Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

EMSBILLING.COM

EMSBILLING.COM

Group Clop
Discovered 2023-07-26 20:43 UTC
Est. attack date 2023-07-26

Description:

Just a moment...

Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 39

Third Party Employee Credentials: 1


External Attack Surface: 29


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • trustandsafetysupport.aws.com
  • b84d57fbcf2ff7928cfcbda7358da997538178b6cbce792eb6ceacb1e7d20c7cemsbilling.com.whoisproxy.org
  • b84d57fbcf2ff7928cfcbda7358da9973d6b7df4446a466ffea725b08d7eee8demsbilling.com.whoisproxy.org
  • b84d57fbcf2ff7928cfcbda7358da9979d4bc47b76149a8575f48efd0a0b3919emsbilling.com.whoisproxy.org
  • b84d57fbcf2ff7928cfcbda7358da997bd51bf32520496408f67fb448f8e0330emsbilling.com.whoisproxy.org
MX Records
  • us-smtp-inbound-2.mimecast.com. Mimecast
  • us-smtp-inbound-1.mimecast.com. Mimecast
TXT Records
  • atlassian-domain-verification=RMNjzMw7RkhtixTqcIBanyfcJZcnWd5E/lFGRm3pIt5hz6PLfqwyElm3wI9CsiB3
  • atlassian-domain-verification=YyGmAk9A2LAA7phBHyqyB49OVDagH+jh6SxH5Rk0scPG86bcjJzer2jM28+UwWXF
  • google-site-verification=HqPEzyH-T-VLiey_qbNaz7q9sikjn-M9aXnbrbRtAoE
  • google-site-verification=TTZVYdM5anJEuIhYu-b4J3zJ4AKVlumAa0_L21fsf1I
  • intacct-esk=F6F6B1D04224A563E0533606690A124C
  • smartsheet-site-validation=AqTqy4hFpvM_c853w4KVNIIRarD0H377
  • v=spf1 include:spf.protection.outlook.com include:us._netblocks.mimecast.com include:_spf.atlassian.net include:spf.myconnectwise.net include:spf.constantcontact.com include:_spf.salesforce.com include:_spf.intacct.com -all
  • v=verifydomain MS=6706628
  • ZOOM_verify_ITJw6KjlTQGyk7YwaDtCWw
  • _0u8gn5czjfxxp2d2vo9qb6hprpyg8o7
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Salesforce Sage Mimecast Zoom

Leak Screenshot:

Leak Screenshot