Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Durvet

Group: Qilin

Discovered by ransomware.live: 2025-11-05

Estimated attack date: 2025-11-05

Country: US

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 58

Third Party Employee Credentials: 0


External Attack Surface: 4


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • us-smtp-inbound-1.mimecast.com.
  • us-smtp-inbound-2.mimecast.com.
TXT Records
  • jamf-site-verification=3BpDqa4GjoBkazNk81y4fw
  • v=spf1 include:us._netblocks.mimecast.com ip4:12.171.61.3 ip4:50.87.172.208 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.0.0/16 include:spf-us.emailsignatures365.com include:sendgrid.net ip4:192.254.115.42 ~all
  • 0ed1fe018ae767dcf90dad463a9e0f9d08865382a0
  • A0x5PCmTgaDx1tLSJ69/42vqwVndxKDc25L7UU0eL/CcPEWaeD5JLVVYtbM4AtoniR1P9iJQQu/xdAGOg089rQ==
  • MS=F3663D582F2754B4E02CD1B9140CF91AF6861F2F
  • apple-domain-verification=B0XhKxrbgn8JW2WI
  • facebook-domain-verification=jwgnw496bwwsktjodxyn5ydr7iaeht
  • google-site-verification=8JowFKmVTXD9FFwsxeuCcy-2zmXCQULuS4MDTwFyxf4
  • infor-cloudsuite-domain-verification=5FX88Q23V6QPMU299N7NEGAN8MRSZEZ89YDZSDSUBNNB4ZUXRHXTDUPUXK2N8FTE
Cloud / SaaS Services Detected
Apple JamF SendGrid Mimecast

Leak Screenshot:

Leak Screenshot