Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Ankara-İzmir

Group: Thegentlemen

Discovered by ransomware.live: 2026-02-06

Estimated attack date: 2026-02-06

Country: TR

Description:

aniyht.com The Ankara-İzmir High-Speed Railway Line Project (AİYHT) is a significant project under the General Directorate of Infrastructure Investments of the Republic of Turkey's Ministry of Transport and Infrastructure, which will connect Turkey's capital, Ankara, with İzmir, the country's third most populous city. The 503-kilometer-long high-speed railway line will pass through the provincial boundaries of Ankara, Eskişehir, Afyonkarahisar, Kütahya, Uşak, Manisa, and İzmir.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • gdpr-masking@gdpr-masked.com
  • abuse@ihs.com.tr
MX Records
  • aniyht-com.mail.protection.outlook.com.
TXT Records
  • v=DMARC1; p=quarantine; rua=mailto:administrator@aniyht.com; ruf=mailto:administrator@aniyht.com; fo=1; adkim=s; aspf=s; pct=100; rf=afrf; ri=86400; sp=quarantine
  • _guci0tjgvn5pyl2u2irqjlj355uvrh7
  • v=spf1 include:spf.protection.outlook.com -all
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot