Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Eanes ISD schools

Group: Qilin

Discovered by ransomware.live: 2025-12-22

Estimated attack date: 2025-12-22

Country: US

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 5

Compromised Users: 18

Third Party Employee Credentials: 28


External Attack Surface: 13


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • alt3.aspmx.l.google.com.
  • alt4.aspmx.l.google.com.
  • aspmx.l.google.com.
TXT Records
  • H.uXaT4wgav7cjEg@GF3ApMT-Qz.@aPwh3d9.ysm
  • adobe-idp-site-verification=7d1262f15c1b9595411e17254df46d0ad95035ba0e0b433fa33085f19417dab7
  • jamf-site-verification=AUvFlPn6r8KPtzoOZi4fqA
  • ZOOM_verify_XpCTCP0YQ2WQSQCuowmHyw
  • asv=58d98fc19f344d8924ec9e9e099229e1
  • MS=ms98529833
  • virtru-site-verify=icIjQ5g6rnUWNmPks49ydlDqe2ROHxTFbG08ZKfB
  • apple-domain-verification=TVpkFf0Id36HKcPX
  • google-site-verification=0e0vYeTPQ-TOQwxxb0CsYhxl4fQyWN8hesdO0dgzlSI
  • v=spf1 ip4:74.125.137.27 Ip4:152.160.0.0/16 ip4:50.223.178.203 ip4:216.17.93.137 ip6:2607:f8b0:4023:c0d::1b ip4:173.194.204.27 ip6:2607:f8b0:400d:c07::1a ip4:172.253.113.27 ip6:2607:f8b0:4023:1::1b ip4:142.250.152.27 ip6:2607:f8b0:4001:c56::1b ip4:64.233." "171.27 ip6:2607:f8b0:4003:c15::1a ip4:74.125.148.0/22 ip4:162.216.126.0/23 ip4:66.195.143.26 ip4:8.12.72.20 ip4:66.193.126.69 ip4:35.190.247.0/24 ip4:64.233.160.0/19 ip4:66.102.0.0/20 ip4:66.249.80.0/20 ip4:72.14.192.0/18 ip4:74.125.0.0/16 ip4:108.177.8.0" "/21 ip4:173.194.0.0/16 ip4:209.85.128.0/17 ip4:216.58.192.0/19 ip4:216.239.32.0/19 ip6:2001:4860:4000::/36 ip6:2404:6800:4000::/36 ip6:2607:f8b0:4000::/36 ip6:2800:3f0:4000::/36 ip6:2a00:1450:4000::/36 ip6:2c0f:fb50:4000::/36 ip4:172.217.0.0/19 ip4:172.21" "7.32.0/20 ip4:172.217.128.0/19 ip4:172.217.160.0/20 ip4:172.217.192.0/19 ip4:172.253.56.0/21 ip4:172.253.112.0/20 ip4:108.177.96.0/19 ip4:35.191.0.0/16 ip4:130.211.0.0/22 ip4:208.75.120.0/22 exists:%{i}._spf.mta.salesforce.com include:customerspf.schoolme" "ssen" "ger.com include:mailgun.org ~all
Cloud / SaaS Services Detected
Adobe Apple Microsoft 365 JamF Mailgun Zoom

Leak Screenshot:

Leak Screenshot