Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo theallisoncom

Group: alphv

Discovered by ransomware.live: 2023-07-26

Estimated attack date: 2022-06-14

Description:

1500 ++ SSN of employees as well as customer data and all accounting 112GB DATA:http://vqifktlreqpudvulhbzmc5gocbeawl67uvs2pttswemdorbnhaddohyd.onion/data Site with SSN DOB EMAIL https://theallison.xyz



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • d342396a.ess.barracudanetworks.com.
  • d342396b.ess.barracudanetworks.com.
  • theallison-com.mail.protection.outlook.com.
TXT Records
  • v=spf1 ip4:50.226.67.162 ?include:reseze.net ?include:spf.synxis.com ?include:spf.protection.outlook.com include:_spf.psm.knowbe4.com include:spf.ess.barracudanetworks.com ~all
  • 154aajp3tvdd91fahdog6vjrul
  • 1pc5vi9tqchpch0o5q2hksh81u
  • 5qj5bul8t1vhkdnhu7318bphe7
  • MS=ms59980127
  • ksbe2tff8bpnlbkk1rd72vcbl
  • lgqpon1nt4u599q65nmo3jhoge
Cloud / SaaS Services Detected
Microsoft 365 KnowBe4

Leak Screenshot:

Leak Screenshot