Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Headwater Companies LLC

Group: ransomhub

Discovered by ransomware.live: 2024-02-26

Estimated attack date: 2024-02-26

Country: US


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 0


External Attack Surface: 1



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse cscglobal.com
MX Records
  • headwaterco-com.mail.protection.outlook.com.
TXT Records
  • apple-domain-verification=DeiXnSrieHJC0959
  • apple-domain-verification=yXorA9eWEzqfskh8
  • knowbe4-site-verification=6080ad31557ce29eae08733f8fb0cda2
  • linkedin-site-verification=14404f84-b8e8-46df-8059-8cf94fd49ce4
  • v=spf1 mx include:spf.protection.outlook.com ip4:198.17.42.0/24 ip4:142.0.176.128 ip4:24.181.205.2 -all
  • MS=ms15205993
  • MS=ms82310233
  • amazonses:NFwuj8zFQztrNdnhTsFMHUrGWRIq7vFYzcYdr8TEGN0=
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail Microsoft 365 KnowBe4

Leak Screenshot:

Leak Screenshot