Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo defi SOLUTIONS.

Group: bianlian

Discovered by ransomware.live: 2024-04-23

Estimated attack date: 2024-04-23

Country: US

Description:

defi SOLUTIONS is a company that develops SaaS based loan origination software solutions. It also provides a platform that enables transferring and receiving loan documents and a web-based auto loan portfolio marketplace. The company serves consumer finance companies, banks, credit unions, etc.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • trustandsafety support.aws.com
  • 3ae1bbf8-02de-4613-9221-1ad7517eed1a identity-protect.org
MX Records
  • us-smtp-inbound-2.mimecast.com.
  • us-smtp-inbound-1.mimecast.com.
TXT Records
  • MS=ms54113006
  • apple-domain-verification=tdpCK21FRGYoNZ93
  • atlassian-domain-verification=EG8BbEIjV6tVj/79sRUFfcyHUyqx3LqBo6Wz+aIWGffIGHXq7337Ax/3/Iyv3EUQ
  • ca3-916bd35c939346f2b3e554994ff33fad
  • pardot511281=47f25d458fcbb4a22b7056911d65ad94a4565262f89018ddcf48c7962b1d1ce2
  • specops-verification-code=52917e0a-3577-4467-9abc-50ae4698a8df
  • status-page-domain-verification=bzd7wwnz6q9p
  • v=spf1 mx ip4:206.192.101.151 ip4:4.78.133.151 ip4:50.238.139.151 ip4:4.34.178.91 ip4:12.178.254.74 ip4:20.72.73.113 ip4:168.245.47.185 ip4:168.245.50.23 ip4:208.235.248.20 " "include:spfa.defisolutions.com include:spfmandrill.defisolutions.com include:spf.protection.outlook.com ~all
  • zoho-verification=zb29563391.zmverify.zoho.com
  • MS=ms34525851
  • MS=ms46620900
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Salesforce Zoho Campaigns

Leak Screenshot:

Leak Screenshot