Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

cenviro.com

cenviro.com

Discovered 2022-08-26 16:46 UTC
Est. attack date 2022-08-26

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 4

Third Party Employee Credentials: 2


External Attack Surface: 5


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • p67n43ed3mjnetworksolutionsprivateregistration.com
  • abuseweb.com
  • domain.operationsweb.com
MX Records
  • cenviro-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • MS=ms75498947
  • l1bfjpmarsqgnqsdlj4n3rv7he
  • google-site-verification=oljV5bbM-AJpuNhYiv7Qjd4nHyeHIakokwyQjBYtdTA
  • zZYLSmO9SnCTGzG6fHfIH3TbfG368VXUeCETPflgfJSmAPz4w0QR2oALLs5DB/sGLYsHj3euPE3KjVJbi2NLew==
  • 16nde59fc9ai602kv8a2rcctso
  • v=spf1 ~all
  • v=spf1 mx ip4:218.208.21.102 ip4:118.101.186.142 ip4:218.208.21.71 ip4:175.142.119.194 ip4:43.231.225.133 ip4:124.217.225.187 ip4:43.231.225.132 include:spf.protection.outlook.com -all
  • fhqqcm9agb38m2ai0sj6mgpqa3
  • sending_domain1023361=a37eb8bd8d14342f21f6d5a11309875039930556aa4d4e4dd629c2c1d6f4c518
  • pardot1023361=3047057782ba8d3741067f033909f7895436c522a08bcd373171bb5e207fac3c
  • 6f67thmhgi73cdp4tueg5aqp8h
  • linkedin-site-verification=55975e42-679c-40de-a70b-ebbf26f1bbb1
  • tvp8a3hr2ki51519udi44gqrfl
  • 9qeshbc5482mmgg127eutv8bl9
Cloud / SaaS Services Detected
Microsoft 365 Salesforce