Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

EMSBILLING.COM

EMSBILLING.COM

Group Clop
Discovered 2023-07-26 20:43 UTC
Est. attack date 2023-07-26

Description:

Just a moment...

Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 39

Third Party Employee Credentials: 1


External Attack Surface: 29


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 3f1884989191fad1f4d7fe693cfa06042ba0df3fb7273efb25ac86d81fc0e6d3emsbilling.com.whoisproxy.org
  • 3f1884989191fad1f4d7fe693cfa0604ceb26e9c3c565cf5a31a55c2c653cebeemsbilling.com.whoisproxy.org
  • trustandsafetysupport.aws.com
  • 3f1884989191fad1f4d7fe693cfa060401346e43f2a46fcdf66cbf53eb47d04femsbilling.com.whoisproxy.org
  • 3f1884989191fad1f4d7fe693cfa0604274a25fb8e7635cfec92528aa960e3c8emsbilling.com.whoisproxy.org
MX Records
  • us-smtp-inbound-2.mimecast.com. Mimecast
  • us-smtp-inbound-1.mimecast.com. Mimecast
TXT Records
  • _0u8gn5czjfxxp2d2vo9qb6hprpyg8o7
  • atlassian-domain-verification=RMNjzMw7RkhtixTqcIBanyfcJZcnWd5E/lFGRm3pIt5hz6PLfqwyElm3wI9CsiB3
  • atlassian-domain-verification=YyGmAk9A2LAA7phBHyqyB49OVDagH+jh6SxH5Rk0scPG86bcjJzer2jM28+UwWXF
  • google-site-verification=HqPEzyH-T-VLiey_qbNaz7q9sikjn-M9aXnbrbRtAoE
  • google-site-verification=TTZVYdM5anJEuIhYu-b4J3zJ4AKVlumAa0_L21fsf1I
  • intacct-esk=F6F6B1D04224A563E0533606690A124C
  • smartsheet-site-validation=AqTqy4hFpvM_c853w4KVNIIRarD0H377
  • v=spf1 include:spf.protection.outlook.com include:us._netblocks.mimecast.com include:_spf.atlassian.net include:spf.myconnectwise.net include:spf.constantcontact.com include:_spf.salesforce.com include:_spf.intacct.com -all
  • v=verifydomain MS=6706628
  • ZOOM_verify_ITJw6KjlTQGyk7YwaDtCWw
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Mimecast Sage Salesforce Smartsheet Zoom

Leak Screenshot:

Leak Screenshot