Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo FCC

Group: hunters

Discovered by ransomware.live: 2025-04-30

Estimated attack date: 2025-04-30

Country: ES

Description:

Exfiltraded data : no - Encrypted data : yes


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 86

Third Party Employee Credentials: 3


External Attack Surface: 14


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • aspmx3.googlemail.com.
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • aspmx.l.google.com.
  • aspmx2.googlemail.com.
TXT Records
  • zoho-verification=zb66990560.zmverify.zoho.com
  • amazon-business-verification=83813cc4ddc63da5b47f55e620a7a757b64fc71e6488509a590f042ccd28d499
  • apple-domain-verification=AUGdbCz3lBRRHSnH
  • atlassian-domain-verification=dTLAJibj8K94F8TOP+c99l3bIY6YVRjJyTDHaSDii9UkFam/WlWz/gDROhUn2gzH
  • duo_sso_verification=C4m4P4ZQUqkeA0gkIN6NmilzZ1biX7JCIXgHl3LR56Q6aHGKUWsgmv7aN5yRtxbw
  • google-site-verification=pJydF60Q977O3uLJOV-KJHud3Q7wOO0FAg2K32HMj6s
  • google-site-verification=tA8TAk5dj3CaFngDHzv45n6VkI85UvTV-BTswv6kvqU
  • nordpass-domain-verification=69078fdf79b543b384d679c1c9a5be61
  • v=spf1 ip4:208.91.114.151 ip4:192.64.236.0/24 ip4:192.64.237.0/24 ip4:192.64.238.0/24 ip4:163.47.180.0/23 ip4:34.202.239.6 ip4:54.221.227.204 include:_netblocks.google.com include:_netblocks2.google.com include:spf.forumcomm.com ~all
  • yahoo-verification-key=2kBGylXI3c+1uDag69qHK3lX4ysSorrcneiRfAD8jiE=
Cloud / SaaS Services Detected
Apple Atlassian Zoho Campaigns Cisco Duo

Leak Screenshot:

Leak Screenshot