Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Hive
Discovered 2022-12-21 20:16 UTC
Est. attack date 2022-12-21
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

Alvaria, (pronounced: ahl-vahr-ee-uh), a global leader delivering optimized customer experience and workforce engagement software and cloud services technology solutions.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 4

Third Party Employee Credentials: 14


External Attack Surface: 3


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • beth.zindelaspect.com
  • whoisabusealpinedomains.com
  • domainadminalpinedomains.com
MX Records
  • alvaria-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • linear-domain-verification=t5vvfax3crqj
  • linear-domain-verification=5wgxtqktgt37
  • slack-domain-verification=Bd3pB1VDMuhrhGecTf56kWM6OQdLFU0xBwNubh4A
  • v=spf1 ip4:63.84.151.36 ip4:63.84.151.39 ip4:63.84.151.41 ip4:63.84.151.14 ip4:198.207.147.224/27 ip4:204.239.0.224/27 ip4:169.136.14.21 include:spf.protection.outlook.com include:_spf.salesforce.com include:sent-via.netsuite.com ~all
  • apple-domain-verification=gnraMoxUbnjsVj5U
  • zoom-domain-verification=ZOOM_verify_770ddf52f8f54fb0af44a56fc4241716
  • sophos-domain-verification=4aab8dc475a625d0bac39e7b54c6883eb56eabaa23c5b71f500ccac0067cf4b9
  • linear-domain-verification=p2ne2bnmtiwp
Cloud / SaaS Services Detected
Apple Salesforce Slack Sophos Zoom