Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo GOLDSTARPENS.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: US

Description:

[AI generated] GoldstarPens.com is a manufacturer and supplier of customizable writing instruments and promotional products. Beyond pens, they offer a range of items like flashlights, tech accessories, drinkware, bags, and more. They utilize state-of-the-art printing technology for customization, serving as a resource for businesses looking to enhance brand recognition. With a global reputation for quality and affordability, Goldstar Pens is a trusted partner for organizations worldwide.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 28

Third Party Employee Credentials: 3


External Attack Surface: 10


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints markmonitor.com
MX Records
  • goldstarpens-com.mail.protection.outlook.com.
  • us-smtp-inbound-1.mimecast.com.
  • us-smtp-inbound-2.mimecast.com.
TXT Records
  • gkjprginemuprratu602pgd66j
  • mebDrwxnDq/lfSxb20PXnOosZZO058vCebB0tFpUkWPS1iIHN9ukpleVM3hzEBx0znypaSPMeZVXKiAz36PRig==
  • ojdifmdj2738hnovnr7s8g6mso
  • pardot637481=3a568141f96b427be4bd30f11257f5b9c0f20954c22599b20d1c73891bd29e90
  • pardot637481=4e3cee2125a049ab85a53cf7d9947086a2b5c770e3b69b4246966444098f6ac1
  • pardot637481=f6f8ba8e2728d299776a5e62c89e7460ed6594bbebd31f098186cd2bc633a7c9
  • pardot637491=a031999153b90b016e570b05df8c590a0909abf7de4408a6e87006dae7738d4a
  • v=spf1 include:_s00156177.autospf.email ~all
  • MS=ms78298180
  • Yt2QMriMQSXCofI5hVnUBMjgEhey4PbXJ1/LEW38IbCeIptcmtPeP57kotIK0y8rEFUUiCDhi6bylBFXqkNa5A==
  • dizKPeOc1GH/R7VapVhMJqUmF/vHdYKrcfpLEvcF4yaa55highdtLKiKiQ086huHaaaiZiziPlkUberpkHXZ2A==
Cloud / SaaS Services Detected
Microsoft 365 Salesforce

Leak Screenshot:

Leak Screenshot