Group:
Clop
Discovered by ransomware.live: 2025-10-27
Estimated attack date:
2025-10-27
Country:
Description:
[AI generated] Milgard.com is a manufacturer and supplier of high-quality windows and doors in the United States. They offer a wide array of products, including vinyl, aluminum, fiberglass, and wood-clad windows, as well as patio doors and moving glass wall systems. The company is renowned for its innovative designs, energy efficiency, and commitment to customer satisfaction. Milgard also provides professional installation and repair services.
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 3
Third Party Employee Credentials: 1
External Attack Surface:
1
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- milgard-com.mail.protection.outlook.com.
- v=msv1 t=B9ABAFC2-E83E-4F83-8101-B2F16B62928F
- v=spf1 ip4:204.8.105.35 ip4:204.8.106.75 ip4:209.147.114.234 ip4:52.1.22.130/32 ip4:52.1.25.104/32 ip4:52.200.152.15/32 include:spf.protection.outlook.com include:_spf.salesforce.com include:usb._netblocks.mimecast.com -all
- 0ed1fe018a73435e0d58764c6abd464f9aaf7817bf
- 123oadmkapobuhsqer2g81ed24
- DmyxJLX+5/mwbeL4eJAYJDRcWCEcdyRZyoXYguPSBkk2Gk/0NvMTs+nFo/8yJOep0h2gLHjbEP3+ybJc3uwQqg==
- MS=ms40549854
- bgefi7jv698kcuidtfd1rmasi4
- google-gws-recovery-domain-verification=53499109
- google-site-verification=UulTdFb-dsduXn6LlQWh51MdsGqtEZTPP-qTX2zrJsI
- google-site-verification=WxRTymTqVUKQ6dswODT9Lm3B7v3DjuzGyWBvnYvGGv0
- google-site-verification=nB2EFF_KcE-FGYa9S6gCytO6ED-327FdEout_Z0ARbs
- google-site-verification=xd4i92vcj9jwezbml_ku3cjnms0qmbrjfg2mhlamq5g
- knowbe4-site-verification=0062c6a44f96f871c880c5609b928088
- pardot_131721_*=2e0be9734e5414b3e788fde6001dd6d7221fb3d3f782497abdf376007f41e13d
- svmjetsbsmc2tar5n03lloi8jb
- v8fotf42npmbt8rh1qc01jtern
Cloud / SaaS Services Detected
Microsoft 365
Salesforce
KnowBe4
Mimecast
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.