Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo The Cressi

Group: Qilin

Discovered by ransomware.live: 2026-01-08

Estimated attack date: 2026-01-08

Country: IT

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 7

Third Party Employee Credentials: 2


External Attack Surface: 7


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@tucows.com
MX Records
  • cressi-com.mail.protection.outlook.com.
TXT Records
  • v=spf1 include:spf.protection.outlook.com a include:_spf.arubabusiness.it ip4:78.4.94.34 a:mailing.aldersoft.com ip4:31.14.143.32/28 ip4:93.57.63.210 include:turbo-smtp.com include:pro.turbo-smtp.com ip4:5.249.133.215 ~all
  • ri49ch6cps1h60pv6150g88t64
  • MS=ms59398328
  • sophos-domain-verification=27192791e3802e7f8631d2352503c337caec43ce
Cloud / SaaS Services Detected
Microsoft 365 Sophos

Leak Screenshot:

Leak Screenshot