Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo SGK INC

Group: Coinbasecartel

Discovered by ransomware.live: 2025-11-13

Estimated attack date: 2025-11-13

Country: US

Description:

Based in Des Plaines, Illinois, SKG is a marketing company that specializes in global brand development, activation, and deployment. The company is...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 6

Compromised Users: 10

Third Party Employee Credentials: 46


External Attack Surface: 6



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • mxb-00645501.gslb.pphosted.com.
  • mxa-00645501.gslb.pphosted.com.
TXT Records
  • sending_domain1066002=935177fe29ed48f8c72bbe4258090f3b70fadf4b9857925f2f1fabc63d09a826
  • apple-domain-verification=Yt3LZarlHdcbtEov
  • v=msv1 t=76EC1935-217B-4CF2-BA21-C016AB635614
  • R0812+3Y1wRE3+SicD8QPZWerbJAPPQD6UqaQab2TE23bjEy+sZRuDsxzrRO0JjoZPWQeTeL8XqeueKMcK1ljg==;
  • R0812+3Y1wRE3+SicD8QPZWerbJAPPQD6UqaQab2TE23bjEy+sZRuDsxzrRO0JjoZPWQeTeL8XqeueKMcK1ljg==
  • atlassian-domain-verification=hWgJwaL8X9anO4cUXqkKgLoZrEV9lsBWxjW7l5D8MXVdCoaI8mFnGHDOT1ioJu9T
  • v=spf1 include:spf.protection.outlook.com include:mktomail.com ip4:66.151.5.11 ip4:66.151.5.12 ip4:66.151.5.13 ip4:64.94.183.11 " "ip4:66.151.5.113 include:amazonses.com include:spf-00645501.pphosted.com include:outbound.mailhop.org ~all
  • adobe-idp-site-verification=0ad78978-66a1-4dfb-a9f3-b336a015f364
  • jamf-site-verification=s_yBLTdHPYasVIz76uKPKA
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Marketo JamF Proofpoint

Leak Screenshot:

Leak Screenshot