Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo CLEO.COM

Group: clop

Discovered by ransomware.live: 2025-01-24

Estimated attack date: 2025-01-24

Country: US

Description:

[AI generated] CLEO.COM is a fintech startup that offers an AI-driven budget assistant to help individuals manage their finances. Its primary service enables budgeting, saving, and tracking spendings in an innovative way. Geared towards millennials, Cleo provides insights into spending habits, gives financial advice, and allows for easy management of money across multiple accounts. It operates in the UK and the US.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 11

Third Party Employee Credentials: 3


External Attack Surface: 4



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • cleo-com.mail.protection.outlook.com.
TXT Records
  • ZOOM_verify_mZrPD4UUT5-3Y8ogf60CEg
  • atlassian-domain-verification=x4zQWN4RKUYt80nLiXKqM9lZaNUO79JkokMMmXPSEqa0A9V4vu1k4G8QLq4jU/S7
  • include:_netblocks.eloqua.com -all ip4:129.145.21.39
  • cisco-ci-domain-verification=25d0681ba473e8db6b400f34ac844b3df3d15f9265860d73261d9bcffde0f2d0
  • k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDpDCE+FicPuc28f0mppTrjpIHMXo2RQw3wFWU/R5xn657Frh4zF3XSCVkin4R9ZgxUAS/TDQwC5wLf3Y7EmuQZtZVwlrRZEkpMaGUsE8Rn9nuAlNWvSZuxYXz+BoB2cs/iHHEfK4zgb5C/Z+GQk9YhOZuaGUbOEqxJ9xt6BlcigwIDAQAB
  • amazonses:w4QlIitjMM/YNkkpcWuJZzP99Tk1m/DOfdCZVwB6D20=
  • knowbe4-site-verification=5c75ffb0bf2e00693e13a805894cc1dc
  • as=1469138553
  • v=spf1 ip4:208.46.32.212 ip4:208.46.32.211 ip4:129.145.21.39 ip4:208.46.32.225 ip4:208.46.32.190 ip4:208.46.32.230 ip4:208.46.32.196 ip4:208.46.32.4 ip4:208.46.32.228 ip4:54.240.61.107 ip4:54.240.61.108 include:spf.protection.outlook.com include:authsmtp." "com include:mktomail.com include:mail.zendesk.com include:m.lessonly.com include:_spf.google.com include:email.freshdesk.com include:_netblocks.eloqua.com include:_spf.salesforce.com -all
  • k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCnIo1zyP/0vzEGusrGEDK1RI3CXK34gRVwWIRkynEGnD+gdcomJvaCQ2d9vHLi1MaDFtLt+WQfOIcdEw+ZFhICQ4S/mr2luO4yT/MzUxw9QpqT4zyp8EzIZkoMFY28OpNuynW4lfQyq9VMGEn0jCMRN8OEreBtnp9IvN97LVtZ8QIDAQAB
  • uL3P8uvtaf9dLZqz/LbsJZs256Ul1TcnwYH7+ZuyCGVHCuSqSC1St0AWrhNf4YDfh+cfBPr9hSPH0bPNsnHxSQ==
  • MS=ms49132910
  • google-site-verification=Wzk7GdjExEawC5lRibje6MTSVA6T_cFq7jHsViyEppM
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Microsoft 365 Salesforce Zendesk Marketo KnowBe4 Cisco Zoom

Leak Screenshot:

Leak Screenshot