Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

US District Court / Law company

uscourts.gov

Group Everest
Discovered 2023-04-26 22:51 UTC
Est. attack date 2023-04-26
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

On sale access to the network US District CourtEmployee access,full controlAV: NoNetwork access of a lawyer with tons various confidential documents is included in this sale. Internal correspondence,tax,banks,ssn,dl,court cases. State IL.Price 15,000$Payment: btc,xmrContact email: everestransomteam@onionmail.org or jabber: everestgroup@exploit.im,everestgroup@thesecure.biz

Infostealer activity detected by HudsonRock

Compromised Employees: 13

Compromised Users: 5113

Third Party Employee Credentials: 14


External Attack Surface: 109


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • securityuscourts.gov
MX Records
  • mail3.uscourts.gov.
  • mail1.uscourts.gov.
TXT Records
  • apple-domain-verification=BJ8iQXsXSFyn9f3f
  • v=spf1 include:spfh.ao.uscourts.gov -all
  • _3qvsn5hqkhfr5qyvg2j2vdkgru5wb97
  • MS=ms96408798
  • cisco-ci-domain-verification=3fff3dc36ffc9349f0826b7cf2d154fd79a1d4f2e06d11d19db8a977eab343b0
  • adobe-idp-site-verification=7734476fc0fc1203dfda054f872a2f4aa3c08208214df45aca0e9fc1dd114d8b
Cloud / SaaS Services Detected
Adobe Apple Microsoft 365 Cisco

Leak Screenshot:

Leak Screenshot