Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group: Qilin

Discovered by ransomware.live: 2025-11-13

Estimated attack date: 2025-11-13

Country: IT

Description:

N/A

Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 16

Third Party Employee Credentials: 5


External Attack Surface: 14


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • hostmaster@viabizzuno.com
  • FEC98D70EF12489DFA3989B4C67C972E_2643821_a@whoisprivacy.com
  • legalservices@eurodns.com
  • 9BEDDDE2DD9E4A326810FAA3609E3A1B_2643821_t@whoisprivacy.com
MX Records
  • viabizzuno-com.mail.protection.outlook.com.
TXT Records
  • ZA=0nb51mjm7Zr6maFURaiTHQ==
  • amazonses:VCEJfCUpD5kft/cDYnetJ/0BQsZP9Bhh5Hkgx6R1l2I=
  • amazonses:hz8oROUK7mt8HGtmJX0Uvo4XoPyV9ERs9rpVT1bnm6U=
  • apple-domain-verification=gr7Ef7V1pBO7G5SN
  • arn:aws:ses:us-east-1:277559926443:identity/viabizzuno.com
  • brevo-code:dba916780fc52706370f776b81e2b1b0
  • google-site-verification=AuEzZBToAsItwbKy_aqwovSMl9QL71GVujWjQufzaE4
  • v=spf1 a mx ip4:83.103.115.233 ip4:83.103.115.226 include:spf.protection.outlook.com include:spf.eu.exclaimer.net include:spf-de.emailsignatures365.com -all
  • MS=1D956FE7FEF0837C6AC29D39D699AC34FCA5EAD3
  • MS=ms49568093
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail Microsoft 365

Leak Screenshot:

Leak Screenshot