Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo NHS.UK

Group: Clop

Discovered by ransomware.live: 2025-11-13

Estimated attack date: 2025-11-13

Country: GB

Description:

[AI generated] NHS.UK, operated by the National Health Service of England, plays a crucial role in providing health-related services and information to the UK population. It offers a plethora of resources about diseases, treatments, and preventative care. In addition, NHS.UK helps citizens locate and access health services including local GPs, hospitals and pharmacies. Its sites also provide tools for booking doctor's appointments and ordering repeat prescriptions online.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • dnsteam nhs.net
MX Records
  • mail.nhs.uk.
TXT Records
  • google-site-verification=dwWXwcFQckdoNrWU_5siMlG_aXHlXMhkddd7xDehP5c
  • hj2d5sn0b4h0p6ait9lh1qp24h
  • 1.2.3.4
  • v=spf1 ip4:195.104.77.0/23 ip4:10.176.129.120 ip4:10.228.178.230 ip4:194.72.83.215 ip4:194.72.83.216 ip4:194.155.93.52/31 include:esa1.hc1668-91.c3s2.iphmx.com " "include:esa2.hc1668-91.c3s2.iphmx.com include:spf.protection.outlook.com include:_spf.nhs.net include:spf.mandrillapp.com -all
  • apple-domain-verification=NiFUi4F53AsxfAxv
  • facebook-domain-verification=lv7tnthk77oqcuocg7u86rnoafjj3z
Cloud / SaaS Services Detected
Apple Mandrill

Leak Screenshot:

Leak Screenshot