Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

se.com

se.com

Group Cactus
Discovered 2024-02-19
Est. attack date 2024-01-17
Country FR

Description:

Download link #1: https://***************.onion/SUMMIT01/PROOFMirror: https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/SUMMIT01/PROOF 

Infostealer activity detected by HudsonRock

Compromised Employees: 12

Compromised Users: 2706

Third Party Employee Credentials: 365


External Attack Surface: 109


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@nameshield.net
MX Records
  • de-smtp-inbound-2.mimecast.com.
  • de-smtp-inbound-1.mimecast.com.
TXT Records
  • adobe-idp-site-verification=622dcab59c38d10640a49a43212a3d5cfab14d6fceebe67c033ff76ce890161e
  • lovable_verification=workspace_01kgse1mqkey3rmhbchmcxtwh5
  • atlassian-domain-verification=IUsyq0ps6NhQSSAt3gkN688EjXUbqie77kAjH9QMNrD2VgJHZj2n9JrTqIicWJZA
  • atlassian-domain-verification=Fg7BQJK1jasMWzi2DznJaZPiP6LXLAlgXpKYQqdI/Tf3YruULC+vsBZLCwyETP6/
  • airtable-verification=f310a00de5f600ef7e75f94afe034730
  • atlassian-domain-verification=eghqOJ/7NsTub2FkWGKgo3V13gmomwJnG/YX8Xa2gKG07nsNy8STmqLwic1HbcCY
  • atlassian-domain-verification=EC7toFnaf5ZxNbCWV1wfOhdaqbNUJfoj7Rw6CP5rcma95EbTfjGSrhAU1ym2Mfcs
  • google-site-verification=h9fFgC-4Ewgax9CfgXSybXd3YcOViFck1ne9UxQ2SB4
  • yandex-verification: 945d9382972544b7
  • onetrust-domain-verification=84b23b3aed454a1eba46b3dad4f180ea
  • mandrill_verify.zI6-HAsONKwasvlvvf_zxA
  • cursor-domain-verification-wkg51n=XVJr2LcSe4BA9UawVqumRNgLv
  • work-accounts-domain-verification=JLLfiGUtquBTi85fqn6HWzK3LLexsb
  • globalsign-domain-verification=M5PtGLw32A_LoIDe5wNl0qUjOZPrhQze4o8_RFucOV
  • MS=b1c9d4ce-738a-4c07-8fad-e0afa621b287
  • canva-site-verification=PZ12XM4dFemgms6w821Ybw
  • atlassian-domain-verification=bhaGZHZEDTosyrA+DwJcaLQUTvKZaImxmhox10eRvoBGIufpk+TjLP6BNmFcP3DM
  • bugfender-saml-delegation=479vpkgct4
  • apple-domain-verification=baQOBxMkDgBFwF8l
  • paloaltonetworks-site-verification=74c75720f2f4a8b19f5e6974b05e633ad3a2e697beddf72118b921ab9a42722c
  • smartsheet-site-validation=jeYrV2llaFegK9hHVD6miP3eP0fzxDK7
  • fastly-domain-delegation-WoRR6JPZ-00549561-20251106
  • mongodb-site-verification=5nLcONPh6IYwl3BGrYHsveCB5LS1CMVn
  • atlassian-domain-verification=hq98PdgYFNzjKRVg4oT2WGmerFieN1AAva9IaConyIRjEhR3v3fW2xXBVzbTAFba
  • MS=ms84104626
  • v=spf1 include:spf.protection.outlook.com include:de._netblocks.mimecast.com include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email -all
  • fvoPpcbA=86cc3cdcc4701d2cc6a15f36da60ce15
  • remarkable-domain-verification=9d88f407-9d69-4e21-bb99-60f12cfd700e
  • atlassian-domain-verification=zcJGVUorI1i0Q4admefVCPwkOKDgZDaIrapEGazuk0J2eRF4ouU/xE/iUrjLo9CI
  • docusign=8d9d0f84-01bb-43f6-9e4a-3fef317f24a0
  • pendo-domain-verification=iskRGsB6ZyZLF7RTi--6NxhBd6k
Cloud / SaaS Services Detected
Adobe Apple Atlassian Mailchimp Microsoft 365 OneTrust Mimecast DocuSign

Leak Screenshot:

Leak Screenshot