Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo coBuilder

Group: dragonforce

Discovered by ransomware.live: 2025-06-17

Estimated attack date: 2025-06-17

Country: NO

Description:

(including complete databases) Cobuilder is a tech company providing digital solutions for the construction industry, aiming to enhance collaboration, digitalization, and sustainability across the entire value chain. Their offerings include asset data management, digital product passports, and sustainability reporting to meet new requirements. Cobuilder's solutions facilitate seamless information flow among construction stakeholders by integrating with other BIM software through APIs. They also provide consultancy services to develop digital strategies that optimize efficiency and reduce costs.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 10

Third Party Employee Credentials: 0


External Attack Surface: 6


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse key-systems.net
  • abusereport key-systems.net
  • info domain-contact.org
MX Records
  • cobuilder-com.mail.protection.outlook.com.
TXT Records
  • ZU6T5MVDKYXWJ9ZP4QG2WYNMZWRFW50H93NBKQN1
  • Sendinblue-code:2463789aa47d7291090f4bd3e61a977e
  • MS=ms79319605
  • MS=ms63338667
  • ms-domain-verification=8af0ed47-e7a7-4f81-93eb-5a7479587027
  • Sendinblue-code:9ab02bcc89504c0071afdfcc7ab94eb3
  • v=spf1 include:_spf.mailersend.net include:spfa.cpmails.com include:_spf.mlsend.com include:servers.mcsv.net include:spf.protection.outlook.com include:spf.sendinblue.com +ip4:77.40.171.0/24 +ip4:185.80.1.131/32 +ip4:185.80.0.128/32 -all
  • apple-domain-verification=DbwauZpE2hlSSXtd
  • pi4ue192v58llq3ru6hll54r3m
  • ms-domain-verification=56c43fef-0f3a-4f7f-86ac-555983e2eb8e
  • d365mktkey=Jrf3dxI0oy7i16NjirRvLHL3feUD0KzGFtYxx4rfdiYx
Cloud / SaaS Services Detected
Apple Microsoft 365 Sendinblue

Leak Screenshot:

Leak Screenshot