Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo wachter.com

Group: blackbasta

Discovered by ransomware.live: 2024-11-19

Estimated attack date: 2024-10-16

Country: US

Description:

Wachter is a technology integration company that designs, installs, and maintains technology for businesses across the United States.SITE: www.continentalserves.com Address : 16001 West 99th Street Lenexa, KS 66219 United StatesTEL#: 913-541-2500ALL DATA SIZE: ≈200gb 1. Employees personal folders and docs 2. Financial data 3. Confidential 4. Human Resources & etc…


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 21

Third Party Employee Credentials: 5


External Attack Surface: 18



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • registrar-abuse cloudflare.com
MX Records
  • wachter-com.mail.protection.outlook.com.
TXT Records
  • mp44ip5anam9eselh7gb2j6pqn
  • docusign=e32fa146-3df5-44c2-87cd-a4ac37c01511
  • 6o1ocpvr9it4s0adolf78io17t
  • vmware-cloud-verification-93ae95ab-8960-4c2d-9562-a1faddb76e97
  • lt5mhsqcjic8ibmk7jldcqcvg2
  • intersight=78b8c10fbf3f65b6892c2fa743489e707a0306390440cfa2ba701b2ee06bd94e
  • atlassian-domain-verification=EsxXgiCqYMFe59XLzbfuAnS2wrqXeU9MhAL/zbtaC33HCtgZwG9FWvFDOV8bHWvr
  • 7mudm9vea87odtv9j82to79t62
  • ciscocidomainverification=7d0647d6e3bedefbb0b09228a92a1ee7799236c046f7b40b1cfc9f398390e3c9
  • v=spf1 include:spf.protection.outlook.com include:emailus.freshservice.com include:stspg-customer.com ip4:66.206.200.46 include:us-spf.email.litmos.com a:b.spf.service-now.com a:c.spf.service-now.com a:d.spf.service-now.com include:2331978.spf10.hubspotem" "ail.net ip4:66.206.200.60 ~all
  • docusign=65a9194b-20d6-4175-90a7-687aa1e5596d
  • infoblox-domain-mastery=ae64a9686d7a926cd7ccf2fb20aaf24023f2fa7491a4f47ea7707ea63cfbe660fd
  • vb52k6a9idnapek22tnpn1fgnk
  • qo2f2hlvkhoq196q87rbrsnhiq
  • rtife0njho3g5htuvnaf01vaq
  • apple-domain-verification=2tDgvJEsUI6pnMvV
  • FEUFyV9KnVPHKA91Obxmc74B42GnXTTtDpHemel4frMJ7HuteZCMOkmLGr4xvYC30GqWyE4KEMHTO0GZFDBHFg==
Cloud / SaaS Services Detected
Apple Atlassian DocuSign ServiceNow

Leak Screenshot:

Leak Screenshot