Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo MKS.COM

Group: Clop

Discovered by ransomware.live: 2025-11-07

Estimated attack date: 2025-11-07

Description:

[AI generated] "N/A"


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 91

Third Party Employee Credentials: 30


External Attack Surface: 13


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse key-systems.net
  • abusereport key-systems.net
  • info domain-contact.org
MX Records
  • mxa-00369f01.gslb.pphosted.com.
  • mxb-00369f01.gslb.pphosted.com.
TXT Records
  • v=DMARC1; p=none; fo=1; rua=dmarc_rua@emaildefense.proofpoint.com; ruf=dmarc_ruf@emaildefense.proofpoint.com
  • pardot1043321=11c9883363ef078c64a2e45017af8c56b837e104ff07eef388de457f4a05382e
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
  • MS=ms54780765
  • google-site-verification=cbByyUgIQ4KdPTBeqxLI39EYEz34lJWbfLMrEi9DfFw
  • google-site-verification=oVMv6vKzEmWpV2sDrMKV398CChaZ4Y3aN6tTl2B1HXI
Cloud / SaaS Services Detected
Microsoft 365 Salesforce Proofpoint

Leak Screenshot:

Leak Screenshot