Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo TRANETECHNOLOGIES.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: US

Description:

[AI generated] N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 211

Third Party Employee Credentials: 70


External Attack Surface: 48


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • trustandsafety support.aws.com
  • 1d94e9dc-f8a0-4207-9919-c07dfe7d527b identity-protect.org
MX Records
  • mxb-00240e01.gslb.pphosted.com.
  • mxa-00240e01.gslb.pphosted.com.
TXT Records
  • apple-domain-verification=CU7ybs1v1CS5lQfF
  • amazonses:3ctkc3p+fRaU/G2jR/lWtqVideauAqWqUVB8KZLIyXc=
  • google-site-verification=KFGzmvhFWFQlDHOmBD-U4vLxxIJuIbHMXoN0yonB5YY
  • ibmid=948f0388-04ab-4f44-af57-089e9b4c5421
  • amazonses:zcxqwyMo6KE5AAy/pmVFknQaS6A/Ca8frFm67ZCeBHM=
  • lucid-verification=FPgCqcRuzgehcT9TDQXPQAGy
  • teamviewer-sso-verification=6ef619aabeb2467e9a136ffe08c8318d
  • \"2aamitjuhb38issoscbegbsssh\
  • google-site-verification=zJ7V8YbXzEDcYp4OIrSmW0dMij7LV85GmEv3nPJm8ro
  • atlassian-domain-verification=Qz82GvcVdTdBde8f9UKIOkpjBnPj84fpLZr3bWO2Wr2qezmasqv8WnvPP8oO/XAT
  • adobe-idp-site-verification=0c16002a9ebe2a28b2226860a9a236b633630fad7036a572dca0816a682de520
  • onx=241033d0-bddc-4fb8-8f27-8fcf7f038a0b
  • postman-domain-verification=d794e24a8dd529fbf733e014deb27bd295454563a92e188065a39da557bc432fbc694b1d0b4e2915b7800a304783d24c0ac58a79af9267ee441b872d1f8447ff
  • Cisco-ci-domain-verification=235af847a1b95d60bd9b3fab41ac3213dac6ccdb7441610d4a7efad433efe424
  • onx=a99f07e9-2cbe-4e99-9e96-c3d734671a4f
  • amazonses:QfH336tcRAA9+6R/IQys/TJU9TOaX1L6AUwURhjAnrw=
  • atlassian-sending-domain-verification=438b28e0-1c35-4281-a22f-f99c956995ad
  • wiz-domain-verification=fb55fd42b1fb1dc8d622acd69395eed67f65f7c7be4282515a608f7893e816e6
  • figma-domain-verification=db8c8a74fdfacc4ef6d99a24413553ec12aaf0f60166b0c0bfa87f992afdb4cd-1723829474
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com include:mktomail.com ~all
  • miro-verification=f83c05ccf93d71c66ef3d4c44ad9d708d72811dc
  • nintex.5dc57bf0b77b3f0e11bae0ae
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Marketo Miro Teamviewer Cisco Proofpoint

Leak Screenshot:

Leak Screenshot