Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Rhysida
Discovered 2025-06-16
Est. attack date 2025-06-16
Country US
City Houston

Description:

CNPC USA CNPC USA Corporation is a Houston-based company that was founded in 2011 to help connect North America with CNPC's worldwide operations.

Infostealer activity detected by HudsonRock

Compromised Employees: 56

Compromised Users: 385

Third Party Employee Credentials: 28


External Attack Surface: 54


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • wangld@cnpc.com.cn
MX Records
  • mx3.cnpc.com.cn.
  • mx1.cnpc.com.cn.
  • mx2.cnpc.com.cn.
TXT Records
  • 88ac574156d812ed3467cadd070f53ed2a3c3792905f3ba4db1a40bde49a69ed
  • v=spf1 ip4:107.150.125.94 ip4:219.143.68.2 ip4:219.143.68.3 ip4:61.232.0.0/26 ip4:219.143.68.64/26 ip4:219.143.68.4 ip4:219.143.68.5 ip4:223.69.170.30 ip4:223.69.170.31 ip4:223.69.170.32 ip4:223.69.170.33 ip4:223.69.170.34 ~all
  • 201704091100362h5r5zvpy29jt7rlzllwon27c5d7zlr9m2hunfmiq0r1mvryza
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot