projecthoneypot.org |
DOMAIN |
IP Blocklists |
— |
16 |
32 |
|
2026-08-06 |
http://iplists.firehol.org/ |
URL |
IP Blocklists |
url |
8 |
24 |
|
2026-08-06 |
Abuse.ch |
DOMAIN |
IP Blocklists |
— |
20 |
20 |
|
2026-08-06 |
http://www.projecthoneypot.org/ |
URL |
IP Blocklists |
— |
16 |
16 |
|
2026-08-06 |
http://www.projecthoneypot.org/?rf=192670) |
URL |
IP Blocklists |
— |
16 |
16 |
|
2026-08-06 |
http://osint.bambenekconsulting.com/feeds/ |
URL |
IP Blocklists |
— |
14 |
14 |
|
2026-08-06 |
http://osint.bambenekconsulting.com/feeds/) |
URL |
IP Blocklists |
— |
14 |
14 |
|
2026-08-06 |
http://urandom.us.to/ |
URL |
IP Blocklists |
— |
12 |
12 |
|
2026-08-06 |
urandom.us.to |
DOMAIN |
IP Blocklists |
— |
12 |
12 |
|
2026-08-06 |
readme.txt |
DOMAIN |
Ransomware Actors |
— |
2 |
9 |
|
2026-08-06 |
EmergingThreats.net |
DOMAIN |
IP Blocklists |
— |
8 |
8 |
|
2026-08-06 |
proxylists.net |
DOMAIN |
IP Blocklists |
— |
4 |
8 |
|
2026-08-06 |
http://free-proxy-list.net/ |
URL |
IP Blocklists |
— |
8 |
8 |
|
2026-08-06 |
http://www.stopforumspam.com/ |
URL |
IP Blocklists |
— |
8 |
8 |
|
2026-08-06 |
http://www.stopforumspam.com) |
URL |
IP Blocklists |
— |
8 |
8 |
|
2026-08-06 |
StopForumSpam.com |
DOMAIN |
IP Blocklists |
— |
8 |
8 |
|
2026-08-06 |
TEMP.Hex |
DOMAIN |
ATT&CK |
— |
5 |
7 |
|
2026-08-06 |
https://cleantalk.org/ |
URL |
IP Blocklists |
— |
7 |
7 |
|
2026-08-06 |
https://cleantalk.org/) |
URL |
IP Blocklists |
— |
7 |
7 |
|
2026-08-06 |
win32k.sys |
DOMAIN |
Vulnerabilities |
— |
4 |
6 |
|
2026-08-06 |
Info.plist |
DOMAIN |
ATT&CK |
— |
4 |
6 |
|
2026-08-06 |
http://www.emergingthreats.net/ |
URL |
IP Blocklists |
— |
6 |
6 |
|
2026-08-06 |
DShield.org |
DOMAIN |
IP Blocklists |
— |
6 |
6 |
|
2026-08-06 |
files.txt |
DOMAIN |
Ransomware Actors |
— |
1 |
5 |
|
2026-08-06 |
File.txt |
DOMAIN |
ATT&CK |
— |
3 |
5 |
|
2026-08-06 |
https://blog.talosintelligence.com/2019/04/sodinokibi-ransomware-exploits-weblogic.html |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/ |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
TEMP.MixMaster |
DOMAIN |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
https://www.secureworks.com/blog/revil-the-gandcrab-connection |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
https://www.secureworks.com/research/revil-sodinokibi-ransomware |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/ |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdf |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
https://attack.mitre.org/groups/G0034 |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
TEMP.Zagros |
DOMAIN |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
https://www.microsoft.com/en-us/security/blog/2022/05/09/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself/ |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/microsoft-threat-actor-naming?view=o365-worldwide |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2021GTR.pdf |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
TEMP.Veles |
DOMAIN |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2017/12/attackers-deploy-new-ics-attack-framework-triton.html |
URL |
ATT&CK |
— |
5 |
5 |
|
2026-08-06 |
mail.ru |
DOMAIN |
Sanctions |
— |
4 |
5 |
|
2026-08-06 |
gmail.com |
DOMAIN |
Cryptocurrency |
— |
5 |
5 |
|
2026-08-06 |
bitcointrader.ai |
DOMAIN |
Phishing |
— |
5 |
5 |
|
2026-08-06 |
https://threatfox.abuse.ch/faq/#tos |
URL |
Malware Attribution |
— |
5 |
5 |
|
2026-08-06 |
https://www.torproject.org/ |
URL |
IP Blocklists |
— |
5 |
5 |
|
2026-08-06 |
https://feeds.dshield.org/block.txt |
URL |
IP Blocklists |
— |
5 |
5 |
|
2026-08-06 |
https://dshield.org/ |
URL |
IP Blocklists |
— |
5 |
5 |
|
2026-08-06 |
https://dshield.org/) |
URL |
IP Blocklists |
— |
5 |
5 |
|
2026-08-06 |
ME.txt |
DOMAIN |
Ransomware Actors |
— |
1 |
4 |
|
2026-08-06 |
DECRYPT.txt |
DOMAIN |
Ransomware Actors |
— |
1 |
4 |
|
2026-08-06 |
ransomed.vc |
DOMAIN |
Ransomware Actors |
— |
2 |
4 |
|
2026-08-06 |
http://purl.org/dc/elements/1.1/ |
URL |
CERT Advisories |
— |
4 |
4 |
|
2026-08-06 |
http://www.botvrij.eu |
URL |
Domains/URLs |
— |
4 |
4 |
|
2026-08-06 |
ntconfig.pol |
DOMAIN |
Vulnerabilities |
— |
2 |
4 |
|
2026-08-06 |
FormHandler.cgi |
DOMAIN |
Vulnerabilities |
— |
2 |
4 |
|
2026-08-06 |
ftp.NetBSD.ORG |
DOMAIN |
Vulnerabilities |
— |
2 |
4 |
|
2026-08-06 |
ftp.sco.com |
DOMAIN |
Vulnerabilities |
— |
2 |
4 |
|
2026-08-06 |
ftp.freebsd.org |
DOMAIN |
Vulnerabilities |
— |
2 |
4 |
|
2026-08-06 |
http.sys |
DOMAIN |
Vulnerabilities |
— |
2 |
4 |
|
2026-08-06 |
admin.cgi |
DOMAIN |
Vulnerabilities |
— |
4 |
4 |
|
2026-08-06 |
bug.cgi |
DOMAIN |
Vulnerabilities |
— |
4 |
4 |
|
2026-08-06 |
system.keychain |
DOMAIN |
Mobile ATT&CK |
— |
2 |
4 |
|
2026-08-06 |
org.gnome.login |
