Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo elliott-turbo.com

Group: dispossessor

Discovered by ransomware.live: 2024-04-19

Estimated attack date: 2023-08-16

Country: TD

Description:

More information in our telegram channel https://t.me/snatch_team Persons responsible for data leakage:Mike Lordi:CEO+1 636-464-5123mlordi@elliott-turbo.com;Shane Reph:COO, VP+1 636-464-5123sreph@elliott-turbo.com;Chad Elliott:President+1 803-327-5005chad_elliott@elliott-turbo.com;Yasuyuki Uruma:CEO+1 412-653-3378uruma@elliott-turbo.com;Geordie Cruickshank:CFO, Financial Officer+1 636-464-5123, +1 724-600-8927geordie_cruickshank@elliott-turbo.com;Bill Cox:VP+1 412-653-3378bill_cox@elliott-turbo.com;Mark Babyak:Director, Engineer+1 724-600-8250mbabyak@elliott-turbo.com;Carol Gatewood:Secretary, Secretary, Legal Affairs+1 724-493-3969+1 724-600-8377cgatewood@elliott-turbo.com;Ronald Josefczyk:Director, Director, Engineering, Director, Operations,


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 1


External Attack Surface: 0



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • mxa-001e5402.gslb.pphosted.com.
  • mxb-001e5402.gslb.pphosted.com.
TXT Records
  • cisco-ci-domain-verification=f730356f0337fe60c866fbc55fc6cdcfbbac910eece9aaec8cf6038ccdfb82c
  • google-site-verification=eD4m-OTkEu0Dz39H9_RXnAtKE05gitCUUzbDKve0FgM
  • google-site-verification=fI-wh3BsuPbj7mhh3_Hk6IDTt4IzTWkwSw02T5McUWc
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all
  • MS=1D458BFEE2314FD7A3EE36A3E109D4A01E6A3EAE
  • adobe-idp-site-verification=4e700aa4c6b8fcb5ad73d8330d2869a611b70bca63b4adea896555c001efd3fd
  • atlassian-domain-verification=1XtmmLTsQYzFeSRmBR4lpyp73gdJWGI1w3fA6M0sgHBaYLjLMvImT4a9f3Ra6Ihh
Cloud / SaaS Services Detected
Adobe Atlassian Cisco Proofpoint

Leak Screenshot:

Leak Screenshot