Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

OAK PARK & RIVER FOREST HIGH SCHOOL

oprfhs.org

Discovered 2025-06-21 12:18 UTC
Est. attack date 2025-05-16
Country US

Description:

Welcome to Oak Park and River Forest High School! Oak Park and River Forest High School provides a dynamic, supportive learning environment that cultivates knowledge, skills, and character and strives for equity and excellence for all students.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 4

Third Party Employee Credentials: 21


External Attack Surface: 6


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • mx1.oprfhs.iphmx.com. Cisco/IronPort
  • mx2.oprfhs.iphmx.com. Cisco/IronPort
TXT Records
  • google-site-verification=JV8gx67QHYElaR7yAQI63NyBjx9qDS413zsfSenQDt4
  • google-site-verification=LLK8kRExWQuASn4KF78U0LY1YhkFMv7R5EKLSZ40QnI
  • google-site-verification=MiZ8dfuozgWGoXElFSC8LieWa6bJ5c3YNme4I0OkmCU
  • openai-domain-verification=dv-2cBeyXz6JtezOAB2KdSD1zyV
  • v=spf1 include:spf.protection.outlook.com include:guardianconduct.com ip4:209.41.186.152/32 ip4:69.211.135.95 ip4:76.12.61.252 ip4:199.36.164.0/22 ip4:68.232.143.13 ip4:66.195.14" "3.26 ip4:68.78.54.25 ip4:50.19.229.242 ip4:67.90.101.66 ip4:68.232.140.249 ip4:208.185.66.67 ip4:12.228.6.215 ip4:205.237.106.3 ip4:143.55.227.190 ip4:159.135.236.59 ip4:198.244.49.16/28 -all
  • ZOOM_verify_q1C_XYZzTCSaNhU-IeRnAA
  • _globalsign-domain-verification=ig9EbABDJ-YO9Eox8eHDqZgrDf3tr0PXVW_tU0S3qR
  • adobe-idp-site-verification=30aa97fa87b93690df02431b9ed3991bd4e90d41adfda86e2afd2962002f7af5
  • apple-domain-verification=Ta9HkKtq3XCwnwWD
  • duo_sso_verification=TAmf8bYOWDFPoQyGx7SR4M9SMifo3Ti1D75g0oV5IVTpiaDUhLxymvRRG4PhVoaY
  • google-site-verification=4r3-vZqUyzLzPdlRhpNUPkwcvyuJ62rKhvwaShyUt70
Cloud / SaaS Services Detected
Adobe Apple Global Sign OpenIA Cisco Duo Zoom

Leak Screenshot:

Leak Screenshot