Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

STERIS.COM

steris.com

Group Clop
Discovered 2022-12-22 20:02 UTC
Est. attack date 2022-12-22

Description:

403 - Forbidden: Access is denied.

Infostealer activity detected by HudsonRock

Compromised Employees: 46

Compromised Users: 184

Third Party Employee Credentials: 29


External Attack Surface: 77


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • mxa-0021b801.gslb.pphosted.com. Proofpoint
  • mxb-0021b801.gslb.pphosted.com. Proofpoint
TXT Records
  • smartsheet-site-validation=Lh42-AnnFfZB_GPxJ6VVEmsX9qH-4Uoj
  • 49t2mlus0rodomrov9nu5pjmv4
  • 4qkq16hvtr8hu3qrt8m3qj036f
  • asv=857cda38bf09b0be15faf07c5bf630bb
  • eci-domain-verification=Mum8dSKcLN
  • pjioj0CbvE7OQeyvvqCZWNU4O0q6MNqd2gifssHbvbY9+PfNNSBxUxzLeorTGN99gnA+tTT/vPLFc8F+bEfqGQ==
  • i402gvmj7qi4uq794hosdcjps
  • rnb8vdmavdje11l3j22tsp13m3
  • MS=ms82651690
  • sending_domain66792=23e38c51ce1de9b424ae2b7920146f87af060bf2cfaeaa463c3168392ff38ca2
  • sending_domain1102972=e74e0a28c40ab6bb064d79bd7eea43ff2bdb6f54db24968bc406fb668f7ddaa8
  • heyhack-verification=88c53086-21d0-46eb-8472-91ccd99b6fb7
  • _6penpz2twl0gvb4luj1ehub91l2jgpf
  • bdrhcv4doc7gmmrdmefm744rji
  • 713iu9rg9r1q5lv3oab4d8nkhg
  • 00Dca00000442Fd=1TBca0000000CPN
  • pardot1102972=2b6aca26e28dac2f4e31ee8cfe49a62588f2ceaf9f194329578011b3e497a8e8
  • 00D300000006CIs=1TBUN00000009cn
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
  • heyhack-verification=ddc6f480-675c-4de8-9cc1-959c2918b080
  • q0ST7fP1zi+ZesLIVGXRPZLTvLDebvZeSLsY9bU+Vn/t10CSBVUx2hE1KyocJm9NrZ3JhyWyOibv3ElmQsPtkA==
  • zcrd77y9j9dbmz44n0mzrs7gy1bjv7sk==
  • q380lgpwtzvd1sjpjr9nmzv5d291m12q
  • _zfoean2j5xexc5f5ild2c9e344hsgx8
Cloud / SaaS Services Detected
Microsoft 365 Salesforce Proofpoint

Leak Screenshot:

Leak Screenshot