Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Culligan

Group: termite

Discovered by ransomware.live: 2024-11-17

Estimated attack date: 2024-04-26

Country: FR

Description:

Founded in 1936, Culligan Entreprises is a global water treatment company specializing in premium services and water treatment solutions.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 4

Third Party Employee Credentials: 4


External Attack Surface: 0



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • tldsupport cscglobal.com
  • culligan.emea pec.culligan.it
  • dnsadmin culligan.com
MX Records
  • mxa-00305802.gslb.pphosted.com.
  • mxb-00305802.gslb.pphosted.com.
TXT Records
  • v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com
  • pardot584793=bffa3acfb93b1328ad6b86d65ee8e4cb51585516420ea08fc532e1e198a32b8b
  • PrPJcnNjJR6AUKWjDpqe2hUow2pGjgqzkCR3AfHvDrE=
  • 4DSROK4K2NtD1qN60NZyPHwV2eB3pkguMjTFsmREoZ2oCD/8zqf6moJCFK37H7b59+/t0tgkAd4F3jJweoaBJA==
  • Da3fE4kQE+19mzcwigfUQfjpHwq8isSFHWcRktsUuN1uRM3re4AAQMRiTsqRm/HFHuxFkNwnSWb0AwuhTJ26iA==
  • MS=ms27830982
  • pardot1044463=135e25d407d82e964751a50987cb8fae6f959e82d329bcb7909bdcb159a2ff6d
  • sending_domain1044463=45323302aa87ae01956c5c9502e60389e4a8cbe7a8d3d5cfe3c37190fdc9511d
  • v=spf1 IP4:37.71.155.61 include:spf.protection.outlook.com include:amazonses.com include:spf-00305802.pphosted.com include:spf.mailjet.com include:spf.mandrillapp.com include:aspmx.pardot.com include:eskerondemand.com include:spf.odmad.quest-on-demand.com" " -all
  • google-site-verification=yqWhCtlk9wKYLjl5VWWZixjRhvhfW5sWPTOIjGOjV3A
  • apple-domain-verification=3QGWVDn30y8FZavp
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail Microsoft 365 Salesforce Mandrill Mailjet Proofpoint

Leak Screenshot:

Leak Screenshot