Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Chroma Color

Group: Play

Discovered by ransomware.live: 2024-06-12

Estimated attack date: 2024-05-17

Country: US

Description:

United States


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 2

Third Party Employee Credentials: 14


External Attack Surface: 0



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • usa.mx1.mailanyone.net.
  • usa.mx2.mx25.net.
  • usa.mx3.mailanyone.net.
  • usa.mx4.mx25.net.
TXT Records
  • duo_sso_verification=wkNuEVtwVhpgLM2qTRyUnKgZlWx5LoDjRify01nSSGMgwHSd8Jv3G6ekddjZ5h2E
  • google-site-verification=RyhOMAbH8aYP1Cpro6OBYJJkuvKq000Y-n3nozGreJU
  • v=spf1 include:spf.mailanyone.net include:spf.protection.outlook.com -all
  • 693d22fg6ytv2r2h2p7054sn5tfqngrl
  • MS=ms45872575
Cloud / SaaS Services Detected
Microsoft 365 Cisco Duo

Leak Screenshot:

Leak Screenshot