Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo PenLink

Group: Play

Discovered by ransomware.live: 2026-02-22

Estimated attack date: 2026-02-22

Country: US

Description:

United States


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 1


External Attack Surface: 5


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • us-smtp-inbound-2.mimecast.com.
  • us-smtp-inbound-1.mimecast.com.
TXT Records
  • jamf-site-verification=L6zA1wb63kkSK1QrFv-9qg
  • MS=ms15340479
  • nc8wt4d7d4d7223rnj3z6qpny5zj2d4h
  • wvxqbl13pd7v76yll1l2s7673tz8gchy
  • _o4vwqprv94jcnv7whtukbdg83469eq3
  • sending_domain652333=9c469de7a4ae6ccec884faae412c9ffe8b9e12b73eb39ed7e02f318dc64e3cc0
  • 8E6C095772A8E265E70B35A23C3B92167F53C5CFF71F3905C1330F9FEF207A8C
  • _bq2c5syy3ft79fz5ekglothj78kacp1
  • 00df4000004m3kdeaq
  • cursor-domain-verification-0e7y30=7at1WMjVBSM5EZ2wPY3cTEZA2
  • wiz-domain-verification=9524a0badfcca25e9650750ee55137e247e6e8c35e2012e9d00be482e5f2cf1c
  • have-i-been-pwned-verification=00ce8e6d9bdba955f864d5931dea8c82
  • amazon-business-verification=fded1d5c4f912dd5c897bb0a665fac933631da2ccf09555deecbbbce8b8396d3
  • v=spf1 mx include:_netblocks.mimecast.com include:spf.protection.outlook.com include:amazonses.com include:_spf.salesforce.com include:aspmx.pardot.com include:docebosaas.com -all
  • BaZ/HjXioRSebZ73DMy7rbRDso/CSUq941LH7lwrNKTvTYoGcS7tpArGm4WzNe/NU9bNw2quJ0bDdDQmwG2dJA==
  • openai-domain-verification=dv-spqp3M0h4IdECtXZ4Hfj7PrV
  • wiz-domain-verification=bdafb723759674812bf9d9f884d7226a3b0f397afdca2bb0d52c1fca44c8fd19
  • 581261DAACE39536BB5C2D0615784ABEC1EEBE8D1745DE9ECE2A3288FB89F568
  • invisionapp-verification=0014195372053467682232477821229720031848
  • ncf5jql2f4ptc6qczgjqtbg7tsrypr4d
  • 7D267B32A66DB3DC89CA11C654770DCCEC82B085C18821B36AEBE23D0AE70AAD
  • cisco-ci-domain-verification=3be5d61118b746023626ba3765b44ab38012b76c84d0a8943215ea539c06749d
  • apple-domain-verification=e8zLCkk3wYZTsmKP
  • asv=dbfef2971dbc418f661255d3157fa460
  • Foxit-domain-verification=e2814dfd1e3afce888eeafdacc1d05a0
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail Microsoft 365 Salesforce JamF Cisco Mimecast Have I Been Pwned

Leak Screenshot:

Leak Screenshot