Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Axure Software Solutions - a company with an extremely low level of protection was hacked

axure.com

Group Alphv
Discovered 2023-07-26 14:58 UTC
Est. attack date 2023-05-05
Country US

Description:

Who is Axure Software Solutions The Most Secure (NO!) UX Platform. Don't let security hold you back. Host, share, and gather feedback on your UX design projects and Axure RP files using our secure hosting platform, Axure Cloud for Business. We implement security practices and tools to protect your information and data, from the system architecture to how we operate. Start building Axure UX prototypes today with a free 30-Day trial of Axure RP & host on our secure platform, Axure Cloud for Business. Headquarters: 707 Broadway Ste 1600, San Diego, California, 92101, United States Phone Number: (619) 272-4489 Website: www.axure.com

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 4716

Third Party Employee Credentials: 1


External Attack Surface: 86


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • d0d6a5bed976a984bf1153961ac0e753d4a75e19d4f35172ae046598aea66c65axure.com.whoisproxy.org
  • d0d6a5bed976a984bf1153961ac0e753c95c1802a8989afbfc46332a12f8fbacaxure.com.whoisproxy.org
  • trustandsafetysupport.aws.com
  • d0d6a5bed976a984bf1153961ac0e753cf2caa77be434ea454c4c978585acca7axure.com.whoisproxy.org
  • d0d6a5bed976a984bf1153961ac0e7538c4333866b066dbd945bcfc385e38ceaaxure.com.whoisproxy.org
MX Records
  • aspmx.l.google.com. Google Workspace
  • aspmx2.googlemail.com. Google Workspace
  • aspmx3.googlemail.com. Google Workspace
  • alt1.aspmx.l.google.com. Google Workspace
  • alt2.aspmx.l.google.com. Google Workspace
TXT Records
  • MS=ms55684458\
  • \"apple-domain-verification=PByaVtOMM4jq8H3o
  • google-site-verification=Z-L8Em70MmN1ZlTEPwO2ZoZFXJjj6HKB5m8IOIb3DBw
  • v=spf1 a ip4:216.128.11.1/24 include:_spf.google.com include:servers.mcsv.net include:spf.mandrillapp.com include:6853018.spf03.hubspotemail.net include:amazonses.com ~all
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail HubSpot Mailchimp Microsoft 365 Mandrill

Leak Screenshot:

Leak Screenshot