Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Merko Ehitus

Group: Qilin

Discovered by ransomware.live: 2025-12-15

Estimated attack date: 2025-12-15

Country: EE

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 0


External Attack Surface: 1


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • merko-ee.mail.protection.outlook.com.
TXT Records
  • atlassian-sending-domain-verification=b3ff828d-d3cb-4313-b3e0-8f43c02bee0f
  • atlassian-domain-verification=WA8bb1O0zD9v3kAvzAcmM6zDhqhUpN9iETgVFnSFeNlJH/CfX6WMnHIQcO4jOlIh
  • google-site-verification=5mxaWmwthkqdm7BxdDbu7iv5K0ZA88noPfpHdKzc8Tg
  • apple-domain-verification=3Vf27djsowc6GGv
  • v=spf1 a mx include:spf.protection.outlook.com a:directo.gate.ee include:servers.mcsv.net ip4:194.204.13.172 ip4:194.204.17.218 ip4:194.204.13.165 ip4:194.150.66.175 include:amazonses.com include:mailer.recommy.com include:sendsmaily.info include:_s" "pf.smaily.com ~all
  • MS=ms80504678
  • fCIhGab7EcNMWPZIyNRrwboRPH+QQySDGQXk6HpyEKlxGYXfag0HVG88BmDuKJNtVI2O2KUYkQLID1JaMp9erg==
  • google-site-verification=YsXvVlaIWCKwXTD7oeL8NrV2y723tOvPtoecaftN2RA
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail Mailchimp Microsoft 365

Leak Screenshot:

Leak Screenshot