Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Alphv
Discovered 2023-07-26 16:30 UTC
Est. attack date 2022-11-20
Country TH
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

We have stolen 500 GB of data, you have exactly one week to contact us, otherwise the data will be published!

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 4893

Third Party Employee Credentials: 4


External Attack Surface: 100


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • nokair-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • google-site-verification=QsOYsKVFnWc2XmjVinlLAacNk4oxTdE9q_NS61V3Ex0
  • MS=ms89783719
  • amazonses:XQ4QlnbE0z6OYWGBOQ0Cn45KWUQnpwEN/wXbneAJlDQ=
  • v=spf1 ip4:210.86.181.20 ip4:210.86.181.27 ip4:210.86.181.28 ip4:210.86.181.29 include:spf.protection.outlook.com include:sendgrid.net include:amazonses.com include:spf.sabre.com ~all
  • \009 google-site-verification=bASCu7v62ndb7FBUKUeZIkHGhzxEG-8mdWMxeh_hLZI
  • google-site-verification=MWxzTYfyU_Q2X2SJ0RTrOZNlyydg6oza7J8S7FjhTWU
  • amazonses:Q0guC4hSAHKquP9xK9uuF5H7Uud84jNouaaOsKy4grg=
Cloud / SaaS Services Detected
Amazon SES/WorkMail Microsoft 365 SendGrid

Leak Screenshot:

Leak Screenshot