Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Country Inn & Suites by Radisson

Group: everest

Discovered by ransomware.live: 2024-10-19

Estimated attack date: 2024-10-19

Country: US

Description:

Thousands and thousands of client’s personal information,credit cards info, internal emails, incidents, messages Full calendar of past and future bookingsAnd complete negligence in storing passwords and private data, Evidences that management is aware of events and is not taking any actionThe company must follow the instructions to resolve the issue with us before the timer ends, […]



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints markmonitor.com
  • whoisrequest markmonitor.com
MX Records
  • radissonhotels.in.tmes.trendmicro.eu.
TXT Records
  • onetrust-domain-verification=21af34eab16746a989ce85ed8ff862e8
  • apple-domain-verification=7pRVrrdqq81xOmvENMqEmbUMtYI7GI-aOdL5kKkK_eQ
  • atlassian-domain-verification=KX2aLAPZ1iNXTguqChaB9yaOzVmpXWkkjqN68yZOjyaxXYfivmXNjBk53KpUpudc
  • MS=ms55195023
  • HEWqEaHE5znFinfNRI8O8YZNI2jSGLRESsxYhrXvRrQ=
  • docusign=650288ba-d9dc-421d-8592-2d507d551901
  • m76FAtXv2pWKcXLPG7NwR7BpXxo5SUtoZ1XHK9gRTEE=
  • facebook-domain-verification=h4ce35te1zqi5hukx67ohi8gg54j58
  • amazonses:IQ2BikmmmJk4t6Va6EHC91kFWEjM1+2Z2zGGiYapQn0=
  • v=spf1 mx a ip4:52.208.166.252 ip4:93.165.150.78/32 ip4:207.166.86.53 ip4:207.166.92.11 ip4:207.166.94.53 ip4:207.166.95.11 ip4:128.177.144.7 include:spf.protection.outlook.com " "include:spf.rezidor.com include:spf.tmes.trendmicro.com ip4:155.56.208.100 ip4:18.198.35.158 ip4:3.65.86.245 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.0.0/16 ip4:208.185.229.0/24 ip4:208.185.235.0/24 ip4:62.190.159.144/28 ip4:62.190.59.144/28 " "ip4:128.177.154.7 ip4:65.221.28.5 ip4:87.253.232.0/21 ip4:185.189.236.0/22 ip4:185.211.120.0/22 ip4:185.250.236.0/22 ip4:216.71.96.0/22 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.8.0/21 ip4:52.254.72.70 ip4:216.119.209.33 ip4:216.119.217.33 " "ip4:199.91.136.28 ip4:149.96.5.209 ip4:149.96.5.7 ip4:149.96.6.7 ip4:149.96.6.3 ip4:149.96.6.2 ip4:149.96.5.2 ip4:149.96.6.209 ip4:149.96.5.3 ip4:149.96.5.6 ip4:199.91.140.28 ip4:149.96.6.6 " "ip4:149.96.14.2 ip4:148.139.0.2 ip4:199.91.141.22 ip4:199.91.141.145 ip4:199.91.141.23 ip4:199.91.140.26 ip4:148.139.2.2 ip4:148.139.3.2 ip4:199.91.139.24 ip4:199.91.140.28 ip4:148.139.1.2 " "ip4:199.91.136.28 ip4:37.98.234.2 ip4:148.139.0.31 ip4:199.91.137.2 ip4:37.98.232.12 ip4:199.91.139.22 ip4:37.98.232.26 ip4:199.91.136.26 ip4:199.91.137.26 ip4:199.91.139.145 " "ip4:199.91.141.24 ip4:148.139.1.31 ip4:149.96.13.2 ip4:37.98.232.2 ip4:199.91.139.23 ip4:37.98.235.2 ip4:149.96.2.26 ip4:149.96.195.2 ip4:149.96.1.26 ip4:148.139.104.16 ip4:149.96.133.2 ip4:149.96.221.2 ip4:148.139.105.17 " "ip4:103.23.67.26 ip4:103.23.65.2 ip4:149.96.220.2 ip4:199.91.136.28 ip4:148.139.105.16 ip4:103.23.64.2 ip4:148.139.104.17 ip4:103.23.66.26 ip4:149.96.194.2 ip4:199.91.140.28 ip4:149.96.132.2 " "ip4:167.89.77.138 ip4:40.113.134.102 ip4:3.210.182.90 ip4:155.56.208.101 ip4:155.56.208.100/30 ip4:167.89.115.56 ip4:167.89.115.83 ip4:167.89.115.52 ip4:167.89.115.120 ip4:50.31.156.96/27 ip4:104.245.209.192/26 ip4:50.31.205.0/24 -all
  • tmes=8612b6da00992d451e5bcb0f6b0d8320
  • google-site-verification=3XjU1xiCpaCqu0TWJAF_n0-XiIk5dOxCQD-pSN6cGW4
  • Dynatrace-site-verification=6ef875f3-76e5-490c-84ff-523a04a5d056__1kve3bmna0ao065i45e1um1m5r
  • adobe-idp-site-verification=9315089c4b3efc289f8a4784eda956fdff914eace9dcc8b19ae15233ea22dfb3
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Microsoft 365 OneTrust DocuSign

Leak Screenshot:

Leak Screenshot