Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo knvb.nl

Group: lockbit3

Discovered by ransomware.live: 2023-04-14

Estimated attack date: 2023-04-14

Country: NL

Description:

305gb.The Royal Dutch Football Association is the governing body of football in the Netherlands. It organises the main Dutch football leagues, the amateur leagues, the KNVB Cup, and the Dutch men's and women's national teams.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • knvb-nl.mail.protection.outlook.com.
TXT Records
  • google-site-verification=m26gAFenHNZmrZFtBMnh1gwzSltuvmm7Ia7MQWO8nxQ
  • atlassian-domain-verification=essAJlsF8zCdyEz718cLmxPpxhpch4HKk9b8OzAycyHTTkr9ALi4QCrGrfbmBl71
  • MS=ms23121662
  • google-site-verification=LauTBOmevDhb_AShlHVcn3BLcq58oBabW00PXDsjVlk
  • facebook-domain-verification=7r9c57h605c0fekktbilei35r9yo3f
  • msfpkey=3gsbnw3nd01ntl39r9wrd7dr4
  • atlassian-sending-domain-verification=ddea52ae-aff6-4a6d-9c9f-920fc3d2903b
  • GKeHVanx4lHFm2yUvVMCMIxGcUHkqyq5p2VDnKf/rTtKqNbvgUKbQa4aZjoH4PS2HUsemoBufUyjSPainA+z6A==
  • v=spf1 ip6:2a02:348:b4:e70b::1 ip4:34.105.97.52 ip4:34.74.92.186 ip4:34.89.171.151 ip4:34.90.134.143 ip4:5.39.185.40 ip4:34.90.145.140 ip4:35.198.110.229 ip4:34.90.40.234 ip4:34.159.131.87 ip4:34.34.77.208 ip4:34.105.64.154 ip4:34.75.4.19 ip4:35.246.159.1" "16 ip4:217.114.97.6 ip4:176.62.196.142 ip4:80.112.253.130 ip4:185.46.182.1 ip4:185.46.182.200/29 ip4:185.46.182.208/31 ip4:31.134.203.164 ip4:31.134.203.165 ip4:31.134.203.166 ip4:31.134.203.188 ip4:172.104.250.102 ip4:31.134.203.248 ip4:31.134.203.249 ip" "4:208.72.90.0/24 ip4:74.117.207.0/24 ip4:74.117.206.70 ip4:217.114.99.36 ip4:217.114.99.37 ip4:217.114.99.38 ip4:217.114.99.43 ip4:217.114.99.55 ip4:217.114.99.57 ip4:217.18.68.165 ip4:159.135.230.45 ip4:83.138.181.0/24 ip4:168.128.66.6 ip4:83.98.197.35 i" "p4:46.31.50.212 ip4:37.0.95.137 ip4:149.210.144.179 ip4:85.222.231.11 ip4:185.64.33.133 ip4:185.64.35.133 ip4:213.144.242.0/28 ip4:89.146.30.0/27 ip4:213.144.234.160/27 ip4:46.44.162.254 ip4:89.146.1.51 ip4:89.146.1.52 ip4:89.146.1.63 ip4:46.44.142.238 ip" "4:89.146.1.57 ip4:89.146.63.164 ip4:91.218.37.0/24 ip4:185.46.182.201 ip4:46.31.48.0/21 ip6:2a02:22a0:0:1:2::2a ip6:2a02:22a0:0:1:2::2e ip6:2a02:22a0:0:2:2::12 ip6:2a02:22a0:0:1:2::2 ip6:2a02:22a0:0:1:2::5 ip6:2a02:22a0:0:2:2::5 ip6:2a02:348:b4:e70b:" ":1 ip4:208.76.56.0/21 ip4:216.146.32.0/20 ip4:80.231.25.0/24 ip4:80.231.219.0/24 ip4:103.11.200.0/22 ip4:199.19.0.0/21 ip4:204.13.248.0/22 ip4:208.78.68.0/22 ip4:162.88.36.0/23 ip4:162.88.4.0/23 ip4:162.88.24.0/24 ip4:162.88.28.0/24 ip4:10.144.155.128/26 " "ip4:129.148.164.0/25 ip4:129.148.215.0/25 ip4:129.149.6.0/25 ip4:129.149.38.0/25 ip4:138.1.170.0/24 ip4:147.154.32.0/25 ip4:147.154.63.0/24 ip4:147.154.126.0/24 ip4:147.154.191.0/24 ip4:162.88.24.0/21 ip4:192.29.72.0/25 ip4:192.29.88.0/25 ip4:192.29.103.1" "28/25 ip4:192.29.134.0/25 ip4:155.248.148.0/25 ip4:131.186.12.0/25 ip4:138.1.156.112 ip4:130.35.132.195 include:spf.protection.outlook.com include:spf.mandrillapp.com include:_spf.relay.mailprotect.be include:amazonses.com include:_spf.cobytes.email inclu" "de:_spf1.mailgun.org include:_spf2.mailgun.org include:_spf.eu.mailgun.org -all
  • Mt+UwP0ad5OG2BL1j3kQNP7qc52xdDVOlzIih4l9KbM=
  • detectify-verification=330eda1b4bc0f1676c6dda790e6ed324
  • google-site-verification=g26X2CckbmVSYZU9nqEwlo9UHmm1kL0bYsGjC1BXa14
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Microsoft 365 Mailgun Mandrill

Leak Screenshot:

Leak Screenshot