Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo MSX International

Group: nokoyawa

Discovered by ransomware.live: 2023-05-23

Estimated attack date: 2023-02-22

Description:

For more than 25 years, MSX International has been a dedicated partner to leading automotive brands around the world. They support them in transforming their businesses and in managing their operations across the areas of Customer Experience, Repair Optimization, Learning and...



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • msxi-com.mail.protection.outlook.com.
  • mailgate2.msxi-euro.com.
  • mailgate.msxi-euro.com.
TXT Records
  • N+uDQpslTJY7u2g2Z1CWBTR8oL3jGkmj4DzSu/bCWH4=
  • _globalsign-domain-verification=22Qf83Nf6ptictgyMg3ldyjusVZ4YgCtZ1UYV0EuV9
  • atlassian-domain-verification=hHtOHpxrW65sZ7J2MYAiPGr9VGVo1kmkmhR98aw1LtE05d7TpAxpX0UjCeKrTa7F
  • fsverification-itservice.msxi.com=339341df8efb761c421a8c94f15138a1c60ace48acc3c4db82852f20876a2609
  • L1UGB6BRGUY2BL84CCB8HEOHS9CKZEQCN6HK19S4
  • box-domain-verification=e8d688addd2d21047a9fc536f9725a9415935d2a96e9ce94bd397b84a2ae3479
  • google-site-verification=5vIqtEj5cl8-4b8jUtzdlWwnklawbfHD61okLsNFe7w
  • v=spf1 ip4:213.183.0.196 ip4:139.60.152.0/22 ip4:162.247.216.0/22 ip4:13.81.0.0/16 ip4:185.176.242.35 ip4:198.180.251.55 include:spf.protection.outlook.com include:spf.jobdiva.com a:mailgate.msxi.com include:servers.mcsv.net a:c.spf.service-now.com -all
Cloud / SaaS Services Detected
Atlassian Box ServiceNow

Leak Screenshot:

Leak Screenshot