Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

www.nelson.edu

www.nelson.com

Group Qilin
Discovered 2025-04-16 19:16 UTC
Est. attack date 2025-04-16
Country US

Description:

Data from Nelson University contains thousands of personal employee and students records. All data will be published fully on 24 April 2024. If management of University will not pay ransom .Nelson is a publisher of educational products. They ...

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 223

Third Party Employee Credentials: 22


External Attack Surface: 43


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • nelson-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • pardot985611=293022498113d39d4c68d3db74e1f4d2e5277fc8d73b7017259e0803b081631d
  • v=spf1 ip4:20.104.105.54 ip4:69.32.227.81 ip4:69.32.147.12 ip4:69.32.147.10 ip4:69.32.130.143 ip4:69.32.227.166 ip4:69.32.146.100 ip4:107.22.121.105 include:spf.protection.outlook.com include:sendgrid.net include:_spf.salesforce.com include:aspmx.pardot." "com include:_spf.psm.knowbe4.com ~all
  • google-site-verification=Ew4qdmrLtTRpx3-F0OAXwupljuNy3pXqwc6lofF1go4
  • MS=ms15980938
  • CxVpX2h0Sc7y1I6rLEmSyfJZunkNao4wjZGqHvWL7CssHyWmT5a6pZNs3uoT9bX1Pabku/hFqEoVuYr73JDsdg==
  • smartsheet-site-validation=dqAnXndUZF9jipOvQFn2Nge-LgMJpi3V
  • apple-domain-verification=RI9bedcrdUtwpawr
  • MS=ms29936744
  • MS=ms89473235
  • 1password-site-verification=GGWEGUQ5A5AWNODBDRPDOHPJ4Y
  • figma-domain-verification=888b6720e238f531d42db985ae2cb192c30ed3b33de99afaf69ac3f6329f5f5d-1746629887
  • sending_domain985611=3872408c268bfd47d5829fafb2ec6d23ebd900b4eafcbbf010294e5b7470e9ae
  • duo_sso_verification=nrFV7iDqNgzpOYDwlNESTEy3PO6eVKy9fY3MOe5JR8rtXNDDfVewtpdum8tGgfxm
  • MS=ms92572920
  • _n176bh90hnakzlckzux7y9cl708b16y
  • MS=ms71440361
  • atlassian-domain-verification=SddZIaTjaaA5tkNYg0vaQHabfZDxPdoc2/wSfMQT2Jc763MuEmaDwuXLbOwV1yur
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Salesforce KnowBe4 SendGrid Cisco Duo

Leak Screenshot:

Leak Screenshot