Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Alberta Construction Safety Association

Group: play

Discovered by ransomware.live: 2025-05-05

Estimated attack date: 2025-05-05

Country: CA

Description:

Canada


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 46

Third Party Employee Credentials: 0


External Attack Surface: 10


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
  • Please ask the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Other contacts of the queried domain name
MX Records
  • youracsa-ca.mail.protection.outlook.com.
TXT Records
  • 6kom2j1tc6ed5mrlltgtk83dq0
  • v=spf1 mx a ip4:20.175.105.216 ip4:204.191.127.128/29 ip4:204.191.38.105 ip4:35.80.141.6 ip4:44.229.121.55 include:spf.protection.outlook.com include:mail.imismailcenter.com include:spf.mandrillapp.com include:servers.mcsv.net ip4:208.185.235.0/24 ip4:148" ".59.108.0/23 ip4:148.59.106.0/23 -all
  • google-site-verification=4yWV_0eBC1hsuuhnzSDjS9P1m1pkicIQL9VHITzwXdI
Cloud / SaaS Services Detected
Mandrill

Leak Screenshot:

Leak Screenshot