Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

EAGLE.ORG

eagle.org

Group Clop
Discovered 2022-12-22 20:02 UTC
Est. attack date 2022-12-22

Description:

American Bureau of Shipping (ABS) Eagle.org

Infostealer activity detected by HudsonRock

Compromised Employees: 39

Compromised Users: 171

Third Party Employee Credentials: 20


External Attack Surface: 86


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • mx0a-00495e01.pphosted.com. Proofpoint
  • mx0b-00495e01.pphosted.com. Proofpoint
TXT Records
  • autodesk-domain-verification=tIsFRLnMGb6xL6GEmU3A
  • msfpkey=7b4hiu9eskunkrbe0a9ias6tp
  • teamviewer-sso-verification=105328983d184ec4ab15a4e74d2d7303
  • apple-domain-verification=3hCvOHJtdXcxR0FM
  • parsec-domain-verification=td_2fsaWAygmIcvbJg2KrPj1BUYhz3
  • nqLYg/1yZm8fbCmWWaEQdPKFlfQB6tDYyLGr7707+zOqmAlZi4mo6FfLOwlkVAxdBwX/OYTbBKmN46RaYnqnQg==
  • dtm-domain-verification=uJg7fk5c5_WoKpyh6fl3KMbdSbLZXve6isW-dI9cD3A
  • foxit-domain-verification=822adb0d65034a8b45a3b90332bbed1a
  • 5nh4knelfnvm16r9jj82trer83
  • 4qr8x7421nvd1jcnxp1rz8rjm6lqnqm2
  • wrike-verification=NjY1Mjc2MDphYTFmNWUwNDkzNTRmZThmMmE1ZGE4ZDc3NDIzNmM2NDk4YzgxZDBhZGY4MDQ5M2ZlMjU2YTQ2Y2E0Y2I4Yzg1
  • atlassian-domain-verification=pgEDtGh5Pg/kuZa0xtN1gEPg5Ta78NeyMaxZ1hyVsAxqJ6iuZoCmh51qXf7MAWLa
  • mongodb-site-verification=9YmyGhZ1ui28JH1K5tP9QGvofzU8erIv
  • adobe-idp-site-verification=5a29a383222fe377b6c471c4f9a8d3e288a2de0a32aa69808c011cd01b1f14c7
  • atlassian-domain-verification=uXvIm1od/ANcTTvQR0JX5a3BlA1MS6rbipSpYd2/ow9ZCoAqDnZc3WsMpu62GXUK
  • atlassian-domain-verification=BnSF9FoL3XlJv8k8M999yVMUq8aETL5iAgJziXfvmk/Gez58iy/gMnfoRYE/iFt/
  • google-site-verification=z9N-z1RW01Zr__RzJYqSmmOXQ_pFO8j9uCDW2_m7jIY
  • 8db6hanavnkt0js9158uu8jd16
  • adobe-sign-verification=47f1a8c2e71293a07bd0177d2973a9cdb471ed52fedeba8fdcb77e81bee87c52
  • vqmb7m9xh5hrx8c5yq19bq2plcqvtwkn
  • MS=ms99798667
  • miro-verification=e5a5bdbb8477dc5b7403dc325df46f175087414a
  • v=spf1 ip4:205.220.169.114 ip4:205.220.181.114 ip4:204.225.178.170 ip4:204.225.178.171 ip4:35.80.141.6 ip4:44.229.121.55 ip4:148.59.100.16/28 ip4:40.71.34.249 include:_spf.act-on.net include:spf_c.oraclecloud.com include:spf-westus.emailsignatures365.com " "include:spf.protection.outlook.com -all
  • d365mktkey=kYdV9JzZvDD3wqPTNmxrTn4wT9p5WuEdPEs8zGxO1rQx
  • cursor-domain-verification-vb1ay8=oAz1OEntY5geRXSzXqFd9IY0d
  • hpe-greenlake-domain-verification=2d5136356e583441586b6d686a37374b6f73336e58314336747a6a6c337a7471
Cloud / SaaS Services Detected
Adobe Apple Atlassian Autodesk Microsoft 365 Miro MondoDB Oracle Cloud Proofpoint Teamviewer

Leak Screenshot:

Leak Screenshot