Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Savanna Technical College

Group: royal

Discovered by ransomware.live: 2023-03-29

Estimated attack date: 2023-03-27

Country: US

Description:

Savannah Technical College provides dynamic education and variable services to its students in many locations. They've lost almost 100GB of their internal information. We are ready to share it with you.You can find there tons of personal data of their employees, financial documents, auto park information, insurance, passports, and even a note from sheriff.You are welcome!



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mx2.hc4181-17.iphmx.com.
  • savannahtech-edu.mail.protection.outlook.com.
  • mx1.hc4181-17.iphmx.com.
TXT Records
  • v=spf1 include:spf.protection.outlook.com exists:%{i}.spf.hc4181-17.iphmx.com include:spf_c.oraclecloud.com ip4:176.31.145.254 ip4:167.89.16.8 ip4:107.20.210.250 ip4:72.162.204.47 ip4:52.1.14.157 ip4:107.23.16.222 ip4:54.173.83.138 a:smtp.notification.com" " a:smtp1.notification.com a:list.tcsg.edu ip4:66.151.109.0/24 ip4:72.162.204.20 ip4:72.162.204.45 ip4:72.162.1.0/24 ip4:23.103.200.0/24 ip4:23.103.201.0/24 ip4:72.162.204.47 -all
  • ivFC25ca9rLSeSCHNwjC9ija1q0C4YYmrqki8m0pBMw+Ne44OasfhxhFl57wQuDdvJ7Ej+FQqGNbJUUKQHiN/Q==
  • google-site-verification=oUX9X4putbNWiPtETfbAHFVsyD6bfPwALUN8aRaA_Z0
  • cisco-ci-domain-verification=1c0771b108f01c94bbc5858fdfe73351e5f43c975dc3dabe615a7b080c00ff9d
  • BR4O9YL4X2YAOCXH0FXUP6JDQA4HR0LTAM445YW92
  • MS=ms32382350
  • v=msv1 t=a2d2fafeeee6b14a8616f2ef6c21dc
Cloud / SaaS Services Detected
Microsoft 365 Oracle Cloud Cisco

Leak Screenshot:

Leak Screenshot