Group:
Termite
Discovered by ransomware.live: 2025-04-11
Estimated attack date:
2025-04-10
Country:
Description:
Provider of information technology services focused on digital transformation for enterprises. The company specializes in offering small and medium enterprises managed services, data analysis with Power BI, digital project management, technical training and IT support services, thereby enabling companies to modernize and uncomplicate their processes and offer technological support.
DNS Records:
The following DNS records were found for the victim's domain.
- abuse@combell.com
- activation@combell.com
- info@domain-contact.org
- weareonit-com.mail.protection.outlook.com.
- v=spf1 ip4:82.143.87.50 ip4:194.78.103.34 ip4:212.123.10.48/28 ip4:46.240.135.254 ip4:81.82.211.83 ip4:81.82.250.121 ip4:154.63.66.16 ip4:154.63.66.2 ip4:81.95.117.226 ip4:79.132.231.86 include:spf.protection.outlook.com a:mwe1-cbc-aks.westeurope.cloudapp" ".azure.com include:_spf.eu.sparkpostmail.com include:servers.mcsv.net include:spf.eu.exclaimer.net include:autotask.net include:_spf.telavox.se include:spf.flowmailer.net -all exp=_spfexp.weareonit.com
- hq10ieqbrokvv5qah33odbi2j5
- openai-domain-verification=dv-epqA9BQqUrm3YBw4HF7qoA9z
- QVzCDP3hWfxssRaxtf1Q7mPj7838QXJH
- fc6iarqrdhet9qlprqkjqmsp
- google-site-verification=IFECPi13N2g8I8igv3PODvG_fPML1LcjqNLuhDt0i64
- sophos-domain-verification=039b9b92d34a7c7ef2d0dc96338046502c814af04464c8cf53df7b4ac12367f2
- apple-domain-verification=W711JUZfs8B3Yx8B
- zoho-verification=zb19641699.zmverify.zoho.eu
- google-site-verification=Ib_lvryKmLymhDmRJmDAO2TDOqyfY-S73IFHL455s7I
- MS=ms31890072
Cloud / SaaS Services Detected
Apple
Mailchimp
Microsoft 365
Zoho Campaigns
Sophos
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.