Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo ZILLI

Group: Snatch

Discovered by ransomware.live: 2023-09-18

Estimated attack date: 2023-09-19

Description:

ZILLI works with ultra-fine calfskin suede and glazed lambskin, but also with exotic animal skins such as peccary, python, crocodile, ostrich and kangaroo, all requiring specific expertise. Jackets are made entirely by hand and decorative stitching and finishing touches are also completed by hand. In



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@ovh.net
MX Records
  • zilli-com.mail.protection.outlook.com.
  • mib.tims.fr.
TXT Records
  • v=spf1 a:mib.tims.fr a:mib-invitation.tims.fr ip4:178.33.229.118 ip4:54.240.53.155 ip4:54.240.53.156 ip4:54.240.53.157 ip4:81.252.159.181 ip4:37.235.93.0/24 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.0.0/16 include:spf.protection.outlook.com" " include:spf.mandrillapp.com include:_spf.bigcommerce.com include:sendgrid.net -all
  • MS=ms81628272
  • v=DMARC1; p=none
  • google-site-verification=Pkz_I12T61w6C5OAHM3hiHYqq3SbEQKyG8iwl5fS6ek
Cloud / SaaS Services Detected
Microsoft 365 Mandrill SendGrid

Leak Screenshot:

Leak Screenshot