Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo CMHHELI.COM

Group: Clop

Discovered by ransomware.live: 2026-02-07

Estimated attack date: 2026-02-07

Country: CA

Description:

[AI generated] Canadian Mountain Holidays or CMH Heli-Skiing & Summer Adventures is a travel business that offers luxury heli-skiing and summer adventure packages. It is one of the oldest heli-skiing companies, operating since 1965. With numerous lodges across British Columbia, Canada, they provide guided hiking, skiing, and mountaineering trips in the wilderness.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • cmhheli-com.mail.protection.outlook.com.
TXT Records
  • airtable-verification=cbf36902f44d792c96c202e9ac9b150b
  • apple-domain-verification=51ciagx9n18R6jWL
  • d365mktkey=1KUWGT7VAJPwKbkGw4F0mVBEKJ6SSxV1gcWxchEbqD8x
  • facebook-domain-verification=6bd9rfehlr42w676yvtc8ssc8dvfg2
  • globalsign-domain-verification=D6A6C48373984D9431F243F8F1F0DBA6
  • google-site-verification=NIPPlehZyr_J09cDNAbJwa8A4bDqVwftI6OAaP2goCg
  • google-site-verification=omgZZ10Z-D_TK5HSjV5osmAbFTsnTYpMDhCtBp3jkzM
  • v=spf1 ip4:204.191.80.195/32 ip4:184.94.119.12/32 a:cmhmail01.cmh.com include:spf.protection.outlook.com include:mailgun.org -all
  • 4+jfkIOx9nyg6IrJYuW+1Qe/jkdcgEDUOsm2NvoHAN5hhJVHGLjEG+xGg/GXVPtmfBssQUs13vl0m6Xww0sSyg==
  • 986ssnyrlqyc5v6bn7xj29pg4bcrldr7
  • _3zldwnlc25lsacim61siiintevewse3
Cloud / SaaS Services Detected
Apple Mailgun

Leak Screenshot:

Leak Screenshot