Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

http://www.adven.com

adven.com

Group Royal
Discovered 2022-11-09 11:22 UTC
Est. attack date 2022-11-09

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 5

Third Party Employee Credentials: 9


External Attack Surface: 14


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • adven-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • af3e942d57dd56de49d367fc0dd5ebd8aad011be1beeb8db2f
  • google-site-verification=aWB7lgCZfoUYZmF2ItMveGOy7AQI3yU2wSbc9oi0VpM
  • google-site-verification=v2IXo5D0qXo7YnD2C5fs2Gu0OWZdywDRkGN8vmRatec
  • apple-domain-verification=5SOAxxTnSFDMny8h
  • v=spf1 a mx include:spf.protection.outlook.com include:spf.vardes.lv include:mailer.recommy.com include:spf.mailjet.com include:sendgrid.net ip4:95.217.107.33 ip4:95.217.104.240 ip6:2a01:4f9:4a:289e::2 ip6:2a01:4f9:4a:264f::2 ptr ip4:46.22.220.113 ip4:46." "22.220.113 ip4:185.43.105.124 ip4:195.66.94.27 ip4:194.103.214.0/24 ip4:194.157.153.194 ip4:87.253.232.0/21 ip4:185.189.236.0/22 ip4:185.211.120.0/22 ip4:185.250.236.0/22 ip4:194.126.126.32/28 ip4:194.126.101.96/27 ip4:194.126.106.64/27 ip4:80.235.21.0/24" " ip4:62.65.42.128/27 ip4:88.196.160.130/32 ip4:80.235.4.100/32 ip4:80.235.79.160/28 ip4:80.235.79.224/28 ip4:185.43.106.0/24 ip4:217.146.65.105 ip4:81.7.169.128/25 ip4:194.19.134.0/25 ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144." "0/20 ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149.72.0.0/16 ip4:159.183.0.0/16 ip4:223.165.113.0/24 ip4:223.165.115.0/24 ip4:223.165.118.0/23 ip4:223.165.120.0/23 ip4:103.151.192.0/23 ip4:185.12.80.0/22 ip4:188.172.128.0/20 ip4:192.16" "1.144.0/20 ip4:216.198.0.0/18 ip4:77.86.247.13 ip4:77.86.247.21 ip4:77.86.247.134 ip4:77.86.247.149 ip4:77.86.247.154 ip4:77.86.247.214 ip4:77.86.247.230 ip4:77.86.251.39 ip4:77.86.251.41 ip4:77.86.251.42 ip4:77.86.255.242 ip4:77.86.255.243 ip4:169.38.94." "35 ip4:169.38.94.36 ip4:169.38.94.39 ip4:169.38.94.43 ip4:169.38.94.44 ip4:169.38.94.46 ip4:169.38.94.47 ip4:169.38.94.49 ip4:169.38.94.51 ip4:169.38.94.54 ip4:169.38.94.57 ip4:169.38.94.61 ip4:169.38.94.62 ip4:195.201.75.0/27 ip4:195.201.75.32/27 ip4:195" ".201.73.224/27 ip4:213.139.173.144/28 ip4:88.198.228.224/27 ip4:89.166.55.64/27 ip4:85.131.41.206/28 ip4:212.146.22.6/25 ip4:94.237.5.0/24 ip4:94.237.6.0/24 ip4:45.66.245.116 ip4:45.66.245.117 ip4:45.66.245.118 ip4:45.66.245.119 ip4:45.66.245.120 ip4:45.6" "6.245.121 ip4:45.66.245.122 ip4:45.66.245.123 ip4:45.66.245.124 ip4:45.66.245.125 ip4:62.122.28.0/24 ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144.0/20 ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149.72.0.0/16 ip" "4:159.183.0.0/16 ip4:223.165.113.0/24 ip4:223.165.115.0/24 ip4:223.165.118.0/23 ip4:223.165.120.0/23 ip4:85.254.49.59 ip4:85.31.99.24 ip4:81.198.164.220 ip4:37.153.133.0/24 ip6:2a13:aec0::/32 ~all
  • c9b12a03a0838ece3247140461955d2c05e7ed5864d6e2c951
Cloud / SaaS Services Detected
Apple Mailjet SendGrid