Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Eisai Co., Ltd

Group: Atomsilo

Discovered by ransomware.live: 2021-12-21

Estimated attack date: 2021-12-21

Country: JP

Description:

[AI generated] Eisai Co., Ltd. is a Japanese multinational pharmaceutical company headquartered in Tokyo. Established in 1941, it's one of the leading firms in the field of neurology and oncology. Eisai produces several drugs used globally such as Aricept for Alzheimer's disease and Halaven for breast cancer. Aside from drug creation, Eisai also engages in global health initiatives.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@key-systems.net
  • info@domain-contact.org
  • abusereport@key-systems.net
MX Records
  • mx2.hc5257-81.iphmx.com.
  • mx1.hc5257-81.iphmx.com.
TXT Records
  • MS=ms57623310
  • atlassian-domain-verification=DKN5aew8PGFuJoldLMoEOKlC/hykCtcMkOROO7I3a1hMbvDwhx8fnafaDyLWPwKR
  • bvnvqyxd8jbyh65ytmtsll897lblkwkd
  • google-site-verification=SyQ0NZqTwiRC9lp8koyBV2iqNcfH8UU1JRmX0EwGBsQ
  • openai-domain-verification=dv-TZrzaIL8QopZUkntbpA8iDx8
  • docusign=e6c322a3-7fe5-46a3-a5e1-11519bc5dbf1
  • 1f2kpgd0xyg7cn4k933mmq0h3jxkht9j@
  • smartsheet-site-validation=4kkMmttA3b_Jb4DFkiCQOz12NsBt5v4T
  • google-site-verification=g4myDWCgq5OqxjKcb79Imywqb55HSKh0l2atXOEyh8A
  • v=spf1 ip4:65.222.204.128/29 ip4:64.212.42.50/28 ip4:173.251.54.0/24 ip4:216.203.18.48/29 ip4:213.212.101.0/24 ip4:62.73.153.0/24 ip4:122.215.103.200/29 ip4:68.232.200.69 ip4:198.245.93.166 ip4:52.5.134.202 " "ip4:24.157.37.170 ip4:24.157.37.171 ip4:74.84.203.40 ip4:128.136.57.200 ip4:3.136.228.225/32 ip4:34.202.79.235/32 exists:%{i}.spf.hc5257-81.iphmx.com include:_spf-sfdc.successfactors.com include:ae.veevasystems.com " "include:spf.protection.outlook.com include:_spf.salesforce.com include:docebosaas.com ~all
  • docusign=02b9849f-43d9-4130-8af5-405a3de2a5c5
  • vWZBCnkHdRJW3DUmKg/cPDVZy8NzuyfB1eSOASaCS/IVNA8QHd53FENESFlsi/LAFwsPFohU1zuNDHUnMSubdA==
  • amazonses:z09kUlsrqq+FdgX49Y6qbz9A1nxhIfbruwMtgSwH9qs=
  • mindmanager-verification=062270213e5b151da9684f997d1fd734d368ad4eb56f6c67fc565f4ce164aabc
  • un3ouuoqpce06tf0fd6phfi9dg
  • pexip-ms-tenant-domain-verification=711a1ef9-5059-44bd-9fac-4eebcaf08c56
  • apple-domain-verification=n5RdIYmo6ySGKlFV
  • 6rvjrpfmjvbnt1hbcf3l48sgaf
  • _cbc-idp-site-verification-7d24c6=9d3c11b6d130de019b7c3ab84ddee91d4817a84cfa6098268a1bacac6f54e6ae
  • MS=ms31898891
  • _o8empkgnnvaf0fld3497gkbits017fj
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail Microsoft 365 Salesforce DocuSign

Leak Screenshot:

Leak Screenshot