Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Sunstar Americas

sunstar.com

Group Royal
Discovered 2023-04-03
Est. attack date 2023-03-30

Description:

Sunstar Americas is a part of the Sunstar Corporation is famous for its dental products. They lost about 118GB of their data including their customers' personal information and other internal corporate data.Soon you will be able to take a look by your self.

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 5

Third Party Employee Credentials: 7


External Attack Surface: 14


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 85db6f16191acfc99ef2ef9b556e379d-41590490@contact.gandi.net
  • abuse@support.gandi.net
MX Records
  • sunstar-com.mail.protection.outlook.com.
TXT Records
  • google-site-verification=-iLwhPKWMzsfY1klKVZumyXJSxL5mkM052KVu_I0lMU
  • v=spf1 include:spf.protection.outlook.com include:_spf.salesforce.com include:spf.emailsignatures365.com include:_spf.psm.knowbe4.com include:_spf.internal.sunstar.com include:_spf.cmail.ondemand.com include:amazonses.com include:mktomail.com ip4:195.141." "58.2 ip4:195.141.212.40 ip4:155.56.208.100/30 ip4:157.133.97.216/31 ip4:169.145.66.70/31 ip4:169.145.66.72/31 ip4:4.1.54.146/30 ip4:38.98.56.178/30 ip4:185.44.132.132 ip6:2603:10b6:510:23c::24 ~all
  • atlassian-domain-verification=BciO8271BwCZCicqyUt9YhU3yIQlf1lf11BKdvj7Q2gQEeQl49BPesB0TFdCRvaA
  • box-domain-verification=3015f64aebfdb20031fbb533d11bdcf31f086730d122812a10f15c13fbf4a412
  • knowbe4-site-verification=235b3357383c20ef378d8735e1a8e1f3
  • knowbe4-site-verification=c7d2039ef361106083c327b809f87704
  • amazonses:HLwo5GaIgJ4oF0Kx61j6i6ivSB7V+pxv6qGZtQq+M/8=
  • adobe-idp-site-verification=a8c577e48acd009787c9319dd9cfdc8a85bfc30f8ee900a1efe5ce84bc24d28e
  • have-i-been-pwned-verification=dweb_wxmw0ijcaqbzmih43v871htm
  • apple-domain-verification=oCfkv029Ssu27Bme
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Salesforce Box Marketo KnowBe4 Have I Been Pwned

Leak Screenshot:

Leak Screenshot