Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group: Timc

Discovered by ransomware.live: 2026-04-09

Estimated attack date: 2026-04-09

Description:

We breached into their intranet and have total control of it , with 1TB+ data exfiltrated including covid-19 database and SaaS src code like oncomine KB and Other PII Full data breach after the DDL


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@support.gandi.net
  • aad399a70645e633599a6a46ed94639f-4075817@contact.gandi.net
  • oncologica@dbs.agency
  • hello@dbs.agency
MX Records
  • cluster8.eu.messagelabs.com.
  • cluster8a.eu.messagelabs.com.
TXT Records
  • ca3-5e0fbc6208504355be8dc8f5eb8de0f1
  • ca3-6970e59b0a2d48718e82f499d25993c2
  • v=spf1 include:spf.protection.outlook.com include:spf.messagelabs.com include:_spf.hostedemail.com include:oncologica.it -all
  • MS=ms17082175
Cloud / SaaS Services Detected
Microsoft 365