Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo The People's Federal Credit Union | tpfcucom

Group: alphv

Discovered by ransomware.live: 2023-07-26

Estimated attack date: 2022-05-09

Description:

We successfully exfiltrated 95 GB of sensitive date of The People's Federal Credit Union: billings, financial invoices, documents, reports and etc.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • mail.tpfcu.com.
TXT Records
  • 5pcsc48b9qntm2j2ntaak9ldro
  • google-site-verification=4k6wsbHmdpopkcvDBsqNPCeYNr165SYwBhyi3QgDGQo
  • google-site-verification=rFgvBDjiG_e7QIKnm2clmR9qnFdIk75oqeQg9TN8IUY
  • MS=EFD63E6FC9B293198BBBB4D4F01DB31BF8BE43CD
  • v=spf1 include:sendgrid.net ip4:166.73.7.0/24 ip4:173.219.132.201/28 ip4:173.219.132.194/28 ip4:166.73.0.0/16 ip4:166.73.7.0/24 ip4:144.86.200.33/32 ip4:144.86.200.12/32 ip4:66.193.114.33/32 ip4:66.193.114.111/32 ip4:208.235.248.0/24 include:spf.mandrilla" "pp.com include:spf.cashedge.com include:_spf.act-on.net -all
Cloud / SaaS Services Detected
SendGrid

Leak Screenshot:

Leak Screenshot