Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

ALLEGIANTAIR.COM

ALLEGIANTAIR.COM

Group Clop
Discovered 2023-07-19 01:16 UTC
Est. attack date 2023-07-19

Description:

Attention Required! - Cloudflare

Infostealer activity detected by HudsonRock

Compromised Employees: 10

Compromised Users: 4308

Third Party Employee Credentials: 16


External Attack Surface: 105


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 701c97ad3fc2ad9132b6f8063b054711689050bb68dc40c6a677e3e376f61e31allegiantair.com.whoisproxy.org
  • 701c97ad3fc2ad9132b6f8063b0547114a72d7224b39123a58f201eeccd1e8d6allegiantair.com.whoisproxy.org
  • trustandsafetysupport.aws.com
  • 701c97ad3fc2ad9132b6f8063b0547110235c3b6ab51cdda9358c7e6bfcb5aceallegiantair.com.whoisproxy.org
  • 701c97ad3fc2ad9132b6f8063b05471104c256b59ff566a9f7d2c06f926c5dffallegiantair.com.whoisproxy.org
MX Records
  • mailstream-east.mxrecord.io.
  • mailstream-west.mxrecord.io.
  • mailstream-central.mxrecord.mx.
TXT Records
  • MS=A4F85C223BAE500245C81333B6D8D5B6D02A1272
  • Dynatrace-site-verification=115bc8f7-5e5a-49e9-80b6-02271ed86a44__2jh6anlf89mge5eh4c4gnbjhdc
  • atlassian-domain-verification=EbvcVC2OLeaWg3pW9IcjxFwu2sEv6q6lUGahn4xrtKFx9KIZBRYu7vvHzuU7rza7
  • v=spf1 include:spf.protection.outlook.com include:_spf.airline-choice.com include:amazonses.com include:_spf.ultipro.com ip4:98.187.3.0/24 include:sendgrid.net include:_spf.salesforce.com ~all
  • intersight=de360069bfccb232af96bbad80ddc54c60138ae9a396b6385bcbb164dea72052
  • atlassian-sending-domain-verification=f7cf9e4d-ba02-4b2f-a663-89669c783bb4
  • notion-domain-verification=uPPfWUlMSP7XtBYB8h4WgxLjDdMdrHsbnJi7HwUmg9V
  • dtm-domain-verification=DWf991T5QMUv1lzXFT_7L3hcYyygFLd3jztZtWMy9S0
  • cisco-ci-domain-verification=1e0ad83133a624b421b3046e983eb36b19e0b3f9d4d79b1d3ed02789cde81545
  • oh1q9r72tt1mvb8m3cielqunvj
  • miro-verification=9c6c2fcd646138d9bf079d40aec3067c82d1ce80
  • notion-domain-verification=qN3DzDaWOJNmgKNYnTVFaKm1oBKuNsbggx1w6hqiXlH
  • onetrust-domain-verification=9b9ac7305789409f941c613c1d868561
  • google-site-verification=8Xl8zNAGqO6_XRqq04GrK8Jy4Wpy1w_Cn7bN93-jCs4
  • figma-domain-verification=aa1d35e7696430370e4de96e2df9aba705256f71f54b4b03bdfbac9b67fe892d-1745273439
  • webexdomainverification.4C675B8AB4BDB136E053AB06FC0A3F65=30aca7b7-5e00-4ea5-8dc1-39d8d3905bfc
  • 3f8753dc-904c-4eb3-a1f5-fd97e7219b6b.edge1.pingone.com
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Salesforce Miro Cisco SendGrid OneTrust Cisco Webex

Leak Screenshot:

Leak Screenshot