Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo hitachi-hta.com

Group: Warlock

Discovered by ransomware.live: 2025-08-17

Estimated attack date: 2025-08-17

Country: JP

Description:

all data


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 4

Third Party Employee Credentials: 10


External Attack Surface: 46


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse gcd.com
MX Records
  • cluster6a.us.messagelabs.com.
  • cluster6.us.messagelabs.com.
TXT Records
  • bmmg4v0hk7l9rsnt4b1esjdsm6.
  • MS=FA2F908EE6F9B94E62B2ABDFBB9CBE01B4281341
  • teamviewer-sso-verification=d0bfbadc236c418c9a93297ed1d409fd
  • FiMwPgS33ZF6yg3Afj0PtxKdfxZCnIYptceY+xDG+c4gaQ36kDUJJHhcbW48ywXIJPQ+wlCF2Q7WhN1wKZTB2A==
  • v=spf1 exists:%{ir} ip4:204.93.206.10 ip4:204.93.206.11 include:spf.protection.outlook.com include:spf.messagelabs.com ~all
Cloud / SaaS Services Detected
Teamviewer