Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Hunters
Discovered 2025-02-06
Est. attack date 2025-02-06
Country US
City Greenville

Description:

Exfiltraded data : yes - Encrypted data : no

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 42

Third Party Employee Credentials: 34


External Attack Surface: 7


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@cscglobal.com
MX Records
  • robertshaw-com.mail.protection.outlook.com.
TXT Records
  • cpsqt5rkkcmsvvx1n9xy5kq5905my8wj
  • h2hbwlrrccmjb1c7ygcxqcjj9wqhj0qz
  • k1bq7mh62zkpbcnt75g1lc8dts4v41h8
  • kgbs6gcg0sh17n5w6sswd8ljdd71qfqj
  • q3bqzqkw6hln0gr5kvc1z1fzbg6scrfy
  • tjwgr7yvln5mhq7rc028dmknryfxgv77
  • facebook-domain-verification=6zz4tmz7wv5uhfgym5o36a1uxag210
  • teamviewer-sso-verification=ddcebb1923fd45db88cd388f0d6cdc42
  • x2e0i9SNj964BTH19IzjBEYiKqs4/AOqgkELD9W9CDriuWovp3qgTzvKS20uV8kudvwbSH8ZiS824t5HKCFZYg==
  • atlassian-domain-verification=/CdgFvzkQ7Xc2oHfSRnpYwTF07Z1DUbqIclbDEwaPuxa6EZz26B/jbUARFrMO4vQ
  • v=spf1 include:spf.protection.outlook.com ip4:80.188.30.170 ip4:40.136.185.54 ip4:64.47.197.9 ip4:38.97.236.0/24 ip4:64.106.168.235 ip4:46.243.56.31 ip4:54.173.211.88 include:_spf.salesforce.com include:auth.msgapp.com include:24059946.spf01.hubspotemail" ".net ~all
  • MS=ms96811119
  • 59qvh8rx0g5kqx82874g0z20d4tqpxx2
  • 8blkpcs9nmzhh9jy54tkbjl2880352sc
  • 9wk0kjgs4r00twtp21z9ksf1b0j9r5pc
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Salesforce Teamviewer

Leak Screenshot:

Leak Screenshot