Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Coldwell Banker D’Ann Harper, REALTORS

cbharper.com

Group Medusa
Discovered 2025-03-16 20:30 UTC
Est. attack date 2025-03-16
Country US

Description:

Coldwell Banker D’Ann Harper, REALTORS® stands as the residential real estate brokerage in Central and South Texas, boasting a presence with multiple strategically located offices and a dedicated team of over 550 sales agents. This real estate firm is part of the larger Coldwell Banker network, which spans the globe with over 3,000 offices and nearly 100,000 sales agents. Coldwell Banker D'Ann Harper REALTORS corporate office is located in 18756 Stone Oak Pkwy Ste 102, San Antonio, Texas, 78258, United States and has 117 employees. The total amount of data leakage is 133.30 GB

Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 2

Third Party Employee Credentials: 3


External Attack Surface: 29


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • cbharper-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • google-site-verification=QsJE411h4dee8pRa_BXHNsP-4LPb0L-WCPji8p2oSbg
  • google-site-verification=jNAFkzzAkdzS9FF01y_y3vjq04Ogeg6GaC6n8X1Ar0Y
  • MS=1978E4A16B2F514A52A39C0B9D1BFC702A4C175B
  • v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/14 ip4:104.47.0.0/17 ip4:51.4.72.0/24 ip4:51.5.72.0/24 ip4:51.5.80.0/27 ip4:20.47.149.138/32 ip4:51.4.80.0/27 ip4:20.92.116.22 ip4:40.86.225.121 ip4:13.74.137.176 ip4:40.113.3.253 ip4:20.49.202.3 i" "p4:20.98.2.159 ip4:13.93.42.39 ip4:40.86.165.91 ip4:20.79.220.33 ip4:20.92.233.59 ip4:52.138.216.130 ip4:20.98.33.77 ip4:20.93.157.195 ip4:40.86.217.129 ip4:23.100.56.64 ip4:20.58.22.103 ip4:40.86.171.128 ip4:20.79.222.204 ip4:13.77.59.28 ip4:40.114.221.2" "20 ip4:20.97.70.227 ip4:40.69.19.60 ip4:52.170.22.60 ip4:13.94.95.171 ip4:20.116.107.216 ip4:198.2.128.0/24 ip4:198.2.132.0/22 ip4:198.2.136.0/23 ip4:198.2.145.0/24 ip4:198.2.186.0/23 ip4:205.201.131.128/25 ip4:205.201.134.128/25 ip4:205.201.136.0/23 ip4:" "205.201.139.0/24 ip4:198.2.177.0/24 ip4:198.2.178.0/23 ip4:198.2.180.0/24 ip4:209.61.151.0/24 ip4:166.78.68.0/22 ip4:198.61.254.0/23 ip4:192.237.158.0/23 ip4:23.253.182.0/23 ip4:104.130.96.0/28 ip4:146.20.113.0/24 ip4:146.20.191.0/24 ip4:159.135.224.0/20 " "ip4:69.72.32.0/20 ip4:104.130.122.0/23 ip4:146.20.112.0/26 ip4:161.38.192.0/20 ip4:143.55.224.0/21 ip4:143.55.232.0/22 ip4:159.112.240.0/20 ip4:141.193.32.0/23 ip4:159.135.140.80/29 ip4:159.135.132.128/25 ip4:161.38.204.0/22 ip4:87.253.232.0/21 ip4:185.18" "9.236.0/22 ip4:185.211.120.0/22 ip4:185.250.236.0/22 ip4:143.55.236.0/22 ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144.0/20 ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149.72.0.0/16 ip4:159.183.0.0/16 ip4:223.165" ".113.0/24 ip4:223.165.115.0/24 ip4:223.165.118.0/23 ip4:223.165.120.0/23 ip4:35.190.247.0/24 ip4:64.233.160.0/19 ip4:66.102.0.0/20 ip4:66.249.80.0/20 ip4:72.14.192.0/18 ip4:74.125.0.0/16 ip4:108.177.8.0/21 ip4:173.194.0.0/16 ip4:209.85.128.0/17 ip4:216.58" ".192.0/19 ip4:216.239.32.0/19 ip6:2001:4860:4000::/36 ip4:172.217.0.0/19 ip4:172.217.32.0/20 ip4:172.217.128.0/19 ip4:172.217.160.0/20 ip4:172.217.192.0/19 ip4:172.253.56.0/21 ip4:172.253.112.0/20 ip4:97.77.23.34/24 include:spf.protection.outlook.com -al" "l
  • google-site-verification=psyDxGDGNJqY8rULBh3iPb_4zwrmK4daoyK17rZBYFU
  • google-site-verification=AboEQfLvUS37PBLuXsNkVsF_e3SKv1VaADgrQ3KuaPw
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot