Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo COSI

Group: Karakurt

Discovered by ransomware.live: 2023-08-02

Estimated attack date: 2023-08-02

Description:

COSI, Columbus, Ohio's dynamic Center of Science and Industry, inspires the scientists, dreamers, and innovators of tomorrow. We've taken about 75GBs of data from this organization. You will find there their projects information, lots of accounting and financial documents, contracts (some of them are confidential), clients contacts, donations information an so on. There are also databases containing clients, partners and employee data, transactions and correspondence. Wait for the release.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@tucows.com
MX Records
  • cosi-org.mail.protection.outlook.com.
TXT Records
  • r8vbnb7vcgjh6v8n63mvkccw8ms9qmcd
  • v=spf1 ip4:192.254.121.248 include:spf.mandrillapp.com include:spf.protection.outlook.com include:_phishspf.knowbe4.com include:spf.ticketure.com ip4:159.112.241.219 include:_spf.intacct.com -all
  • 0ed1fe018aaf9825f89c08457dbc1c832f47aaab10
  • MS=ms55479471
  • intacct-esk=3B184292258E979DE06349068D0A3AE3
Cloud / SaaS Services Detected
Microsoft 365 Sage KnowBe4 Mandrill

Leak Screenshot:

Leak Screenshot