Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Maintel

Group: cicada3301

Discovered by ransomware.live: 2024-06-20

Estimated attack date: 2024-06-19

Country: GB

Description:

Maintel is a provider of managed cloud communications services for the private and public sectors. The company is was founded in 1991 and is headqu artered in London, England. Downloads: http://cicadacnft7gcgnveb7wjm6pjpjcjcsugogmlrat7u7pcel3iwb7bhyd.onion/maintel-dataleak


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 1

Third Party Employee Credentials: 48


External Attack Surface: 4



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • maintel-co-uk.mail.protection.outlook.com.
TXT Records
  • atlassian-domain-verification=au/rzJIk0RhsjgSMjt2P0aspYlpasO4SWFHAjJaWEgBXYfKrfME4tGkgulj3UDdo
  • google-site-verification=Z8FNOf6w1uHoV0O54pqu1QgU-np1icjgu6yW9F9czDA
  • v=spf1 ip4:176.57.252.100 ip4:195.60.197.41 ip4:195.60.196.248 ip4:213.152.40.201 ip4:213.122.191.193 ip4:213.122.191.194 ip4:18.156.149.64 ip4:195.60.196.1 ip4:195.60.196.3 ip4:195.60.196.14 ip4:195.60.196.19 ip4:195.60.197.1 ip4:195.60.197.6 ip4:195.60." "197.7 ip4:195.60.197.23 ip4:195.60.197.52 ip4:195.60.197.71 ip4:176.56.252.100 ip4:161.71.14.224/28 ip4:176.57.249.196 include:autotask.net include:spf.protection.outlook.com include:spf.smtp2go.com include:ciphr247.com include:spf-uk.emailsignatures365.c" "om include:theaccessgroupSPF.smtp.com include:_spf.salesforce.com a mx -all
  • apple-domain-verification=cOZXx43m78wJe6F7
  • atlassian-domain-verification=UUE1KmW0QfGmbIPjaDTxko0/ivmhKTfgy02iJODcnaTVRe/KGZIVG67I3GK9cd5z
  • google-site-verification=TqygnmNOC0agJOchcs5S-55Yk_hGH43Py7Ydr-jOQiw
  • cisco-ci-domain-verification=7bf765596680bd641570340bb972b9f3063e28e87f1568845502184bd9ef7c3f
  • docusign=a83ad47c-e2b2-4bad-b941-d192788838d2
Cloud / SaaS Services Detected
Apple Atlassian Salesforce Cisco DocuSign

Leak Screenshot:

Leak Screenshot