransomware.json b/clusters/ransomware.json index 8c15a5d2..2241e68a 100644 --- a/clusters/ransomware.json +++ b/clusters/ransomware.json @@ -27672,7 +27672,8 @@ "http://lbbpoq6d2jglpw7dxarr6oaakgnlxt5nmrza5ojlufsuffuzexajsuyd.onion/", "http://lbbp2rsfcmg5durpwgs22wxrdngsa4wiwmc4xk6hgmuluy6bvbvvtlid.onion/", "http://lbbov7weoojwnqytnjqygmglkwtim5dvyw3xvoluk5ostz75ofd6enqd.onion/", - "http://lockbitapt2d73krlbewgv27tquljgxr33xbwwsp6rkyieto7u4ncead.onion/ec_page3.php" + "http://lockbitapt2d73krlbewgv27tquljgxr33xbwwsp6rkyieto7u4ncead.onion/ec_page3.php", + "http://lockbitfnszjao7hayqsd424m74k5jxc52hozvabjrut7pjfsfaaaoad.onion" ], "refs": [ "https://threatpost.com/lockbit-ransomware-proliferates-globally/168746", @@ -28355,7 +28356,14 @@ "meta": { "links": [ "http://eraleignews.com/", - "http://wn6vonooq6fggjdgyocp7bioykmfjket7sbp47cwhgubvowwd7ws5pyd.onion/" + "http://wn6vonooq6fggjdgyocp7bioykmfjket7sbp47cwhgubvowwd7ws5pyd.onion/", + "http://basheqtvzqwz4vp6ks5lm2ocq7i6tozqgf6vjcasj4ezmsy4bkpshhyd.onion/", + "http://bashe4aec32kr6zbifwd5x6xgjsmhg4tbowrbx4pneqhc5mqooyifpid.onion/", + "http://basheqtvzqwz4vp6ks5lm2ocq7i6tozqgf6vjcasj4ezmsy4bkpshhyd.onion", + "http://basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion", + "http://basherykagbxoaiaxkgqhmhd5gbmedwb3di4ig3ouovziagosv4n77qd.onion", + "http://bashete63b3gcijfofpw6fmn3rwnmyi5aclp55n6awcfbexivexbhyad.onion", + "http://bashex7mokreyoxl6wlswxl4foi7okgs7or7aergnuiockuoq35yt3ad.onion" ], "refs": [ "https://www.ransomlook.io/group/eraleign (apt73)" @@ -29374,7 +29382,8 @@ "http://66ohzao6afsv2opk22r2kv6fbnf2fthe7v4ykzzc5vjezvvyf3gocwyd.onion/", "https://2nn4b6gihz5bttzabjegune3blwktad2zmy77fwutvvrxxodbufo6qid.onion/", "http://y6kyfs2unbfcyodzjrxadn4w5vyulhyotdi5dtiqulxbduujehupunqd.onion/", - "http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/api/blog/get" + "http://embargobe3n5okxyzqphpmk3moinoap2snz5k6765mvtkk7hhi544jid.onion/api/blog/get", + "http://3o5ewrzhqoyodfs5kll4cjxagdfrpuu474panwobm4im7ejfpaux5jyd.onion/" ], "refs": [ "https://www.ransomlook.io/group/embargo" @@ -29904,7 +29913,44 @@ }, "uuid": "6a20c736-d83c-502f-8a9f-379a556fb4ac", "value": "interlock" + }, + { + "meta": { + "links": [ + "http://vlofmq2u3f5amxmnblvxaghy73aedwta74fyceywr6eeguw3cn6h6uad.onion/" + ], + "refs": [ + "https://www.ransomlook.io/group/playboy" + ] + }, + "uuid": "4e672e18-c9e3-5b29-a500-8615a1b9c1a8", + "value": "playboy" + }, + { + "meta": { + "links": [ + "http://hellcakbszllztlyqbjzwcbdhfrodx55wq77kmftp4bhnhsnn5r3odad.onion" + ], + "refs": [ + "https://www.ransomlook.io/group/hellcat" + ] + }, + "uuid": "f5ffee22-b5d1-5d55-8dd2-5db26d184cde", + "value": "hellcat" + }, + { + "meta": { + "links": [ + "http://ks5424y3wpr5zlug5c7i6svvxweinhbdcqcfnptkfcutrncfazzgz5id.onion/posts.php", + "http://ks5424y3wpr5zlug5c7i6svvxweinhbdcqcfnptkfcutrncfazzgz5id.onion" + ], + "refs": [ + "https://www.ransomlook.io/group/killsec3" + ] + }, + "uuid": "455c76ae-4abe-5237-90eb-87e9530e240c", + "value": "killsec3" } ], - "version": 137 + "version": 138 }