Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Carigali Hess Operating Company

Group: hunters

Discovered by ransomware.live: 2024-07-13

Estimated attack date: 2024-07-13

Country: MY

Description:

Country : Malaysia - Exfiltraded data : no - Encrypted data : yes


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 5

Compromised Users: 3

Third Party Employee Credentials: 4


External Attack Surface: 3



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • compliance_abuse webnic.cc
  • reg_252475 whoisprotection.cc
  • adm_252475 whoisprotection.cc
  • tec_252475 whoisprotection.cc
MX Records
  • carigalihess-com.mail.protection.outlook.com.
  • chocjda.mail.protection.outlook.com.
TXT Records
  • MS=ms70332699
  • ZOOM_verify__mDd1ciMTOit6BO9AC3P1Q
  • goi6r46bskaur9g9lqjb1qf8hl
  • UE33BHE1GK8CWWQOYR683K5IPNHXVU2NCO7RT5M1
  • adobe-idp-site-verification=2e65c0b4a2e99e41e40776ea1175cbf844cbcfe5378f9645f3133289a361936f
  • 1dYb7zV17qOvqsFYCQOdJdKvyIKX7og4UCHnX0cGN6oU2Y5+4S/B8Z4waIs8qaEzcG3SPQHP9J+RwRJPjoqsmQ==
  • TXT zoho-verification=zb69063173.zmverify.zoho.com
  • MS=DEB28B72B305E986D4E7F215AD6D212508F28816
  • v=spf1 mx a include:spf.protection.outlook.com ip4:210.19.71.86 ip4:210.19.71.88 ip4:210.19.71.91 -all
Cloud / SaaS Services Detected
Adobe Microsoft 365 Zoho Campaigns Zoom

Leak Screenshot:

Leak Screenshot