Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo WEATHER.COM

Group: Clop

Discovered by ransomware.live: 2026-01-25

Estimated attack date: 2026-01-25

Country: US

Description:

[AI generated] "Weather.com" is primarily recognized for providing comprehensive weather forecasts and information online. It is owned by IBM and forms a part of The Weather Company, offering localized forecasts for places all over the world. Besides weather updates, it furnishes weather-related news, insights, educational content, and safety tips. In addition to its web presence, the service is accessible via smartphone apps and a TV channel, The Weather Channel.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 16

Compromised Users: 3640

Third Party Employee Credentials: 3


External Attack Surface: 97


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@cscglobal.com
MX Records
  • alt1.aspmx.l.google.com.
  • aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • aspmx3.googlemail.com.
  • aspmx2.googlemail.com.
TXT Records
  • google-site-verification=o4PbIFpHUUVW4AchOXwIsM8rUJsdNvLm3UR3OUdZyqM
  • apple-domain-verification=Kt9gLmYacIfnO9IF
  • 9f14672tfzjd965slzkm133vsr8j21gc
  • google-site-verification=i-J-BDfU7ek0Y-FJHtkqvf9BZcUBg6s8VshVCv_LUJo
  • mongodb-site-verification=dncd3pi5Qbt17W4RaM7hD0THvIco77Nv
  • 00da0000000l1vmma0
  • asv=54ca4d7869945159566edeb424193599
  • google-site-verification=Dk7Le19ZpfucXUuXR5E56YbGjvnU6LMLhGL3rOUBmAU
  • lucid-verification=mfz.QDV@xnf*ntc123gta
  • 1password-site-verification=ARV7XCTH2ZEZFPX75UY55TK3LM
  • new-relic-domain-verification=0f631387bf014cffae10bc9b979b7056
  • adobe-idp-site-verification=779780a8c92cfd098df1f76f573b0ab2747d3123de4694cc75fdb12f10264b35
  • MS=ms39994037
  • google-site-verification=bnuH4zPufd7ChB6NQnrMbsxaifcIOzqDbKkFQFPspNA
  • atlassian-domain-verification=x4mGWF20kUREoGAPK0AAelillieNsnLqv2j4/2A3iDPRcqHeMJ3L2AT4raKJBwRY
  • slack-domain-verification=UoVswhJuJLwGELpIn564H0ty7Fgg6mvAI28itovF
  • google-site-verification=uNTSYiIzOLrbUa6_Cug8_8j1gt8qJBBe5iD32gqZmjc
  • browserstack-domain-verification=981e7d75-519d-4b34-959a-b020c6ea774f
  • smartsheet-site-validation=HmF6Si2DOd3yA6Re-KgxDRw6PRnJ9FxX
  • happeo-site-verification=2b54fd7e1da04d29921d800a2277ad4e
  • hvntc1c3swgf9n72hympkt76bjj9dj1f
  • adobe-idp-site-verification=4f3e3a355b58e39ed82785f9fd8789cf479b6f9bf83845691110eb21acc017a6
  • airtable-verification=11df1efe5bdb14ba3e891f0f9bec6d67
  • amazonses:RBGPvHrsj9+f8y4UZ/RiSZ1SECUDOCm4aaFBColrE7I=
  • v=spf1 ip4:96.8.80.136 ip4:96.8.80.135 ip4:96.8.82.135 ip4:96.8.84.135 ip4:96.8.88.240 ip4:208.106.251.89 ip4:65.212.71.11 ip4:96.8.93.78 ip4:96.8.93.79 ip4:96.8.92.25 ip4:185.57.95.81 ip4:54.208.146.123 ip4:52.90.110.211 ip4:54.174.191.95 a:zgateway.zuor" "a.com include:_spf.google.com include:amazonses.com include:mktomail.com include:spf.mandrillapp.com include:_spf.salesforce.com include:apexportal.nbcuni.com ~all
  • docusign=002393a4-7df4-4031-83c1-98aeafa93c9f
  • google-site-verification=HcrGJjb9usn0d4pKJBL_HnMMnGnswKoiS_33CczKbZk
  • jamf-site-verification=lQUlN-k2oNrqeiPG8N0emA
  • knowbe4-site-verification=ecfa587cd67b3b63076be6739be0b0a9
  • onetrust-domain-verification=ef12e9cda41f4f47b0d581f1b370690d
  • atlassian-sending-domain-verification=51201d1e-525c-4687-8a0e-98035a0f881b
  • facebook-domain-verification=99utolohhvsbcdxkj52qgala019hyj
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Microsoft 365 Salesforce Slack Marketo JamF KnowBe4 Mandrill OneTrust DocuSign

Leak Screenshot:

Leak Screenshot