Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Medusa
Discovered 2024-10-03 08:36 UTC
Est. attack date 2024-10-01
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

Emerson is a technology, software, and engineering company providing solutions for customers in industrial and commercial industries. Emerson corporate office is located in 8000 W Florissant Ave, St. Louis, Missouri, 63136, United States and has 67,000 employees. This is oracle database of their subsidiary company Zedi. The total amount of data leakage is 938.00 GB

Infostealer activity detected by HudsonRock

Compromised Employees: 93

Compromised Users: 1132

Third Party Employee Credentials: 300


External Attack Surface: 154


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mxa-00300601.gslb.pphosted.com. Proofpoint
  • mxb-00300601.gslb.pphosted.com. Proofpoint
TXT Records
  • infoblox-domain-mastery=2bec1c11b28dd94ccb2c20c4ec0a917961a15b82a63584dc746ca5c2ec796a22d5
  • atlassian-domain-verification=0jeh9afZk6ZRdBpPsFp/lhLJZPzuXMEv1ws7PmENaUqB8ESzwWkkf1D8NBaepCvw
  • _qon25w7klomrikm0oovy1oyix16ndjp
  • 2CqWLk3jYC1kkyo3a+Jn50D3sj6HUC41oTwKBPveLId35/eQucpB3xttP8ht0rz9DlkHww/XYbLQiyYxdLhcRw==
  • google-site-verification=iN_Zf6SubRPgKi4inx3PPoSaf0n5o2r8n6GlONoSTSo
  • autodesk-domain-verification=ckL2Hhfwll4k8YkQ-sxD
  • MS=ms15409228
  • adobe-idp-site-verification=54edae49b362c829d176d3ef9f7e3f45bb7dd9f99085432b5a17ed938fb38f57
  • 00DRt00000QDrE2=1TBRt0000000sbV
  • MS=ms36304165
  • meltwater_sso_20200421_t3-2732
  • smartsheet-site-validation=wjfhLHmh4cYhi1WsErY8mSGMUmMo_Sgu
  • sending_domain918843=089ffaaf583449a9c7d577c3a98278daba18016686b6578de8cc34ea08b99a14
  • traction-guest=1587ce44-a0e3-42e9-8ed6-ab39176b20c7
  • apple-domain-verification=0LC3RVRyzvLE1icY
  • MS=ms37029122
  • onetrust-domain-verification=5522b3362730477a879338b39e5fd451
  • bw=DxHz7LEKmBp8yNzTnDpco1CTZgksRAWjxWlrbZiYXq72
  • pardot948362=a3493a5cd784c48c9dbf6f6cb0a386c12741af68cf6b22ca5479a32742b6bcf8
  • ms-domain-verification=55f8f3c5-b952-499b-886e-c1edc3cc7781
  • docker-verification=1843c122-cdbe-4cee-a955-501c378ecbde
  • MS=ms59172994
  • onetrust-domain-verification=77b84320988145f4a31c43f9dc01fb2b
  • anthropic-domain-verification-62aebn=ZsnoVodaCVUfZlUw9Z5uWCf2n
  • ms-domain-verification=9fb5fe4f-40bd-4afd-bdc3-d29aec0bbe56
  • docusign=15a1dc46-efc2-4c20-83bd-dc07bdcce91e
  • MS=ms12594487
  • ygdsvdqb41zdqh69hkns19zwzlxxhf9s
  • teamviewer-sso-verification=ef31fb29415b464785df0d1fc7b1df45
  • mongodb-site-verification=zqD0q0LbSfJthZaBpfcLezrGLbiYitDQ
  • _ucyhgqbps85kxxywrpnqwfx3qwhu6d0
  • v=spf1 " "include:%{ir}.%{v}.%{d}.spf.has.pphosted.com" " include:et._spf.pardot.com ~all
  • ms-domain-verification=1311b50e-37bd-4791-9f07-157f3d4459da
  • MS=ms69181525
  • wrike-verification=MjcyMTM3MTowMmU5MjRmZDQ4Y2YxODgxOWNlZWZmZjliYzY1ZDE1MTQ0NjU4OTY0ODhjZGI0MmQ5ZmMyNDM5NzFiMDg0Mjgy
  • ca3-6a86742d28da4b89b92bea254e52d0f6
  • MS=ms97059319
  • docusign=1cc5721a-0202-4c50-b4ae-415457a1547c
  • _fd0l5w20rhd8xmwy5qcgweuly2dl3da
  • atlassian-domain-verification=jPY2khghVVg4xibLHi9sLospmNwwfD/egSNPYh8knnIYDJ4U5Vp2/PC6g/UL/4w1
  • ms-domain-verification=2d37193b-4083-475b-b715-7bda69fa98ee
  • ciscocidomainverification=4157b32101837d9ff88e7c171da4988d6a6a61342c57b704d5f7f1e67a68925c
  • smartsheet-site-validation=xpBjbMgtxC7bDw8FnyZzWM6Ul7B1un-X
  • 00DcY000007l0tN=1TBcY00000007RJ
  • google-site-verification=RK6kLHi7fFTcQhU3mcOQonWJLKz9894Boq7T0sUR0KI
  • onetrust-domain-verification=940765887ade4201a4c24492fa244391
  • drift-domain-verification=18c9db80f4f1b02755d08bb50b7f81ced5771b18fd709ef29911ec7d04f5b5b5
  • 00DcX000004E6ZV=1TBcX00000001Tx;00DVC000008HSRV=1TBVC00000001gr;00DRT000009YbMX=1TBRT00000002Rd;00Dca000003wsfp=1TBca00000004Mz;00Di0000000jTAB=1TBVU00000000OD
  • wrike-verification=MjY4ODQwNDpkZTdlNzc2MWZmMzViYjNhMThjNDg0ZTAzOGI2NTlhOGM0OTA3NGE0ZDc2MTA5MWU5ZTg0OTFjNjJmN2MyYzJm
  • 00Di0000000jTAB=1TBVU00000000OD;00Dca000003wsfp=1TBca00000004Mz
  • xkgzgvlb6zjpx5yxvwrtgt19cfsf8cl6
  • v=verifydomain MS=ms<55449BE3-56C1-4d44-A242-2B1C6E06770D>
  • rq7zhhsrp1p2rjf89yq2qtv9z0lyr85q
  • dtm-domain-verification=t8c0owf0fpbvu3qDMlCwo7dafbb51kHr1TmlCnbrmB8
  • xpBjbMgtxC7bDw8FnyZzWM6Ul7B1un-X
  • make-domain-verification=fc19ab38-e91e-4d57-9b97-f24b77f858f4
  • reachdesk-verification=oW4xJppKrSbZiG23AnTGjDPmZyaNo6EZ3k0FrRA0d4ALdRlxny7B6Dv3WCrx7asy
  • mongodb-site-verification=BqjQgqaOXnMRNXZHP8AeYPnH0Zq5EGeZ
  • atlassian-domain-verification=WPHaHy3InKYtepoCKSq9t5Qslgq5nEymmmlSNJb74cULMcmcVPLzNVWp9u9ACEPG
  • ms-domain-verification=bc2c6b49-01a8-4795-970b-f6c5a63f7039
  • Dynatrace-site-verification=89217b09-90fb-4ab2-9559-c1b5b2532c73__m83s9s8lg328ebtffn0b1i3cvo
Cloud / SaaS Services Detected
Adobe Apple Atlassian Docker Microsoft 365 Salesforce Anthropic Teamviewer Autodesk OneTrust DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot