Conti2

Conti Wizard Spider 2020 RaaS. run-as-admin.exe UAC. mojobiden.com+paymenthacks.com C2. supp24yy support onion. 2022 Conti Leaks.

Threat Profile
Type Ransomware
Programming LanguageC++
C2 ProtocolHTTPS/TOR
First Seen2020
Targets Kritik Altyapi
Purpose / Capabilities
  • Ransomware (RaaS)

C2 Servers 5

2 Active
Address Port Protocol Status Action
mojobiden.com
443 HTTPS Active
mojobiden.com
80 HTTP Active
paymenthacks.com
443 HTTPS INACTIVE
paymenthacks.com
80 HTTP INACTIVE
supp24yy6a66hwszu2piygicgwzdtbwftb76htfj7vnip3getgqnzxid.onion
80 HTTP INACTIVE

⚠ C2 addresses are shared solely for threat intelligence and defensive purposes. Unauthorized access to these addresses constitutes a criminal offense.

Research Reports (3)

Critical

Conti Ransomware -- run-as-admin.exe, mojobiden.com+paymenthacks.com C2, Destek Onion | Kritik

Conti 515KB run-as-admin.exe. mojobiden.com paymenthacks.com C2. supp24yy6a66hwszu2piygicgwzdtbwftb76htfj7vnip3getgqnzxid.onion destek.

Read Report →
Critical

Conti Ransomware -- mojobiden.com Siyasi Lure, paymenthacks.com, Tor Onion C2 | Kritik

Conti 515KB run-as-admin.exe. mojobiden.com siyasi lure + paymenthacks.com C2. supp24yy... Tor onion destek.

Read Report →
Critical

Conti -- run-as-admin.exe 515KB, mojobiden.com/paymenthacks.com C2, TOR Onion, net stop | Kritik

Conti run-as-admin.exe 515KB. C2: mojobiden.com, paymenthacks.com. TOR onion. net stop wuauserv.

Read Report →