Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Soja de Portugal

write.as

Discovered 2026-06-04 09:09 UTC
Est. attack date 2026-06-03
Country PT

Description:

***.pt ***.com/c/soja-de-portugal/458493209 491GB leaked from there as a result of this breach. What kind of data leaked: - SAP data - contacts - contracts - planning - logistics - projects data - personal data - employee data - partners data - customers data - financial data - correspondence - production data - quality control data - offers and proposals - data related to Sorgal, Avicasal, Savinor and other brands - other sensitive business data Instead of negotiations, threats were made and the leaked data was not even reported to anyone here is the text they wrote https://***.as/***.md

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • hostmastergdns.com
MX Records
  • mx2.emailsrvr.com.
  • mail.write.as.
  • mx1.emailsrvr.com.
TXT Records
  • facebook-domain-verification=87eeqarifuzm0q17j6fuws09fcu482
  • brave-ledger-verification=72cd6a405dd0d426c30ade7c2ba7482647ed52f02a9848a5a01c5a9c1e1dd383
  • v=spf1 include:mailgun.org include:emailsrvr.com include:mailbox.org ~all
Cloud / SaaS Services Detected
Mailgun