Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Festspielhaus Baden-Baden

Group: play

Discovered by ransomware.live: 2024-03-27

Estimated attack date: 2024-01-25

Country: DE

Description:

Germany


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 4

Third Party Employee Credentials: 0


External Attack Surface: 1



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mx01.badencloud.de.
  • mx02.badencloud.de.
TXT Records
  • Sendinblue-code:57d99cb09b6f65bd6622ce16b7dccb4a
  • cisco-ci-domain-verification=5a20b66e80d667aa1b6d4b80878e9c8d054a483971b60d109e1588efc6d810b4
  • facebook-domain-verification=ys1m3jouhgi6f67g322ojd9qlp0oza
  • google-site-verification=y12BqRdTI5wn9MLsNrN7243bLEluD-jav8OB3qkmjZs
  • mandrill_verify.5LEcF8UTdEd4eVzQ23mzgQ
  • v=spf1 a mx ip4:46.237.241.170 ip4:217.8.62.164 ip4:217.28.97.145 ip6:2a02:ba8:97:128:250:56ff:fe8a:3491 include:servers.mcsv.net include:_spf-ipa.badencloud.de include:_spf-mta.badencloud.de " "include:spf.protection.outlook.com include:spf.sendinblue.com ~all
Cloud / SaaS Services Detected
Mailchimp Cisco Sendinblue

Leak Screenshot:

Leak Screenshot