Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Play
Discovered 2024-06-23 21:17 UTC
Est. attack date 2024-06-10
Country US

Description:

United States

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 24


External Attack Surface: 2


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • trustandsafetysupport.aws.com
  • b3227927797f4c3c3103e980699534a5147086db20b0a13863e696082b7daa22belletire.com.whoisproxy.org
  • b3227927797f4c3c3103e980699534a5212cb4f73be5b0ba0e8b2705cdfcfcd7belletire.com.whoisproxy.org
  • b3227927797f4c3c3103e980699534a59d58da980c3c65f7b34c7e46ba85d95fbelletire.com.whoisproxy.org
  • b3227927797f4c3c3103e980699534a5f955f63fbb19d2d69001b844a09d4132belletire.com.whoisproxy.org
MX Records
  • belletire-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • v=spf1 ip4:50.173.129.42 include:spf.protection.outlook.com include:amazonses.com include:_spf01.mykronos.com include:_spf.psm.knowbe4.com include:mailgun.org ip4:216.46.93.237 ip4:216.46.96.238 ip4:216.46.96.239 ip4:12.104.201.5 -all
  • MS=E58B0C86974613BA19CEDFE6F3151ABCFB4F866E
  • anthropic-domain-verification-2c8ybk=dlc6TFoLVV0WQSIHDx4UuaGBT
  • atlassian-domain-verification=jpthlraVfADTUScQ76gmakRWLMigReekFCxFw4xPh6asspA2hMcGUdmcaAa6ZmaX
  • cursor-domain-verification-smz704=RqNW2JiybHvi1WYWggJXmG7j2
  • duo_sso_verification=FWQ6f38RksOQnueyLIMGkefZQO94EsEHCiJOEbEzCuFsTDpc9qdgRy3dF62bqyjT
  • facebook-domain-verification=yjjnxl99xshjtkljg8echx7gbm48v6
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Anthropic Mailgun KnowBe4 Cisco Duo

Leak Screenshot:

Leak Screenshot