Group:
Royal
Discovered by ransomware.live: 2023-04-24
Estimated attack date:
2023-04-18
Description:
MW Components is focused on accelerating the entire process of delivering custom, stock, and standard parts to virtually any volume and against demanding deadlines. This time MW Components hasn't coped with deadlines and soon you will be able to download their data and see how they accelerate their their processes in their documents. Files of 274GB size that we obtained contain SSNs, passport data, detailed accounting and finance documents. Stay online!
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- us-smtp-inbound-1.mimecast.com.
- us-smtp-inbound-2.mimecast.com.
- openai-domain-verification=dv-b3jtFeiTfutr3Ne1GfJ31GSp
- apple-domain-verification=U0FyKQbCjBoJYuNQ
- MS=ms11462730
- google-site-verification=YPYO9vdHsBCMXjyjogO8cmSDmFabQtqn3_m-aBFt-fA
- atlassian-domain-verification=MW4oiQoYNXqqydHrBMTwlGdW01SrkUOC9qzExESA4WnmXnMk4GMlm70ogm53tU7u
- Target: 0ed1fe018ac7121f98b13c4b9da060b766cc6dd090
- v=spf1 include:us._netblocks.mimecast.com include:_spf.sendergen.com include:sendgrid.net ip4:8.34.161.0/24 ip4:3.14.207.17 ip4:208.86.168.7 ip4:208.86.171.32 ip4:174.128.1.0/24 ip4:98.101.213.178 ip4:208.86.170.134 ip4:208.86.170.218 ip4:199.250.204.69 i" "p4:70.39.232.80 ip4:143.170.71.76 ip4:192.184.120.0/24 ip4:172.81.116.127 include:spf.protection.outlook.com include:spf.constantcontact.com include:_spf.act-on.net include:8642978.spf08.hubspotemail.net include:_spf.ultipro.com -all
- qv35ko0k3g95khhgbq9aat4uiv
- hj=[2187541]-19112025
- b8bpouualrt280b32abe9jpdcp
Cloud / SaaS Services Detected
Apple
Atlassian
HubSpot
Microsoft 365
SendGrid
Mimecast
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.