Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo curtisint.com

Group: cactus

Discovered by ransomware.live: 2025-02-12

Estimated attack date: 2025-01-21

Country: CA

Description:

<p>Appliances.<br><br>“Curtis International Ltd. manufactures and distributes quality, value priced consumer electronic &amp; appliances. Our product line includes a broad range of items, such as televisions, audio equipment, home appliances, and other electronic accessories. We market these products under several well-known brand names, including RCA, Proscan, FRIGIDAIRE™, HAMILTON BEACH® , Culinary Chef™, &nbsp;Budweiser, Bud Light, Pepsi, Mountain Dew, Dr. Pepper, Orange Crush and Curtis. ”<br><br>Website: <a href="https://www.curtisint.com/">https://www.curtisint.com/</a><br><br>Revenue : $37.2M<br><br>Address: 7045 Beckett Dr Unit 15, Mississauga, Ontario, L5S 2A3, Canada<br><br>Phone Number: (800) 968-9853<br><br><mark class="marker-yellow"><strong>Download link #1:</strong></mark> <a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/CURTIS/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/CURTIS/PROOF/</a><br><br><mark class="marker-yellow"><strong>Mirror:</strong></mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/CURTIS/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/CURTIS/PROOF/</a><br><br><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:</strong></mark> Personal identifiable information, corporate confidential docs, customer data, contracts, NDAs, invoices, legal docs, financial data\payrolls, corporate correspondence, employees personal folders, database backups with customer information, etc.</p><p><img src="/uploads/20210311_111813_9ac5df14b6.png" alt="20210311_111813.png"><img src="/uploads/Beatrice_Passport_a2c1ded0ad.png" alt="Beatrice Passport.png"><img src="/uploads/Curtis_International_Ltd_Final_FS_May_31_2023_f26a268f6e.png" alt="Curtis International Ltd. - Final FS May 31, 2023.png"><img src="/uploads/Epson_and_Curtis_Confidential_Settlement_Agmnt_and_Mutual_Release_5d2b14afcc.png" alt="Epson &amp; Curtis Confidential Settlement Agmnt &amp; Mutual Release.png"><img src="/uploads/Curtis_Terms_of_Settlement_SIGNED_Sep_16_2024_4a28f8164a.png" alt="Curtis - Terms of Settlement - SIGNED Sep 16 2024.png"></p>


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 3

Third Party Employee Credentials: 0


External Attack Surface: 1



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • curtisint-com.mail.protection.outlook.com.
TXT Records
  • C0U4R38594
  • H1CCG8VHVHDIPQPVAJ1VDRXIO1VSU79KZRDT4LQP
  • WNJJIMMGFVK8E1JT1IWF7B2ZPRLSKGVNGD1T8VQU
  • _globalsign-domain-verification=HlYkOI4qy3P6xY7UYN_ex_RbsafoZvFdpZjrgVItAR
  • duo_sso_verification=5eWNAqQ6jXDd0RBEzrJqXqqlzImi5tTnFX9PYuT1xEKIOkyYrp7L8yA08g9UZeUW
  • jde65315b9a9h3u18cule1onhl
  • pnipb9f39aomaligo9fjkmqif7
  • tmes=bb90f21ecd4ff3c1ac923224ef43c8f4
  • v=spf1 include:spf.hornetsecurity.com include:spf.protection.outlook.com ip4:206.116.49.118/32 IP4:216.208.218.154 IP4:216.208.218.144/28 IP4:67.71.199.0/29 -all
Cloud / SaaS Services Detected
Cisco Duo

Leak Screenshot:

Leak Screenshot