Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Sanoviv Medical Institute

Group: Worldleaks

Discovered by ransomware.live: 2026-02-10

Estimated attack date: 2026-02-10

Country: MX

Description:

[AI generated] Sanoviv Medical Institute is a health and wellness facility located in Rosarito Beach, Mexico. This holistic hospital specializes in integrative medicine, nutritional therapies, detoxification, functional medicine, and mind-body healing therapies. Offering inpatient programs, the facility focuses on treating a variety of health issues, including chronic degenerative illnesses and preventative health care.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • c2e4193d-a595-48a4-83ba-8db934774b42@identity-protect.org
  • trustandsafety@support.aws.com
MX Records
  • mx-01-us-east-2.prod.hydra.sophos.com.
  • mx-02-us-east-2.prod.hydra.sophos.com.
TXT Records
  • MS=1E253F1A00AFB88749EABC67CBF26432D462B738
  • sophos-domain-verification=3dfe0be2adf98e87e4d7f56f03eef788096614b3d9012d2f32f6c6316f4118e1
  • v=spf1 ip4:189.223.124.230/31 ip4:18.220.109.217 ip4:189.202.144.210 ip4:148.163.156.76 ip4:148.163.158.73 ip4:18.220.12.142 ip4:18.216.7.10 include:_spf.ezinedirector.com include:_spf_useast2.prod.hydra.sophos.com include:ezinesend41.email ~all
Cloud / SaaS Services Detected
Sophos

Leak Screenshot:

Leak Screenshot