Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo apollomd.com

Group: Qilin

Discovered by ransomware.live: 2025-06-12

Estimated attack date: 2025-06-06

Country: US

Description:

All data of this company will be available for download on 16.06.2025.ApolloMD is a fully integrated and coordinated national group practice,that partners with more than 100 leading medical facilities across the country to provide multidiscip ...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 2

Third Party Employee Credentials: 1


External Attack Surface: 1


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • us-smtp-inbound-1.mimecast.com.
  • us-smtp-inbound-2.mimecast.com.
TXT Records
  • v=spf1 ip4:207.246.254.85 include:spf.protection.outlook.com include:_spf.salesforce.com include:us._netblocks.mimecast.com include:sent-via.netsuite.com include:spf-009b8d02.pphosted.com -all
  • pardot86652=2397449ecfd1f7eacfac8309d7ee9c9faf36875a21a2eed2290a6d5a87fcb263
  • Cr08MFtlcc+v8Cb7zPo/z3jrOazkwUeDr6W1S/UIL3bS8pyDMd8VeNao6nUKBhQ10r7cShkJRhG6NQMtZVlC8A==
  • apple-domain-verification=ikapFfxh1iBQtFeB
  • atlassian-sending-domain-verification=c7959ac9-8a91-4460-9a62-a0c3b5588925
  • 0ed1fe018a25e0e25671e14ca0b8761a7157ff30a0
  • sending_domain86652=274054623188ec25bb9adbf8cd99526311d869af25f9afb0f60cfea011493db3
  • ZOOM_verify_Wubs23u9Q8CbDBp9l-HUmA
  • atlassian-domain-verification=OSBlSi01iCm39d1ZMFg0jKV0RGdZpJbwS3Vuel5LzgcLjBEbVZR5E9ty2Ycqpt3q
  • Account Engagement emails pass SPF automatically, but we recommend setting it up as a best practice.
Cloud / SaaS Services Detected
Apple Atlassian Salesforce Mimecast Proofpoint Zoom

Leak Screenshot:

Leak Screenshot