Group:
Clop
Discovered by ransomware.live: 2025-02-12
Estimated attack date:
2025-02-12
Country:
Description:
[AI generated] Morris Group is an international company that offers a range of financial solutions, assets management, fintech innovation, and real estate services. Originating in Switzerland, they combine a global perspective with deep local knowledge to deliver integrated services to companies, communities, and individuals. Their key sectors include financial services, health services, and fintech. They are committed to sustainable development and community investment.
DNS Records:
The following DNS records were found for the victim's domain.
- morrisgroup-co.mail.protection.outlook.com.
- citrix-verification-code=fe110bc3-1960-4d33-984a-83617e74d4ba
- _qymlk2evtpivp1t2fl8o9pisa5zyku2
- google-site-verification=rDy1zdZvU7xMBE4qYKXs7wls9yF50zOymvpiEjIip8o
- atlassian-domain-verification=H8KpKxXDwXfGCrIycBGp18lJZ97WkQssDWmyRYVGD6HwHBsi3PsaeYMpLnoRcBam
- ahrefs-site-verification_08b90023e7c848d42672f573e914268735ea39bfc51496c3b02fac84e89ba076
- ZOOM_verify_SMLRRr9mREK4IuY9cfIbZA
- pardot_48752_*=92f00f11967e263e12dedc24bccd8017dfbf16e9057b4737dbb371a6234d6948
- google-site-verification=z4yxaQaFD2TIJswf_XZ7_nbLhPLcg3pIEbuIXbHyZZ4
- d0662868-bf64-418c-9189-4462f17b74ee
- Foxit-domain-verification=3bbf18c227d478c944941844eee7840b
- sending_domain48752=9a35ee2d34a8ff64ccbbf275b5d9197d0aa11a5493a24b7fb83dc105c53aeb11
- knowbe4-site-verification=2a45e518e98e76176cc68e50fc578f4c
- v=spf1 ip4:47.179.9.170 ip4:76.53.152.110 include:spf.protection.outlook.com include:_spf.salesforce.com include:aspmx.pardot.com include:shops.shopify.com include:_spf.psm.knowbe4.com include:_spf.samanage.com -all
- facebook-domain-verification=dnjsnmk81afg4vcx8evm4ync71ts54
- 00d61000000y4ecea0
Cloud / SaaS Services Detected
Atlassian
Salesforce
Shopify
KnowBe4
Zoom
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.