Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

The Post and Courier

postandcourier.com

Group: Blacksuit

Discovered by ransomware.live: 2024-04-15

Estimated attack date: 2024-04-15

Country: US

Description:

The Post and Courier is the main daily newspaper in Charleston, South Carolina. It traces its ancestry to three newspapers, the Charleston Courier, founded in 1803, the Charleston Daily News, founded 1865, and The Evening Post, founded 1894. Through the Courier, it brands itself as the oldest daily newspaper in the South and one of the oldest continuously operating newspapers in the United States. It is the flagship newspaper of Evening Post Industries, which in turn is owned by the Manigault family of Charleston, descendants of Peter Manigault and Mr. Pierre Manigault himself as a president for a group of companies.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 15

Third Party Employee Credentials: 1


External Attack Surface: 21



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • us-smtp-inbound-2.mimecast.com.
  • us-smtp-inbound-1.mimecast.com.
TXT Records
  • MS=F8E01795FF3502D041112663C5B666FC50FCF46B
  • ca3-97d480a9897648d595f944cc6da4f87c
  • v=spf1 include:us._netblocks.mimecast.com include:spf1.postandcourier.com include:spf3.postandcourier.com include:sendgrid.net ~all
  • google-site-verification=gL-Bl7ULCV3KMihbJROJq1d-i5LSRD9mevTMCnIYlPQ
  • google-site-verification=FvrmXEaEHqbn0d_t8JS_BUeJVAnfL-0hIXS_D5u9lBQ
  • _2boo8rysfizk8k05640l8ss43dwnlxv
  • _tc9l497bal6wckojgt2mctt4aalz9xk
  • google-site-verification=ntDpiw-45rzm7t4vJV9qBksydFQ5XWrcXEbgnT9AWIY
  • google-site-verification=rAW9DX7yfiFF82k05QGF6LbZBkxcKxMTzAwNv0OCKAM
  • logmein-verification-code=26a057c4-53ec-476d-9f1f-45d13f16e880
  • 0ed1fe018a368aacd8ca044918a7693f9568433154
  • atlassian-sending-domain-verification=54c8b387-a766-4781-9a5a-fa87cf7964bb
Cloud / SaaS Services Detected
LogMeIn SendGrid Mimecast

Leak Screenshot:

Leak Screenshot