Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group: Qilin

Discovered by ransomware.live: 2026-03-22

Estimated attack date: 2026-03-22

Country: US

Description:

N/A

Infostealer activity detected by HudsonRock

Compromised Employees: 5

Compromised Users: 31

Third Party Employee Credentials: 10


External Attack Surface: 18


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@gcd.com
MX Records
  • southwire-com.mail.protection.outlook.com.
TXT Records
  • successfactors-site-verification=Y2U2MDgwNDhjNDk1YzBmMTlmN2YwZGUyYThmYTFiMmM4ODZhZDgyZjdkMzc5OTkxOWRiZDk0NjAzODRlMjZhNg==
  • google-site-verification=fUTGj1U6EVmvl1xR_YQSKRLJiX2RSwVlF8hj-OEXb-0
  • apple-domain-verification=FWcochYbrl3xlWfK
  • atlassian-sending-domain-verification=f1c605db-e502-4a80-a1e3-faabbcf14fc5
  • pardot_151881_*=eb69acbe750057656ee1d184815034904144fb34f7dfee6db744827c1b66f088
  • docusign=890598fa-ac07-4c5c-a72c-03abbe6c0055
  • webexdomainverification.4C675B8A1F7EB136E053AB06FC0A3F65=5f231194-8591-4d23-b861-cc1919901177
  • 5XgDnG27yF+WbLJuDj+6Fti7G441bX05eub2+IWGcSdsthMCIRFRQLsuFfCY2g66TOUh7NbuVYVf+YBfiapiqQ==
  • atlassian-domain-verification=VBrxfs//fMdUTDKW6DDvh5TLaKPT9QW4wKdVTWOHSsMvkCS6Sb5RzK1qpPf43cCS
  • v=spf1 include:spf.protection.outlook.com include:%{l}._spf.southwire.com ip4:40.114.15.27 ip4:40.76.221.254 ip4:208.78.169.130/32 ip4:23.253.197.137/32 ip4:208.254.39.76/32 ip4:204.155.56.4/32 ip4:204.155.56.3/32 ip4:63.98.229.132/32 ip4:12.159.76.40/32" " ip4:70.42.227.151/32 ip4:70.42.227.152/32 ip4:207.10.34.35/32 ip4:149.72.231.47 ip4:74.213.147.0/24 ip4:192.235.102.127/32 ip4:20.85.85.243/32 ip4:20.85.86.82/32 include:mailgun.org include:successfactors.com ~all
  • v=verifydomain MS=1284888
  • docusign=44bcb16e-80b3-4a2d-adc7-355c3eccf273
  • google-site-verification=iZdAdd0bHq4a3DOr493Kbo3hz6xqyTJKSyV377S3ho4
  • apple-domain-verification=Si7pyHW6lvU97x8A
  • cisco-ci-domain-verification=2980a165054b23ea954ce3d15a848ef9269ca785781eb5fb1243b1be75ee1b1f
  • google-site-verification=23Zn5nxJuELlJzxDVTf7SZfppl__eR6p9CTrsnuuyY4
  • rq0cilf8v9fd5j99tr0o2n7fha
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Mailgun Cisco DocuSign Cisco Webex

Leak Screenshot:

Leak Screenshot