Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo PHARMARON.COM

Group: clop

Discovered by ransomware.live: 2025-07-07

Estimated attack date: 2025-07-07

Country: CN

Description:

[AI generated] Pharmaron is a global drug research and development service provider. The company offers a range of services including drug discovery, preclinical development, clinical trial services, chemistry, manufacturing and controls (CMC), and pharmaceutical R&D services. Based in China, it has operations in North America and Europe, aiming to serve the international pharmaceutical industry.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 3

Third Party Employee Credentials: 0


External Attack Surface: 3


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • pharmaron-com.mail.protection.outlook.com.
TXT Records
  • cx23rcmrmdgjtj7822p1b06mmxtypb74
  • knowbe4-site-verification=18b92f9e3ba9fe84593d336e2b86076c
  • MS=ms46733994
  • docusign=bca3ab2f-387e-4c7b-86ee-10467afafdec
  • docusign=4e897245-531e-45aa-b5f2-cbbd4179c074
  • docusign=25116f53-628a-4100-8083-3eb59df886a0
  • sending_domain1041311=c53f73d0cccd756c5138b5a213e49484f39629bb82299b21f121a70d26a1add0
  • sophos-domain-verification=a6410ae29be42e1800b61043d8fb1c105ea09051fb6560a9f60113715ad74fd7
  • thq87lfpxlw517rht1qf2ytm7hvn9j7d
  • v=spf1 +a +mx include:_spf.elasticemail.com +include:spf.protection.outlook.com +ip4:1.202.225.48 +ip4:1.202.247.156 include:aspmx.pardot.com ~all
Cloud / SaaS Services Detected
Microsoft 365 KnowBe4 DocuSign Sophos

Leak Screenshot:

Leak Screenshot