Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

The Lutheran World Federation

lutheranworld.org

Group Rhysida
Discovered 2024-01-06
Est. attack date 2024-01-06
Country CH
City Le Grand-Saconnex

Description:

The Lutheran World Federation

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 12

Third Party Employee Credentials: 101


External Attack Surface: 3


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • registrar-abuse@cloudflare.com
MX Records
  • lutheranworld-org.mail.protection.outlook.com.
TXT Records
  • MS=ms81775045
  • T/fSkCcYOTDI2izMl81xNi1aDDep+kcWvKuixyQQYlKbwCphcm/9nLS2rELvwJdoY/aLEuR21SfAx0JXzjtmDQ==
  • anthropic-domain-verification-4cnfg5=a9uQnM0H8RntoqWri8dIELoRj
  • apple-domain-verification=C2lDDarKYwerlvbe
  • d9573c0e-281f-4eda-ae5d-a6d62636ed0c
  • docusign=69c5fecc-a991-41cd-9456-373382588891
  • protonmail-verification=fcf37b9d08874b515f7631b924e9158639805761
  • v=spf1 mx ip4:193.73.242.0/24 ip4:54.228.196.38/32 ip4:85.222.158.192/28 include:_spf.odoo.com include:spf.protection.outlook.com include:spf.event-works.com include:spf.mandrillapp.com -all
Cloud / SaaS Services Detected
Apple Microsoft 365 Proton Mandrill DocuSign