IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE20 IOCs

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

TD
The DFIR Report
Published May 11, 2026Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYAkiraINFRASTRUCTURE1rpc.ioCAPABILITYAkiraBumblebeeMETA StealerVICTIMunknown
Adversary(1)
Infrastructure(1)
Capability(5)
Victim

Indicators of Compromise

Indicators of Compromise20

TypeIndicatorConfidenceScoreFirst Seen
SHA2564142d5efd4ea2abab77f2f0a917610e2ff976bf9e19d7ad1e9156eccdc5412db
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA13d5ee8429ef00824c0351cba507dfeb92b54f83b
file-hashintel-blogmalware
Medium
53
Oct 9, 26
MD573ce2438d4ed475e03727b7b000d2794
file-hashintel-blogmalware
Medium
53
Oct 9, 26
MD577fbe265fd65c7f7b6d323fb6de6a4fd
file-hashintel-blogmalware
Medium
53
Oct 9, 26
MD5c92cf9a1af5b1fe25cdcb8771ce52be4
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1ba80d7b038758a129861e1e498e462cc3d68ae20
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA256d9487fdc097f770e5661f9e5dee130068cb179d33716abff1a21c8cb901f25a6
file-hashintel-blogmalware
Medium
53
Oct 9, 26
CVECVE-2025-55182
aptbotnetespionage
High
80
Jun 2, 26
SHA2561795eacd2c58894ccdd6be8854fe6456c3b069a3a873432343b57b475b256aee
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1c98ee41f09ae079a5643626f57eb84f92205bb2b
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA2568c2665adf8bfab65463f2a9bd1b7bb0231de3f5c1e6a2e51479e44aaac2e7bf0
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA2562d4b4bb18b8445e49eeda571982874403befcecf78266e3d405f6529d98bee46
abusealienvault_ransomwarebad reputation
Medium
42
May 12, 26
MD5f985b8d6d635c266fc4779dad77aa75c
file-hashintel-blogmalware
Medium
53
Oct 9, 26
MD5b2d51212744f404714fd909e87254d98
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1b44c8084b88d31113ee51758740eb84c251bdae8
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA25619021e53b9929fdf4b7d0e0707434d56bb73c1a9b7403c8837b44d1c417198dc
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1114ec028a3fc4ed50056ee8166b0c39acff6ff03
abusealienvault_ransomwarebad reputation
Low
34
May 12, 26
Domain1rpc.io
indicatorintel-blogmalware
Low
28
Apr 7, 26
MD5b188fbc6ff5557767e73e4c883a553a3
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1aa9218994798ae31a19d3e7e39cfac2e2ee55840
file-hashintel-blogmalware
Medium
53
Oct 9, 26

IOC Relationship Graph

IOC Relationship Graph20 total IOCs
SHA256SHA1MD5CVEDomain
SHA2566SHA16MD56CVE1Domain1Actors1Malware5REPORTFlash Alert: EtherRat and AkiraAkiraBumblebeeMETA StealerMimikatzNetScan
scroll to zoom · drag to pan · click IOC to open