Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Kewaunee Scientific

Group: Coinbasecartel

Discovered by ransomware.live: 2025-11-20

Estimated attack date: 2025-11-20

Country: US

Description:

Kewaunee Scientific Corporation designs, manufactures, and installs laboratory, healthcare, and technical furniture products. The company operates ...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 13

Compromised Users: 2

Third Party Employee Credentials: 1


External Attack Surface: 4


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • kewaunee-com.mail.protection.outlook.com.
TXT Records
  • v=spf1 ip4:206.152.14.54 ip4:203.31.36.92 ip4:173.236.227.99 include:spf.myconnectwise.net include:spf.protection.outlook.com include:_spf.ultipro.com include:spf.US.exclaimer.net include:spf.zohomail.com include:zohodesk.com ~all
  • zoho-verification=zb60254536.zmverify.zoho.com
  • 1password-site-verification=DNGLYJ5GSRBV5GKS2FPTBYSLDE
  • Fat9QKuuR6/Xgi4dcY2PGNFDaLklO0EQOs8p7U7SjL0SIekR3ipBLjUHJRShV4XVoBeS4Kzfyr5QHwS4n1UuZg==
  • MS=ms83517502
  • apple-domain-verification=W3GTkT6lXX0oWgPI
  • atlassian-domain-verification=RQepEJZ42a5iRsHhR8bgSIHjkkUhSC/z14qovhlgHRdCXl9qPhDwZuka1u08h3mC
  • atlassian-sending-domain-verification=b54379fe-5da9-4658-8b5d-3d6c28a99601
  • h7MnX1ox1FCkQ4o5lJEYrisRmxyUuiq98L0JJdDjNis9JcZP4BcceMKM95Ddl7AON/uX1cMYo0C+gaSo2BBZ7w==
  • logmein-verification-code=28813091-78d1-44a7-8930-27b1c23237f5
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 LogMeIn Zoho Campaigns

Leak Screenshot:

Leak Screenshot