Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo marinabaysands.com -  Singapore Hotel (Internal Server)

Group: babuk2

Discovered by ransomware.live: 2025-03-12

Estimated attack date: 2025-03-12

Country: SG

Description:

marinabaysands.com -  Singapore Hotel (Internal Server)


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 12

Compromised Users: 388

Third Party Employee Credentials: 11


External Attack Surface: 113


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints markmonitor.com
  • whoisrequest markmonitor.com
MX Records
  • marinabaysands-com.mail.protection.outlook.com.
TXT Records
  • v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:spf.synxis.com ~all
  • miro-verification=7f20fbcc44d036e95fb0141908e14b81932f2a32
  • v=msv1 t=0821513D-1D89-4063-83E6-89CC89A03E40
  • apple-domain-verification=plrGNNMtRjnesijX
  • aghfYV+8Nt2QBdBwAQJNQQFDWlZtt48W5jeVKJ1ONAjN2m9Fu6YvdBlZlnstI5ZOV4BB1BJlnNIqtAZqBQXmCw==
  • _saml-domain-challenge.dfb69ddb-19d5-4365-809a-02a77b6de7f5.sands.marinabaysands.com=a1d14ad5-9d0c-4b30-a8e1-3f725bf60be3
  • onetrust-domain-verification=20f0474e894d4f19a20a6850a2f6efa0
  • 0258f0a7-afab-40d3-a7dd-5fc9161996f6
  • Dynatrace-site-verification=5fb2d353-4fed-47ff-842f-fe68099e0422__i6jqtfgql2j29stsc5vqbk7aan
  • atlassian-domain-verification=ofGinK0YKAAGVMAVLdw/LVRF7QaGCM/a9Z4ADZicY5Yy0OLIIq0l0/S30O/enUaz
  • onetrust-domain-verification=a889292bc5574f0da0ed8be059096280
  • aliyun-site-verification=ff395070-a587-4f96-b8ba-a362333b9d8c
  • google-site-verification=30xNGmDPxHv20iwlE44kjcR5iQSgjhP2efAf9fRibSo
  • docusign=0d500a56-d124-4be3-a531-9f648af0a13b
  • docusign=8d973568-a64b-4575-9e5a-cc534dfde534
  • google-site-verification=DNSuCIMA6VBj_DSRVLLp41TNiVk37P5-hp-kJmc-AcE
Cloud / SaaS Services Detected
Apple Atlassian Miro OneTrust DocuSign

Leak Screenshot:

Leak Screenshot