Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo JBCC Corp

Group: mallox

Discovered by ransomware.live: 2023-06-28

Estimated attack date: 2023-06-28

Description:

INFO: https://www.zoominfo.com/c/jbcc/431568723 DATA: CISDOM.7z.004: https://anonfiles.com/3eH2a3zez6/CISDOM_7z_004 CISDOM.7z.003: https://anonfiles.com/KfH1a5z6ze/CISDOM_7z_003 CISDOM.7z.002: https://anonfiles.com/MfHca7zfzd/CISDOM_7z_002 CISDOM.7z.001: https://anonfiles.com/FeH5aaz7z5/CISDOM_7z_001​ Password: &q.&i_R327:3p1<dBtEK~L02HT(4C3JZ



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mgc.cybermail.jp.
TXT Records
  • google-site-verification=-8RqlPcg7ZN1yWcqpD3jWx0KcyeFgT5MCIskNm1mTJw
  • v=spf1 include:spfcm.cybermail.jp include:amazonses.com include:spf.smktg.jp include:spf.securemx.jp ip4:18.176.141.199 ip4:35.75.52.188 include:mail.zendesk.com include:spf.protection.outlook.com include:_spf.salesforce.com " "ip4:210.239.141.205 ip4:210.239.141.206 ip4:210.239.141.207 ~all
  • MS=ms21999286
Cloud / SaaS Services Detected
Amazon SES/WorkMail Microsoft 365 Salesforce Zendesk

Leak Screenshot:

Leak Screenshot