Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo COSI

Group: Karakurt

Discovered by ransomware.live: 2023-08-02

Estimated attack date: 2023-08-02

Description:

COSI, Columbus, Ohio's dynamic Center of Science and Industry, inspires the scientists, dreamers, and innovators of tomorrow. We've taken about 75GBs of data from this organization. You will find there their projects information, lots of accounting and financial documents, contracts (some of them are confidential), clients contacts, donations information an so on. There are also databases containing clients, partners and employee data, transactions and correspondence. Wait for the release.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@tucows.com
MX Records
  • cosi-org.mail.protection.outlook.com.
TXT Records
  • v=spf1 ip4:192.254.121.248 include:spf.mandrillapp.com include:spf.protection.outlook.com include:_phishspf.knowbe4.com include:spf.ticketure.com ip4:159.112.241.219 include:_spf.intacct.com -all
  • 0ed1fe018aaf9825f89c08457dbc1c832f47aaab10
  • MS=ms55479471
  • intacct-esk=3B184292258E979DE06349068D0A3AE3
  • r8vbnb7vcgjh6v8n63mvkccw8ms9qmcd
Cloud / SaaS Services Detected
Microsoft 365 Sage KnowBe4 Mandrill

Leak Screenshot:

Leak Screenshot