Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Campaign for Tobacco-Free Kids

Group: Blacksuit

Discovered by ransomware.live: 2024-02-05

Estimated attack date: 2024-02-05

Country: US

Description:

Campaign for Tobacco-Free Kids



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • icann-abuse-reports tierra.net
MX Records
  • usb-smtp-inbound-2.mimecast.com.
  • usb-smtp-inbound-1.mimecast.com.
TXT Records
  • 0ed1fe018aa4b73618ec694936b835375d271e2bff
  • MS=34E57A3768F540058FBB399CAAF744AFF2FBEBC2
  • MS=ms17065001
  • ZOOM_verify_UhE7sIXuTQOsjdzzL2-otw
  • apple-domain-verification=TBEUTxyx8wzKPRg9
  • docusign=66b694bb-e1d7-46ac-89e0-32796eaf5ef4
  • google-gws-recovery-domain-verification=58597269
  • google-site-verification=1kPLehfP9P4isb__5Lkeo3hVknjD8dwKJXfSsexLN7c
  • o0rWRORfNFXy2Vua7vGxIsR4HmOAwdem9gPehtCe7k0c4a/2X60SbcYUjiqgc3nmdEKh1/eEtD1Sfg26eWaMWQ==
  • ppe-f8929442a9bc8ea6972e
  • v=spf1 include:usb._netblocks.mimecast.com ip4:209.59.154.122 ip4:64.124.184.42 ip4:209.59.188.192 ip4:66.231.180.192/27 ip4:69.174.82.32/27 ip4:69.174.83.128/25 ip4:204.28.10.0/23 ip4:4.59.154.122 +mx include:salsalabs.org include:s" "alsalabs.net include:return.smtpcorp.com include:spf.myconnectwise.net include:spf.protection.outlook.com include:_spfprod.ngpvan.com include:docebosaas.com include:spf-use1.docebopass.com ~all
  • v=verifydomain MS=ms95651193
Cloud / SaaS Services Detected
Apple Microsoft 365 Mimecast DocuSign Zoom

Leak Screenshot:

Leak Screenshot