Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Play
Discovered 2023-05-29 22:56 UTC
Est. attack date 2023-05-29
Country CA

Description:

Canada

Infostealer activity detected by HudsonRock

Compromised Employees: 7

Compromised Users: 18

Third Party Employee Credentials: 19


External Attack Surface: 17


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • fea434e06bfdb61e8c0f5ccc4e04e8dab87c15f36d55ba93d2de26979ffc4439soroc.com.whoisproxy.org
  • fea434e06bfdb61e8c0f5ccc4e04e8da8cc293c22ac0bc71eb5489e54402bd58soroc.com.whoisproxy.org
  • fea434e06bfdb61e8c0f5ccc4e04e8daed63b5f00aa4f3bf40616dd944481c04soroc.com.whoisproxy.org
  • trustandsafetysupport.aws.com
  • fea434e06bfdb61e8c0f5ccc4e04e8da2f3eb1ab52eb7e302db1276f5ab94bc3soroc.com.whoisproxy.org
MX Records
  • soroc-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • 185fad99562af1b5._domainkey=v=DKIM1; k=rsa; h=sha256; s=email; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAt5CXM4Okyq4iYYYeD5sydI+Pbderf44z86epv/qY0lDX6yK3EdX7NZD5Xvn3rSARfFJcjn1eXPuLktewC5ONKRObnqMsCwUOU5UlWR979/" "uuGV4EYw9wIY6JndJHaZeevNPc9dLu7CzClfjYt3X2qoVkd1sfoBsNxq5FjF9v6Qpt9X+tYxYD+AglfOpZ1IWyA/RNvHIfyL2POo1Ud7z11PtsPlMpctODRfUMT1vNQ64Kb/roYFYZFT6RD7zDBAH0R8XUj2rFvgF5DuDGx8U3BEdYMXrR2nXwxCxxwqBfI/UEiizdd2umoX21NuYI0NqGlx5fGhRe1Q7SeoEYwoWZcQIDAQAB
  • zoho-verification=zb95021491.zmverify.zoho.in
  • ms-domain-verification=ded3fbbb-2bff-4545-be33-011f3c2c1d7e
  • vcvsnd7jlc27k6tviacep5k10m
  • docusign=a529852b-e3c5-4adc-a0a1-e04526be24ba
  • 8a5jt6fn97fu2t354j8a6ug1fe
  • a66dbf1d-2978-4e9b-b8ea-b0ada7b0fa6f
  • 15fo3kkkc3pcjofd1dvvr7vs25
  • v=spf1 include:_s01039529.autospf.email -all
  • nordpass-domain-verification=c8501958b2485ccb0bc2c39e8e2f526d97c3e133e3e0631a73cc21b5c4a0b4f4
  • google-site-verification=r5YgSArg0FmYj3m2SRG1Fop5tuXQRQDSO5_H7AjzpnQ
  • ms-domain-verification=1eb3e12d-4612-46cc-b693-fdad8f6b7b7e
  • MS=ms16945405
  • atlassian-domain-verification=amoeggD4og2PfXrQa/0oP4PjD2czoIgGkjyvpYCjU7RakwCJnUGjO4pjxg4Q9i0U
  • apple-domain-verification=fIUKNEPpS30ws3d5
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Zoho Campaigns DocuSign

Leak Screenshot:

Leak Screenshot