Ransomware Group intelligence
Kawa4096
InactiveTrack Kawa4096 with 17 published victims and 1 known leak locations in a single intelligence view.
Overview
Kawa4096 is tracked by Breach House as a ransomware group with 17 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | kawasa2qo7345dt7ogxmx7qmn6z2hnwaoi3h5aeosupozkddqwp6lqqd.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (17)
Search, filter and paginate the victim timeline for Kawa4096.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | ********.org id21413 View details | United States | Other | — | |
|
********.org |
|||||
| Ransomware | **********.net id21394 View details | United States | Other | — | |
|
**********.net |
|||||
| Ransomware | **********.com id21391 View details | United States | Other | — | |
|
**********.com |
|||||
| Ransomware | icmconv.com id21295 View details | United States | Other | — | |
|
icmconv.com |
|||||
| Ransomware | carestlhealth.org id21294 View details | United States | Healthcare / Pharma | — | |
|
carestlhealth.org |
|||||
| Ransomware | sbamh.org id21290 View details | United States | Other | — | |
|
sbamh.org |
|||||
| Ransomware | gatewaycsb.org id21012 View details | United States | Other | — | |
|
gatewaycsb.org |
|||||
| Ransomware | heimhaus.de id21007 View details | Germany | Other | — | |
|
www.heimhaus.de |
|||||
| Ransomware | tokiomarine-nichido.co.jp id20917 View details | Japan | Other | — | |
|
tokiomarine-nichido.co.jp |
|||||
| Ransomware | www.ogr-jp.com id20916 View details | Japan | Other | — | |
|
www.ogr-jp.com |
|||||
| Ransomware | www.malonebailey.com id20907 View details | United States | Other | — | |
|
www.malonebailey.com |
|||||
| Ransomware | **********-*******.co.jp id20906 View details | Japan | Other | — | |
|
**********-*******.co.jp |
|||||
| Ransomware | *************.org id20905 View details | Other | — | ||
|
*************.org |
|||||
| Ransomware | Morningsideservices id20859 View details | United States | Services | ||
|
www.morningsideservices.com |
|||||
| Ransomware | ******.de id20858 View details | Germany | Other | ||
|
www.******.de |
|||||
| Ransomware | ******.com id20857 View details | United States | Other | ||
|
www.******.com |
|||||
| Ransomware | ******.org id20856 View details | United States | Other | ||
|
******.org |
|||||