Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Christies Auction House - christies.com

Group: ransomhub

Discovered by ransomware.live: 2024-05-27

Estimated attack date: 2024-05-27

Country: US

Description:

Visits: 2 Data Size: 2GB Published: False


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 5

Compromised Users: 707

Third Party Employee Credentials: 4


External Attack Surface: 4



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse cscglobal.com
MX Records
  • mxa-00380302.gslb.pphosted.com.
  • mxb-00380302.gslb.pphosted.com.
TXT Records
  • docusign=21c33c42-43ac-4410-b3c8-7354c5d8eb10
  • MS=ms62399924
  • bksbslc74yl32z815jl4y39ry6zsnqnb
  • v=spf1 include:spf-00380302.pphosted.com ip4:65.51.86.20 ip4:168.245.29.129 ip4:149.72.44.127 a:b.spf.service-now.com a:c.spf.service-now.com a:d.spf.service-now.com include:spf.mailjet.com include:smtp.app.echomark.com include:5f1bb19e-spf.mta.getcheckre" "cipient.com -all
  • google-site-verification=ZmbULqyejwszBNF5zruBreOh24i-v527CgFhLiKbFKE
  • miro-verification=48a6294f7caecf3b636912b207567f8f481f9fd3
  • FKeZgVM50J3MQh8d0+04YWgNqSG5FA5+fTnEZhXe+CSp6MxeSdtz40/pVv2IpXN6ZVIFbGy9lkxwQN6DMPB5bw==
  • atlassian-domain-verification=v4aweDT4FOCXsSjfkwo2plXxP6BBlUKqy1f5V3ahhuaCepIR8WWB7p18CctJQlOe
  • google-site-verification=Dnb7KDc5GjndfetoQLZFaoxiZYpgPT66idoBuHI9O94
  • ciscocidomainverification=74ccbf6c64a4ad501f4a5e2a3990f4f72b66a40c6ac092fe7e7ccc9514c9f9c
  • k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQClR/LrhqrSwzgCZ0xsZr0+YItnyOILgAjwGoCp1HmW4dU3gzjAFAxLMqqmA5zGmL3wWpYVypCQd4toX258MurC/Y+IUqdmX4G/taQF3gJK9P41+32BbMpANuUVgRbOHcABOCB/pu+p2LYj95Sx4Jq6TLp3h/TsY5S7liYuL60JvQIDAQAB
  • googlesiteverification=sX1C9Rg0sfP2kISjVSVTrqfnGuZcm9S_KRKDjJleJU
  • th0tx99k1xcpfxbx2fk01xntyd26bpr4
  • gsdd3odqhd1qk6qombm3uvkogo
  • docusign=032e43cd-5f60-4c53-a05e-9eab65467d2a
  • extensis-domain-verification=73b88f2c-1ed8-41ba-a660-42c04a7f5ec5
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Miro Mailjet DocuSign ServiceNow Proofpoint

Leak Screenshot:

Leak Screenshot