Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

VOLARIS.COM

VOLARIS.COM

Group Clop
Discovered 2023-03-23 12:35 UTC
Est. attack date 2023-03-23

Infostealer activity detected by HudsonRock

Compromised Employees: 17

Compromised Users: 30130

Third Party Employee Credentials: 159


External Attack Surface: 110


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 6bc839432c2995b1b0a7dedcc0c1664bc55c9a55adc67e4337f8ee6df3fac62evolaris.com.whoisproxy.org
  • 6bc839432c2995b1b0a7dedcc0c1664bdf809a69aaf103670ec1e1d2532d896bvolaris.com.whoisproxy.org
  • trustandsafetysupport.aws.com
  • 6bc839432c2995b1b0a7dedcc0c1664be4c1d691a9d35f2f946ce4561a85daebvolaris.com.whoisproxy.org
  • 6bc839432c2995b1b0a7dedcc0c1664b96e3373f750afb165b4550bd6784b764volaris.com.whoisproxy.org
MX Records
  • mxa-00693e01.gslb.pphosted.com. Proofpoint
  • mxb-00693e01.gslb.pphosted.com. Proofpoint
TXT Records
  • atlassian-domain-verification=/dOu4DGVuibXj5Fy9LXRQ2Ov07Tjg4iaQBtAprk87VKmKBPfQtpunvK13fIIDh2z
  • google-site-verification=eo_4xwkkDeDsWtl9okTnALQ0ZEkcz0emNzhkTEaEXJM
  • 40LFKXK2VN5162POOGH3KBAYULOZGX7EXU0MBU1X
  • D8895313
  • google-site-verification=ATu5WMd805peZ5nbhSPNOVbM2j3L5wkjROzp7gGR-MU
  • MS=ms30673672
  • atlassian-sending-domain-verification=cce33b6d-d30d-405a-92c3-146b356742ec
  • 358822c3cddc4375b2aaa08961519079
  • nup1l3k56bsak94k1igtles1gj
  • google-site-verification=1LfsowhFmaygpXvwyw7wLCodX8m3cQX-sukyEf9qv_o
  • XTQS72GWDU9QJ1GFYNP8VPF6S5PUMA0YVGV1QBTF
  • google-site-verification=TlmyWYe82tRuM_VV0WyCkbf6p9Up-3rCD1atuENs6-E
  • google-site-verification=Oom5U- DcjpGkxm8LctYvUddSWwitV0lNih99Yu-rtUw
  • v=spf1 ip4:52.201.86.119 ip4:100.24.214.111 ip4:192.161.146.64/28 ip4:198.11.248.123 ip4:169.53.3.154 include:spf.protection.outlook.com include:_spf-dc4.sapsf.com include:spf-00693e01.pphosted.com" " include:mail.zendesk.com include:_spf.atlassian.net include:_spf.psm.knowbe4.com include:_spf.salesforce.com ~all
  • google-gws-recovery-domain-verification=40897738
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Salesforce KnowBe4 Zendesk Proofpoint

Leak Screenshot:

Leak Screenshot