Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2025-03-18 14:32 UTC
Est. attack date 2025-03-18
Country US

Description:

All data will be published on Mar. 21. Cleveland Municipal Court The court is located in the Justice Center in downtown Cleveland. The Cleveland Municipal Court has the ability to hear and decide specific kinds of cases including civil dispu ...

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 1

Third Party Employee Credentials: 4


External Attack Surface: 2


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • clevelandohio-gov.mail.protection.outlook.com. Microsoft 365
  • clevelandohio-gov.mail.protection.outlook.com. Microsoft 365
TXT Records
  • rah5jepopj4pifunmgu1t2lsa5
  • 9d89roqm7sup97ed1vt5tk43ug
  • cisco-ci-domain-verification=1b57058c31434c7bc94fbb088eda86fee8bf6455b71b103de1865cbeb8345cb4
  • MS=ms52504583
  • 3jmsp0sraoknr836i7l0v64mtt
  • v=spf1 mx include:amazonses.com include:spf.protection.outlook.com ip4:12.133.230.126 ip4:69.54.50.131 ip4:162.155.55.130 ip4:12.133.230.106 ip4:204.156.203.160 ip4:216.128.251.155 ~all
  • a8oqfuft3hcffqkkt95e0fblto
  • apple-domain-verification=PYXu5DENzTVEVbZ2
  • 5su3183jte50bbo7om5jk7uek4
  • dropbox-domain-verification=ksyebp0n16cj
  • NnrkgJdqA1Ajd5T6qqD0AEDcx4tMG/47EIiusGlBXWRr+HIMPfm5eb51LAKaEPtnJLnm7owSGoX8sQ5B0OQjxQ==
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail Dropbox Microsoft 365 Box Cisco

Leak Screenshot:

Leak Screenshot