Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.ccls.org

Group: Lynx

Discovered by ransomware.live: 2025-10-21

Estimated attack date: 2025-10-21

Country: US

Description:

The Chester County Library & District Center was established in 1962 and moved to its current location in 1980. Largely supported by the County of Chester, the library serves as the District Center as well as the Chester County Library System headquarters. Although we serve primarily West Whiteland and Uwchlan Township residents, our expansive and comprehensive collection of nearly 328,000 items helps to support the other 16 member libraries in the system. The Henrietta Hankin Branch Library, also supported by the County of Chester, opened in July of 2003 to serve the northern region of Chester County. Our collection of over 93,600 items serves the residents of Upper Uwchlan and West Vincent Townships as well as several other townships in the area. Both libraries serve as community centers, providing work space, meeting rooms, homework and research help, and a wide variety of educational and cultural programs.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 24

Third Party Employee Credentials: 0


External Attack Surface: 8


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • mx2-us1.ppe-hosted.com.
  • mx1-us1.ppe-hosted.com.
TXT Records
  • v=spf1 ip4:204.108.131.16/32 ip4:34.199.114.191 ip4:216.17.113.47 ip4:140.234.254.122 ip4:140.234.254.123 ip4:140.234.252.62 ip4:140.234.252.93 ip4:18.160.41.63 ip4:18.160.41.77 ip4:18.160.41.85 " "ip4:18.160.41.97 ip4:68.178.232.100 ip4:208.117.49.214 ip4:205.251.196.103 ip4:205.251.199.142 ip4:205.251.193.33 ip4:205.251.194.208 ip4:204.108.252.75 " "include:ne16.com include:spf.constantcontact.com " "include:outboundmail.blackbaud.net include:outboundmail.convio.net include:e2ma.net ~all
  • knowbe4-site-verification=7a100037b0769577a584ce36a8fc72a7
  • e2ma-verification=95dgb
Cloud / SaaS Services Detected
KnowBe4

Leak Screenshot:

Leak Screenshot