Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.servicepower.com

Group: apt73

Discovered by ransomware.live: 2024-05-02

Estimated attack date: 2024-05-02

Country: GB

Description:

Large software development company Service Power. Great Britain. Documents of internal systems, credits to internal resources. 328 MB


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 79

Third Party Employee Credentials: 0


External Attack Surface: 0



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • usb-smtp-inbound-1.mimecast.com.
  • usb-smtp-inbound-2.mimecast.com.
TXT Records
  • v=spf1 include:usb._netblocks.mimecast.com ip4:54.167.71.127 ip4:206.196.5.32 ip4:76.80.150.235 ip4:3.123.97.29 ip4:52.5.147.85 ip4:52.21.80.226 ip4:54.167.71.127 a include:mail.zendesk.com" " include:_spf.salesforce.com include:380173.spf07.hubspotemail.net include:spf.protection.outlook.com include:amazonses.com -all
  • atlassian-domain-verification=V4BX499qmhYc2zaRYHu0JPWuaUDIacQN5Bya45I3W2TYdKoGYx7PW/GdMLoPxM9q
  • mongodb-site-verification=qRdU1CMVy7CmqhYhM6YKNyccJOhwddtj
  • have-i-been-pwned-verification=ef21fe222bede49709b4fe323b71ea3a
  • logmein-verification-code=O41mc5BM9px0w63q2jdub0r9J
  • google-site-verification=aIBQbQv9-C94txupSIRPPTSn4TAcq8t9_IEY8ToivQc
  • apple-domain-verification=RBgTYc1AdYB71NRo
  • MS=ms79043187
  • atlassian-sending-domain-verification=1c624cae-1e67-485d-b723-c1e23c6cb389
  • google-site-verification=google-site-verification=IKER4Nvx1wDNxGOfgQ6ia4MQNvKm3lWH1HKf1TaE-p8
  • v=DMARC1; p=quarantine; rua=mailto:noreply@servicepower.com; ruf=mailto:noreply@servicepower.com; adkim=r; aspf=r; rf=afrf
  • cursor-domain-verification-j6h02w=rZLFO0CzPYijuklRTrmReNmVG
  • mongodb-site-verification=z6xDI5ZRMFQChjf9Ggqr1vp3GaTt2dFu
  • smartsheet-site-validation=RgIYY7F3YTwbgzucCSJaqE9xOdsnLr2B
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail HubSpot Microsoft 365 Salesforce Zendesk LogMeIn Mimecast Have I Been Pwned

Leak Screenshot:

Leak Screenshot