Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo CORPADS_2

Group: blackbasta

Discovered by ransomware.live: 2023-03-08

Estimated attack date: 2023-03-08

Country: DE

Description:

Aurubis – Metals for progressWith our metals, we create the foundation for technologies of the future. Being smart and connected doesn’t work without metals. Whether renewable energies, electric vehicles, digitalization, or urbanization, the demand for metals will continue to rise. For more than 150 years, Aurubis has produced copper and other metals that are crucial for modernization and for the ongoing development of our lives over the next decades. As a result, the company considers itself a real multimetal provider.SITE: https://aurubis.com Address Aurubis AG, Germany



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse key-systems.net
  • abusereport key-systems.net
  • info domain-contact.org
MX Records
  • mx1.hc1207-1.eu.iphmx.com.
  • mx2.hc1207-1.eu.iphmx.com.
TXT Records
  • apple-domain-verification=6fVWkXix0zwxLMLE
  • Generated by Verizon DNSTool V 2.9
  • mindmanager-verification=19993dc8f0a4531641fdc7f7cf33785479e3dd3b5384303971e247eb07404b98
  • cisco-ci-domain-verification=53289dc5be692af09c190f75c3b16721492d465bc3365706328fd049d497bc1a
  • c0xh6j1zsbkjjy6n6srd47p8p7kj3t7x
  • atlassian-domain-verification=YYKayxEjQXF9a4n0TsEnZysiNmzN6QbRxHp2QPb264c4ZEjM1ap8yWGTczxoHKGI
  • google-site-verification=kCAe6OzNsDjBj10NkmxGn1DScTKsxGrNq2xOEDMg4UU
  • v=spf1 a mx exists:%{i}.spf.hc1207-1.eu.iphmx.com ip4:209.116.111.220 include:_spf.salesforce.com include:spf.mailjet.com include:ipreomail.com include:_spf.zimpel.de include:spf.protection.outlook.com ~all
  • ciscocidomainverification=69e1daf8661d44620cfd2db727680efc0286ab22753aecc5853adc50d5221ea6
  • openai-domain-verification=dv-npzazOk6ZJOAK8Hy7XS0cC8E
  • dropbox-domain-verification=s7m1100zbfm5
  • MS=D9114F3F702958BF3C4477A08B403DA550013302
  • miro-verification=b4bb0fddae29e5da61fd3192df99d72abf85c758
  • have-i-been-pwned-verification=87f2388c3b557025dd4c9d8235f41575
  • atlassian-domain-verification=PvtqW6mn8gZRjMzLEnYUOTKtL2DhF8FpLp6eugvEpRgyy827kVuR3mZB0L3rfkF9
  • H+o85WHdptJHeFh2eMnKmYELx5q+tIKnhmxDye3AyuH5pcqubqCCGJIJcNOR7ntOrzTTydmO/bKiB7OoX6Kgxg==
  • cisco-ci-domain-verification=18e7409a9f8f4be933c3c5df6345a3a0f3fc8e7899f736c15d3adcf4a53b3c4
  • 702cd1c59c3c8920fa77f2c8a18df0d730668918b65b5b3dd8
Cloud / SaaS Services Detected
Apple Atlassian Box Dropbox Salesforce Miro Cisco Mailjet Have I Been Pwned

Leak Screenshot:

Leak Screenshot