Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Montana State University

Group: Royal

Discovered by ransomware.live: 2023-05-02

Estimated attack date: 2023-04-29

Country: US

Description:

Montana State University, located in the city of Bozeman, is an educational institution that offers a variety of academic programs and activities for students as well as a variety of personal document of the same student for everyone interested. They failed to storage personal data in a right way and lost 105GB. You can find there money flow of a big University as it represented in numerous financial and administrative documents. Students' personal and medical information is also available like in our previous post about their affiliated college. We will share it soon.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 22

Compromised Users: 197

Third Party Employee Credentials: 17


External Attack Surface: 106



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • montana-edu.mail.protection.outlook.com.
TXT Records
  • docusign=ce2822dd-6a65-484b-bd8d-ed06d8792016
  • OklrmepcZwGCX154yT5ftd4/JOl68Zud9QAwMp4FVtVRx0P9kMkf0H1ZSgxava2Nuo5g/M/7uxkLjXaOdA3wrA==
  • ecostruxure-it-verification=1d6e7750-cadd-4835-b22e-73e2cf5e0af7
  • docusign=51305af3-6e6c-448a-b2a6-5339f46536fe
  • pardot1072752=b232cbe8547b59764c02c412388690a67f1ec52e921e37d094e1ffbd87b36625
  • ii17g4onvdcsf6mortc7bgvgmh
  • v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:_spf.mlsend.com ~all
  • MS=ms17986118
  • d365mktkey=MZBwEzBCtrg2DCxuE2HI3U8xQctXxUhrC5Rp9AIRtBIx
  • adobe-idp-site-verification=03fb826d-ecce-49fb-831d-64910a2fde17
  • google-site-verification=wThAlRv5Jq_zt3q7zq13uaxW2Dnj9oex_eBH8kdHnuM
  • d365mktkey=1FteQJf4Ogh90DQcxXMi2ATqFI9elWUYxxPQS9hdLDQx
  • e2ma-verification=l5mbb
  • sending_domain1072752=b7c11bd58da0a6d13b2e3376157db4316208f2ac9aa4d1432159259c0bd6e940
  • atlassian-domain-verification=DbibmRQvmYAfSso/7WMVB5PBVjx/d4atIWIzdti2vm2k56neOa/KrWP2MdXRZI6Y
  • apple-domain-verification=qIDmP7uMWggNxwFA
  • ciscocidomainverification=72bd71c0af498eca294b8327beb11f5adc177a5a0b1206c5bb4dd08ae0981679
  • ffcf033a6eea477d98b09dc9f649b9e6
Cloud / SaaS Services Detected
Adobe Apple Atlassian Microsoft 365 Salesforce DocuSign

Leak Screenshot:

Leak Screenshot