Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo MASHOLDINGS.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: LK

Description:

[AI generated] MAS Holdings is a leading manufacturer of intimate apparel, sportswear, performance wear and swimwear. Headquartered in Sri Lanka, it's one of the world's most recognized design-to-delivery solution providers in the apparel and fashion industry. MAS operates with a network of factories in 15 countries, employing over 99,000 people worldwide.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 98

Compromised Users: 310

Third Party Employee Credentials: 365


External Attack Surface: 112


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
  • masregistrar masholdings.com
MX Records
  • eu-smtp-inbound-1.mimecast.com.
  • eu-smtp-inbound-2.mimecast.com.
TXT Records
  • ERPSf6qu6E64emV8/6k0VJ1cQgxHmF4GoAAPbVM+g4yr8UF/v5SfMHzoYR0cT7KuntfaoIxkUhVdlP3E48nIEQ==
  • globalsign-domain-verification=baa21d8e8587bd0c8ab9145a6374677d
  • cQHgaapHla2eHBsBeNf4Cl9BPY7iO/d5iTIVrQkuiIBa7IGZNsw1haVhSl/I8oA+5rVnbbNNIq9PKgxI/Cqtcw==
  • MS=ms24461520
  • eomdq247jjm0c1ba81ukjcsreq
  • globalsign-domain-verification=2D8982A1044ECDA306050AA5EE9D3EF9
  • globalsign-domain-verification=2B1DD30CBE69BE5C1645C87248259881
  • facebook-domain-verification=jvv2kjihh86mhvf0exbcuctliuilw3
  • globalsign-domain-verification=1B131FB7FC1BCE2FEE8ACEFB6E1BA64B
  • KaM3l3QU4DR7Awl8ArhXyCEwlucoeci7zz7ZUjT74HOGPBaOiSFNtz8074ton+LYgh4EO2W97T57xHTu53pUlQ==
  • HrVw/hWKPXVgbTQQufqZkLpI8QwWtcufElX5om7kTUuOjrDaiCaHDGiCZrBvvP8RqsQcTm8WiGSIUK69236Pcg==
  • atlassian-domain-verification=6/nfGPX1lkV0NvwqO9YXSlxbd8yDMml35JVyuEV17MTZ2GJ8ZcWTRBetML4UGBY4
  • ECEB958260DB9F66386703EB658F851D
  • globalsign-domain-verification=305FE5353D2F3CC49DEA2F72C463AE97
  • uk1n1mn3f9tsj45hndooj5dvfg
  • globalsign-domain-verification=6e99b90f23c4812d2281b05bfc69ee02
  • globalsign-domain-verification=257CCD35CC475B4BAF5D507885FDD56A
  • v=spf1 include:eu._netblocks.mimecast.com include:spf.protection.outlook.com -all
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Mimecast

Leak Screenshot:

Leak Screenshot