Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo multi-wing.com

Group: ransomhub

Discovered by ransomware.live: 2024-06-24

Estimated attack date: 2024-06-13


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 6

Third Party Employee Credentials: 14


External Attack Surface: 2



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • legalservices eurodns.com
  • info multi-wing.com
  • itservices eurodns.com
MX Records
  • multiwing-com01c.mail.protection.outlook.com.
TXT Records
  • d365mktkey=wv46ZjRgtAVJqxjOsDMOmySxpcqhvAJN7i9zkoEsvAwx
  • d365mktkey=1pMI6NM5XReU3zuj5lZRXyGciZxEcwmjxavQjyNjfGkx
  • d365mktkey=rw3skFn9G1zIytlIghmfUigCmsbEh2ixfy0Kbfuti6Ix
  • atlassian-domain-verification=nCaGMpzU19JXzLFZif7TEZLO1/Hw4aQvAgrHoFXQpIB6GjyZ7CpBwFjZaMyPUx5u
  • openai-domain-verification=dv-AFPC7uSavrLrj1cFGdaxG6ds
  • jxql5sGlqcb/gBVk/kQy5faL9qgj3yb4xG9PUvLFp3KnaiavD7e+5Xb2bU1OdOteT3CuuG8OiE7ntAgECOsXEg==
  • v=spf1 ip4:147.29.171.48/28 ip4:77.221.246.160/29 ip4:77.221.246.168/29 include:spf.protection.outlook.com -all
Cloud / SaaS Services Detected
Atlassian

Leak Screenshot:

Leak Screenshot