Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.heitech.com.my

Group: Devman

Discovered by ransomware.live: 2025-11-04

Estimated attack date: 2025-11-04

Country: MY

Description:

Ransom: 500k 60gb


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 19

Compromised Users: 118

Third Party Employee Credentials: 33


External Attack Surface: 83


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain yeahhost.com.my
MX Records
  • fa98d20c-cc19-4f3b-885b-d6804a8d1346.in.tmes-sg.trendmicro.com.
TXT Records
  • v=spf1 mx a ip4:202.171.33.8/32 ip4:202.171.42.198/32 a:mx1.heitech.com.my a:mx2.heitech.com.my include:spf.tmes.trendmicro.com -all
  • facebook-domain-verification=eycd7xfnvnxvnjdbhgqnvpmb1xv7k7
  • globalsign-domain-verification=dk6XxdZ2X-BCjTiXjcD3qHWz3eXFLFTvCGK5klzlEF
  • MS=ms75671192
  • cisco-ci-domain-verification=7e75343668da6be41365727fcd051e0e0f4b6112aeb9bab0e3a2a6be0f479551
  • google-site-verification=aAxDunPnhLfHrTf5ylWRr37MWEnOSQ5QWvEtyUNZLqM
  • globalsign-domain-verification=MGyFOzkjZNO6r6i1UTmsNGMrThsldLgegn_tfBv9VE
  • globalsign-domain-verification=lVMCugTUySR4V38WqowN0TuwGdcBahxtFNSFj0JZhB
  • dtm-domain-verification=M7L54MTQJeUPTxeBtDhVF-knkwdcQQkPEe4mqjjIXiA
  • google-gws-recovery-domain-verification=54271579
  • globalsign-domain-verification=QDriWdGnnqWUgO45P3y6LWRaUbama7bpvjh1D3Z2WH
  • tmes=63f29b2d61268cdf18069901529f631f
  • google-gws-recovery-domain-verification=5047556
Cloud / SaaS Services Detected
Microsoft 365 Cisco TrendMicro

Leak Screenshot:

Leak Screenshot