Conti2
Conti Wizard Spider 2020 RaaS. run-as-admin.exe UAC. mojobiden.com+paymenthacks.com C2. supp24yy support onion. 2022 Conti Leaks.
Threat Profile
Type
Ransomware
Programming LanguageC++
C2 ProtocolHTTPS/TOR
First Seen2020
Targets
Kritik Altyapi
Purpose / Capabilities
- Ransomware (RaaS)
C2 Servers 5
2 Active
| Address | Port | Protocol | Status | Action |
|---|---|---|---|---|
mojobiden.com
|
443 | HTTPS | Active | |
mojobiden.com
|
80 | HTTP | Active | |
paymenthacks.com
|
443 | HTTPS | INACTIVE | |
paymenthacks.com
|
80 | HTTP | INACTIVE | |
supp24yy6a66hwszu2piygicgwzdtbwftb76htfj7vnip3getgqnzxid.onion
|
80 | HTTP | INACTIVE |
⚠ C2 addresses are shared solely for threat intelligence and defensive purposes. Unauthorized access to these addresses constitutes a criminal offense.
Research Reports (3)
Conti Ransomware -- run-as-admin.exe, mojobiden.com+paymenthacks.com C2, Destek Onion | Kritik
Conti 515KB run-as-admin.exe. mojobiden.com paymenthacks.com C2. supp24yy6a66hwszu2piygicgwzdtbwftb76htfj7vnip3getgqnzxid.onion destek.
Read Report →Conti Ransomware -- mojobiden.com Siyasi Lure, paymenthacks.com, Tor Onion C2 | Kritik
Conti 515KB run-as-admin.exe. mojobiden.com siyasi lure + paymenthacks.com C2. supp24yy... Tor onion destek.
Read Report →Conti -- run-as-admin.exe 515KB, mojobiden.com/paymenthacks.com C2, TOR Onion, net stop | Kritik
Conti run-as-admin.exe 515KB. C2: mojobiden.com, paymenthacks.com. TOR onion. net stop wuauserv.
Read Report →