Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.enea.com

Group: Incransom

Discovered by ransomware.live: 2025-12-01

Estimated attack date: 2025-12-01

Country: SE

Description:

79gb


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 2

Third Party Employee Credentials: 1


External Attack Surface: 12


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse namebay.com
MX Records
  • mx1.hc1636-5.c3s2.iphmx.com.
  • mx2.hc1636-5.c3s2.iphmx.com.
TXT Records
  • apple-domain-verification=7yM66Lfya2Lg4PZJ
  • _hdedtv9m45w1ycpftwp4rucx7vn40mm
  • cursor-domain-verification-y64dfn=fNInlb1Puubx54v4QJbNXm20w
  • adobe-sign-verification=4d1ef523ee76a1d5981e172b3f02e1b
  • atlassian-domain-verification=AdNPmFiTIBNw5DbNxcBV3bQIYMUOneBVhNG7Iy8W5eV5CeEbazYtJMgXayCt/Etm
  • vpytenD/JIBdVHai/3yl7nLbPtzb3AtZvWEmbtt8FpxQ618jvMAIE6cZloUuVz6Cx+TQ3mMyupxbPcB7kRxSsA==
  • _std75pa5s9gyadq6sejxl5u4qmrr8c5
  • atlassian-domain-verification=5oiaVwchEbgdEoCmihDTNygULMi7IQ5s819PCiC9oB83WQwtNzUIRPjxeFxBw20U
  • pardot952443=57b58c389667f077fa73c2d2dfa620635024917dc8146bd066d6a2c81173b7f3
  • atlassian-sending-domain-verification=edda0cbf-ff0e-40cf-8cde-36ba87f533db
  • v=spf1" " mx" " include:spf.protection.outlook.com" " include:servers.mcsv.net" " include:_spf.salesforce.com" " include:_spf.atlassian.net" " include:spf-eu.emailsignatures365.com" " ip4:72.85.155.85" " ip4:63.246.9.118" " ip4:204.15.171.6" " ip4:209.202.128.38" " ip4:52.48.127.60" " ip4:63.246.30.82" " ip4:217.114.80.100" " ip4:91.227.208.0/24" " ip4:185.64.72.0/24" " ip4:91.213.250.0/24" " ip4:194.71.205.0/24" " ip4:213.206.105.0/24" " ip4:34.245.210.0/24" " ip4:66.240.227.0/24" " ip4:63.143.57.0/24" " ip4:135.84.216.0/24" " ip4:193.202.22.150" " ip4:62.7.173.0/24" " ip4:192.36.1.0/24" " ip4:52.129.17.4" " ip4:198.37.153.11" " ip4:208.91.114.151" " ip4:62.7.173.0/24" " ip4:167.89.0.0/17" " ip4:192.174.80.0/20" " ip4:147.253.208.0/20" " ip4:168.245.0.0/17" " ip4:34.211.27.137" " ip4:34.211.27.236" " ip4:34.213.22.229" " ip4:34.249.70.175" " ip4:34.251.56.38" " ip4:34.252.236.245" " ip4:52.51.22.205" " ip4:54.187.228.111" " ip4:34.209.119.136" " ip4:34.211.27.82" " ip4:34.212.5.76 " " ip4:34.253.110.0" " ip4:34.253.57.155" " ip4:35.167.157.209" " ip4:35.167.7.36" " ip4:52.19.227.102" " ip4:52.24.176.31" " ip4:54.72.208.111" " ip4:54.72.24.111" " ip4:54.77.2.231" " ip4:192.46.232.245" " ip4:194.195.244.130" " ip4:216.71.136.200" " ip4:192.36.1.139" " ip4:80.252.176.139" " ip4:13.111.68.217" " -all
  • MS=ms78401664
Cloud / SaaS Services Detected
Apple Atlassian Mailchimp Microsoft 365 Salesforce

Leak Screenshot:

Leak Screenshot