Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.bestop.com

Group: Qilin

Discovered by ransomware.live: 2025-05-22

Estimated attack date: 2025-05-08

Country: US

Description:

In the shadow of the Rocky Mountain foothills in 1954, Tom Bradley started Bestop in a small upholstery shop in Boulder, Colorado. He envisioned a Jeep top that could easily open up to let in the pine-scented air and warm sun, making his driv ...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 15

Third Party Employee Credentials: 1


External Attack Surface: 8


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • us-smtp-inbound-2.mimecast.com.
  • us-smtp-inbound-1.mimecast.com.
TXT Records
  • google-site-verification=86FZztV5rvb0zHexjzocJG-7yP-yxwiLOP_Y6jDt1XY
  • google-site-verification=ILpyaIlUJ-tsWXrQH-0h9eFxF__DB96WTjZGv2g_7GU
  • google-site-verification=MyyT8O5r-pNlCuteuYLnnThLUciWU07jZqSCoQCSe70
  • google-site-verification=WXTxeRmHaBbzOcpB3avRgy8n-gxcNN6YfLw2GQsvE9g
  • google-site-verification=lEuyxJf2ONPzMLr-cclm-vHn20bzfs_rM5Ui8LPtJww
  • k63sqptl636bt306mblihbe29p
  • klaviyo-site-verification=RFDHuG
  • qtslpv0p065vkclqj9rea138ul
  • v=spf1 +a +mx include:us._netblocks.mimecast.com +include:_spf.bigcommerce.com +include:servers.mcsv.net +include:spf.protection.outlook.com +include:mailgun.org +include:bounces.sp.netsuite.com +include:relay.mailchannels.net " "+include:xdp.com ~all
  • 0ed1fe018ae872f93663614d8f856686b86d603c04
  • MS=ms35465428
  • _globalsign-domain-verification=rwoLf76hKlFDOOnyex0_MP1xsGYIRJ4WpeSFbfKfPQ
  • apple-domain-verification=sHDAjJMoYGc2L6TK
  • facebook-domain-verification=g2zvvj8ul2iyjjvsuhsoac2ykz3ine
  • fd1hjbrch0vctscana93ngqchs
Cloud / SaaS Services Detected
Apple Microsoft 365 Mailgun Mimecast

Leak Screenshot:

Leak Screenshot