Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Chaos
Discovered 2026-04-14
Est. attack date 2026-04-14
Country DE
Data exfiltrated 150 GB

Description:

Founded in 1983, ITC Construction Group is a Commercial and Residential Construction company that specializes in residential high rises, mixed-use developments, and select commercial projects.

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • itcgroup-com0i.mail.protection.outlook.com.
TXT Records
  • rovag_verification_token=CB4B4EB1C7214CB99294752512537121
  • itc-group.com: 0x04HnN4639BhnHUe/g06Xn6WeHu2r4i060K8JX11Iuv6fyFskopnWJe8ik0qlbnOQxUqx9+wrVWHU2D5d6AJg==
  • v=spf1 ip4:103.47.205.238 ip4:198.102.221.98 ip4:69.10.233.86 ip4:162.248.127.196 ip4:208.118.119.163 ip4:69.196.64.142 ip4:72.2.55.189 ip4:66.119.182.99 include:spf.protection.outlook.com -all
  • MS=ms76947353
  • TEYV20ZHt8+fU+vWP2T6triM45nND8e5/GLzfwIDQGBorPT2uRWggwbve/p1ua8SWfEMas5yqhEVn6qCl4Cikw==
  • 0x04HnN4639BhnHUe/g06Xn6WeHu2r4i060K8JX11Iuv6fyFskopnWJe8ik0qlbnOQxUqx9+wrVWHU2D5d6AJg==
  • 0x04HnN4639BhnHUe/g06Xn6WeHu2r4i060K8JX11Iuv6fyFskopnWJe8ik0
  • zoho-verification=zb34417332.zmverify.zoho.com
  • have-i-been-pwned-verification=dweb_k0cq0zdm8em42newbqslwg9a
  • AKPDhH0zHyTOnwy6aCh7o1bcv39igM2BiEJ11/pXuMxg9Ld+PsCGU5ReXarHoQYhlCL/TGLDZVh61lJ4atQutw==
Cloud / SaaS Services Detected
Microsoft 365 Zoho Campaigns Have I Been Pwned

Leak Screenshot:

Leak Screenshot