Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo WITS.AC.ZA

Group: Clop

Discovered by ransomware.live: 2025-10-27

Estimated attack date: 2025-10-27

Country: ZA

Description:

[AI generated] WITS.AC.ZA is the online domain for the University of the Witwatersrand, located in Johannesburg, South Africa. Also known as Wits University, it offers undergraduate and postgraduate courses across a wide range of disciplines, such as commerce, law, management, humanities, health sciences and more. Known for its research-intensive focus, Wits University is one of Africa's top learning institutions.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 187

Compromised Users: 9171

Third Party Employee Credentials: 687


External Attack Surface: 144


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mx1.hc2078-71.eu.iphmx.com.
  • mx2.hc2078-71.eu.iphmx.com.
TXT Records
  • ufO1sh3mohMMqJBoKSWr0J8ITf4uYBRycvlJ/Rp+/n7dr5dM5hNcnVFosYHH7xdFbp/LxHoX1yIS4habPmYEXw==
  • MS=ms99071949
  • everlytic-site-verification=03e9727a512982420d413604dde6a1e7266529c9591e9a7d41543b5f224253bcaad80666e060fc2140e1cc74500ce6721246d29593fbfe49a737a381c95d2305
  • everlytic-site-verification=2148213de6eb76c2d3226c178c8ebbfcfd2d2d9420bd2fe4878c84bf7a4861b12d59ec25d3865cd5427ec66e09ec3f720fe1e0a71f6593ccd7167cb7ec9370f6
  • ciscocidomainverification=63c04492f024d2480ae4156c1fedb4a8286c6ebbfee25eadbf13195807c8f7fb
  • everlytic-site-verification=362dc54fe74c74b43832e47735e38676a327c8b182fbc04791e1f07c0596a1736f0062e8d31a2e942d54e17b34e198df6d8346166d6a684d9183fb18882d8d94
  • google-site-verification=cQQjTdb5QMfOog-Dh2PJPjnH6P-_hPWLXaHKneL0nFA
  • CwvL2zuIZmMJzSwY6nzsTSB2lI+Y/J5lpDGCtsuHkf8MCHsPCdPklNevwRLwr3AlRDMwbz8R1WvCuBHvljaChA==
  • atlassian-domain-verification=cWDULScpPExdeU3ZIonqa1mKlEFOWVpPfasuKXs/iWTPSlzy/uagB4YLDAEkCmLa
  • v=spf1 include:tdbpbvu13f.powerspf.com include:26606987.spf07.hubspotemail.net ~all
Cloud / SaaS Services Detected
Atlassian HubSpot Microsoft 365

Leak Screenshot:

Leak Screenshot