Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Deibel Laboratories

deibellabs.com

Group Anubis
Discovered 2025-12-19
Est. attack date 2025-12-19
Country US
City Lincolnwood

Description:

Data breach at a U.S. food safety and quality testing laboratory.

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 3


External Attack Surface: 1


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@rebel.com
MX Records
  • mx2-us1.ppe-hosted.com.
  • mx1-us1.ppe-hosted.com.
TXT Records
  • o5v879ep5viabk4p5ns40vehjh
  • pardot1089132=0056d248fe81544b3c7d009f7e5de679d689f14a16c501ac82e9cdfc4c5547fe
  • pardot1089132=40f209e85d9fcbebe7209f5bb6ed80e184ede87ca32703e996a8b04932145452
  • sending_domain1089132=b920d0bd1c8bba188dd58c864e5e6174463b1fe4c11937eb5ba3b14e0cdaf860
  • v=spf1 ip4:137.26.237.162 ip4:216.110.146.230 ip4:107.180.41.249 ip4:172.173.105.54 ip4:172.202.72.130 ip4:20.29.9.133 ip4:20.84.145.196 ip4:40.67.176.204 ip4:40.83.22.133 ip4:74.249.254.75 ip4:96.77.241.138 ip4:52.165.81.61 ip4:172.169.162.227 ip4:20.83." "25.96 include:spf.protection.outlook.com include:_spf.intacct.com include:spf.US.exclaimer.net include:spf.myconnectwise.net include:us._netblocks.mimecast.com include:_spf.salesforce.com include:sendgrid.net include:_spf-us.ppe-hosted.com -all
  • 31uestpcd9ucd9kp5afbhbdifi
  • YDABPKWRRQPAYYM6BCFAGQ3FUC7RGT2X
Cloud / SaaS Services Detected
Salesforce SendGrid Mimecast Proofpoint Essentials

Leak Screenshot:

Leak Screenshot