Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo PAYBACK.GROUP

Group: Clop

Discovered by ransomware.live: 2023-07-26

Estimated attack date: 2023-07-26

Description:

PAYBACK GROUP: Home



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • payback-group.mail.protection.outlook.com.
TXT Records
  • v=spf1 ip4:62.128.13.137 ip4:213.95.186.78 ip4:213.95.1.0/28 ip4:62.128.1.0/24 ip4:213.95.72.0/22 ip4:213.95.71.0/24 include:spf.protection.outlook.com include:spf.mailjet.com include:spf.qb-feedback.com include:_spf.questback.com include:i-grasp.com -all
  • MS=ms96281662
  • _0rec3t7c3gdqnd4yrs5lx4r967gg6dc
  • _i22ytg7e78zk9a7l457eouz5k5e0ymp
  • apple-domain-verification=vID8ePIkg6UamSrq
  • google-site-verification=ISfMuoqRpBdMGOx2awGgcpo3h_srjLChmNV6J6NzhHw
Cloud / SaaS Services Detected
Apple Microsoft 365 Mailjet

Leak Screenshot:

Leak Screenshot