Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Lincoln Investment Planning LLC

lincolninvestment.com

Discovered 2025-05-06
Est. attack date 2022-06-07
Country US
City Philadelphia

Description:

Lincoln Investment was founded in 1968. This company provides investment advice and banking services. …

Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 50

Third Party Employee Credentials: 3


External Attack Surface: 30


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • d47563a.ess.barracudanetworks.com.
  • d47563b.ess.barracudanetworks.com.
TXT Records
  • google-site-verification=xmssaQtKkKmYKCebnXmccsxjIK7ejjorFeV05GOyuMk
  • 00DU8000009c7Y8=1TBU80000000ExR
  • 00D5e0000045OBh=1TBVV00000009mT
  • d25942bd31df2c004d78d189c73897c9
  • _2qitx927kg3ftsu18274stijpzcvg17
  • 7QjxpTRWXBTF/9uDz3F+cCLvD02lmPisvTp+Zm3CeeoWCAHxP0vVDFQK2NETYXgm5w7Pm5fa6jZGuhKQVXZ7dw==
  • hb5hwr5xbwcqj8xz0bv5yqmh4bgt8gd4
  • _l352owrotj9pfysuj6dcmojha10r18c
  • apple-domain-verification=jBCmu2g4ub0dLsQh
  • MS=13653343CD15D4FB0F119186444E4A4E41A7D791
  • 00DU7000008xflh=1TBU70000000HIb
  • v=spf1 ip4:20.47.149.138 ip4:23.253.182.0/23 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:51.4.72.0/24 ip4:51.4.80.0/27 ip4:51.5.72.0/24 ip4:51.5.80.0/27 ip4:52.100.0.0/14 ip4:64.78.151.128/26 ip4:66.59.0.0/19 ip4:67.59.141.128/28 ip4:69.20.119.216/29 " "ip4:69.48.230.0/25 ip4:69.72.32.0/20 ip4:72.19.192.0/18 ip4:76.12.109.192/27 ip4:87.253.232.0/21 ip4:104.47.0.0/17 ip4:104.130.96.0/28 ip4:104.130.122.0/23 ip4:141.193.32.0/23 ip4:142.0.176.0/20 ip4:143.55.224.0/20 include:spf1.lincolninvestment.com " "include:spf1.marketing.pro ~all
  • google-site-verification=zTomt-J0i4gS0Ib4l7p1sd_XViV25Zzxz6xmUmivsIQ
  • _lizvh7x8t3ed4r52to77cn1ymteqxor
  • google-site-verification=r0DS9_EzAspvIDlaQD86fx0pThtlxfkMUjEjSsSrU3M
  • google-site-verification=PvnLKY4bB0Y8Kym8kFTkINg8QRz0fyFpESx3VUFRQ0A
  • spf2.0/pra a mx include:senderidhost.messageprovider.com -all
Cloud / SaaS Services Detected
Apple