Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ENTRUST.COM

Group: Clop

Discovered by ransomware.live: 2025-11-13

Estimated attack date: 2025-11-13

Country: US

Description:

[AI generated] Entrust.com is a global company that specializes in digital security services. They offer digital certificates, public key infrastructure (PKI), and other digital identification solutions and access-control technologies for organizations. They serve private and public institutions, including large corporations and government entities, to help them secure their data, digital transactions, and communications.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 63

Third Party Employee Credentials: 8


External Attack Surface: 18


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • trustandsafety support.aws.com
  • 832e83c1-68c4-425d-8388-6cbe5400a2c2 identity-protect.org
MX Records
  • mxa-0015a003.gslb.pphosted.com.
  • mxb-0015a003.gslb.pphosted.com.
TXT Records
  • figma-domain-verification=13e70f2c99b6e7f7c629d67a7ec2ad8e5ff5baed298584a6f087c8406edaf09b-1753895825
  • google-gws-recovery-domain-verification=48640566
  • pardot885253=c8e3632912ec5d8770e57b353ea0e06bbcf2e64efa31adedb6ac2e529597803a
  • atlassian-domain-verification=KpnQnsYsfD4LsvTQy8NuHL7n6r7omf4Lm0/mzNnXHdkZ/OESXSrL/mt9xTPaLdXy
  • docker-verification=dc10d748-3c6a-4981-845c-f188609f0ad5
  • cisco-ci-domain-verification=52bd614545cb9a6c77860c305968cccad9b520a85582599d7664e3d1ab57e2ab
  • sending_domain885253=0185dcc4bc1a864653c638d4b103b9eae1962b6a8a246ee50a49e51cb703d140
  • jamf-site-verification=IN3H-X3rVabxoPlOwv5gkw
  • jetbrains-domain-verification=36u24tfp415b6uzpyldzgdwmk
  • intersight=78a17abf44ac41ac501e4ddf705460253e4bbad17d37c6c49137a9a6800ef63f
  • asv=513e9823ec574ad1d1f85601aa156373
  • adobe-idp-site-verification=773d08ef53ff6f1ee3f8b95b1ad40dd3dcb3b34fa6b17c335e44687161594e99
  • wpe-verification=Onfido
  • google-site-verification=-ARAj8VJVvwjePn1qQGUdec6cZsD-z4n6GltDs77Lcs
  • 2FRJbh9zunH07baVZyUBTr8hZXP
  • onetrust-domain-verification=8ee709af0feb4debad197ee6251c7640
  • v=spf1 include:_u.entrust.com._spf.smart.ondmarc.com include:docebosaas.com -all
  • vPeVWa8K=7b8f62a2a0b5e3be6715bf7cfb3955d9
  • slack-domain-verification=uRUKerbLEHPaMqfdaBvNwUobGqTpwcXfKHTu3hdf
  • 1password-site-verification=XRL3ZEH3MFCMBJ6TDGAF2LTC2I
  • brevo-code:8eef0d0c60aa38e477beb580df7d450d
  • Gregg3478Egress
  • pardot885253=5649cd6e71415724d39747c95640a90a90c05a6bc5ffe1f70b6a2ed3ed657d77
  • docusign=1c7467dc-de73-4a75-ab69-ed68eafebc1b
  • atlassian-domain-verification=gLpNm3HfYi69xvO2lASv+O7hH+r32i9CA9kc0fdGe7F7oTRvPgDeh93g4NwtPs1W
  • adobe-idp-site-verification=4bdf521e83a7d31cd468020db7a08371452bfddb0934bb2c748eebe2fdfd02fb
  • 3a6a2aae-7256-4cec-b721-03d5e942521d
  • bill-one-domain-verification=8cfa0019-cb67-4ce2-90a8-f6bf828efe27
Cloud / SaaS Services Detected
Adobe Atlassian Salesforce Slack JamF Cisco OneTrust DocuSign

Leak Screenshot:

Leak Screenshot