Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

MAXIMUS.COM

MAXIMUS.COM

Group Clop
Discovered 2023-07-26 20:36 UTC
Est. attack date 2023-07-26

Description:

Moving people forward - Maximus

Infostealer activity detected by HudsonRock

Compromised Employees: 135

Compromised Users: 2096

Third Party Employee Credentials: 271


External Attack Surface: 122


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • trustandsafetysupport.aws.com
  • 3a808987ffae6ff79adfed59d7da05a32407a299d75dc539ef32645321c1ad06maximus.com.whoisproxy.org
  • 3a808987ffae6ff79adfed59d7da05a3b8b6cef1a55fe2483ca23fe81579e655maximus.com.whoisproxy.org
  • 3a808987ffae6ff79adfed59d7da05a31ad2ae066dbd2506562776bda68ae488maximus.com.whoisproxy.org
  • 3a808987ffae6ff79adfed59d7da05a34a8c321739f60c79f15bdaa6db287a38maximus.com.whoisproxy.org
MX Records
  • mx2.hc4848-77.iphmx.com. Cisco/IronPort
  • mx1.hc4848-77.iphmx.com. Cisco/IronPort
TXT Records
  • dell-technologies-domain-verification=maximus.com_3546d67d-3921-4159-9dbf-794e760e7aad_1782932128
  • duo_sso_verification=awpjRAVhzP9UEMqsQdUD4DGVxtPFk2z7ARU0a1V74hddMYiWRtarWCirRHWZO0qt
  • facebook-domain-verification=ht46npflj4gwznuht5maozywlxffd7
  • google-site-verification=xiFnCjlngAuUdfRI3dyGOE_SV1XotCIgyqY-ikK2faY
  • jzM2FmjR0x4f9/MvaE9PZ9tVrVbmVTHUzPiuqvtibmSUW+TaikYEIEuxTIow4AoD9ztHFiBwuG6NofTUzuAzQw==
  • p50bX5lbhwqosM0AK2qJhu1Xdv40BHJHr9xD8LJe0wY82ea82RW0MOGB36eMp/LGZAtMbeugt1DkPm/9ScXWxg==
  • smartsheet-site-validation=i2euBlQk7fI15bHi0zXHJwMBA-Y5A1o3
  • v=spf1 include:_spf.maximus.com include:spfip.maximus.com include:spfhost.maximus.com -all
  • +z5KPAqrz3AXKaLSi4JnZKGd5JjJ+SJN4KmTYSij96NdVvkc9qQz5zxQfyvhquAOtPWwsahwdKGOUS5PDq/lOQ==
  • MS=ms71820680
  • adobe-idp-site-verification=6e6503588d625580f5bb579ce86131ecb2c8dc6e5a54a3aa4a99cd0030615eb1
  • apple-domain-verification=RvD1kZTMKboSBfFD
  • atlassian-domain-verification=LiIIkWGoteAW51TkL2GMyFOkQlhyZxG3TesZoO3C9Ue91tIE9ua8Sl/32glPnhIi
Cloud / SaaS Services Detected
Adobe Apple Atlassian Microsoft 365 Cisco Duo

Leak Screenshot:

Leak Screenshot