Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2026-05-05 23:24 UTC
Est. attack date N/A
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

N/A

Infostealer activity detected by HudsonRock

Compromised Employees: 45

Compromised Users: 1140

Third Party Employee Credentials: 38


External Attack Surface: 122


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mxa-00133a01.gslb.pphosted.com. Proofpoint
  • mxb-00133a01.gslb.pphosted.com. Proofpoint
TXT Records
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all
  • adobe-idp-site-verification=264047c04b2bf3922d05cb6e8529d3ddf76120f96a57b175aa07cb166fbbe257
  • docker-verification=01b98e7a-79fd-42e9-8863-b79cd3340c1a
  • atlassian-domain-verification=auTgem9wYz8TJ4/edmVGsXVSFA3yO8+wvuzK39GZc/+e9IGfjO0NWcpHlY9UpP8y
  • teamviewer-sso-verification=77d908e82d304eaf953ba520c9ce3959
  • atlassian-domain-verification=1NwOcM5fsokgHOpaNRSfsQsP4O6DPp9TwNQpZrHdAWbx+gAtrBCSf8cax4Nx8Gm5
  • docker-verification=fa78b0c7-2fc3-478f-8115-62a6f027077d
  • postman-domain-verification=b3e64101663f53109145418461f9f015e58232dea81b28a47eb2a147c6f4466b17b4cc9af40bcbfa9a70e6a3d6a241b3c1aeddd08578a84c898fc8a81feca716
  • ciscocidomainverification=5b0c2a6027025e43d96e182d6bd9a4e1d72526ea24b39760b0ae59fd626386bd
  • cursor-domain-verification-m35p25=XG1G1GLEp2X5TMF0tvn3X3hRe
  • hcp-domain-verification=4f82731b9abd76938024809a112982d15dd28e6e2b042b5b1c19a4cf2d79de96
  • neat-pulse-domain-verification-3NlVBpX=5457d1f1-3d12-4f14-aa15-8e78cbffd052
  • docusign=bce9e262-cf66-4e17-860b-8c82d94f0ee3
  • apple-domain-verification=iPIFHJkpzZ5jHVUj
  • smartsheet-site-validation=joG1vbv_dnWvdFtsB4JpHIE7DpM-L7dA
  • SFMC-8syD5zDIJYx5eDQUc0EyzbOi-DAlKFsaOscDKLeO
  • apple-domain-verification=3kPSkh6DtIUKj9qv
  • amazonses:n8wb0sSYFN/Tthlp7lmUe8q7pOW29DlM0sw8lOzN1Tk=
  • google-site-verification=MEI6K2LN3mVs0Bgl8jXz1dQ_yRXTr8DZeoYNJGX15cc
  • docusign=30ce9b1f-0bc0-4934-aba7-5cff87b4685e
  • nitro-verification-code=MzYzMzIyNzU3MjU5ODQ3MzE4OA==
  • _xawwoxiyeh61i8wlsfkzoinpsomj0u8
  • facebook-domain-verification=ltnx7dczl60j3jaf739riq8qrh89yh
  • SFMC-zFc7zLpyY3mTyS2OUpBHLoZgX_PGQOV1ifMUZ9Vq
  • amazonses:438nuyXy3ycfAdGc/BdpPOsZFGQfUmjbqwVuSg3033s=
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Docker Teamviewer DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot