Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo DC ADVISORY

Group: alphv

Discovered by ransomware.live: 2023-07-26

Estimated attack date: 2022-04-20

Description:

FIRST DATA PACK, 63 GB CLIENTS DOCUMENTS.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints markmonitor.com
  • whoisrequest markmonitor.com
MX Records
  • eu-smtp-inbound-1.mimecast.com.
  • eu-smtp-inbound-2.mimecast.com.
TXT Records
  • adobe-idp-site-verification=42ba43e05789e09e650a5f6c1e5986ce0532b0d084ad412811e3055055903182
  • 1password-site-verification=XUMG56X4BVFHBHWPNHBFH5G5EE
  • PYRimvCkNgK9B2JEzUki1eV8kX4=
  • duo_sso_verification=yr1FucUWIR6DfeBZ5103oAthy0yPRruOR28wjySWYcmeFPRfoSRL5SQJelBDnuDF
  • 0ORF8P672HGR3KZ4SOGJQ45GH4QNQMPMZDFEUXGC
  • 0ed1fe018a7a1bb440e72c4c0cbb34aa1fb318a14f
  • v=spf1 ip4:185.111.53.19 ip4:213.61.245.229 ip4:31.221.97.19 ip4:45.62.176.76 ip4:192.254.125.237 ip4:80.36.68.158 include:eu._netblocks.mimecast.com include:spf.protection.outlook.com include:servers.mcsv.net include:gatormail.co.uk include:_spf.ultipro." "com include:_spf.salesforce.com include:spf.emailsignatures365.com -all
  • knowbe4-site-verification=309c25f37bf2a69ab998d11468b16e30
Cloud / SaaS Services Detected
Adobe Salesforce KnowBe4 Cisco Duo Mimecast

Leak Screenshot:

Leak Screenshot