Group:
Cactus
Discovered by ransomware.live: 2023-10-16
Estimated attack date:
2023-09-26
Description:
Since being founded in 1995 OMNIVISION has been at the leading-edge of technology, developing and delivering advanced digital imaging, analog, and touch & display solutions for multiple applications across several industries. As a global fabless semiconductor organization, our award-winning innovative technologies have enabled smoother human/machine interfacing solutions within the automotive, medical, security & surveillance, computing, mobile phone, and emerging technology spaces.
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- mxa-0028f402.gslb.pphosted.com.
- mxb-0028f402.gslb.pphosted.com.
- atlassian-domain-verification=NeiN7i8l6q/Jfeqo3sZ9k4GnTayVvsH0QQEOYw0JMa9h9DybFzk3pKzVaQInndgb
- 9luaq9a6h34fa3mr781804qki2
- v=verifydomain MS=1066884
- 3k5tf0id78dallcf36r1va404p
- google-site-verification=awrbm5N_05gJOLY7L9QzdO8CVSfU7Y12nn5Udg0f7_U
- +1o0SKCXEn+OwXzpA7XCmuHzlh4ahxQh/zq9tJtqSQFw4ip9u0y1YRb081l4mU6H3MphftZpLd6b8SXGZTjsdQ==
- jqr9h5g3rlgp4cuvtoloaife32
- apple-domain-verification=Xap7uHLATyyjtozm
- v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
- rstjam8kktdhekjuc0tvd7fiqd
- MS=ms73554678
- _cluwztp4v8raf55q061dfjucqhr1fbl
- ms67796139
- IRETqtba9wqHJr5xKrkAWdyx2yv74J7UmkgT5o5akdqlwDOtLryILRHtsmrzrIKRq2eJtZbajhJJPcrYooYITw==
- MS=54BE86BA3F8919C4E0D2DD94C93CCFABD56E62BA
- _j7ejggkvkroiadm5iv0iywtn71d411d
- MS=3896F2E300DE5143994D6883BF7993808721F55C
- openai-domain-verification=dv-p16kKRFLTaaTQ7P05czdmj84
- MS=ms38201695
- wombat-verification=3KwxVCQV1HEp-aRXRTKKaZ5G0frhk
- n4m28nmk057d74j8sqq72dat3g
- MS=ms44736586
- duo_sso_verification=hPB5fL3WAvMj4YFVTxfEzrVrz9Qh10RsRBuaNNBNYVI0TT41PSKrnpaRMdTMb17n
- MS=ms74939766
- MS=ms84833008
- k1uso3crvp1511mmdnpcp8etiq
- pkuen0740sl3trgpo6g34uq2nn
- et7a9hle57f15ahvkuudmbanvu
Cloud / SaaS Services Detected
Apple
Atlassian
Microsoft 365
Cisco Duo
Proofpoint
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.