Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Homeocan

Group: blacksuit

Discovered by ransomware.live: 2024-04-09

Estimated attack date: 2024-04-09

Country: CA

Description:

Homeocan has been an industry leader in the homeopathy and natural products sector since it's founding in 1987.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 4

Third Party Employee Credentials: 0


External Attack Surface: 2



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • paul.andersen egatedomains.ca
  • jasonleeroyer sympatico.ca
MX Records
  • homeocan-ca.mail.protection.outlook.com.
TXT Records
  • MS=ms17167914
  • _globalsign-domain-verification=f2-ywNMwvmAPau9okmfhy4_O74Uo9uYxsn-KXnqjeQ
  • brevo-code:429898f12c7027a15bae812cc49c53e8
  • ca3-ef1ba4a2965e41999d6b82463b381c9d
  • facebook-domain-verification=her7hfc8ypqh5wk7h257nyt42jjoza
  • google-site-verification=StwU6wWej9mRx8aV3tN7_MUujqG7rWhzq3l99SefS_Y
  • google-site-verification=i7uT8bjXAnid2h-iUUHpY9BOqxcNR2N3WIL6ylVD8e0
  • v=spf1 a mx include:send.homeocan.ca include:spf.mandrillapp.com include:_spf.elasticemail.com include:servers.mcsv.net include:spf.protection.outlook.com ~all
Cloud / SaaS Services Detected
Microsoft 365 Mandrill

Leak Screenshot:

Leak Screenshot