PULSE NAME
Ransomware Initial Access Brokers Exposed
WHITE AlienVault 2025-04-11 Modified: 2025-05-11
5
IOCs
LOW VOLUME
An investigation into a brute force attack on an exposed Remote Desktop server led to the discovery of a larger ransomware ecosystem, particularly initial access brokers. The attack began with domain enumeration and successful compromise of an account from multiple IP addresses. The threat actor's unusual behavior of searching for credentials in files prompted further investigation. Analysis of the IP addresses revealed connections to Hive ransomware and BlackSuit. Pivoting from TLS certificates uncovered a network of geographically distributed infrastructure with a pattern of domain names. The case highlights the importance of thorough analysis in incident response and provides insights into the operations and motivations of ransomware actors.
Indicators of Compromise (5)
All FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 65899cd65dd753d2eef5463f120ae023e873e1bd 2025-04-11
FileHash-SHA256 6bc8b8f260f9f9bfea69863ef8d3c525568676ddadc09c14655191cad1acdb5b 2025-04-11
FileHash-SHA256 b884cce828f06fb936fd5809d5945d861401c606c4ebe894464c99e6473e9570 2025-04-11
domain 1vpns.com 2025-04-11
domain specialsseason.com 2025-04-11