Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo heimhaus.de

Group: Kawa4096

Discovered by ransomware.live: 2025-07-07

Estimated attack date: 2025-06-22

Country: DE

Description:

www.heimhaus.de


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 25

Third Party Employee Credentials: 0


External Attack Surface: 7


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • heimhaus-de.mail.cloud.nospamproxy.com.
TXT Records
  • 1password-site-verification=A2HD3CBRINCR5GDE3JAPKW5CKM
  • v=spf1 a mx a:w019ebed.kasserver.com ip4:85.13.155.24 include:spf.lamapoll.de include:spf.heimhaus-de.cloud.nospamproxy.com include:spf.protection.outlook.com ~all
  • Aa+JcVWeklvGLIylN8gy5kKHYBX4mbLCge6MoZCDB3Q=
  • MS=8BB23DB0EF672EC441938FFDCBF337E4DE184A88
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.