Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo amcor

Group: Coinbasecartel

Discovered by ransomware.live: 2025-11-25

Estimated attack date: 2025-11-25

Country: AU

Description:

Amcor is a global leader in developing and producing packaging solutions for a wide range of products, including food, beverage, medical, and perso...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 76

Compromised Users: 17

Third Party Employee Credentials: 127


External Attack Surface: 19


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse cscglobal.com
MX Records
  • amcor-com.mail.protection.outlook.com.
TXT Records
  • ZOOM_verify_XyBDVftKQo22EUO3TjQb0A
  • smartsheet-site-validation=ycyiIHueTd1lO-PwtUXVDNAAVr8zRerd
  • MS=MS16368772
  • msfpkey=q8qf2w0v5qgyvc882dtow18q
  • MS=ms24101417
  • nintex.59a354e9e894bf253792aaa3
  • firebase=amcor-product-database
  • pardot_198352_*=a5acee292ff824b595c3fafc1b1c9755fe3d66cb577f69e635445bb19f8c9c98
  • adobe-sign-verification=585fd30265d6b38e907bd852daf27c72
  • miro-verification=b9309ad99064ce1214a7953314deb71bc5381dea
  • nsb8vrur05bgd2v1lkjn9eddqt
  • docusign=34c14371-a532-40cd-811b-acebfea5728a
  • 22CA46EF68
  • docusign=d1d7273c-3438-48c0-a378-50569e99987d
  • pardot_198352_*=2f244d078a016dcefda1e41aad12848502f8eda9f7e631df66087def9afd1754
  • dynatrace-site-verification=b2a5dc28-6239-4c95-800e-7fe8b8519b61__q5ulccm4vna2i8fhvqs82rg24c
  • v=spf1 include:spf.protection.outlook.com ip4:51.143.2.119 ip4:13.66.130.121 ip4:20.96.2.88 ip4:20.230.234.206 ip4:20.122.27.14 ip4:52.177.186.121 ip4:142.54.44.35/32 ip4:142.54.44.34/32 ip4:142.54.44.33/32 ip4:142.54.44.21/32 ip4:206.164.255.95/32 ip4:20" "8.185.229.0/24 ip4:208.185.235.0/24 ip4:148.59.108.0/23 ip4:148.59.106.0/23 ip4:91.205.116.0/24 ip4:191.242.202.105/32 ip4:59.154.147.162/32 ip4:139.130.187.10/24 ip4:142.54.44.104/32 ip4:206.164.255.72/32 ip4:220.101.55.26/32 ip4:13.94.215.190/32 ip4:40." "86.115.90/32 ip4:149.72.231.47/32 include:2176008.spf02.hubspotemail.net include:spf.bombbomb.email include:eskerondemand.com include:_spf.salesforce.com include:_spf.psm.knowbe4.com include:6af455.workshop-spf.net -all
  • apple-domain-verification=BGfzRO7TzQzaY00i
Cloud / SaaS Services Detected
Apple HubSpot Microsoft 365 Salesforce Miro KnowBe4 DocuSign Zoom

Leak Screenshot:

Leak Screenshot