Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group: Akira

Discovered by ransomware.live: 2024-01-09

Estimated attack date: 2024-01-09

Country: US

Description:

Viridi Parente designs and builds fail-safe battery systems for industrial, medical, commercial, municipal, and residential building applications. 70 GB of data contain lots of files with accounting, payment, projects information. There are also many nondisclosure documents, NDA and personal documents of employees. Uploading is coming.


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • us-smtp-inbound-1.mimecast.com.
  • us-smtp-inbound-2.mimecast.com.
TXT Records
  • v=spf1 include:us._netblocks.mimecast.com include:spf.mandrillapp.com include:spf.protection.outlook.com include:_spf.odoo.com include:sendgrid.net ~all
  • wrike-verification=NDI5MDQwMjowMGMwZGNlMDU4MmE1ZTE4Yjc3NDA1MDExNDBmZWVjOGZhNjMzNmVmMjgxMjkyYmM2ODdhNThjZWMwM2ZjOTE2
  • 0ed1fe018a5d86a537deb44f82839b292eae3c1c5a
  • Foxit-domain-verification=7f266ceb6646143936d4c600ca9f06ec
  • MS=ms70009164
  • Value = MS=ms58935784 TTL = 3600
  • apple-domain-verification=oSbCgYPB9b9JBVoZ
  • ca3-167ac327088f4f9ba96ba8222495cec1
  • google-site-verification=agIhx2ZgkaWORUvP9zy6hz9mrkmo2rV7sIrM67SRB4s
  • h27vvb7ib5oh08nnjakuq0fjnf
  • teamviewer-sso-verification=8303f701578047d7952817b980edd627
Cloud / SaaS Services Detected
Apple Microsoft 365 Teamviewer Mandrill SendGrid Mimecast