Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo COPELAND.COM

Group: Clop

Discovered by ransomware.live: 2025-10-27

Estimated attack date: 2025-10-27

Description:

[AI generated] N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 12

Third Party Employee Credentials: 8


External Attack Surface: 10


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse cscglobal.com
MX Records
  • copeland-com.mail.protection.outlook.com.
TXT Records
  • zapier-domain-verification-challenge=4657c8af-0490-44ea-aaa6-bc46f6ee4e03
  • MS=ms18232351
  • MS=ms52265020
  • _dagu8d22fq70dcqhdqbqx6nan7kh4un
  • atlassian-domain-verification=GCiwM9FvPGh0u9I6eaH/XuvHFbw4rIpaW2VRLa8FyVvyRhfLkONYq0zi1sulw26i
  • _a2yph3qiffx31xz4fglrhha31wvcgie
  • MS=ms64143222
  • v=DKIM1;h=sha256;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyhVs7s6XLLYtF+VVOl7myHn9jK/GeOj7jttttgIwM2XWpsaci4QflJ6hi46V1TP+Qx4mPqVX0dh9QcSVuO/cGgCS3Osy6Tzrcr+OLsak18IqdU/aYV2IwvV0Mm3ogLJJoJnBrepdRpi9aEWDxxv983ZalHIN51vkGF0RAJFQ4eom7lAc5csG+gkRAwRvOCBg" "YsMD1okp6epv98uF3DnIvgr7Zwzw4eEXUAJJ/QLZjpgbPNa0NYSfFRMP4AFZibn48tu9NKtm4Sx8O457IL9QnLmc0ovGoQ4ur9nlijSfOG/xsdD3NhCmGBu7EJMHSR9YotGRZ7t7o8R5xIj/w45czQIDAQAB
  • onetrust-domain-verification=853292980b3e4036918f92142f83c5f0
  • _qzjg6zc8jtzv3ntbwim1tvjm35dmv7g
  • 0FEE7A1DF7D22692C7E21C752FA45CA5F418AFDA3AF5D502241C63FCD8910902
  • atlassian-domain-verification=P0DnNFo6vyOiSUpXBOTJjznq9c2XPCGrOXCq29QFUubMn19Qgn63GILp8jBJk8Li
  • sending_domain948362=9e5708e7e3578494ef9ca415fa7fef0dcaa14196974d5f2d328a322b7ecda0cb
  • meltwater_sso_20240611_TRITON-21330
  • google-site-verification=9nCIpWxKg5aWNphnlOdf91i8H7OBYGHUEJRKk07UF20
  • MS=ms48494591
  • _qcs5lzn8rn8u31h5csrdi385n9hnsp9
  • cisco-ci-domain-verification=1a7b3e4e1461104ae2f14a1aa29429a9de155e6ff5dd951a7c97c919b951b0d7
  • v=spf1 include:spf.protection.outlook.com include:_spf.salesforce.com include:rnmk.com include:spfhost.messageprovider.com ip4:52.36.206.42 ip4:159.112.248.120 ip4:52.1.84.206 ip4:54.148.7.163 ip4:74.249.148.247 ~all
  • MS=ms69609917
  • google-site-verification=Pb5PrQ74Fs3ABLyg0Kd54tvw3jBCgWoTMLS_y2FCiiE
  • MS=ms17895396
  • MS=ms76842365
  • cisco-ci-domain-verification=42ba1a55906894bd3aa4813e265f14de15d5645deda3c1e2713e6e6da5fd023e
  • atlassian-sending-domain-verification=15af0bbf-6a82-4f31-9753-8d96f05bee9e
  • MS=ms97981907
  • ca3-5c80ec2454d448e88b82a07be4804cb5
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Salesforce Cisco OneTrust

Leak Screenshot:

Leak Screenshot