Tool
AttackCapture
- First Reported
- May 5, 2026
- Latest Reported
- Sep 14, 2026
Reported Context (10)
- Figure 2. Hunt.io AttackCapture of the exposed open directory containing the forti1.sh to forti8.sh reconnaissance scripts targeting the FortiGate SSL-VPN service.The reconnaissance sequence begins with forti1.sh, which Exposed Directory Reveals FortiGate and MeshCentral Intrusion Targeting Thai Broadband Provider
- This campaign was identified by our researchers from an open-directory cloned on the 17th July from the IP address 95.181.173[.]36 with Hunt.io's AttackCapture capability: Hunt.io Links UK Council Attack to SonicWall SMA1000 Exploitation Campaign
- four months earlier, on different infrastructure, run by the same wallet holder. Searching Hunt.io's AttackCapture corpus for the exact Monero wallet string hardcoded throughout this toolkit returns eleven hits. Nine Redis Cryptomining Botnet Compromised 3,562 Servers, Revealed by Operator’s Exposed Files
- the Hunt.io platform we can see this IP has been is linked to Sliver malware on port 31337, with AttackCapture entries exposing the threat actors infrastructure: The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum-Based C2
- variable (SECRIT_KEY) found within the ZIP archive we reviewed provided an unexpected pivot. Querying Attack Capture's Code Search returned an open directory carrying the same typo at 77.105.161[.]235:8000, captured on Flying Eagle Android RAT: Leaked Code, 170 Servers and Night Dragon
CVE (26)
Malware (8)
People (4)
Threat Actors (12)
MITRE ATT&CK (79)
Vendors (27)
Products (54)
Tools (49)
Industries (19)
Countries (34)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.