Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Mr Christmas

Group: Qilin

Discovered by ransomware.live: 2025-12-02

Estimated attack date: 2025-12-02

Country: US

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 6

Third Party Employee Credentials: 0


External Attack Surface: 6


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
  • th6g76mr6pu networksolutionsprivateregistration.com
MX Records
  • mrchristmas.com.1.0001.arsmtp.com.
  • mrchristmas.com.2.0001.arsmtp.com.
TXT Records
  • google-site-verification=iMWeScKs25gY4wpvv27FIN9kE9cAcAjR097dFOobKyk
  • v=spf1 ip4:216.37.70.30 include:spf.protection.outlook.com include:relay.worldspice.net include:mail.zendesk.com -all
  • MS=ms21619144
  • facebook-domain-verification=fkcwohy991a00ksayezodaycuiinxh
  • klaviyo-site-verification=QRN5Ga
  • d3gm119offcs1j925tejjaoj4
  • google-site-verification=mHYmXpAjPT5VH-2Fd1NlAZLNgV-3mjGY1nTZVavV9wE
Cloud / SaaS Services Detected
Microsoft 365 Zendesk

Leak Screenshot:

Leak Screenshot