Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Henry County Schools

Group: Blacksuit

Discovered by ransomware.live: 2023-12-05

Estimated attack date: 2023-12-05

Country: US

Description:

Henry County Schools operates high schools, middle schools, and elementary schools throughout the state of Georgia.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 96

Compromised Users: 284

Third Party Employee Credentials: 283


External Attack Surface: 47



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mx1.hc2252-94.iphmx.com.
TXT Records
  • smartsheet-site-validation=qzdf0lHBrvQBIWlJkZzXHWYUWKimwnSj
  • ZOOM_verify_01Swo_C3S1iiKoibThR49A
  • google-site-verification=cP6RMqUTT00xaLl-O7tC4X5u1eS5V9Hre2vauYaIX-Q
  • cisco-ci-domain-verification=6af7234dda79278bf01d2e5d21b615a3b05f5a9aeb3c8b991577051f78ff04c2
  • apple-domain-verification=pU67cvrXSC0wGYe5
  • n803d4pwkqx09qc6hb5c0mk23jgbgc9y
  • v=spf1 a:mx1.hc2252-94.iphmx.com include:spf.protection.outlook.com include:_spf.google.com include:mg.infinitecampus.org ip4:168.9.26.0/24 ip4:50.223.178.203 ip4:50.223.178.208 ip4:147.154.59.192/30 -all
  • jamf-site-verification=NEk9qwhfvRpOPDS_0JNhxw
Cloud / SaaS Services Detected
Apple JamF Cisco Zoom

Leak Screenshot:

Leak Screenshot