Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

downies.com

downies.com

Group Settra
Discovered 2026-07-21 12:09 UTC
Est. attack date 2026-07-03
Country AU
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation
Data exfiltrated 550GB

Description:

Downies Collectables Pty Ltd: $1.4M per Month — and $78K in Rent Paid to Itself PROLOGUE We are in p...

Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 115

Third Party Employee Credentials: 0


External Attack Surface: 32


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • registry-abusenexigen.digital
  • salesventraip.com.au
  • downiescomobscure.me
MX Records
  • downies-com.mail.eo.outlook.com. Microsoft 365
TXT Records
  • ms=31001c5957dda10d63750f875eb4e1fc6f7d00c0
  • 2ieby9kith+yjxxh1z5wt0o0gvvvxv5txhudjvijxo/h+ke933t8utwautcrt4bq+mk+xhwiua1sa1odjcy/ba==
  • v=spf1 ip4:210.50.193.118 ip4:203.87.86.6 ip4:14.202.238.185 ip4:210.50.193.116 ip4:13.55.80.197 include:spf.protection.outlook.com include:sendgrid.net include:mail.zendesk.com -all
  • klaviyo-site-verification=ViSTET
  • seal-subscriptions-verification=vm4r0z72teh84ig4ixht
  • 368nb35a6ooavcqcrv7afrgf8l
Cloud / SaaS Services Detected
SendGrid Zendesk

Leak Screenshot:

Leak Screenshot