Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.bahia-principe.com

Group: Ransomhub

Discovered by ransomware.live: 2024-08-02

Estimated attack date: 2024-07-31

Country: ES


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 993

Third Party Employee Credentials: 34


External Attack Surface: 85



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • mxa-004e0901.gslb.pphosted.com.
  • mxb-004e0901.gslb.pphosted.com.
TXT Records
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
  • _xiptntcdq31ga4vyejoi76efd5knihs
  • google-site-verification=rrEgBqH6HoJjKQxL6BxSigHg-6us8ysb0ldayr-i9YU
  • MS=ms89572370
  • google-site-verification=aL5taTE7AP8saFbNzOO-surnXosfR7g1EpTVIXXvDEk
  • MS=9DEBEA7B2CB1615732F382A4C93C6911D0C3AD55
  • google-site-verification=p5vaA8bts0Qxev2hMKWa9gPMmoNuwGtBXHcFehgzau8
  • atlassian-domain-verification=42bPwG67cfp6BhFaaXJUaBXk4OXaahRIUV0uXg4ZKUq6I5MtAXCy9iojLEypeWNA
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Proofpoint

Leak Screenshot:

Leak Screenshot