Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.ahmadiyya.ca

Group: ransomhub

Discovered by ransomware.live: 2025-03-21

Estimated attack date: 2025-03-21

Country: CA

Description:

[AI generated] "www.ahmadiyya.ca" is the official website for Ahmadiyya Muslim Jama'at Canada, a religious community of Muslims who accept Mirza Ghulam Ahmad as the Promised Messiah. The organization promotes a peaceful understanding of Islam and the spiritual rejuvenation through the advent of the Promised Messiah. They also engage in educational, humanitarian, and interfaith activities.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 15

Third Party Employee Credentials: 3


External Attack Surface: 4


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
  • Please ask the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Other contacts of the queried domain name
MX Records
  • aspmx.l.google.com.
  • alt3.aspmx.l.google.com.
  • alt4.aspmx.l.google.com.
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
TXT Records
  • v=spf1 a ip4: 207.61.87.228 ip4:107.20.210.250 ip4:54.229.2.165 ip4:54.153.131.110 ip4:52.1.14.157 ip4:52.30.130.201 ip4:54.66.252.242 include:amazonses.com include:_spf.google.com ~all
Cloud / SaaS Services Detected
Amazon SES/WorkMail

Leak Screenshot:

Leak Screenshot