Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo hunterbuildings.com

Group: cactus

Discovered by ransomware.live: 2023-12-21

Estimated attack date: 2023-11-24

Description:

Download link #1: https://acfckf3l6l7v2tsnedfx222a4og63zt6dmvheqbvsd72hkhaqadrrsad.onion/HUNTER/68ZRg2b1oA20/ 



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • us-smtp-inbound-2.mimecast.com.
  • us-smtp-inbound-1.mimecast.com.
TXT Records
  • v=spf1 ip4:35.231.244.252 include:us._netblocks.mimecast.com include:spf.protection.outlook.com include:spf-us.emailsignatures365.com include:hunterbuildings.zendesk.com include:_spf.createsend.com ~all
  • MS=ms93322487
  • google-site-verification=YZWO_J4lupi-ZFSLUcuwQBtaoiM7dFv4GPCjarUCnOo
  • brevo-code:18cc38cb8587679f7ff9ba47c1a22366
Cloud / SaaS Services Detected
Microsoft 365 Mimecast

Leak Screenshot:

Leak Screenshot