Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo WORLEY.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: AU

Description:

[AI generated] Worley.com is an Australian company providing professional project and asset services in energy, chemical and resources sectors. They aid their customers through entire asset life-cycle, providing global solutions for design and build of new assets; as well as offer maintenance, repair, operations and decommissioning services to optimize their customers' performance.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 124

Compromised Users: 92

Third Party Employee Credentials: 322


External Attack Surface: 74


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • mxb-001ae301.gslb.pphosted.com.
  • mxa-001ae301.gslb.pphosted.com.
TXT Records
  • v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com;ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com
  • ms-domain-verification=81f1a58b-1535-4b9b-b0f1-a9ea1cbe7c9d
  • ms-domain-verification=d7e1b126-9e85-496d-94b3-70063a48a4f0
  • ms-domain-verification=b0549325-149d-4ee2-9e65-81f8501d21e0
  • pardot982812=70e35d200d506626491eeff588e9eee503fe0b442d242241a3da84506379113c
  • docusign=2a2235ff-fd44-4f33-a286-ed6692efe832
  • MS=ms42787008
  • ms-domain-verification=876926ed-dc53-45e2-9d27-cc31f650f925
  • ms-domain-verification=f648eb8a-930c-43bd-995d-0c289223e28e
  • ms-domain-verification=5c391ea0-35da-4e00-bd68-fc3a76e0a186
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com include:spf.protection.outlook.com ~all
  • apple-domain-verification=v9QSpcZS3IF2NtUs
  • ms-domain-verification=c37b1199-e2ce-4299-b214-21abf1e7069b
  • google-site-verification=KL-jbOCge54v5ug3ZVWfCivDxZFjCijZfu9galXkhho
  • docusign=cee51841-09d0-454d-87df-77b3e49e435d
  • pexip-ms-tenant-domain-verification=bb792c5d-6eb4-4b49-a4fb-bb27b40e954c
  • nitro-verification-code=LTk1NzU2OTcyODEzNDAyOTc3Ng==
  • google-site-verification=QdMYWQ7T4hIel08BLUb8t192kmhFaT0-vIGEnmvnR8Q
  • dell-technologies-domain-verification=worley.com_8048d1d8-bba9-4b2c-9fcf-84ff1f086455_1682624741
  • cisco-ci-domain-verification=72fada663ee02de96202b00157b5f35cd9c9a83599a3c581fce3140e67cfb402
Cloud / SaaS Services Detected
Apple Microsoft 365 Salesforce Cisco DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot