Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Metricon Homes

Group: qilin

Discovered by ransomware.live: 2025-07-24

Estimated attack date: 2025-07-21

Country: AU

Description:

Founded in 1976, Metricon Homes is one of Australia's largest and most reputable residential home builders. With nearly five decades of experience, the company has established a strong presence across the country, offering a diverse portfolio ...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 6

Compromised Users: 41

Third Party Employee Credentials: 1


External Attack Surface: 17


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • au-smtp-inbound-1.mimecast.com.
  • au-smtp-inbound-2.mimecast.com.
TXT Records
  • docusign=50be6b0c-03f6-4ccc-8767-8df3647595c8
  • d365mktkey=VAaTFfIz9eSUJwj40FRlP5ab81cZ8dqaZMZNNfCIAucx
  • 4f2ccd6884c123240f54c658c326d27fd5d10ffe
  • MS=ms65699156
  • uYhK1uc5K5ffJNdeOszzsgWOCsurhvSMhyQgMbRBrc67g6QhGqrEop3EwSTnINm8xRdKC2vob+Gk6qhch9pBKg==
  • google-site-verification=xr7KFFuvI1DZ0KddPA_Lrb82kcEX7SR2Hq_q7syK1Gs
  • facebook-domain-verification=lw9k1kvytbor9je7729lvzxsz6b2sv
  • MS=ms36002409
  • 9a300e7d-b7a6-4834-8a96-44c2cce615ae
  • atlassian-domain-verification=gBxUeNCse9/VNEEYARrNjYABOMbfezXfMdDQDUY+LxBCm5x41Rh7FxilL+1ZKX3g
  • v=spf1 ip4:119.9.13.204 ip4:220.101.112.196 ip4:220.101.112.206 ip4:203.43.60.179" " ip4:159.183.181.113 ip4:149.72.116.19 ip4:149.72.117.225 ip4:149.72.119.192 ip4:149.72.119.197 ip4:149.72.119.199 ip4:149.72.119.210 ip4:149.72.147.106 ip4:149.72.148.50 ip4:149.72.155.21 ip4:149.72.160.121 ip4:149.72.166.148" " include:au._netblocks.mimecast.com include:spf.protection.outlook.com include:mailgun.org include:helpscoutemail.com include:spf.mandrillapp.com include:eventsairmail.com include:sendgrid.net ~all
  • autodesk-domain-verification=_YTbzhODV6y14VzQUTY_
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Autodesk Mailgun Mandrill SendGrid Mimecast DocuSign

Leak Screenshot:

Leak Screenshot