THUGS(red) DarkWeb/Monitor_

direwolf

Alive Ransomware Tor v3

capture
Blocked: a challenge page was served instead of the siteCHALLENGE PAGE

The only capture we hold is a challenge page, not the service. It is kept for evidence but is not shown here as if it were the site. View the raw capture.

what the page says

DireWolf Negotiation System - Login

🌙 Dark Negotiation System Login Username Password Login OR USE AN ACCESS TOKEN Access token Verification code Click the image for a new code. Enter with token Should your account credentials become inaccessible, please contact us via qTox by adding the qTox ID listed on our website.
reachability history
The 8 most recent checks.
When Status HTTP Response Bytes Via
41m ago Alive 200 320 ms 22,304 chrome-stealth
2h ago Alive 200 562 ms 22,304 chrome-stealth
3h ago Alive 200 428 ms 22,304 chrome-stealth
4h ago Alive 200 774 ms 22,304 chrome-stealth
5h ago Alive 200 329 ms 22,304 chrome-stealth
7h ago Alive 200 309 ms 22,304 chrome-stealth
8h ago Alive 200 601 ms 22,304 chrome-stealth
10h ago Alive 200 547 ms 22,304 chrome-stealth
security headers
Csp
Raw
default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self' ws: wss:;
Directives
Default src
'self'
Script src
'self''unsafe-inline'
Style src
'self''unsafe-inline'
Img src
'self'data:
Connect src
'self'ws:wss:
Unsafe inline
yes
Unsafe eval
no
X frame options
DENY
X content type options
nosniff
Referrer policy
strict-origin-when-cross-origin
Cross origin
X xss protection
1; mode=block
Cookies
Count
0
Secure
0
Httponly
0
Samesite
0
Score
52
Missing
hstspermissions_policycoopcoepcorp
technology detected
Server
Family
unknown
Protocol
http/1.1
what blocks us
Detected
yes
Kind
js-required
Vendor
Origin
Label
JavaScript required
Confidence
40
Signals
"javascript is required" noticenoscript block
Self clearing
yes
Cleared
no
Waited ms
8342
Http code
200
Via
chrome-stealth
contacts published
  • Total0
crypto addresses
  • Total0
forms on the page
Count
1
Kinds
Login
1
Has login
yes
Has search
no
Has upload
no
Forms
  • Kind
    login
    Method
    get
    Action
    http://direwolf66s5zealav7azcyqeipiswecvvnapyuby3dek473kyqfucad.onion/
    Inputs
    3
    Types
    textpasswordsubmit
    Password
    yes
    File
    no
outbound onion links
  • onion_unique not tracked onion_unique
  • onion_total not tracked onion_total
  • clearnet_unique not tracked clearnet_unique
  • internal not tracked internal
  • external not tracked external
  • total not tracked total
  • truncated not tracked truncated
response headers
HeaderValue
content-encoding gzip
content-security-policy default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self' ws: wss:;
content-type text/html; charset=utf-8
date Fri, 21 Aug 2026 22:16:43 GMT
referrer-policy strict-origin-when-cross-origin
transfer-encoding chunked
vary Accept-Encoding
x-content-type-options nosniff
x-frame-options DENY
x-xss-protection 1; mode=block