Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ILLUMINA

Group: Coinbasecartel

Discovered by ransomware.live: 2025-12-16

Estimated attack date: 2025-12-16

Country: US

Description:

Illumina, Inc. offers sequencing- and array-based solutions for genetic and genomic analysis in the United States, Singapore, the United Kingdom, a...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 12

Compromised Users: 845

Third Party Employee Credentials: 25


External Attack Surface: 82


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints markmonitor.com
MX Records
  • mxa-001ff201.gslb.pphosted.com.
  • mxb-001ff201.gslb.pphosted.com.
TXT Records
  • pardot1083721=2e34c3bedf94df971a1293f07f2a6fd1553fb7f7dbccd3f4596c88d1ef17f4a2
  • status-page-domain-verification=qzn9sfx13n69
  • pardot551052=c1e9e0b9329103913434c8cc2e4e10989d2c94ffbf9d90ff55fe40312def7218
  • google-site-verification=q31G9nSLfsZz_3sXsLn4nnYFeltJFu5NOKlR4TfNpbI
  • miro-verification=0ddb652d88dcdccce585c3065190ef0d817e42a9
  • amazonses:RxKVI/CLcLydIzh8q/RfiDqCQ/tgb9TNtruSaThSeLw=
  • pardot960392=55f780f495d8ad1df9a2c0f1074d671f07dc4753e5a1e18f1146e1aec0ee8da1
  • 00e1d8944a684c2d840192f19baf7ebe
  • atlassian-domain-verification=GZAsbnhE94Acz17hjoAr6nbAR5hPBy+YKntnlt2J8ph3Io58oDE9NoZYM2wKcNLT
  • smartsheet-site-validation=fvfZdrj3DZ_vhfoL6Cpv80zaUpweu_K0
  • identrust_validate=IZwKmsM8ddKV1AM15lV2ezfY2p7ZPAa6fQ81Hi/LdWUl
  • amazonses:m0ByXenOMmrmI/V92cEfe5V1u9lCKFRcj0o/cPjNS48=
  • QuoVadis=591b76e7-ac74-44fe-8796-23001d3e23a3
  • pardot946173=cd80f81cd58c62aea2e531f805d87d717e53a76f6360c05d494ffaa7a9337626
  • google-site-verification=-nk4B1jypRJFEaqEFFqhIkxKDc2nFLeXPDCoEq2t9ns
  • ZOOM_verify_mV-PVTm1RRK6WtugeVNjAw
  • MS=ms68089493
  • postman-domain-verification=4f547f808763d40b6a755c357e923c8164a86ab8bd66e5c5235193c9a70942416768eae75c2b9fe89ca71b8bf1ac4129274326fdb72a160eb38cf4c112dcac69
  • amazonses:llBAzbAzA/LAbxWGM2q3yBEg72qLseaWaJ5TlDgIS8I=
  • amazonses:ApWxoJDZf/NoFXnDtVMYbgBuhy8TeB0ID+oubFHlmo4=
  • identrust_validate=JTI6ofFrGw11w7vQJDoTYPNGrfxbP8bdb+HeDNvDkYrc
  • docusign=93ba5ab0-6421-416e-a09b-cefa1d40ac1d
  • google-site-verification=WHrIdtYANLrL1BTzKVTmC0Q5otr7yufYACZM-0ZsjBU
  • google-site-verification=9X7fJvLFSZ9Eckt1A6YYbvXmTJj_Kl8mJbnP7u24Dzs
  • amazonses:K/uAfqacevzYbCn/ZZfBg+johN+QIdW4ii4o+wZfYOs=
  • amazonses:EIlOjDU+u4eTLZhOTT5wH+gGW+m9eBnaTVWYmwiu98Y=
  • Lo89uoUDbeYq9LnuCZv6l9GMa2uNb537A2bUxpYMexWmaW+N3ov/LjtsgLQTJJ5wTUe6FjEjKEYh6H3zX9eZqw==
  • identrust_validate=Kkb4/3eXTmBhDK00ujUtKZUOoY7tWPncfKtXoZFclKL7
  • adobe-sign-verification=89373a1a320e2d86a6b2ae24e83a82b3
  • cisco-ci-domain-verification=893a37b34b31844db17918761e08d5ff332761cdfa520b2dfc06849af05b631
  • n1SD9rMCGlWVSM51ELzrdwvvyAXuGMmCpKPTxVGtAMnqJT8jyMdWlHS7unggstCFj9QQr+w5i4BrsF63lESlDA==
  • adobe-idp-site-verification=9ec79f45-efbd-4bdd-af3c-a1e5bff67e61
  • amazonses:QRkgGsGxCs6LL9IiLnxY7Xk659rQUDGBlPisOW3VIbs=
  • teamviewer-sso-verification=e1fd06ea0cac4edf89e9d02be7d893f1
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com include:aspmx.pardot.com -all
  • apple-domain-verification=JVplSEq83vVfyGBW
  • identrust_validate=rW19VtiwhCZ40FweXntJJdf1DH7+VZepl0C5ZpI0Is7M
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Microsoft 365 Salesforce Miro Teamviewer Cisco DocuSign Proofpoint Zoom

Leak Screenshot:

Leak Screenshot