Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

spring-green.com/petbutler.com

spring-green.com

Group Safepay
Discovered 2025-05-29
Est. attack date 2025-05-05
Country US
City Downers Grove

Description:

[AI generated] Spring-Green.com / PetButler.com are two distinct services operating under Spring-Green Lawn Care Corp. Spring-Green.com is a lawn care service provider that caters to the needs of residential and commercial lawns since 1977. On the other hand, PetButler.com provides professional pet waste cleanup and removal services to homeowners and community management.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 11

Third Party Employee Credentials: 4


External Attack Surface: 12


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • springgreen-com01e.mail.protection.outlook.com.
TXT Records
  • apple-domain-verification=podNxwBOfWrILTZu
  • zoho-verification=zb24140108.zmverify.zoho.com
  • vpq1is413pejov2u9o2uud17p
  • qfea2v2h7rof33lindv86s00tb
  • v=msv1 t=68F0A18E-0CC3-4B88-B69A-8726CCEC349C
  • atlassian-domain-verification=yr3/B4sJQv1w6SZRZPXLTkG6jZLM9GuYdUdmr0ZalW0L7JM4bhJnA7juOSQ1h2QD
  • facebook-domain-verification=glx1s84e2jo9k1nfr34eaw8s6z630n
  • v=spf1 a:mail.spring-green.com ip4:61.218.64.151 ip4:52.162.166.119 ip4:108.166.43.1 ip4:209.249.129.45 ip4:72.167.238.29 ip4:68.169.202.32/28 ip4:34.226.79.59 ip4:23.96.211.127 include:one.zoho.com include:spf.protection.outlook.com include:zcsend.net in" "clude:mailgun.org include:zohomail.com ~all
  • google-site-verification=AgEVyFt9jdPGi8cFRWO746MZpJSbbpjR2p-vd1-sjVU
  • gmqp69ak4l7b2m4r3k4vb9qqlc
  • B+WLZDYn0nDrUsp6cp9+v4cNQRu5y1LKrYT8t4IQyGSqehBzc1XTtc8YvpSRzzbnE3M7QIS1367UZ8d3vp0XEQ==
Cloud / SaaS Services Detected
Apple Atlassian Mailgun Zoho Campaigns

Leak Screenshot:

Leak Screenshot