Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Moen

Group: Qilin

Discovered by ransomware.live: 2026-01-15

Estimated attack date: 2026-01-15

Country: US

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 5

Compromised Users: 270

Third Party Employee Credentials: 9


External Attack Surface: 75


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@cscglobal.com
MX Records
  • mxb-00932501.gslb.pphosted.com.
  • mxa-00932501.gslb.pphosted.com.
TXT Records
  • _1lv2y0pgkwasd4v3jfdim9p4q6xkat6
  • _l29brxvjjkm192fkbjfin257a3jw7ks
  • teamviewer-sso-verification=85300e028e1241c2b3ea9f7ef5a3543e
  • reachdesk-verification=UXKBFuiaNhBdfQFWB1TNrlsNMAFqLKiCSl4xY3lb2YrIqACoazMtvwFnWAntPB4e
  • _ol2qaujubgh5kalbpzxqj4kv962ooal
  • _wqq7ftttuj36mx8onqkj052vbc85u6b
  • _gui6imi7dreyc9vms8ml2d3hmd93npt
  • cGg7Y67lbY4Dl6vkwQma2Vw+PJvAjefROk1HZfWXE+oMzPj4F7HDUuJBEZ5yYzIbhaHqVXUJxr4y/d8DbQ4+mA==
  • _ihhhq2ghcbmppp0938cl4wdayo5c0ia
  • miro-verification=2ec15c1a0b41b0f599075ee51d0370a67e7e3a6d
  • _no81in5k4wtk68j7sjgqo7t6bchifee
  • docusign=e622155c-db2f-4749-90be-1b865ec91ec4
  • anthropic-domain-verification-sykafa=oEsQHFtTI595ehgJwFKhPXyoR
  • cisco-ci-domain-verification=2d319ae97ee4a03bd15d2fac13186edf92e0930ef50a5dddeea5bc4891826ea6
  • _holnpgl7dkx6fatisxi78eokmzx59cg
  • atlassian-domain-verification=znts1/CZd0JFK/9pFYqZLRgKSKXDbhDvkNCfWWFH7qmoCkx9atvcAfNSIjQfWmeC
  • _u69ibgh9z4liz8xhd4q5sjxj7cqev2h
  • Xmedius-Verfiication=b6caaf96837c3cdf5db9e6f5d276eb37406b452024808dbbe7496a94cb0fa776
  • _fkpwyy5qn8q4e1zyan1etg6klq1rmhy
  • v=spf1 include:fbin.com -all
  • apple-domain-verification=6mFyfUwZwsDSgrw5
  • _a6e9rwgg0120jkuzmgdzmgwdlqf16kc
  • google-site-verification=xu6gzCGs98KnAzlOev2lB5NgGuAWeCnPvXNU_b1uPCE
Cloud / SaaS Services Detected
Apple Atlassian Miro Teamviewer Cisco DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot