Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

joysonsafety.com

joysonsafety.com

Discovered 2023-05-04 18:49 UTC
Est. attack date 2023-05-04

Description:

We took 20TB of data from the company and are publishing the name to encourage them to connect and discuss before we post all the data and cause irrepairable damage to the company. Write in tox https://tox.chat/download.html please 3085B89A0C515D2FB1...

Infostealer activity detected by HudsonRock

Compromised Employees: 32

Compromised Users: 42

Third Party Employee Credentials: 80


External Attack Surface: 28


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • joysonsafety-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • mindmanager-verification=ec9c3833d2daef77604a3cfc097bbc5e919e4c96e8fd13bc34fdf0a2e4474e79
  • myedi-site-verification=QfFt7pwSZjBBxQbyQeJs
  • MS=ms86892290
  • apple-domain-verification=dwTiirhq0Yj0oukL
  • autodesk-domain-verification=2ZrtkJoJvoS-MSl457ki
  • MS=ms98930285
  • I8SeMicoyixmBCidlVdtf42jjgS8ZrO8QxGKhkUc9Arxw6Qh5yEFy8tHjC5u3orbzTGUrJvz1d26mWgJWV7C+Q==
  • 6HMxaEEXEH6sBrvqFqrieOdT7XH53CeIIPaSDOT52GEYwPDfghhCKKq44cxjinOQKEr8O7Geg4ll/fQ5VPQIlw==
  • v=spf1 ip4:114.160.49.98 ip4:160.109.103.168 ip4:208.185.229.0/24 ip4:208.185.235.0/24 ip4:217.6.33.82 ip4:52.250.123.91 ip4:62.159.242.112/29 ip4:62.159.242.96/28 ip4:68.72.228.32/27 ip4:80.146.188.16/29 ip4:87.129.9.66 ip4:85.236.55.185 ip4:35.80.141.6 " "ip4:44.229.121.55 include:spf.protection.outlook.com include:_spf-dc41.sapsf.com mx include:us.confirmit.com -all
Cloud / SaaS Services Detected
Apple Microsoft 365 Autodesk

Leak Screenshot:

Leak Screenshot