Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo h2o.ai

Group: Linkc

Discovered by ransomware.live: 2025-02-19

Estimated attack date: 2025-01-29

Country: US

Description:

As a result of our operation, we have discovered the following concerning data: 1. Unanonymized customer datasets intended for AI training. 2. Full source code of programs from the Git repository, including code for driverless systems, GPT models, and others. 3. A substantial amount of internal information, including contracts, customer personal data, project costs, and project documentation. 4. Backup copies of employee email accounts containing customer correspondence.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse 101domain.com
  • srisatish 0xdata.com
MX Records
  • aspmx.l.google.com.
  • alt3.aspmx.l.google.com.
  • alt4.aspmx.l.google.com.
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
TXT Records
  • anthropic-domain-verification-vvck3z=Oe05abTXdy1LkXGoif8EKT4VK
  • atlassian-domain-verification=dmYJp7OQGUWDoDao21PC5N5KQaLuy7dkTncNYidKucWzavOQmfybxwbnBZLZ1Fx8
  • google-site-verification=5mzi_jxash36oWGKR4jfk6-x1OvJ7oT_XEmWwVOW_Kw
  • google-site-verification=8z_5HPU2hogXcmiDm-syxMSwT017Ej06ezR5Fa1I6ho
  • google-site-verification=GIWxpKSv-MMtggk_e_XRoe6jUgZVXdtUzdO-9i4KW9w
  • google-site-verification=JjtP2wEWk56gI3ot2oBPg32j2R0sEsWmY8agmeaLgS0
  • google-site-verification=NUX1FjFMnZ6qi_FqZb523XmRRhAtalC3fFat8kyJSyU
  • google-site-verification=YaxNbXnA_UHfIKoWOsLnZlQdbUcbjmrxm4LAHEgDI7c
  • google-site-verification=fZI4i66kQkIqnncmCNBFyQUmBk8I9cPxQ81VDCLExZM
  • google-site-verification=sE7pxi_9Lbray4IR1iTWoXiSR_hparLSzK197ks5Hd8
  • google-site-verification=uiwuMC_OoOJGnJV6MJvgRvG8ytiLLteohE-6vVs1vjc
  • v=spf1 include:_spf.google.com include:amazonses.com -all
  • 3rin16i4d2o4h3v6cgm0gat1l
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail

Leak Screenshot:

Leak Screenshot