Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Play
Discovered 2024-01-06 08:47 UTC
Est. attack date 2023-12-21
Country US

Description:

United States

Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 5

Third Party Employee Credentials: 7


External Attack Surface: 2


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • mx-02-us-west-2.prod.hydra.sophos.com.
  • mx-01-us-west-2.prod.hydra.sophos.com.
TXT Records
  • 00DfI00000J9hHO=1TBPW0000000ALx
  • 00Dfl000003boQj=1TBVs0000000G9g
  • facebook-domain-verification=gseezv2cmciurek4a1a4bfpoy9beb1
  • 00DHs000001QKEw=1TBWP0000004S5l
  • 00DHp000002ZEHp=1TBVL00000007Pi
  • 00Da500001O3AcT=1TBV500000001oz
  • 00DKd00000GpoA5=1TBPo000000076N
  • 00Dao00001VZdrZ=1TBcv0000000JM1
  • 00Dal00001MWbYj=1TBV40000000Dzl
  • 00Dfk000003On97=1TBVq0000000eog
  • 00Dal00001BJbGq=1TBVs0000000CZ5
  • 00Dfn00000CMqh5=1TBan0000000Gcf
  • 00Dfh000001vbK1=1TBaJ00000005PW
  • 00Dam00001XQzX9=1TBWj0000000Ac5
  • google-site-verification=w1tOyr6eNopeOIuYH843mCEjB1-5TNPL-moCy0dppMA
  • 00Dfi000003yian=1TBVq0000000e77
  • 00D4x000000KeB4=1TBUS00000004lB
  • 00DfJ00000Z57kf=1TBPn0000000HId
  • 00D6g0000023lTH=1TBUW00000009kr
  • ZOOM_verify_7s04naa0Tlqu2nQFYymHBg
  • cj8r62610iqpu1l745tleqc15q
  • 00DfK00000Apd55=1TBPd0000000Ipm
  • 00Dfn00000C9ft3=1TBan0000000KbR
  • OFF* tvprod.azurewebsites.net
  • 00Da500001TEesQ=1TBVs0000000BGQ
  • 00Dam00001WPHBm=1TBWj0000000ASQ
  • google-site-verification=_ZctOH7b_czIDo_IiStMBoLLljSdT1SXs2C6ne8oaQM
  • y7RocK2sYEY3zd5EJVxeoHKExExstt3Ap/mZDuO9+jTyVaRZ22ACOl8SFm9GoY+6BqCLRxDPP8+8C9w/VR8koA==
  • 00Da500001S66oT=1TBVr0000000AkA
  • 00Dfo000003aN62=1TBVs0000000GCt
  • 00Dam00001aSeN3=1TBWj0000000Dms
  • 00Dam00001afR3p=1TBWj0000000Efh
  • 00DDo000000sHfg=1TBUP00000009Xy
  • twilio-domain-verification=f473a3e6f9a09aea302a1c09af067e7f
  • 00DfI00000NxXtV=1TBQU0000000DGb
  • 00DKj000001CRcd=1TBaZ00000008Lm
  • 00D4W000001UnEE=1TBTV00000002jN
  • apple-domain-verification=YOFyGvqX2QfDkN8H
  • v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC89Gi3F6Hymft7DxHukn+GeNC4I2CivC8ZTbzvHrCXmtziE9VYPVtvN8aCdyTC6vImNo44HxlC3Yp6PI+i9Fv4hgJufg2XqdKzRgL7zp9VKBg4JlBkgpGco89ggr3k1feOT/AH/CIaCaea6oXpxKG7DKv3kKzpjXAwdvxxfXRs5wIDAQAB; n=1024,1455675410,1" "471400210
  • dv2lqefjj7bokq8o5p68n699hj
  • 00DHp000009vLF0=1TBWP0000002ztq
  • 00DKb000000OMjW=1TBUv00000002bK
  • 00DfI00000PZtWj=1TBPr000000056A
  • v=spf1 mx ip4:72.32.154.224/27 ip4:174.143.64.168/28 include:mktomail.com include:spf.protection.outlook.com include:_spf_uswest2.prod.hydra.sophos.com ~all
  • v=verifydomain MS=8911074
  • 00DfJ00000AcU9l=1TBPd0000000G9e
  • 00D4W000008I3rC=1TBUh00000004DJ
  • anthropic-domain-verification-qpzrc1=5GLrHZXv9JVderxnQgZ5ddEBF
  • sophos-domain-verification=319d1d5922335b1d08aea6574df64cabfcaea855f9bc9f67b88a7ea7fbc4c708
  • 00DDm000000HVZA=1TBUN000000071W
  • 00D4W000006jBqY=1TBUq00000002Q4
  • google-site-verification=e6l0UjVD1DuWA6oajDGAtkK-pKZVxZygoOqMQoCSQHs
  • 00Dao00001SgsL9=1TBcv0000000Ee5
  • 00Dal00001PY29Y=1TBVx00000005pJ
  • 00D5f00000882Hs=1TBTN00000006n2
  • openai-domain-verification=dv-RRTBbuRMmHsUXzbSUGIGuGNR
  • 00Dao000019C8Jt=1TBVp0000000BoI
  • 00DHr000003YYXa=1TBPs00000007Xm
  • e2ma-verification=frzcb
  • 00Dfk000003tcfd=1TBVu0000000EPa
Cloud / SaaS Services Detected
Apple Microsoft 365 Anthropic OpenIA Marketo Twilio Sophos Zoom

Leak Screenshot:

Leak Screenshot