Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

SIG.biz

sig.biz

Discovered 2026-04-20
Est. attack date 2026-04-20
Country CH
City Le Grand-Saconnex

Description:

[AI generated] N/A

Infostealer activity detected by HudsonRock

Compromised Employees: 21

Compromised Users: 14

Third Party Employee Credentials: 40


External Attack Surface: 23


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • sig-biz.mail.protection.outlook.com.
TXT Records
  • sending_domain908702=d0aab4691c5c602348c000b412e1cc86ff93ee3e4834cd6ffc404086d4537b67
  • google-site-verification=ZqlQbWc4GzDhnq6_sakAnQoTrpECg10-YTn64vmHSZs
  • zoho-verification=zb25336900.zmverify.zoho.com
  • atlassian-domain-verification=b8fTKOw+EiCxRMNsNCOMes9KSt0vDuLPTyDOvYrkC6tDjHjuzLQEs0HYO6jR+FNa
  • v=spf1 ip4:213.215.157.254 ip4:194.69.46.95 ip4:193.131.180.254 ip4:193.132.52.1 ip4:151.253.65.233 include:successfactors.eu include:spf.protection.outlook.com include:spf2.sig.biz include:spf_visy.sig.biz include:mail.zendesk.com include:amazonses.com -" "all
  • smartsheet-site-validation=N_36z8gV1J3OsbBAbXrog0pWeDYFoHz4
  • lp33x2mhppvhyc9t30p8ls58qxhx99mx
  • 6ff17be63c55de2b547a228d342e53e71f8218614266da8dda
  • apple-domain-verification=9zo8WFK6gMPYwYJO
  • MS=ms73317077
  • ibmid=cdfeace5-1008-4ae9-9bbe-5a6f24602c6b
  • ms-domain-verification=63c0b485-9464-48b3-b8ac-752a96ef473c
  • google-gws-recovery-domain-verification=51244860
  • UmQ1fnX14nVpHg5WUapoteuHyGO/xIOc4+oaGvTggNFcOCVenBZbqmmOGld/FimueRQQCf+gTXp8Ygq7+1Ky/A==
  • sending_domain251992=fb43d2ccc36c8394ea9f5479cdd9c65dc2d8a4976950e84e3a9c608b55b7f3e1
  • pardot251992=7e9b9b5904c8d92f3426a07849de75c99e9243cdde502c231d5f86878d194c5b
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail Microsoft 365 Salesforce Zoho Campaigns Zendesk

Leak Screenshot:

Leak Screenshot