Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo WOODPLC.COM

Group: Clop

Discovered by ransomware.live: 2025-11-07

Estimated attack date: 2025-11-07

Country: GB

Description:

[AI generated] Wood PLC is a leading global project, engineering and technical services company headquartered in the UK. Its diverse portfolio spans energy, chemicals, industrial, environmental and infrastructure markets. They provide performance-driven solutions throughout the asset life cycle, from concept to decommissioning, including consulting, projects and operations.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 40

Compromised Users: 129

Third Party Employee Credentials: 369


External Attack Surface: 33


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse safenames.net
  • 190pzge37wm4 idp.email
  • hostmaster safenames.net
MX Records
  • woodplc-com.mail.protection.outlook.com.
TXT Records
  • v=spf1 ip4:207.11.242.3 ip4:207.11.243.2 ip4:103.15.170.112 ip4:94.31.41.130 ip4:217.18.206.32 ip4:217.18.206.33 ip4:217.18.206.34 ip4:217.18.206.40 ip4:217.18.206.43 ip4:217.18.206.44 ip4:149.72.249.107 ip4:167.89.87.16 include:spf.protection.outlook.co" "m include:servers.mcsv.net include:spf_c.oraclecloud.com include:amazonses.com -all
  • autodesk-domain-verification=MwBeGLyHTsahhlR3P8o7
  • _2qyjxeg911qt3kn3ue4zyae1ymtmzya
  • _936pcs4lni3l9wb37wzefgtxdyx15e5
  • adobe-idp-site-verification=5650bb45b2783fc2ee18d1fb9defbf87e9dd576869f58bd3a430772e0e80223c
  • MS=ms64579584
  • m0t6lcgb8h2pnhcxhrgh6q4y6sbz7q2k
  • performance-review.azurewebsites.net
  • _5ajwioip4pmuoxlwhph0noydp6f5x8q
  • 8D9E860B5AF16C304ADFDC2AD8A800654ACCEBCC03DDE043111B21704E496030
  • f0cq4m5f8lj008dd3fgb287bq90dsfqm
  • 3fd7tcvmq4jlzktk5g6lw6wdw45gwflf
  • ms-domain-verification=b95d0d90-e813-4b82-bf1c-0f3e9a1eed38
  • _olm7ce0qfpm7d71yqsfvmekyslnhdeg
  • _bgoauurrtphdyyknejrxcicd7prmnig
  • fe85afa69fcf480eb2be7136355db29a
  • cisco-ci-domain-verification=4641f4accb69d30a33f0e77ad5bf7f362445219d3bce86d66470866124c35b13
  • dell-technologies-domain-verification=woodplc.com_69c1707a-13aa-4cbf-b4db-d10636be84b0_1740143196
  • Google-site-verification=6acQ-R-_mweiFOtn5NbWcmDeBZRj-3hPudYmR3k_85o
  • 90d83aafb3d14c5cbb1b3e13201005e2
  • n2xzcw1nqpy2nz91vjsz08jfmlj0qsck
  • nitro-verification-code=MTg5Nzk1NzA5NDg3MTI5NTA0Mw==
  • globalsign-domain-verification=100C11464A52DDF43DEDEEB55EA77BF2
  • tc9djhgcclx7kfkrmc8fdlxh7b0xqbyh
  • ckghkrgpvh7n18vfx06q8p89yq3tggqx
  • 3B81BF99A471B6C92070895F84ECE3ECDBF81102749D95A6468C44631946CE5E
  • zdvunrw.impervadns.net
  • _pqf4voopjyukkcns71tjjm049hi7jn1
  • _0y69vg9wnbgcm0e9mj4n5tda97aru8k
  • rjczl0g17splv1cfsvf5sfncg601szf6
  • h41pbzqt3g8xm2ck04ntdy3qvj5crvw7
  • 2462690
  • YXp1cmVfY29tbW9uX2V1
  • google-gws-recovery-domain-verification=62894501
  • onetrust-domain-verification=b888f022324f4c9e9bf5b91138169044
Cloud / SaaS Services Detected
Adobe Amazon SES/WorkMail Mailchimp Microsoft 365 Autodesk Oracle Cloud Cisco OneTrust

Leak Screenshot:

Leak Screenshot