Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

lifting.com

lifting.com

Group Cactus
Discovered 2025-02-25 17:23 UTC
Est. attack date 2025-02-25
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

<p>Industrial Machinery &amp; Equipment<br><br>“Bishop Lifting, founded in 1984, is the most trusted name in the lifting world. Bishop Lifting has the deep expertise, services, and support to solve both routine and complex lifting challenges. They have the above and below-the-hook inventory customers need, when they need it.”<br><br>Website: <a href="https://www.lifting.com/">https://www.lifting.com/</a><br><br>Revenue : $135.8M<br><br>Address: 2301 Commerce St 110, Houston, Texas, 77002, United States<br><br>Phone Number: (713) 512-1700<br><br><mark class="marker-yellow"><strong>Download link #1:</strong></mark> <a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/INDHOIST/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/INDHOIST/PROOF/</a><br><br><mark class="marker-yellow"><strong>Mirror:</strong></mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/INDHOIST/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/INDHOIST/PROOF/</a><br><br><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:</strong></mark> Personal identifiable information, database backups, corporate confidential documents, contracts\agreements, employees and executives personal data, OneDrive exports, financial docs, customer information, corporate correspondence, etc.</p><p><img src="/uploads/Passport_ed7f60ffa4.png" alt="Passport.png"><img src="/uploads/LOCKHEED_MARTIN_5107584_00_9_08_23_360214a333.png" alt="LOCKHEED MARTIN #5107584-00 9.08.23.png"><img src="/uploads/GT_F2023_FS_2023_04_Actual_04cd78f872.png" alt="GT_F2023_FS 2023-04_Actual.png"><img src="/uploads/completed_i_9_10bec724ce.png" alt="completed i-9.png"><img src="/uploads/Bairstow_Lifting_Products_Bishop_Lifting_Mutual_NDA_BLP_Executed_11_3_23_4bb514669e.png" alt="Bairstow Lifting Products Bishop Lifting Mutual NDA - BLP Executed_11.3.23.png"></p>

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 3

Third Party Employee Credentials: 2


External Attack Surface: 1


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • lifting-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • v=spf1 +a +mx include:_spf.bigcommerce.com include:servers.mcsv.net include:spf.mandrillapp.com include:spf.remarkety.com include:20560760.spf07.hubspotemail.net include:spf.protection.outlook.com ip4:18.211.229.31 ip4:44.195.106.178 ip4:74.81.92.70 -all
  • MS=ms57249521
  • WHO0dVB2Kf4eP5DCUFLrDUQ17VCz6ic0pbWPKDwrNWFFRHggvo9HOU3meEnhclyzF9iOhhhZl6ijo3QrcgYaHQ==
  • _globalsign-domain-verification=dyZbeEEa4K_z6oKE71G9wwbKXeor-TSBqlp8I6JT-H
  • apple-domain-verification=07Om375cPkdiWuYo
  • google-site-verification=0mlA_zuGQrLEhM-nb3ZT19qFZp6BCapBM1brTlcXx80
  • google-site-verification=4frG9Ak5HUrkkZ-CYEfhbqSrYCiiyn9p1hYp5uknolM
  • google-site-verification=DaryYGWKdLWcS_gSeAKIFTvJagUbSaNDxVV4y5n-E1Q
  • klaviyo-site-verification=YAdcmX
  • ng9d55s4imag393v1ggmbv1utv
  • openai-domain-verification=dv-PLP8kIt1Ql0Qjs2F86hVDnBV
  • openai-domain-verification=dv-cQ3XQkcrJMDaRLWzvM9mBN0M
  • openai-domain-verification=dv-yiYLOw0NszFXSJvLZLo3j3Fr
  • sophos-domain-verification=66b3cbc51b73bd2549288f8c7ea96a96072d126b
Cloud / SaaS Services Detected
Apple Global Sign HubSpot Mailchimp Microsoft 365 OpenIA Mandrill Sophos

Leak Screenshot:

Leak Screenshot