PULSE NAME
The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy
WHITE The Gentlemen AlienVault 2026-04-20 Modified: 2026-04-20
46
IOCs
MEDIUM VOLUME
The Gentlemen ransomware-as-a-service program has rapidly expanded since mid-2025, claiming over 320 victims with 240 attacks occurring in early 2026. The service provides multi-platform lockers for Windows, Linux, NAS, BSD, and ESXi, enabling comprehensive coverage of corporate environments. During an incident response engagement, an affiliate deployed SystemBC proxy malware for covert tunneling and payload delivery. Analysis of the SystemBC command-and-control server revealed a botnet of over 1,570 victims, primarily corporate and organizational targets. The intrusion progressed from domain controller compromise through credential validation, remote execution via administrative shares, and deployment of Cobalt Strike payloads. Attackers disabled defenses, established persistence through scheduled tasks and services, and ultimately deployed ransomware via Group Policy. The operation demonstrates sophisticated lateral movement capabilities, defense evasion techniques, and integration of mature post-exploit...
Indicators of Compromise (46)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 f4ae5b89db5a6a36dbd98287ab7c860a 2026-04-20
FileHash-SHA1 36d968425629b10f38be17787f8afe4b8afa131e 2026-04-20
FileHash-SHA256 992c951f4af57ca7cd8396f5ed69c2199fd6fd4ae5e93726da3e198e78bec0a5 2026-04-20
FileHash-MD5 30b49ae2f685d4403d3013410f80c2e2 2026-04-20
FileHash-MD5 4200b46a93c6ab059e2b34ce200c4a5b 2026-04-20
FileHash-MD5 44118d8fb41634b3d8d8b1c6fdf9c421 2026-04-20
FileHash-MD5 5f5bf7fc7a9ac89ce0bbb07bd1160078 2026-04-20
FileHash-MD5 6ae7c9a7ea0b8c40a64225734f6bd01d 2026-04-20
FileHash-MD5 c9d004384de06bbc53724b1431dc0fde 2026-04-20
FileHash-MD5 de1a114a2c5552387a1bbb61501bf129 2026-04-20
FileHash-SHA1 2c27a865b3ab1f0bd2ea1e8f7298b5ef9348c5ac 2026-04-20
FileHash-SHA1 3e2272b916da4be3c120d17490423230ab62c174 2026-04-20
FileHash-SHA1 42bcc743c71a9ea083c1c750a398110582796762 2026-04-20
FileHash-SHA1 5264a94271d875675336a503c94ece0baceb58c5 2026-04-20
FileHash-SHA1 68225c5613afe2174ed46e074147676b0f9a3915 2026-04-20
FileHash-SHA1 8468cb5888fb383d25f9144c2b2f61c414cea3f8 2026-04-20
FileHash-SHA1 8cdfedf9416ef9e50548f02e5dfa5dd5aa38c586 2026-04-20
FileHash-SHA1 d6aaed67606d6dab0f652c755d3d363025f60adb 2026-04-20
FileHash-SHA256 025fc0976c548fb5a880c83ea3eb21a5f23c5d53c4e51e862bb893c11adf712a 2026-04-20
FileHash-SHA256 1eece1e1ba4b96e6c784729f0608ad2939cfb67bc4236dfababbe1d09268960c 2026-04-20
FileHash-SHA256 22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67 2026-04-20
FileHash-SHA256 2ed9494e9b7b68415b4eb151c922c82c0191294d0aa443dd2cb5133e6bfe3d5d 2026-04-20
FileHash-SHA256 3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235 2026-04-20
FileHash-SHA256 48d9b2ce4fcd6854a3164ce395d7140014e0b58b77680623f3e4ca22d3a6e7fd 2026-04-20
FileHash-SHA256 5dc607c8990841139768884b1b43e1403496d5a458788a1937be139594f01dca 2026-04-20
FileHash-SHA256 62c2c24937d67fdeb43f2c9690ab10e8bb90713af46945048db9a94a465ffcb8 2026-04-20
FileHash-SHA256 788ba200f776a188c248d6c2029f00b5d34be45d4444f7cb89ffe838c39b8b19 2026-04-20
FileHash-SHA256 860a6177b055a2f5aa61470d17ec3c69da24f1cdf0a782237055cba431158923 2026-04-20
FileHash-SHA256 87d25d0e5880b3b5cd30106853cbfc6ef1ad38966b30d9bd5b99df46098e546c 2026-04-20
FileHash-SHA256 8c87134c1b45e990e9568f0a3899b0076f94be16d3c40fa824ac1e6c6ee892db 2026-04-20
FileHash-SHA256 91415e0b9fe4e7cbe43ec0558a7adf89423de30d22b00b985c2e4b97e75076b1 2026-04-20
FileHash-SHA256 994d6d1edb57f945f4284cc0163ec998861c7496d85f6d45c08657c9727186e3 2026-04-20
FileHash-SHA256 9f61ff4deb8afced8b1ecdc8787a134c63bde632b18293fbfc94a91749e3e454 2026-04-20
FileHash-SHA256 a7a19cab7aab606f833fa8225bc94ec9570a6666660b02cc41a63fe39ea8b0ad 2026-04-20
FileHash-SHA256 b67958afc982cafbe1c3f114b444d7f4c91a88a3e7a86f89ab8795ac2110d1e6 2026-04-20
FileHash-SHA256 c46b5a18ab3fb5fd1c5c8288a41c75bf0170c10b5e829af89370a12c86dd10f8 2026-04-20
FileHash-SHA256 c7f7b5a6e7d93221344e6368c7ab4abf93e162f7567e1a7bcb8786cb8a183a73 2026-04-20
FileHash-SHA256 cc14df781475ef0f3f2c441d03a622ea67cd86967526f8758ead6f45174db78e 2026-04-20
FileHash-SHA256 ec368ae0b4369b6ef0da244774995c819c63cffb7fd2132379963b9c1640ccd2 2026-04-20
FileHash-SHA256 efaf8e7422ffd09c7f03f1a5b4e5c2cc32b05334c18d1ccb9673667f8f43108f 2026-04-20
FileHash-SHA256 f736be55193c77af346dbe905e25f6a1dee3ec1aedca8989ad2088e4f6576b12 2026-04-20
FileHash-SHA256 fc75ed2159e0c8274076e46a37671cfb8d677af9f586224da1713df89490a958 2026-04-20
FileHash-SHA256 fe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68 2026-04-20
URL http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/ 2026-04-20
FileHash-SHA1 f1025bb2f147c01742f263bc0b8d462af9728a22 2026-04-20
domain tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion 2026-04-20