Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

sirva.com

sirva.com

Discovered 2023-10-05 23:33 UTC
Est. attack date 2023-10-05

Description:

We have over 1.5TB of documents leaked + 3 full backups of CRM for branches (eu, na and au)Sirva Worldwide, Inc. provides HR and mobility professionals with the resources, guidance, and support they need to achieve the best possible relocation for...

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 101

Third Party Employee Credentials: 5


External Attack Surface: 48


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegcd.com
MX Records
  • sirva-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • google-site-verification=quuAGUnb9bltPYNGSOB9nBERhjXFcseydEyTCFTeVug
  • google-site-verification=Be-VfcJ3GU5zUre_o0JuxnpZUfg_I92M611DrG0V52s
  • finicity_partner_id:2445583980941
  • finicity_partner_id:2445583989360
  • finicity_partner_id:2445583992053
  • google-site-verification=FlOBZdBtcwZfhAiWuZ6rlFTJsQ7J095Nmbp6YkwsJHc
  • contractworksverify=2uiW788n
  • google-site-verification=E9n4nkPalpQfT24IZ-41o9B7IE0ScVfYcml3GIYvuPs
  • msfpkey=55nzgf1loe1bm28mxkc3z2qll
  • MS=ms73533034
  • t+dI6Er74PIMDEy/jITVWfb5zXbm1OIdmLkyWkzcQQzOTWD0lfAhsTh3+3aHnb+3DkLLmgM8FUXOhtnVSA0bng==
  • v=spf1 include:spf.protection.outlook.com include:spf1.sirva.com include:mail.zendesk.com include:5120690.spf10.hubspotemail.net include:_spf.salesforce.com ip4:67.231.152.177 ip4:206.208.247.35 ip4:206.208.247.36 ip4:40.79.69.112 ip4:104.209.174.117 ip4:" "104.45.74.93 ip4:66.147.237.225 ip4:208.84.65.220 ip4:67.231.158.158 ip4:67.231.151.29 -all
  • prd-us-sf-sirvacom.azurewebsites.net
  • docusign=407fd7bb-ca85-4f38-86ad-8018a79f800e
Cloud / SaaS Services Detected
HubSpot Microsoft 365 Salesforce Zendesk DocuSign

Leak Screenshot:

Leak Screenshot