Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Metroclub.org

metroclub.org

Discovered 2023-10-13 08:05 UTC
Est. attack date 2023-10-13
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

We successfully extracted the entire content of the metroclub.org website, belonging to Metroclub, a private club based in Washington, D.C. The extracted data amounts to 2.1 terabytes. The accompanying screenshot provides a glimpse of critical information, although we are still in the process of collecting additional data. Our haul includes the complete membership list, employee…

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • metroclub-org.mail.protection.outlook.com. Microsoft 365
TXT Records
  • v=spf1 mx a ip4:64.106.173.0/25 ip4:192.69.130.0/24 include:mailer.clubhouseonline-e3.com include:smtp1.clubhouseonline-e3.com include:spf.protection.outlook.com ptr a:billtrust.com include:spf.us.exclaimer.net ~all
  • MS=ms65299004
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot