Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo ANYWHERE.RE

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: RE

Description:

[AI generated] "ANYWHERE.RE" is a proptech solution providing a comprehensive and innovative platform that transforms the real estate industry. It combines Augmented Reality (AR), Artificial Intelligence (AI), and big data for assisting real estate developers, brokers, and agents make data-driven decisions. In addition, it enhances the way potential buyers view and experience properties through virtual tours.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 1

Third Party Employee Credentials: 1


External Attack Surface: 3


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • tldsupport@cscglobal.com
  • nrthost@nrtinc.com
  • admin@internationaladmin.com
MX Records
  • usb-smtp-inbound-1.mimecast.com.
  • usb-smtp-inbound-2.mimecast.com.
TXT Records
  • docusign=872841d7-00c8-490c-96eb-24e262a015a0
  • zapier-domain-verification-challenge=b94213d9-883b-438c-a9f9-25e0a05d26d9
  • google-site-verification=fVyPBYvAGmMlU4NDcrB3gUHNELkcqiXiKgB_Im-p2Zk
  • formstack-domain-verification=3e80cc022d42e5d2536e096457b4339c
  • browserstack-domain-verification=f986b476-aa25-4fa0-80c7-ae85b135760d
  • sophos-domain-verification=6e41e874423e93531dde640da72cd945bc3d8b1efd264b73eef55eb7582db90a
  • monday-com-verification=Vzp9M9wkXo140C0DRYV7ojmHp1rlhcE3dD23D45ox_s
  • google-gws-recovery-domain-verification=60603682
  • proxy-ssl.webflow.com
  • figma-domain-verification=be398f2282a8c8a850734c5e7ec3afaa5de15b570b4885e722a3d593cb3c6e5c-1760549735
  • teamviewer-sso-verification=f190a543b71e4e4996ebec98a76fdf1c
  • google-site-verification=jytxz6GaIEYR2fXV5NWQR0rVDIiNMyZQ_c0iKCrLSIY
  • v=spf1 redirect=2kgonkkk._spf._d.mim.ec
  • msfpkey=7f7upvrvdivymxdnlaqeix8c4
  • google-site-verification=jNlDv8_Nq_pRZVFy5BeVpbkfglDFjF_aUAbK84gDbSk
  • mongodb-site-verification=tCfoQ7DSvQcLBGUFu7qhfl4aBgevkXiV
  • hhrkjxm23lzypq4qgzq8bh1gctskb7jd
  • airtable-verification=3aa4fee7bb1e09f1b744dd83ed3d7e70
  • atlassian-domain-verification=VU7xgQiZZa3avZ4LTJOsUdMn6RqZi0eGbU3Dk4MSPmi12S6yFEvEh/I8tLFNxlcr
  • canva-site-verification=P57tuayyDBc1pKxDhEqvKg
  • miro-verification=cf5511f162d6fe30b1cbde5b05df994e64de6303
  • wiz-domain-verification=65c452e4ee0426a068a5c8f24c3db5446829671e065c7ecedfe37b6e412b8904
  • asv=7cf6b4922dad3e86a19809d5854f7be8
  • 2995046
  • yahoo-verification-key=gUed6BiW3t8kOVCzXh92fvkFM8OZNAlQ6T6u146ALhg=
  • knowbe4-site-verification=540a2fb1810f874042b6c46918f4fd84
Cloud / SaaS Services Detected
Atlassian Miro Teamviewer KnowBe4 Mimecast DocuSign Sophos

Leak Screenshot:

Leak Screenshot