Group:
Everest
Discovered by ransomware.live: 2024-10-19
Estimated attack date:
2024-10-19
Country:
Description:
Thousands and thousands of client’s personal information,credit cards info, internal emails, incidents, messages Full calendar of past and future bookingsAnd complete negligence in storing passwords and private data, Evidences that management is aware of events and is not taking any actionThe company must follow the instructions to resolve the issue with us before the timer ends, […]
DNS Records:
The following DNS records were found for the victim's domain.
- whoisrequest@markmonitor.com
- abusecomplaints@markmonitor.com
- radissonhotels.in.tmes.trendmicro.eu.
- apple-domain-verification=7pRVrrdqq81xOmvENMqEmbUMtYI7GI-aOdL5kKkK_eQ
- adobe-idp-site-verification=9315089c4b3efc289f8a4784eda956fdff914eace9dcc8b19ae15233ea22dfb3
- MS=ms55195023
- HEWqEaHE5znFinfNRI8O8YZNI2jSGLRESsxYhrXvRrQ=
- Dynatrace-site-verification=6ef875f3-76e5-490c-84ff-523a04a5d056__1kve3bmna0ao065i45e1um1m5r
- tmes=8612b6da00992d451e5bcb0f6b0d8320
- onetrust-domain-verification=21af34eab16746a989ce85ed8ff862e8
- google-site-verification=3XjU1xiCpaCqu0TWJAF_n0-XiIk5dOxCQD-pSN6cGW4
- amazonses:IQ2BikmmmJk4t6Va6EHC91kFWEjM1+2Z2zGGiYapQn0=
- m76FAtXv2pWKcXLPG7NwR7BpXxo5SUtoZ1XHK9gRTEE=
- facebook-domain-verification=h4ce35te1zqi5hukx67ohi8gg54j58
- v=spf1 mx a ip4:52.208.166.252 ip4:93.165.150.78/32 ip4:207.166.86.53 ip4:207.166.92.11 ip4:207.166.94.53 ip4:207.166.95.11 ip4:128.177.144.7 include:spf.protection.outlook.com " "include:spf.rezidor.com include:spf.tmes.trendmicro.com ip4:155.56.208.100 ip4:18.198.35.158 ip4:3.65.86.245 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.0.0/16 ip4:208.185.229.0/24 ip4:208.185.235.0/24 ip4:62.190.159.144/28 ip4:62.190.59.144/28 " "ip4:128.177.154.7 ip4:65.221.28.5 ip4:87.253.232.0/21 ip4:185.189.236.0/22 ip4:185.211.120.0/22 ip4:185.250.236.0/22 ip4:216.71.96.0/22 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.8.0/21 ip4:52.254.72.70 ip4:216.119.209.33 ip4:216.119.217.33 " "ip4:199.91.136.28 ip4:149.96.5.209 ip4:149.96.5.7 ip4:149.96.6.7 ip4:149.96.6.3 ip4:149.96.6.2 ip4:149.96.5.2 ip4:149.96.6.209 ip4:149.96.5.3 ip4:149.96.5.6 ip4:199.91.140.28 ip4:149.96.6.6 " "ip4:149.96.14.2 ip4:148.139.0.2 ip4:199.91.141.22 ip4:199.91.141.145 ip4:199.91.141.23 ip4:199.91.140.26 ip4:148.139.2.2 ip4:148.139.3.2 ip4:199.91.139.24 ip4:199.91.140.28 ip4:148.139.1.2 " "ip4:199.91.136.28 ip4:37.98.234.2 ip4:148.139.0.31 ip4:199.91.137.2 ip4:37.98.232.12 ip4:199.91.139.22 ip4:37.98.232.26 ip4:199.91.136.26 ip4:199.91.137.26 ip4:199.91.139.145 " "ip4:199.91.141.24 ip4:148.139.1.31 ip4:149.96.13.2 ip4:37.98.232.2 ip4:199.91.139.23 ip4:37.98.235.2 ip4:149.96.2.26 ip4:149.96.195.2 ip4:149.96.1.26 ip4:148.139.104.16 ip4:149.96.133.2 ip4:149.96.221.2 ip4:148.139.105.17 " "ip4:103.23.67.26 ip4:103.23.65.2 ip4:149.96.220.2 ip4:199.91.136.28 ip4:148.139.105.16 ip4:103.23.64.2 ip4:148.139.104.17 ip4:103.23.66.26 ip4:149.96.194.2 ip4:199.91.140.28 ip4:149.96.132.2 " "ip4:167.89.77.138 ip4:40.113.134.102 ip4:3.210.182.90 ip4:155.56.208.101 ip4:155.56.208.100/30 ip4:167.89.115.56 ip4:167.89.115.83 ip4:167.89.115.52 ip4:167.89.115.120 ip4:50.31.156.96/27 ip4:104.245.209.192/26 ip4:50.31.205.0/24 -all
- docusign=650288ba-d9dc-421d-8592-2d507d551901
- wiz-domain-verification=976e17549ac5ad7a0a9a80aa328e1b090d27d31f69631c7f209ad06885b358a4
- atlassian-domain-verification=KX2aLAPZ1iNXTguqChaB9yaOzVmpXWkkjqN68yZOjyaxXYfivmXNjBk53KpUpudc
Cloud / SaaS Services Detected
Adobe
Apple
Atlassian
Amazon SES/WorkMail
Microsoft 365
OneTrust
TrendMicro
DocuSign
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.