Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Bangchak Corporation

Group: Qilin

Discovered by ransomware.live: 2025-12-25

Estimated attack date: 2025-12-25

Country: TH

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 33

Compromised Users: 5779

Third Party Employee Credentials: 38


External Attack Surface: 117


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • staff thnic.co.th
MX Records
  • mxa-0078c101.gslb.pphosted.com.
  • mxb-0078c101.gslb.pphosted.com.
TXT Records
  • v=spf1 include:spf.protection.outlook.com ip4:61.19.83.219 ip4:203.148.236.82 ip4:203.148.236.83 ip4:223.27.205.109 ip4:110.170.40.228" " ip4:203.148.236.87 ip4:110.170.40.229 ip4:203.151.166.2 ip4:110.170.40.238" " ip4:203.151.166.40 ip4:58.64.9.4 ip4:13.214.32.137 ip4:223.27.205.78 ip4:20.24.155.151 ip4:4.193.206.34 include:spf-0078c101.pphosted.com ip4:110.170.222.0/24 ip4:27.254.248.0/24 -all
  • google-site-verification=j3rYw8iIkEtkqOmfYus1H9LhOf0VCcIW4JLc86QLHYM
  • MS=ms12993502
  • MS=ms59145386
  • docusign=74d83981-0e3c-465b-93ac-c99204d63580
  • apple-domain-verification=SLGODBYuxPIdeaLo
  • ms-domain-verification=9561934c-6712-4a68-9673-f5acebc2cb27
  • docusign=f349fb6f-f519-41e8-939a-4c298064708a
Cloud / SaaS Services Detected
Apple Microsoft 365 DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot