Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ANDREWSDISTRIBUTING.COM

Group: clop

Discovered by ransomware.live: 2025-02-10

Estimated attack date: 2025-02-10

Country: US

Description:

[AI generated] Andrews Distributing is a beverage distribution company based in Texas, USA. It is one of the largest beer distributor in the country, serving more than 26K retail accounts. The company offers a broad portfolio of products covering craft, import, and national brand beers. Furthermore, their services also include brand building, activation, logistics, and marketing to the consumer products industry.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 3


External Attack Surface: 5



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • registrar-abuse cloudflare.com
MX Records
  • andrewsdistributing-com.mail.protection.outlook.com.
TXT Records
  • cisco-ci-domain-verification=7273762306719ba19ebdaf76d2e896ca656015c729d1b3e662cf62b8378ee144
  • g0pnrlsd2645jbsqlc4lhfntv4sbhc9w
  • h36ymss68wdl03fw539sq2q3bpd9yd5q
  • logmein-verification-code=d8b996b5-0963-420b-a098-10428ed9d032
  • smartsheet-site-validation=sNhuptFgMkcBHzt87o2lNJVIbIzahPyR
  • teamviewer-sso-verification=e4d92735c6d94fe89a4dc69b9fd0f5f5
  • v=spf1 include:spf.protection.outlook.com ip4:208.185.229.0/24 ip4:208.185.235.0/24 ip4:148.59.108.0/23 ip4:148.59.106.0/23 ip4:216.183.103.0/24 include:sendgrid.net -all
  • x8kd9cdqry195mp1dt7s0p82n7vdv8bw
  • 00d3h000007moljeaa
  • 2UJaO2hEViJuOJYYwj5GYAq5nuK24909I6esza2Q9cbSMjqkV/pc2At3LZCYIZ6Oi37SI6LjG4W3kewLr8hteQ==
  • _xtgtol0mppa1k1t2f5bcq1cy101kqy0
  • apple-domain-verification=V5mAFw24BWzKWzFY
  • atlassian-domain-verification=g1or1jE6LbnWueCB76kntdDY/2BHRPE3CZjJNDj1D9nl1V4S6Fo4z80AjAwIza8r
Cloud / SaaS Services Detected
Apple Atlassian LogMeIn Teamviewer Cisco SendGrid

Leak Screenshot:

Leak Screenshot