Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo BECHTEL.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: US

Description:

[AI generated] Bechtel Corporation is a global engineering, construction and project management company. It operates in various sectors including infrastructure, nuclear, security, environmental clean-up, oil, gas and chemicals, mining and metals. Founded in 1898, the US-based company is one of the most respected in its field, with projects in more than 160 countries. Bechtel provides design, management, procurement and construction services and is privately held.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 38

Compromised Users: 1646

Third Party Employee Credentials: 186


External Attack Surface: 115


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse cscglobal.com
MX Records
  • mxb-00399f02.gslb.gpphosted.com.
  • mxa-00399f02.gslb.gpphosted.com.
TXT Records
  • google-site-verification=eUJoWNRvyRHTKIZmha4wxwOpoy4QKKTkFD0MHAPfqs0
  • ru03csDcZuwjK99yJEHHcq1T2WPtuiR3r0zBYJZp756ECXjOEUuHBWjeG49xiS3TXHlTLtztaDN5JjKafmYw2A==
  • _U8NOqjcULm2hiXmTTV2
  • YmVjaHRlbA==
  • _lqo0dy2x1bbdoqf0xvfxvschp79o3ni
  • xq9HN+gokt9FTdRemRrCtAi5yqE0swPMku/YN/mjceIPcYQc4cW0Dc79O1z7lV2qA+SMXOrigRhiQodIgix3yw==
  • wRhieipxgdPQxJ4P+kU8a11byaCicn/CncXyxBRYy3oOcAh9cpOASrFZs3srPyRm8CWvROSfcBHsK4iKt2a0Ww==
  • smartsheet-site-validation=SMpXZSuuif6LXwGiyeDdCrQJRitkmw1K
  • _globalsign-domain-verification=wgOMfv3-E-mjh3Hgw-cK1I749GmQ54zmjE7fOUVhnr
  • v=spf1 ip4:147.1.154.111 ip4:147.1.234.176 ip4:147.1.234.177 include:spf-00399f02.gpphosted.com -all
  • docusign=95f2dc95-6e35-4feb-9bf3-86dc7371e608
  • u5pEpMQuf+DEaOfrphjxoLLy9SYCXmAhH0msVGQlrUcaJGbGfYHaWcMXNxAnsz1uK4oLJmq9S3eSaPrT1T7abg==
  • apple-domain-verification=oNSq4MlVOEpdUdGs
  • atlassian-domain-verification=lm9vet5oLT6QuFGFgSHnoV8bqQdC+esF5NB6ERELMAR2nhnaK7ZwKJbzkmOMUOYg
  • pexip-ms-tenant-domain-verification=a246a6ca-35e2-4636-93b0-2c7660fe15eb
  • google-site-verification=s_QuInBgB2VB5nMEbAAyBonK0tYa9WpIjJN0Yz5iYQk
  • fSjj4aMF7d3MI+erzH4EhJEWdNbF9NzWiW8jxSU1aGOJg4vOVOY1X/h/F6cXQXh0mAWNZUodOLoRzpeQDCX80g==
  • google-site-verification=1z0Gz3oxZPQlruBqPnOiazxowU2WarIHkAFeD7Kxfzs
  • A4VkqixrXUQ3n4kGWJHuhV2xX9Gt2qQXIVbIuXwV5DgxP/iuaGuJTXHruzddur6aic+0yEjofhADwmPm+tvSjA==
Cloud / SaaS Services Detected
Apple Atlassian DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot