Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-10-03 15:42 UTC
Est. attack date 2025-07-14
Country US

Description:

[AI generated] Walgreens is an American pharmaceutical retail company, established in 1901. It is one of the largest US drugstore chains, known for selling prescription and non-prescription drugs, health and wellness products, cosmetics, and groceries. It also offers health services like immunization and patient care clinics. Often, Walgreens operates 24/7 to allow customers access to their products and services at any hour.

Infostealer activity detected by HudsonRock

Compromised Employees: 82

Compromised Users: 53771

Third Party Employee Credentials: 52


External Attack Surface: 134


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mx1.hc2985-66.iphmx.com. Cisco/IronPort
  • mx2.hc2985-66.iphmx.com. Cisco/IronPort
TXT Records
  • pardot61522=de4fc0352c1a81bfee1f8d249e1ac466901c91e5d1d5f98495f5014089021a7d
  • _u2z1oknchyyemwm6g07ujn5oa2pg5j0
  • infoblox-domain-mastery=c9428a2cf511af668f57a9e155d46ab452c800005c63a98332544885a19dc96162
  • google-site-verification=Ip9t68zEN4Pu0b1WGjZhuqW5TejqJFuB62Y-axOmVEM
  • onetrust-domain-verification=b4292fece1544cc5ac0adbd23db88d87
  • uber-domain-verification=80c45927-79a5-4e11-b898-5f80f42f8ddf
  • slack-domain-verification=59WikB0MivfpD8YkJSklaExPMULdVn8kZaFwmaEQ
  • v=spf1 mx a exists:%{i}.spf.hc2985-66.iphmx.com ip4:204.15.118.179 ip4:204.15.118.161 ip4:199.241.116.20 ip4:131.124.12.147 ip4:204.15.118.155 ip4:204.15.118.158 ip4:159.183.171.24 ip4:34.211.93.3 -all
  • b4292fece1544cc5ac0adbd23db88d87
  • apple-domain-verification=5wXrzXaXc9FC7wv7
  • facebook-domain-verification=9qfi4d4w1irc6eeahec9kydvsiab54
  • docusign=127cf9ae-f6d7-4b9d-bab5-66901c2765ed
  • mongodb-site-verification=sp4CVawij0Dg08olZPwoMw4A6KjwvYNT
  • Dynatrace-site-verification=d8462443-43f8-4196-a1d9-14666c3b1ade__9ndmbrvq8qmp1913c88biqokl7
  • Dynatrace-site-verification=90500b9a-bd85-4570-9104-9f5d47df7acd__gq6b56esnnv0hg7ffrpjnh76l5
  • knowbe4-site-verification=adce7473628ec1ac45418d42a0fe33aa
  • fe533009bf4f4afbb8374f097733cefa
  • _zr9gs4j0ullnq7kma7o9p37b7m1x2a0
  • cisco-ci-domain-verification=7d6da6349d05264079634e1f78aee2b5dc277b5fa2e249cabe74d502c687f7ab
  • did=did:plc:gncuhzcwzbtyj4uo5qbgvcw3
  • adobe-idp-site-verification=f3d3a39763d085bd2b18e6a31838ede28cfd528a6892da0511b84b16085a6bf0
  • Dynatrace-site-verification=84606470-b7f9-4d5c-92d4-040eac391954__3bm2lbljg2icttlbvi5svbn8c5
  • T5CTBtfMVr2v3DjUjvNzxCDq5aXeApUB6vQ0UeP4KR+eoT5ieU+KHTKiOvYIFi+L0KGWxzkxiMSIbc3nCFWPNQ==
  • axway-amplify=ecd943ad-1ca0-41f2-8eb0-69582db6d6fe
  • onetrust-domain-verification=45537cffc2f44b21b9c99fbccb4f2a16
  • onetrust-domain-verification=1249e63c90544049ad21bd4170c266a3
Cloud / SaaS Services Detected
Adobe Apple Salesforce Slack KnowBe4 Cisco OneTrust DocuSign

Leak Screenshot:

Leak Screenshot