Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo NCH.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: US

Description:

[AI generated] NCH Software is a technology firm that provides a variety of software solutions and applications for different uses. Located in Canberra, Australia, the firm offers reliable, cost-effective, and user-friendly software that includes audio tools, video and business software, utilities and more. Some popular products include WavePad, Switch, and Doxillion. The company has a strong, global user base.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 59

Compromised Users: 26

Third Party Employee Credentials: 39


External Attack Surface: 68


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
  • wendy.cortes2 nch.com
MX Records
  • mxa-0004a701.gslb.pphosted.com.
  • mxb-0004a701.gslb.pphosted.com.
  • mailscan01.nch.com.
TXT Records
  • apple-domain-verification=JuMWJCOEOaCszMS6
  • MS=ms67842292
  • 28yhw327shn65y4mzgs8z5gmb06lkr6z
  • MS=ms62811781
  • v=spf1 mx a ip4:52.200.252.231 ip4:52.21.224.229 ip4:52.6.190.122 ip4:209.126.68.111 include:spf.sendinblue.com include:notifications.issuetrak.com include:_spf.salesforce.com include:spf.protection.outlook.com include:spf-0004a701.pphosted.com ~all
  • _5f27ds6y3tq9fqf437sx7mlragxdbyb
  • cisco-ci-domain-verification=5a9975d215ae66a0501ac36406f14785d12cdf8a072428c99778ea26efd4f19c
  • MS=D24B84391CF0CC1E5CDEE3507D4CDFEAD3B70748
  • SFMC-K20idK-k89hDVvevsccUqS7iS_Ta2hMS5gjynFP_
  • GZyIdL0dZ2tBRgp0i0JGRHz1gfHAiLoDewQJz8xyFR8lySOZiBLGZIVV0UREqmWc2CteAuFEYHtME0qMtrQrxw==
  • ryj3mtcbx1lbgc9jy8tkc2j51k2qxd1g
  • 0zWfIJi8bkRO/NoOJlZomjMXu4btcekEiIKL8qFeVe6mxRaa+NjdPtxVN9bXBHvYn/QlH7QomLKpunNhYqQ97g==
  • Sendinblue-code:403b1e68a4a53d3f49f038a882cf2ede
Cloud / SaaS Services Detected
Apple Microsoft 365 Salesforce Cisco Sendinblue Proofpoint

Leak Screenshot:

Leak Screenshot