Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-11-25
Est. attack date 2025-11-25
Country AU
City Adelaide

Description:

Amcor is a global leader in developing and producing packaging solutions for a wide range of products, including food, beverage, medical, and perso...

Infostealer activity detected by HudsonRock

Compromised Employees: 76

Compromised Users: 17

Third Party Employee Credentials: 127


External Attack Surface: 19


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@cscglobal.com
MX Records
  • amcor-com.mail.protection.outlook.com.
TXT Records
  • hpe-greenlake-domain-verification=534b68417062694a734c546255727368344c323655395365354c424a6a314c56
  • MS=MS16368772
  • msfpkey=q8qf2w0v5qgyvc882dtow18q
  • 22CA46EF68
  • google-site-verification=jqrL_4M0KeOHsnQYWRwb_BW2lKWTmytFHQKI6NCyUhc
  • nsb8vrur05bgd2v1lkjn9eddqt
  • MS=ms24101417
  • ZOOM_verify_XyBDVftKQo22EUO3TjQb0A
  • adobe-sign-verification=585fd30265d6b38e907bd852daf27c72
  • v=spf1 include:spf.protection.outlook.com ip4:51.143.2.119 ip4:13.66.130.121 ip4:20.96.2.88 ip4:20.230.234.206 ip4:20.122.27.14 ip4:52.177.186.121 ip4:142.54.44.35/32 ip4:142.54.44.34/32 ip4:142.54.44.33/32 ip4:142.54.44.21/32 ip4:206.164.255.95/32 ip4:20" "8.185.229.0/24 ip4:208.185.235.0/24 ip4:148.59.108.0/23 ip4:148.59.106.0/23 ip4:91.205.116.0/24 ip4:191.242.202.203/32 ip4:59.154.147.162/32 ip4:139.130.187.10/24 ip4:142.54.44.104/32 ip4:206.164.255.72/32 ip4:220.101.55.26/32 ip4:13.94.215.190/32 ip4:40." "86.115.90/32 ip4:149.72.231.47/32 include:2176008.spf02.hubspotemail.net include:spf.bombbomb.email include:eskerondemand.com include:_spf.salesforce.com include:_spf.psm.knowbe4.com include:6af455.workshop-spf.net -all
  • apple-domain-verification=BGfzRO7TzQzaY00i
  • pardot_198352_*=2f244d078a016dcefda1e41aad12848502f8eda9f7e631df66087def9afd1754
  • docusign=d1d7273c-3438-48c0-a378-50569e99987d
  • smartsheet-site-validation=ycyiIHueTd1lO-PwtUXVDNAAVr8zRerd
  • remarkable-domain-verification=f1e2f103-eebf-460b-ae69-6422b5c0de3b
  • dynatrace-site-verification=b2a5dc28-6239-4c95-800e-7fe8b8519b61__q5ulccm4vna2i8fhvqs82rg24c
  • anthropic-domain-verification-wkxnvr=wSLjBOkVeXf7oBqdexjhVjRQx
  • nintex.59a354e9e894bf253792aaa3
  • wiz-domain-verification=2dc930e231f13d8c1bad7debbbbab12420d7fbf1ecc576e313f28a7d2a62a8cb
  • docusign=34c14371-a532-40cd-811b-acebfea5728a
  • google-gws-recovery-domain-verification=68099674
  • miro-verification=b9309ad99064ce1214a7953314deb71bc5381dea
  • firebase=amcor-product-database
  • pardot_198352_*=a5acee292ff824b595c3fafc1b1c9755fe3d66cb577f69e635445bb19f8c9c98
Cloud / SaaS Services Detected
Apple HubSpot Microsoft 365 Salesforce Miro KnowBe4 DocuSign Zoom

Leak Screenshot:

Leak Screenshot