Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Centrotherm International

Group: Qilin

Discovered by ransomware.live: 2026-01-25

Estimated attack date: 2026-01-25

Country: DE

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 0

Third Party Employee Credentials: 0


External Attack Surface: 1


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mx04.hornetsecurity.com.
  • mx02.hornetsecurity.com.
  • mx03.hornetsecurity.com.
  • mx01.hornetsecurity.com.
TXT Records
  • b29wx5x6jd4jb2nllf7f1hgfl5nz3nrx
  • _82xn4nsv00nn30ydpdvz7bire01e27y
  • 6r1dlcs2sdqp01fn1j2szzp4zk83bst7
  • 0p5dfrmrrzkb26z1s67f207jfyq2k0bb
  • v=spf1 ip4:194.127.107.0/24 include:spf-de.emailsignatures365.com include:spf.hornetsecurity.com include:_spf.salesforce.com -all
  • apple-domain-verification=55ykpS7MSRctGRR0
  • 249m6r4t4s82wl1d4d8gzzvcrp3rshy1
  • google-site-verification=F-B2Sc4nfLuZE64B3Y_qDrtQbnWi5y9hZOIXS7CMucc
  • _hooyl8vnma833p01xpkufxyddb8piax
  • atlassian-domain-verification=4dIeKNNqfxjwzBdajl4gP2hTQK7/5aFY/p2DXFySbFH721CY4wVXlXkcw0q7vIWS
  • _k5ph9b91zyf1apa334hjtpimu3f7eh3
Cloud / SaaS Services Detected
Apple Atlassian Salesforce Hornetsecurity

Leak Screenshot:

Leak Screenshot