DOMAIN |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.crowdstrike.com/blog/double-trouble-ransomware-data-leak-extortion-part-1/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
backgrounditems.btm |
DOMAIN |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
Personal.xlsb |
DOMAIN |
ATT&CK |
— |
2 |
4 |
|
2026-08-06 |
Normal.dotm |
DOMAIN |
ATT&CK |
— |
2 |
4 |
|
2026-08-06 |
w32.tidserv |
DOMAIN |
ATT&CK |
— |
2 |
4 |
|
2026-08-06 |
SSH.COM |
DOMAIN |
ATT&CK |
— |
2 |
4 |
|
2026-08-06 |
com.apple.loginwindow.plist |
DOMAIN |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
history.txt |
DOMAIN |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
krb5.ccache |
DOMAIN |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://attack.mitre.org/techniques/T1106)s |
URL |
ATT&CK |
— |
2 |
4 |
|
2026-08-06 |
com.apple.quarantine |
DOMAIN |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
audit.rules |
DOMAIN |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
login.keychain |
DOMAIN |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
Robots.txt |
DOMAIN |
ATT&CK |
— |
2 |
4 |
|
2026-08-06 |
Freedesktop.org |
DOMAIN |
ATT&CK |
— |
2 |
4 |
|
2026-08-06 |
PubPrn.vbs |
DOMAIN |
ATT&CK |
— |
2 |
4 |
|
2026-08-06 |
apple.awt.UIElement |
DOMAIN |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
Terminal.app |
DOMAIN |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://attack.mitre.org/software/S0029) |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
osx.dok |
DOMAIN |
ATT&CK |
— |
2 |
4 |
|
2026-08-06 |
https://dragos.com/blog/crashoverride/CrashOverride-01.pdf |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.bleepingcomputer.com/news/security/killdisk-disk-wiping-malware-adds-ransomware-component/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://securelist.com/sodin-ransomware/91473/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2017/09/zero-day-used-to-distribute-finspy.html |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2020/07/financially-motivated-actors-are-expanding-access-into-ot.html |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://unit42.paloaltonetworks.com/oilrig-novel-c2-channel-steganography/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.us-cert.gov/ncas/alerts/TA17-318B |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
Agent.btz |
DOMAIN |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://securelist.com/bad-rabbit-ransomware/82851/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.welivesecurity.com/2017/10/24/bad-rabbit-not-petya-back/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://objective-see.com/blog/blog_0x25.html |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://cloud.google.com/blog/topics/threat-intelligence/ivanti-post-exploitation-lateral-movement |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.brighttalk.com/webcast/10703/275683 |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://securelist.com/luckymouse-hits-national-data-center/86083/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://unit42.paloaltonetworks.com/hamas-affiliate-ashen-lepus-uses-new-malware-suite-ashtag/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://lab52.io/blog/wirte-group-attacking-the-middle-east/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.secureworks.com/blog/lyceum-takes-center-stage-in-middle-east-campaign |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://vblocalhost.com/uploads/VB2021-Kayal-etal.pdf |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.clearskysec.com/siamesekitten/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.proofpoint.com/sites/default/files/proofpoint-operation-transparent-tribe-threat-insight-en.pdf |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://attack.mitre.org/software/S0266) |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.crowdstrike.com/blog/wizard-spider-adversary-update/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.fireeye.com/blog/threat-research/2019/01/a-nasty-trick-from-credential-theft-malware-to-business-disruption.html |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.secureworks.com/blog/cybercriminals-increasingly-trying-to-ensnare-the-big-financial-fish |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://securelist.com/blackoasis-apt-and-new-targeted-attacks-leveraging-zero-day-exploit/82732/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://attack.mitre.org/groups/G1004) |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://securelist.com/the-silence/83009/ |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://go.recordedfuture.com/hubfs/reports/cta-2023-0808.pdf |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |
https://www.us-cert.gov/ncas/alerts/TA17-164A |
URL |
ATT&CK |
— |
4 |
4 |
|
2026-08-06 |