Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo VINSON & ELKINS LLP

Group: D4rk4rmy

Discovered by ransomware.live: 2025-08-16

Estimated attack date: 2025-08-16

Country: US

Description:

https://www.velaw.com Vinson & Elkins is a century-strong global law firm that partners with leading companies across key industries on wide‑ranging, complex matters. Blending deep experience with forward‑thinking counsel and close client collaboration, the firm helps organizations pursue goals and navigate…


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 5

Third Party Employee Credentials: 5


External Attack Surface: 3


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • mxa-00197001.gslb.pphosted.com.
  • mxb-00197001.gslb.pphosted.com.
TXT Records
  • google-site-verification=Et6iATF9rZTnnCIfYii8TGnmwqeJ5EqkDrhFtQGvflI
  • lf5+Hgg2UUOwBbnYOJ+fiKbI0DSw99ndpH/xI2RMkS/0gexVQN4GM98NFs36T0NSnzTwD7bc2Ilrm/SeyopofA==
  • v=spf1 ip4:170.55.128.8 ip4:64.124.185.72 include:spf-00197001.pphosted.com ~all
  • wpe-verification=lvinsonelplus
  • 1sbmsqfskwb4vqb1khmvk9wspx310jkj
  • MS=ms39715528
  • SlAzg9DpPPQo28bkRxA+4lVDVJgMVQ0AVLlT9r2kS+1QPdjEiv0VoJSYhKl7P4WixWEZINYqGg9PzdtTIP2/gg==
  • _1v1f74wbogcpefok3iu4v7ikhtwkjeu
  • apple-domain-verification=jwra7lBT4icVUoU1
  • cisco-ci-domain-verification=5203dea0055374cd62466089f7e8856f09bfba1922f9ab75e2c4cc9832279263
  • duo_sso_verification=Xd4QspOjDuvDHC4uZtpOfuVWp2oPlyqKNIBEE0lupuOL1s4r5F6Ba52eySHE67si
Cloud / SaaS Services Detected
Apple Microsoft 365 Cisco Cisco Duo Proofpoint

Leak Screenshot:

Leak Screenshot