Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

https://thesandersfirm.com/

thesandersfirm.com

Group Sarcoma
Discovered 2025-07-07
Est. attack date 2025-07-07
Country US
City Atlanta

Description:

The archive contains data of the following companies: https://thesandersfirm.com/ https://aronovaassociates.com/ https://sgafirm.com/ https://milberg.com/Geo: USA - Leak size: 3 TB - Contains: Files

Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 5

Third Party Employee Credentials: 1


External Attack Surface: 6


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • thesandersfirm-com.mail.protection.outlook.com.
TXT Records
  • google-site-verification=Jkf5LuUeGHAcsy6rDzfmZxMy2ktIrdJPoRKtD8yl17o
  • google-site-verification=MFbYfUYeS8pcpV_Cino_7w7C4lnMTRjWVwW1Yk-_mjM
  • r5qmof69ksh2ire2jnu25gnfpp
  • v=spf1 ip4:38.98.64.160/27 include:dnsexit.com include:sendgrid.net include:spf.protection.outlook.com -all
  • 2u882oefqbcsh1ibnlr99dd6vk
  • 8lpd26m22mnoa5h7irn748psjq
  • MS=ms80334148
  • b7e9n43jtie3hoiaprh043dqb9
Cloud / SaaS Services Detected
Microsoft 365 SendGrid