Discovered
2026-04-26
Est. attack date
2025-10-07
Country
Description:
dnb.com/business-directory/company-profiles.suzhou_yike_kejian_architectural_design_research_institute_co_ltd_nanjing_bra_nch.12f22121a67d4f912a7d8a5b634d830a.html Suzhou Yike Kejian Architectural Design Research Institute Co., Ltd. (Nanjing Branch) is a Chinese architectural design and research firm operating in the Residential Building Construction sector, classified under the Construction of Buildings industry. The company is registered in Nanjing, Jiangsu Province, and operates as a branch of the parent entity headquartered in Suzhou, Jiangsu. It is a small regional design institute serving the competitive Yangtze River Delta construction market, with professionally certified engineers on staff
Infostealer activity detected by HudsonRock
Compromised Employees: 64
Compromised Users: 7503
Third Party Employee Credentials: 35
External Attack Surface:
122
DNS Records:
The following DNS records were found for the victim's domain.
- whoisrequest@markmonitor.com
- abusecomplaints@markmonitor.com
- dnb-com.mail.protection.outlook.com.
- _hp7c20ah0ikfywn17wamfjh8p6786ox
- _hc2sn83etkc85jlw447nruu9dhbpdy5
- v=spf1 ip4:159.137.80.91 ip4:208.226.214.236 ip4:72.19.252.170 ip4:220.130.152.173 ip4:204.92.22.200/30 ip4:12.129.29.143 ip4:158.151.208.120/24 ip4:158.151.214.66/28 ip4:165.193.97.93" " ip4:72.14.161.10/31 ip4:158.106.68.11 ip4:205.216.45.11 ip4:209.112.4.10/31 ip4:209.66.117.11 ip4:209.123.45.224 include:spf.protection.outlook.com include:sendgrid.net include:_spf.salesforce.com" " include:spf1.dm.aliyun.com -all"
- _bvsecjccauqilzo2plgsj9vbrqpp1yw
- ibmid=a9def6cf-843c-4d36-8eca-2c307149bd63
- atlassian-domain-verification=owQCWYzgP3scaCY15u2L4MqN2a/Lda353UApAv4cEJPKscnJmVDwKlOkdpSAKnXa
- jamf-site-verification=XQrh0aSdNcFbATnbldtvFw
- google-site-verification=ZVX3kiXRYyT5I8hIXfdxiVrgjftqr5S-waWjRxNXL0c
- _t087nr0s8p25d17ouy1ln8ppt98veob
- vertexinc-cloud-4c68f493-da79-4f7d-a07e-44d61f8c1b95
Cloud / SaaS Services Detected
Atlassian
Salesforce
JamF
SendGrid
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.