Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

st-group.com

st-group.com

Discovered 2022-12-02 11:06 UTC
Est. attack date 2022-12-02

Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 5

Third Party Employee Credentials: 22


External Attack Surface: 10


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • stgroup-com0e.mail.protection.outlook.com. Microsoft 365
TXT Records
  • apple-domain-verification=tpomedGoscm4Gb23
  • MDAyMjkzNDBzYXAuc3Qt
  • have-i-been-pwned-verification=dweb_5in06zhn0l3k8qnf639wz6wg
  • Rw/ECpxmNIunYnGkv+TVbuRwsNTx5tOzYyjMH11PiwlfbfJak5qRGRycdahTKi6iGxtpYWIGQsVPNWvqwFidKA==
  • _globalsign-domain-verification=t1NCoICxBYDK8hB586rBqZk1DZA6cNP4GeOpTrnNML
  • pardot969463=602ee8b0812689463f0cdf31e882618c62bae2e5fb238ba0bc1f33a84647fd32
  • ioce7jvpelosgq1tv4t7f7m3bg
  • v=spf1 exists:%{i}._spf.mta.salesforce.com include:spf.protection.outlook.com include:servers.mcsv.net include:spf.mailjet.com include:aspmx.pardot.com include:u2622627.wl128.sendgrid.net include:_spf-dc2.successfactors.com include:_spf.qualtrics.com ip4:" "185.46.182.1 ip4:185.46.182.200/29 ip4:185.46.182.208/31 ip4:20.82.87.96/28 ip4:212.237.249.35 ip4:212.237.249.36 ip4:84.241.158.170 ip4:40.68.87.174 ip4:20.101.2.172 ip4:20.101.6.90 ip4:20.103.213.33 ip4:20.126.233.136 -all
  • mandrill_verify.4pJSmWdSNDBLx1PF9tb_-A
  • docusign=3bef76df-a139-4b18-91ec-b49fec307f29
  • teamviewer-sso-verification=20d217e8e4dc4238b2c1814205b49c27
  • globalsign-domain-verification=48F95909270462090DF3F67DC7C924E7
  • apple-domain-verification=1P0W4omkcoPefbp3
Cloud / SaaS Services Detected
Apple Global Sign Mailchimp Salesforce Teamviewer Mailjet SendGrid DocuSign Have I Been Pwned