Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Play
Discovered 2024-02-15 19:47 UTC
Est. attack date 2024-01-30
Country US

Description:

United States

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 15

Third Party Employee Credentials: 1


External Attack Surface: 3


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • b51edebb864dc962c051d57978b826888302c5029a8e61369bd25c18f5c246cfonclusive.com.whoisproxy.org
  • b51edebb864dc962c051d57978b82688bb156d7c652c41342423281270508f54onclusive.com.whoisproxy.org
  • trustandsafetysupport.aws.com
  • b51edebb864dc962c051d57978b82688e99f02effe4606cc4eac1dc7a8143c5fonclusive.com.whoisproxy.org
  • b51edebb864dc962c051d57978b826880c17d20cc2b16d71492b613e596649d4onclusive.com.whoisproxy.org
MX Records
  • alt4.aspmx.l.google.com. Google Workspace
  • alt1.aspmx.l.google.com. Google Workspace
  • alt2.aspmx.l.google.com. Google Workspace
  • aspmx.l.google.com. Google Workspace
  • alt3.aspmx.l.google.com. Google Workspace
TXT Records
  • google-site-verification=ZRmj1yAuLgvAtWFrpZsfmg-upgDWzCz5qIQ1PBw_bPg
  • hcp-domain-verification=b626f52a1ce0b8b0586b857f05c6caf89b88e2bfafd072f832631e0f5037b701
  • mongodb-site-verification=7n9F4qFBCmbMNbilw7iYAfwh5pbQT06a
  • new-relic-domain-verification=0fca30a974ed4ff9bd61d3a5d6fc1fdf
  • pardot187632=8e0c0553a35beea93f1848980eef441b2186a6b69dd20aa8394b1685c9cacbc5
  • slack-domain-verification=OTm3GQPYrT3QIH0u9WNlmsNLRScxfOu2W1wPWy0S
  • v=spf1 include:_spf.onclusive_com._d.easydmarc.pro include:spf.protection.outlook.com include:_spf.salesforce.com include:sendgrid.net ip4:54.75.1.75 ip4:54.228.11.161 ~all
  • MS=ms74961014
  • Probely=ddcf0d6c-91c9-403f-9a23-1e45d27a7f80
  • apple-domain-verification=ZJ4gZJeSly9O8hSg
  • atlassian-domain-verification=U5IeydfNJQGIVNumVBVrK2W2/bdg9t4UOpu6T8s/Ld1Lr0DdMRMnQotkRymKzY00
  • facebook-domain-verification=tziv2dv9c6rm80r71j7f64xfx24cqt
  • google-site-verification=R7hhvGlgd0VFTqHS24iq0aQmGMRj6WEDyY1l-77zdak
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Salesforce Slack SendGrid

Leak Screenshot:

Leak Screenshot