Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo discovery.com

Group: dispossessor

Discovered by ransomware.live: 2024-04-19

Estimated attack date: 2020-12-25

Description:

discovery.com


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 26

Compromised Users: 461

Third Party Employee Credentials: 74


External Attack Surface: 110



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse cscglobal.com
MX Records
  • discovery-com.mail.protection.outlook.com.
TXT Records
  • intersight=3eed01f1c0a0298999a24f5524196023d6685681853a25e41f16b4b1589152a0
  • miro-verification=1e01f8da769be1241fceefd9abf2c317dcd68323
  • MS=ms36845212
  • adobe-idp-site-verification=30a83e41982349d4ad07b4452032d42b2e1ae2e6294336e3b56e9f8a13d370ee
  • docker-verification=5dd105be-3b0d-4d78-b71d-bc3bed7aa08d
  • prowly-verification=37a5b6539ab07a0e45f55a0254ef9bbc88e1ae239f90cea437258514cac5e33b
  • cisco-ci-domain-verification=5cbdf6b96fc2179e607427db03aa7f2986e9ee7a4f936528e611f392e673ea3a
  • v=msv1 t=6911AFCD-8577-4DCA-A486-857FE32804AB
  • +cZoNJlEdITO/FEf/3QoKhZHbeMUwHHrEuA/4NklVDsi+CR1oEsPlTOQ2USM8kq2ecFlVjS7ZEP5VIRoq5gqrg==
  • google-site-verification=ba_1j4qNCApR16lCfInXV0vfPHpWVIbar62rTPT0lrM
  • mongodb-site-verification=RsxPABkPHiD1b91sl269f57Vh0w2vkaT
  • 1zc4cr50d51xyh1xtg07dj163gn5wg0v
  • amazonses:IFkO1GF1OEoaGJsWKoEFq27ohjaVdzIQTUT987u1/kk=
  • apple-domain-verification=B65wRAxZG0SRwTTC
  • lucid-verification=buX5hl#V8fUHRs%c
  • google-site-verification=9FDJi7bDcrcbXxE1ipLCIC7kPA4LI-mTmnw5ZyB7wHI
  • postman-domain-verification=10d52f237bcec58347f02e63a8363c4bc8459e741a18387f99e6d1bc6080992354d8ccbd81adb2c4eacbb42cde459bc1006d0645abd3f673f1c1b716e43a9b3e
  • mongodb-site-verification=LEN6UD3xmzX1D2p8py6V8mYOIQXsJBlK
  • dropbox-domain-verification=dunk3u3d5v9u
  • atlassian-sending-domain-verification=5435b926-8647-4fed-84aa-3351a675cb14
  • docusign=54144bba-6f1d-40c3-837f-8187fa31e58d
  • google-site-verification=HsmtjtMf4nm1c_2lgQJG_8OJDcLCBmQW_NYZ-Rsz2yc
  • d18nsta7prg5yw.cloudfront.net
  • 8Llcqzr/o7jO9rbppa0jdZe2ESPEWbH6Q9UKiwJlb14=
  • MS=ms70384928
  • google-site-verification=3DKdob3tZjiAUJgelZ4J3FIScpXHm0HdrFZu-BSrDdk
  • google-site-verification=7J1nFROGNl6AvL9ZtJwvHNyBdfFSXQtG98BzbhqO6JM
  • 6rv4ky2b39mr6mm45wn9pzsvfn48288w
  • spf2.0/pra
  • autodesk-domain-verification=ym5EYdpGBiwdsykmwdLG
  • smartsheet-site-validation=6p4IocZ0Et_YqWi1W9528MJcZHY22h2t
  • google-site-verification=QRLNPD2x6gJpXNlyzE1CmSAQgMcYGcwdE6MTUUlghHE
  • 0ed1fe018af97b0281310c41399317a3b318219bae
  • ZzgNfbnyO1SNw9vM1XYgFFXrGaEEKnFUpLYhDM2n0TU=
  • adobe-sign-verification=55a65e89d141717e30e740789b947d2f
  • flexera-domain-verification-ggdnjkzkxfxexvbs
  • v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:_spf.createsend.com ~all
  • google-site-verification=q8S4dYAtVpt6uUfaiPbtPyFjA2u2xKqBJU-HnQzXmMs
  • amazonses:ibBFIq81Kxq5T1WsDi6cD3SIF5F6NcOw1bz9cs28dng=
  • d2ucehxhtik1wi.cloudfront.net
  • apple-domain-verification=s2cWlvYJEavwQqC3
  • facebook-domain-verification=x6n1evurloz8vds9d6jxtjdaa8byug
  • atlassian-domain-verification=joqe6L8dNi+aisGbB1XHQa0pDc53V2l0GQQRUtLEcr2997x0+rtrAA5Zw+UgQw3u
  • docusign=efcdaa22-c105-409a-a6cd-6b8a26b0e10c
  • XM630dvLKEbJzSzSFp2xOWE0FVedH5bnkO+WDL1cUgE=
  • onetrust-domain-verification=cc826873d78845889ada9335c8836a8a
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Box Dropbox Microsoft 365 Miro Autodesk Flexera Cisco OneTrust DocuSign

Leak Screenshot:

Leak Screenshot