Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo tnlottery.com

Group: incransom

Discovered by ransomware.live: 2025-01-29

Estimated attack date: 2025-01-29

Country: US

Description:

USA education lottery. We have a lot of DATA this company.750 gb include SQL DATABASE with private clients information.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • mxa-00377a01.gslb.pphosted.com.
  • mxb-00377a01.gslb.pphosted.com.
  • tnlottery-com.mail.protection.outlook.com.
TXT Records
  • a193a814-68fb-4aac-85f8-27bc174747e1
  • apple-domain-verification=3rlHHIXuk2NZrIVZ
  • e2ma-verification=2pagb
  • e2ma-verification=2r
  • e2ma-verification=cpycb
  • e2ma-verification=dsycb
  • eqhnrvg1jg8vigtm3mv4k1kbk9
  • google-site-verification=7OCGY75Ut6k3OFX-dw37f_RJbDFXPyf3coZ4EIQFoVk
  • google-site-verification=fbA1d8C0vUk04eWqtgj64GKbqPsCqr2MgX9D3ca_rZc
  • juvnlv4jeko2tsbutrq9dl24jp
  • rv7ecdfgrs9scchtc29th7kvsk
  • rv7ecdfgrs9scchtc29th7kvsk.
  • t10k3op5ehf416u9ibneu8li89
  • v40t72oi3gg90klu539q3p2317
  • v=spf1 include:_spf.e2ma.net mx a ip4:24.41.6.48/28 ip4:24.41.6.56/28 ip4:217.21.131.0/24 ip4:104.247.82.0/24 ip4:63.232.206.0/24 ip4:24.41.6.49/32 ip4:209.126.30.141/28 ip4:135.237.205.56/32 include:relay.mailchannels.net include:spf" ".protection.outlook.com include:amazonses.c" "om -all
  • 2k9f1n9rsaduik1k1570s7ha1i
  • 2l046nol1v1a0rqq57c2ilncmj
  • 3QhzwQYdyZTRE0HpCn2PeXyjd+C5Ju0vh1VUlet0Vhf4zacZe1WmiL1SyGHTjFHOKh6gOcGSpOPuVsOixzInlQ==
  • MS=C18AF4E9830892E14C8F22621D456FF45440B0C6
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail

Leak Screenshot:

Leak Screenshot