Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

ghimli.com

ghimli.com

Group Cactus
Discovered 2024-04-23 09:50 UTC
Est. attack date 2023-08-26
Country AU
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Download link #1Ghim Li is a global textile and apparel supply chain manager of casual lifestyle knitwear apparel to major U.S. retailers. We supply over 62 million garments a year through our global marketing and manufacturing network. We offer you a total solution package with an integrated one-stop service approach, from in-house product design and development, commercialization of orders, material management, production planning and control, to comprehensive post manufacturing logistics solutions.Website: https://www.ghimli.com /Revenue : $189.1MAddress: 264 George Australia Square St L 42 Ste 4201, Sydney, New South Wales, 2000, AustraliaPhone Number: +65 [REDACTED] 3600Download link #1: https://***************.onion/GHIMLI/fullMirror: https://[REDACTED].onion/GHIMLI/full

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 2

Third Party Employee Credentials: 2


External Attack Surface: 2


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuseascio.com
MX Records
  • ghimli-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • ac10vj4mb8eq221hn1svpdjhtd.
  • ms=ms26134004
  • v=spf1 ip4:118.189.121.189 ip4:118.189.19.13 ip6:2603:1096:100:31::2 include:spf.protection.outlook.com -all
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot