Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo branchgroup.com

Group: cactus

Discovered by ransomware.live: 2025-02-24

Estimated attack date: 2025-02-24

Country: US

Description:

<p>Commercial &amp; Residential Construction.<br><br>“Founded in 1963, The Branch Group is a company that owns and operates different companies that specialize in civil construction, residential and commercial building construction, electrical and pipe installation, and more. The company is based in Roanoke, Virginia.”<br><br>Website: <a href="https://www.branchgroup.com/">https://www.branchgroup.com/</a><br><br>Revenue : $333M<br><br>Address: 442 Rutherford Ave NE, Roanoke, Virginia, 24016, United States<br><br>Phone Number: (540) 982-1678<br><br><mark class="marker-yellow"><strong>Download link #1:</strong></mark> <a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/BRANCHGROUP/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/BRANCHGROUP/PROOF/</a><br><br><mark class="marker-yellow"><strong>Mirror:</strong></mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/BRANCHGROUP/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/BRANCHGROUP/PROOF/</a><br><br><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:</strong></mark> Personal identifiable information, Corporate confidential data, customer information, financial\payroll documents, Employees\executives personal data, IT department documents, corporate correspondence, etc.</p><p><img src="/uploads/Chris_Tucker_ID_22fbc5dcab.png" alt="Chris Tucker ID.png"><img src="/uploads/Branch_Sovos_NDA_07014a5eac.png" alt="Branch Sovos NDA.png"><img src="/uploads/Lori_Beth_Hoel_ID_5284d4273e.png" alt="Lori Beth Hoel ID.png"><img src="/uploads/Breeden_Heating_Air_LF_TPQ_2022_09_NDA_48b06d9916.png" alt="Breeden Heating Air - LF TPQ 2022.09 NDA.png"><img src="/uploads/Branch_interim_financial_statements_May_2023_c9b4b7e60d.png" alt="Branch interim financial statements May 2023.png"></p>



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • branchgroup-com.mail.protection.outlook.com.
TXT Records
  • v=spf1 ip4:52.188.19.157 ip4:20.232.148.218 include:spf.protection.outlook.com include:_spf-sfdc.successfactors.com include:_spf-dc4.sapsf.com include:8516163.spf03.hubspotemail.net include:_spf.psm.knowbe4.com ~all
  • apple-domain-verification=QVjPXbuWuG6YVFjN
  • hs77nitpgbdo8b158pbd224c4b
  • 5aghn8g2o00al3f0af5ouf58vf
  • dJFcY6hSIRqePtrBJt9hAtyl6mxwu6sr0s+7WECdFvRApxU+sBHAeQsVSwTgOIWxwVK7DL4ZhkBoIFEs6SnDfw==
  • bw=O1cmEgyWdQJg54yrDn7HRutVSooJthjmCqomYCOOqHlh
  • n6lrsdmkmp0jko6ajc9atnc33k
  • 31tuuelvap24r406h86a5jmhpu
  • t5g66v98naqc4fo2d33s6aelet
  • Required Data: include:8516163.spf03.hubspotemail.net Current Data: v=spf1 include:spf.protection.outlook.com include:_spf-sfdc.successfactors.com include:_spf-dc4.sapsf.com ~all
  • o5qtfal6rjgj7ornbvbrfaq5t1
  • 0ed1fe018a78199b8ec0d34035b1b3299956fa8641
  • ciscocidomainverification=40620d711a874887e6985b14522373a376551ab86b9f6dba55a917a37ac416ab
Cloud / SaaS Services Detected
Apple HubSpot KnowBe4

Leak Screenshot:

Leak Screenshot