Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Dreyfuss Williams & Associates Co., LPA

Group: Knight

Discovered by ransomware.live: 2023-11-20

Estimated attack date: 2023-11-20

Description:

Domain:www.dreyfuss.com300GB+ of data has been downloaded from Dreyfuss100k+ documents containing information on USA residents including SSN DOB.We wait for you on our chat to take this further if not then we will upload data for the world to see.Disclose a portion of the data : http://r6chas4skrvna72fg5ui3cqkke4fnpinsskvlo57aiolrrdb3r777mqd.onion/dreyfuss/enjoy.zipEnjoy!proof1.png 7.1 KBproof2.png 83.61 KBproof3.png 191.75 KB



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • us-smtp-inbound-2.mimecast.com.
  • us-smtp-inbound-1.mimecast.com.
TXT Records
  • MS=ms38940937
  • v=spf1 include:us._netblocks.mimecast.com include:spf.protection.outlook.com include:spf.ess.barracudanetworks.com ip4:209.221.9.107 a:zixvpm01.datbusiness.com a:zixvpm02.datbusiness.com ~all
  • 0ed1fe018a65b277fb050141d4b45a4a3b818bf35d
Cloud / SaaS Services Detected
Microsoft 365 Mimecast

Leak Screenshot:

Leak Screenshot