Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
TLP:WHITE20 IOCs
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
Threat Actors
Malware Families
Diamond Model
Adversary(1)
Infrastructure(1)
Capability(5)
Victim
Indicators of Compromise
Indicators of Compromise20
| Type | Indicator | Confidence | Score | First Seen |
|---|---|---|---|---|
| SHA256 | 4142d5efd4ea2abab77f2f0a917610e2ff976bf9e19d7ad1e9156eccdc5412db file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA1 | 3d5ee8429ef00824c0351cba507dfeb92b54f83b file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| MD5 | 73ce2438d4ed475e03727b7b000d2794 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| MD5 | 77fbe265fd65c7f7b6d323fb6de6a4fd file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| MD5 | c92cf9a1af5b1fe25cdcb8771ce52be4 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA1 | ba80d7b038758a129861e1e498e462cc3d68ae20 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA256 | d9487fdc097f770e5661f9e5dee130068cb179d33716abff1a21c8cb901f25a6 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| CVE | CVE-2025-55182 aptbotnetespionage | High | 80 | Jun 2, 26 |
| SHA256 | 1795eacd2c58894ccdd6be8854fe6456c3b069a3a873432343b57b475b256aee file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA1 | c98ee41f09ae079a5643626f57eb84f92205bb2b file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA256 | 8c2665adf8bfab65463f2a9bd1b7bb0231de3f5c1e6a2e51479e44aaac2e7bf0 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA256 | 2d4b4bb18b8445e49eeda571982874403befcecf78266e3d405f6529d98bee46 abusealienvault_ransomwarebad reputation | Medium | 42 | May 12, 26 |
| MD5 | f985b8d6d635c266fc4779dad77aa75c file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| MD5 | b2d51212744f404714fd909e87254d98 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA1 | b44c8084b88d31113ee51758740eb84c251bdae8 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA256 | 19021e53b9929fdf4b7d0e0707434d56bb73c1a9b7403c8837b44d1c417198dc file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA1 | 114ec028a3fc4ed50056ee8166b0c39acff6ff03 abusealienvault_ransomwarebad reputation | Low | 34 | May 12, 26 |
| Domain | 1rpc.io indicatorintel-blogmalware | Low | 28 | Apr 7, 26 |
| MD5 | b188fbc6ff5557767e73e4c883a553a3 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
| SHA1 | aa9218994798ae31a19d3e7e39cfac2e2ee55840 file-hashintel-blogmalware | Medium | 53 | Oct 9, 26 |
IOC Relationship Graph
IOC Relationship Graph20 total IOCs
SHA256SHA1MD5CVEDomain