Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group: Qilin

Discovered by ransomware.live: 2026-03-30

Estimated attack date: 2026-03-30

Country: US

Description:

N/A

Infostealer activity detected by HudsonRock

Compromised Employees: 15

Compromised Users: 487

Third Party Employee Credentials: 141


External Attack Surface: 79


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints@markmonitor.com
  • whoisrequest@markmonitor.com
MX Records
  • dow-com.mail.protection.outlook.com.
TXT Records
  • google-site-verification=9fSgKf-7K1puzVgdVp9XYyhWNrR8hHy_yX2KqLhYAkc
  • facebook-domain-verification=kdbj47go8e4a1j9mt6uvgj3idp0xac
  • onetrust-domain-verification=4dd49ca25b164cb1903590361b59d733
  • docker-verification=2a8c8712-a145-4bdf-b11c-23cdab22d289
  • webexdomainverification.D1OL=20b3617e-9112-4285-8931-5d4ff235171b
  • v=msv1 t=990BE763-7C01-4ABB-B26D-AEA045C25743
  • v=spf1 include:spf.protection.outlook.com include:spfa.dow.com include:spfb.dow.com ip4:147.253.221.31 ip4:216.99.64.160/27 ip4:163.198.213.32/27 ip4:140.170.124.0/27 ip4:167.89.39.210 ip4:149.72.27.45 ip4:167.89.28.100 -all
  • 5obCLnAsPoArfu1S+Xwt+9KFeMwKnuCdY6OdA4XHqGroEUw2jDP/0z2q1uGCjBFK9ChUT8CkQDvRUHARZW7TPA==
  • cisco-ci-domain-verification=531353075bb5007ee9face6abdb86c0ffd9f39923162cd82c9fd067a56272075
  • webexdomainverification.D1OL=43b6e555-7f54-4785-b60d-911aeeca5dd6
  • A02D9F3BE2AEC0B3155DB6E4C03989006D5004F44FFA9A4189FB51201AD431D5
  • adobe-sign-verification=564b52856ed56271649fd8a59dc4038d
  • webexdomainverification.D1OL=06ad28a1-dda5-4207-a702-be98a304984e
  • MS=ms73053087
  • webexdomainverification.D1OL=63c7a6df-15c9-45b8-9819-899dd6d5484b
  • _i6snrm6ma731ecp5j2ijkbgly1ufv8t
  • webexdomainverification.D1OL=a5053e8f-a4d9-42b2-943c-2e664ee8f5a7
  • _pki-validation.sip.dow.com
  • adobe-idp-site-verification=c122193c-fcf3-4df2-b019-2be4c2715ed5
  • webexdomainverification.=f1a92f47-e142-4fab-9b48-6be3d63c8fdc
  • FC5D-5646-0815-90DA-C233-BF75-9EBA-D45E
  • webexdomainverification.D1OL=19d8c8d8-8deb-4061-8b10-5b85e6681039
  • webexdomainverification.ES10=4da89572-e3af-4ae0-8ade-211fad38e4ef
  • atlassian-domain-verification=dq2H38ytfsfMrpd2LQUI17ruHXL5twRjofsXEBvtnHjr9NY0lRcyAY7JWLtnVhk+
  • google-site-verification=tfCgE11Y72XiyMmKZR4V5Q_lcljDwdkcSuURtRjOtmk
  • apple-domain-verification=j9RPqwZ4mmFMAkxg
  • dell-technologies-domain-verification=dow.com_04fd3b98-0470-480b-ae2c-edbbfb6cc397_1681650747
Cloud / SaaS Services Detected
Adobe Apple Atlassian Microsoft 365 Cisco OneTrust Cisco Webex

Leak Screenshot:

Leak Screenshot