Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Khidmah

Group: everest

Discovered by ransomware.live: 2025-05-08

Estimated attack date: 2025-05-08

Country: AE

Description:

[AI generated] Khidmah LLC is a comprehensive real estate services company based in Abu Dhabi, United Arab Emirates. Founded in 2009, the company provides a wide range of solutions including property management, leasing and sales, facilities management, home maintenance, cleaning, landscaping, and pool maintenance. With its customer-focused approach, Khidmah caters to residential, retail and commercial properties.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 17

Third Party Employee Credentials: 16


External Attack Surface: 12


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • cluster5.eu.messagelabs.com.
  • cluster5a.eu.messagelabs.com.
TXT Records
  • dOWut/QZQJn/v+ilIIGb7T2Lqr531Eh31FFvOkwPRg2xtJb41rQAVOYyj83ej7BBM3OTtt+irxATR58awjb5sA==
  • n74ntiobs5r6r79j2urte59fdk
  • ycQwsjwmXrYjAIBZui+oc8kcMs2DsbKvGGsGK23VOc39jdOhW5Uu2NJoiAhhBe9dHlYH6kniGuaIzyEoxxxWOw==
  • v=spf1 ip4:147.204.152.42 include:spf.messagelabs.com include:spf.protection.outlook.com include:spf-uae.emailsignatures365.com include:spf.my349235.mail.crm.ondemand.com include:spf.my355856.mail.crm.ondemand.com include:usermail.zohocreator.com -all
  • 1cfl4ux.creator.cs.zohohost.com
  • stripe-verification=203fd0f5ebcfd06d10fbc190304ec2b26d011a5df4c7fa2eb21a3bbdf93b401f
  • docusign=575149ac-3ea4-45af-8646-cbaa4ab69f64
  • Sendinblue-code:6d6c806f19b356c17d0349483f0a6953
  • v=verifydomain MS=3562305
  • MS=ms97780255
  • v=verifydomain MS=5671559
Cloud / SaaS Services Detected
Microsoft 365 Stripe DocuSign

Leak Screenshot:

Leak Screenshot