Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2025-11-19 17:05 UTC
Est. attack date 2025-11-19
Country US

Infostealer activity detected by HudsonRock

Compromised Employees: 111

Compromised Users: 49

Third Party Employee Credentials: 87


External Attack Surface: 85


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • us-smtp-inbound-2.mimecast.com. Mimecast
  • us-smtp-inbound-1.mimecast.com. Mimecast
TXT Records
  • openai-domain-verification=dv-xIG7e0d8eqslAdd60T2QNHoH
  • docker-verification=e1f5a5d7-950d-418b-9396-85fddc7e9630
  • lucidlink-verification=5D9APFJXJ85S55EN0N4084P8VW
  • apple-domain-verification=nJOowuy7v9L9HjQH
  • _3h9cn4sbik87bstp4bi87bi5t06zu0p
  • _g1je4a53i475us354xxr3zm52lw4olb
  • _9wklqpryfv7idjq0eqy32wbitz2gvwh
  • _nf36a8kzjw3kw5lyvpzftp9j6tazraq
  • figma-domain-verification=04b322a08a86424c9e80519c34cc18074e81d431255af61737a64f1f95dd5542-1773859321
  • mailerlite-domain-verification=6ec68f970ea9fefff86de57ff08050336062220c
  • bw=e53rhIaKmeaRSO17aKLC2Ro4vaKX9ZIbdk0ujGFZqx2I
  • infoblox-domain-mastery=b06ecbc191e9cae49ef39ebee7b27ce316f6d43499ee577b9bf8b80d343f4e1bb0
  • wrike-verification=NjU4OTc3ODpkMzg5YjM3OTBhZjE3NWIzYWY3Nzc5YmI3ZmUwM2NkMTNhNWY3YzA4NjI0YmIwMTE2MjZjZGRlNTM0YWUxZGYz
  • anthropic-domain-verification-resspr=rQkgR7trwYw2PLU8r3mA5BfuV
  • onetrust-domain-verification=2dcf9d6feffb4f9c9d172dc52837e6ee
  • anthropic-domain-verification-rm87nn=KIX2CWGBXq9WGgtyNE85HtEhq
  • 1password-site-verification=KAZKO3J37NAEZNHHZHQGAQHAPY
  • atlassian-sending-domain-verification=773e5d04-aaa1-42b4-9910-53c5fa798d03
  • T24NE4LHANAQ7CCI3NFXO2EKQY
  • atlassian-domain-verification=nulzMHzfncvWhjjXMYwi8ykx5mOKxRyd5QxfMPsPudbhGDLayg21udaXqAvZzI6X
  • smartsheet-site-validation=cRrxYoO2fFwIAAsMy-yfTSv3dxas_Lyr
  • Dynatrace-site-verification=fc5b0f38-c372-43e5-909a-dec63d4a41b3__h925b8j9h5ris4vl08pv0o33rf
  • 23d6a6988f7e33087273b5b746afe42b
  • v=spf1 redirect=44o6209j._spf._d.mim.ec
  • teamviewer-sso-verification=8b15664f186d4bb2814a31f35cc84298
  • google-site-verification=DkQCMjLtebnhZ4ldyNfoUyNHQDS_0XLh6a3ddykD4X0
  • postman-domain-verification=fbe93b8f51f3e7291ba0224f7e79e15213c02489cd1167aa55ca522902c91482d0b26e7a39e6b3b7dfb072a5f60c53fed6201ce1265649e4dfe66576bce98730
  • airtable-verification=23d6a6988f7e33087273b5b746afe42b
  • _rdpt9dml0mo95ws13t770dkg8zs8gws
  • knowbe4-site-verification=76ddf81273b80787dd744c87491a10b4
  • 76ddf81273b80787dd744c87491a10b4
  • autodesk-domain-verification=zEMvXSQuHouoiPJYOrfV
  • miro-verification=394b91fc8edc965907678a7e7e85b7f7b5b77fbb
  • _kytuaxem6ftv5rdt26qofyq8jo1qia6
Cloud / SaaS Services Detected
Apple Atlassian Docker Anthropic OpenIA Miro LucidLink Teamviewer Autodesk KnowBe4 OneTrust Mimecast

Leak Screenshot:

Leak Screenshot