Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

USG.EDU

USG.EDU

Group Clop
Discovered 2023-07-07 16:24 UTC
Est. attack date 2023-07-07
Country US

Description:

University System of Georgia

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 2424

Third Party Employee Credentials: 6


External Attack Surface: 102


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • usg-edu.mail.protection.outlook.com. Microsoft 365
TXT Records
  • zoho-verification=zb39991105.zmverify.zoho.com
  • onx=31da5f57-d404-4621-83ce-4848a8cae799
  • MS=ms86634768
  • adobe-idp-site-verification=3a92c0ee648d30454e77eb19ddba76cb56e4a2dc86b35145814f3f863fb4f30f
  • docusign=1f446f77-d923-4151-a01b-0c0c989901d8
  • apple-domain-verification=91winymMM4uUy15x
  • jamf-site-verification=JJ78M5cywXGtAPpIHXtafQ
  • Ro9fdyvnXjUr0OzgG3QHmfbswNHNDY/SW5ZqX/Az0Q228tsmuNYnfa3PRDXTmMJX9+otFzowI6FRR2fND8APuw==
  • status-page-domain-verification=0l3zbwtpnnl1
  • v=spf1 ip4:168.16.103.25 ip4:168.16.103.27 ip4:168.16.103.36 ip4:54.240.33.32 ip4:54.240.33.33 ip4:54.240.33.34 ip4:168.25.0.0/16 ip4:168.24.0.0/16 ip4:131.144.7.204/30 ip4:168.16.64.150 ip4:74.84.145.40 ip4:74.84.145.39 ip4:50.31.156.96/27 ip4:104.245.20" "9.192/26 ip4:50.31.205.204/30 ip4:50.31.205.0/24 ip4:168.16.103.42 ip4:168.29.144.102 include:spf.protection.outlook.com include:servers.mcsv.net include:stspg-customer.com -all
  • MS=ms98242169
  • intersight=71ee61d70f7c8536a552fcb7636874c6cc8278a752d30a8b5a60288e5616c28f
  • atlassian-domain-verification=kC1Y7pa4Z/skOad7ZBAKsmywwvZCKn8aUs2t5y5afxPwhB7nZnEaTUnmON2KGrhl
  • google-site-verification=daS8eAH9ikmVCvdlEftkkDYXe06LKAPAYp7MQWokB9U
  • status-page-domain-verification=pyyc4r8cbddr
  • docusign=328403a3-21f9-47de-aae3-0cd7486eea82
Cloud / SaaS Services Detected
Adobe Apple Atlassian Mailchimp Microsoft 365 JamF Zoho Campaigns DocuSign

Leak Screenshot:

Leak Screenshot