Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Lake Superior State University

Group: Qilin

Discovered by ransomware.live: 2025-11-25

Estimated attack date: 2025-11-25

Country: US

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 38

Third Party Employee Credentials: 19


External Attack Surface: 21


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • solson lssu.edu
MX Records
  • alt1.aspmx.l.google.com.
  • alt3.aspmx.l.google.com.
  • aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • alt4.aspmx.l.google.com.
TXT Records
  • sfp2yy3y5ldfp0q37zphk7475s20rt8n
  • v=spf1 exists:%{i}._spf.lssu.edu ip4:198.110.216.0/21 ip4:208.75.120.0/22 ip4:205.207.104.0/22 ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144.0/20" " ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149.72.0.0/16 ip4:159.183.0.0/16 ip4:223.165.113.0/24 ip4:223.165.115.0/24 ip4:223.165.118.0/23 ip4:223.165.120.0/23" " ip4:209.61.151.0/24 ip4:166.78.68.0/22 ip4:198.61.254.0/23 ip4:192.237.158.0/23 ip4:23.253.182.0/23 ip4:104.130.96.0/28 ip4:146.20.113.0/24 ip4:146.20.191.0/24 ip4:159.135.224.0/20" " ip4:69.72.32.0/20 ip4:104.130.122.0/23 ip4:146.20.112.0/26 ip4:161.38.192.0/20 ip4:143.55.224.0/21 ip4:143.55.232.0/22 ip4:159.112.240.0/20 ip4:198.244.48.0/20 ip4:204.220.160.0/20" " ip4:141.193.32.0/23 ip4:159.135.140.80/29 ip4:159.135.132.128/25 ip4:161.38.204.0/22 ip4:87.253.232.0/21 ip4:185.189.236.0/22 ip4:185.211.120.0/22 ip4:185.250.236.0/22" " ip4:143.55.236.0/22 ip4:198.244.60.0/22 ip4:198.245.81.0/24 ip4:142.0.176.0/20 ip4:38.106.32.46/32 ip4:24.110.64.0/18" " ip4:204.232.162.112/28 ip4:204.232.180.112/29 ip4:204.232.180.128/29 ip4:69.20.119.216/29 ip4:76.12.109.192/27 ip4:67.59.141.128/28 ip4:209.41.176.224/28 ip4:69.48.230.0/25" " ip4:136.147.176.0/24 ip4:13.111.0.0/16 ip4:136.147.182.0/24 ip4:136.147.135.0/24 ip4:199.122.123.0/24 ip4:199.30.234.56/29 ip4:74.203.184.208/30 ip4:199.30.234.64/26" " ip4:199.30.234.192/27 ip4:74.203.184.32/27 ip4:207.195.176.0/20 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/14 ip4:104.47.0.0/17 ip4:199.15.212.0/22 ip4:72.3.185.0/24" " ip4:72.32.154.0/24 ip4:72.32.217.0/24 ip4:72.32.243.0/24 ip4:94.236.119.0/26 ip4:37.188.97.188/32 ip4:185.28.196.0/22 ip4:192.28.128.0/18 ip4:103.237.104.0/22 ip4:130.248.172.0/24" " ip4:130.248.173.0/24 ip4:75.126.84.128/26 ip4:67.228.8.0/25 ip4:67.227.149.19 ip4:64.56.208.32/27 ip4:67.228.91.90 ip4:67.228.158.174 ip4:174.36.44.116/30 ip4:50.201.66.168" " ip4:63.71.8.0/21 ip4:199.30.232.0/21 ip4:63.150.153.0/28 ip4:205.186.164.205/32 ip4:74.203.184.0/23 ip4:8.31.233.165/32 ip4:207.195.160.0/19 ip4:198.187.196.100 ip4:198.187.196.130 ip4:38.106.32.22/32" " ip4:199.255.192.0/22 ip4:199.127.232.0/22 ip4:54.240.0.0/18 ip4:69.169.224.0/20 ip4:23.249.208.0/20 ip4:23.251.224.0/19 ip4:76.223.176.0/20 ip4:54.240.64.0/18 ip4:76.223.128.0/19 ip4:216.221.160.0/19 ip4:206.55.144.0/20" " include:_spf.google.com include:_spf.sparkpostmail.com include:_spf.salesforce.com include:secure.giftlegacy.com ~all
  • ZOOM_verify_Z_Db7UUYSgifiEWeLGB-dA
  • v=spf2.0/pra include:_spf.sparkpostmail.com
  • MS=32A72CD7FB81899C11C63AC43A6936D3E1CC6E3A
Cloud / SaaS Services Detected
Salesforce Zoom

Leak Screenshot:

Leak Screenshot