Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Leicester City Council

Group: incransom

Discovered by ransomware.live: 2024-04-03

Estimated attack date: 2024-04-03

Country: GB

Description:

We have downloaded about 3TB of private information.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 415

Third Party Employee Credentials: 1


External Attack Surface: 87



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • eu-smtp-inbound-1.mimecast.com.
  • eu-smtp-inbound-2.mimecast.com.
TXT Records
  • _globalsign-domain-verification=J0CdLpRH7IRCjr71Hmbzf-GOCZP2wSL5lREgjEgR7f
  • QuoVadis=e515ff7b-e9bd-49f8-95ce-d6c52787653e
  • docusign=3fa6da7e-d6f9-4c9e-a88a-d3eae1655321
  • vqj00ypqnfjj8gxydpr42ykn2p22t6m8
  • access-domain-verification=ac8801a7838a062c36b751cdf2c9807cd3c7f572f995acd40e7fe48947e5567d
  • v=spf1 redirect=bbww42ty._spf._d.mim.ec
  • z6wm2l30zz9z21r284h3w1p3vmkzzkr2
  • _globalsign-domain-verification=4WkB469HT3DgmWlF3LxTBT19MHWbl_H0o-lBa7RofY
  • _globalsign-domain-verification=tjRIrLRKEaXq3ltN8tykbQX_zEkf5Yi8vujNgn7D67
  • msfpkey=443g4etxkx3jvj1zn1l0q97da
  • o6jRIx9M9DnK3AG9Yz0sVfv1n5YJVHslB0MdcfJ059ETNvrF7t5SwVEstU2vqeN6SuMGYmFat85ILRSKiSvFdQ==
  • cloudflare-verify.leicester.gov.uk 554412116-992936041
  • MS=ms61413877
  • meDY/dBrtMJWCW3+WWDAhyKs7Rjv4fFqGbsSXba+va2nQoYJrP9pKxd+/oAMGWWdhhMRVQP+58TYVyigMDMr+g==
  • docusign=ddf067c2-3894-44f2-b561-0fb6ef15ed50
  • _globalsign-domain-verification=adJ4u8mj5210iIcMa--qPsCWhONFSW_UIWy9j8HdL5
  • _globalsign-domain-verification=ygki0T5unNsmsTlg5Dm2xGagbfBWFwZUEtFlw276KR
  • MJ_VFY=ced4c9f0bb049539537314dcb1879493.txt
Cloud / SaaS Services Detected
Microsoft 365 DocuSign

Leak Screenshot:

Leak Screenshot