Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Unite Here

Group: incransom

Discovered by ransomware.live: 2023-12-20

Estimated attack date: 2023-12-20

Country: US

Description:

UNITE HERE is a labor union in the United States and Canada with roughly 300,000 active members. The union's members work predominantly in the hotel, food service, laundry, warehouse, and casino...



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse enom.com
MX Records
  • east.smtp.mx.exch090.serverdata.net.
  • west.smtp.mx.exch090.serverdata.net.
TXT Records
  • monday-com-verification=EIn5jO2hOxOKTZEiGTfrzW6ccbC-3WS1rTumtzklaVc
  • MS=ms30188966
  • amazonses:Kk0ppF5hGPEQKYxxFGNgbh5kA6MsxqqIcj452YNAsO0=
  • intacct-esk=93CD51F0195D6618E053AA06A8C07C49
  • v=spf1 include:spf.intermedia.net ip4:96.126.103.30 ip4:45.79.147.79 ip4:68.71.252.161 ip4:104.237.143.251 ip4:50.116.48.244 ip4:192.225.170.98 include:spf-2248456.jmsend.com include:sendgrid.net include:mailgun.org include:registroactivo.com include" ":emailus.freshservice.com include:sender.zohobooks.com include:_spf.intacct.com ~all
  • apple-domain-verification=xHnLN2tNG1OWC6RZ
  • 36176F4DE8
  • logmein-verification-code=1693f8fc-5fad-419e-b474-fc25de2bafed
  • miro-verification=cdbd3248ea1e4b5e32481d5191682e8d5434e3ff
  • google-site-verification=oZQ3FghViX5DrBhNEaBt7dznzLaN-Q0tRqffZlPfi0s
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail Microsoft 365 Miro LogMeIn Mailgun SendGrid

Leak Screenshot:

Leak Screenshot