Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

MSAMLIN.COM

MSAMLIN.COM

Group Clop
Discovered 2023-06-23
Est. attack date 2023-06-23

Description:

MS Amlin - Global Specialty Insurer and Reinsurer

Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 1

Third Party Employee Credentials: 3


External Attack Surface: 3


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@cscglobal.com
MX Records
  • cluster5a.eu.messagelabs.com.
  • cluster5.eu.messagelabs.com.
TXT Records
  • d365mktkey=HyVGF9dvkG6iLmFvmSLM7PJU0QUAbGvTxMFjwjexuyEx
  • v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~all
  • onetrust-domain-verification=1744eba8ce9343359c4cfe9f7eba3455
  • onetrust-domain-verification=97cba5bae7814b92a42e6c5385bf5c4b
  • asuid.vanish.togo\0106BA3B16CDFE2C65112E1DA121451CC32B0177B900A808AFF7C8F935BF6957B88
  • atlassian-domain-verification=a0fqqbEWmk7hVcYhH5BEK82tcsoYAZzlnPrDMU1GG8AKzvyLhWSrnzG8z9ycLjxV
  • 40fpdvtxbl0tyt58m0tjf5rpt3mwnktk
  • _05qeeyxfrpjqrnb70b3tkri18ybuq61
  • _5elycfc2ioahg2rwq9n0xy0rrfbp76d
  • ca3-eb45a974869548a8a2c4b88970d42057
  • docusign=cef48017-0f2a-4ff8-b020-8017980e4524
Cloud / SaaS Services Detected
Atlassian OneTrust DocuSign

Leak Screenshot:

Leak Screenshot