Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.glynmarais.co.za

Group: cactus

Discovered by ransomware.live: 2024-06-23

Estimated attack date: 2023-10-12

Country: ZA

Description:

Download link #1:  https://***************.onion/JGM/PROOF/Mirror: https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/JGM/PROOF/DATA DESCRIPTIONS: Employees and executives personal files, personal identifiable information, financial documents, corporate confidential files, correspondence, etc.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • glynmarais-co-za.mail.protection.outlook.com.
TXT Records
  • z80z9bp9dkcyx1vck1ts1v25h8zvygcb
  • MS=ms68731042
  • eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJkb21haW4iOiJnbHlubWFyYWlzLmNvLnphIiwiZXhwIjoxNzI0OTc2MDAwfQ.nkXngbxs-aoBBJzeG0dg29ZkprVQgyJW0Pp6d42cJY8
  • v=spf1 include:spf.protection.outlook.com -all
  • ss52ckfnlt95wh1rw93764fr3g1dkrh1
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot