Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo caltrol.com

Group: cactus

Discovered by ransomware.live: 2025-02-26

Estimated attack date: 2025-02-06

Country: US

Description:

<p>Founded in 1934, Caltrol is an Emerson Impact Partner, they serve as a local, single point of contact for sales, service &amp; applied engineering for Emersons Automation Solutions business.</p><p>Website: <a href="https://www.caltrol.com/">https://www.caltrol.com/</a></p><p>Revenue : $296.3M</p><p>Address: 1385 Pama Ln Ste 111, Las Vegas, Nevada, 89119, United States</p><p>Phone Number: (702) 966-1800</p><p><mark class="marker-yellow"><strong>Download link #1:</strong></mark> &nbsp;<a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/CALTROL/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/CALTROL/PROOF/</a></p><p><mark class="marker-yellow"><strong>Mirror:</strong></mark> &nbsp;<a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/CALTROL/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/CALTROL/PROOF/</a></p><p><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:</strong></mark>Personal identifiable information, corporate docs, contracts\NDAs, database backups with customer information, financial data\payroll, HR dept docs, engineering data, drawings, employee personal documents, corporate correspondence, etc.</p><p><img src="/uploads/5_3585feac79.png" alt="5.png"><img src="/uploads/3_70c6cebe1d.png" alt="3.png"><img src="/uploads/2_dcfbe31a82.png" alt="2.png"><img src="/uploads/1_df9450e8c8.png" alt="1.png"><img src="/uploads/4_4905aeec5d.png" alt="4.png"></p>


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 2

Third Party Employee Credentials: 0


External Attack Surface: 1



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • d145189b.ess.barracudanetworks.com.
  • d145189a.ess.barracudanetworks.com.
  • caltrol-com.mail.protection.outlook.com.
TXT Records
  • openai-domain-verification=dv-8x4WZXJLaK8iuYRfg8eIe33e
  • smartsheet-site-validation=dhUUVAnmAbSYkERvZpxesRHsyh5MgaUw
  • v=spf1 ip4:24.234.251.98 include:spf.protection.outlook.com include:mail.zendesk.com include:spf-westus.emailsignatures365.com include:spf.us.signature365.net include:spf.ess.barracudanetworks.com include:spf01.mykronos.com +ip4:168.245.102.208 ~all
  • 5887e45046a6536bfcbb8c5b72e818f5
  • MS=ms22836641
  • apple-domain-verification=h3m9aEqOIdOoLQ0r
  • ee6a08c504c347c632ad6887d6e01f64
  • google-site-verification=BtYIsuOIHuMRoYn2Wv6PEPMbatVD7COpBwio8IxZUCc
  • logmein-verification-code=e39d93e0-3681-487c-bdc7-fbf2492cc79c
Cloud / SaaS Services Detected
Apple Microsoft 365 Zendesk LogMeIn

Leak Screenshot:

Leak Screenshot