Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo CNQC

Group: akira

Discovered by ransomware.live: 2025-03-12

Estimated attack date: 2025-03-12

Country: CN

Description:

CNQC was established in 1952, which mainly engaged in domestic an d international construction projects and investment, real estate development, capital management, logistics, design consulting an d etc. We are ready to upload more than 90 GB of essential corporate doc uments such as: driver licenses, employees medical forms, financi al data (audits, payment details, reports), rental agreements, co ntact numbers and e-mail addresses of employees and customers, em ployments passport with fingerprints, etc.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 0

Third Party Employee Credentials: 1


External Attack Surface: 3


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • cnqc-com-sg.mail.protection.outlook.com.
TXT Records
  • sophos-domain-verification=de760d02d1ae60f69dfe6de89cb25c4b491fcf33
  • trend-micro-v1-domain-verification.b36e597b949ef080bb08fcbb59cb5817=c79fc705-84c4-4156-8d45-17c7b4fe0896
  • v=spf1 ip4:119.73.144.48/28 ip4:203.125.50.192/27 include:spf.protection.outlook.com ~all
  • 5k6s1n3lsnbapovn1u2fanufrm
  • 70jsrikjfdb308f0ggb8jsm3ks
  • autodesk-domain-verification=RXKN9--Xyu6YF11WMF65
  • r8ca65415agn8ki5eq9apfp9pv
  • sophos-domain-verification=6672a3040cd4d289f16c98573affac31478ae2d1e1059c0bf1c4ea22d3f0aefb
Cloud / SaaS Services Detected
Autodesk Sophos