Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-10-03 15:39 UTC
Est. attack date 2025-08-31
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

[AI generated] FedEx Corporation is a multinational delivery services company headquartered in Memphis, Tennessee. Founded in 1971, it offers courier express, freight forwarding, logistics services globally. Along with these, FedEx provides e-commerce, packaging, shipping and business services. It pioneered a system for real-time tracking of packages which has now become an industry standard. With a fleet of cargo aircraft, FedEx is one of the world's largest airlines.

Infostealer activity detected by HudsonRock

Compromised Employees: 720

Compromised Users: 137925

Third Party Employee Credentials: 461


External Attack Surface: 200


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mxb-0002ee02.gslb.pphosted.com. Proofpoint
  • mapper.gslb.fedex.com.
  • mxa-0002ee02.gslb.pphosted.com. Proofpoint
TXT Records
  • nds.fedexfreight.com._report._dmarc.fedex.com
  • 00D410000006AcD=1TBKd000000CaRC
  • 00D6t0000004eJE=1TBDg000000002q
  • 00Dao00001QLt8g=1TBaZ0000000Dq5
  • atlassian-domain-verification=2job4uakz9KYorWd9PBN8Tq6KRrN2G5yAqKOsHzszADfaQ9PwKiOaAbdtDkZ3lwT
  • facebook-domain-verification=6dxa3a3y7kuvcbd3k0b9ta5wryxj4l
  • 00D60000000Jp09=1TBKf0000004CCC
  • DirectFedAuthUrl=https://purpleid.okta.com/app/purpleid_pwcssonew_1/exk1s5f082kHe8IHg358/sso/saml
  • a0ac3565-0ee7-4385-9d3f-7df29342efe1
  • google-site-verification=uIkOpyVpLatBdblIufx6PlAkHI6l6hjpzYI_3Gq6qMc
  • canva-site-verification=NLONkGkmfzeUU86qZ0vNtg
  • nintex.65ca483f75f5fe12904c87e6
  • google-site-verification=tkMLnurjWwr9PYQiQL3_xLTLs3f7wfMbp7mNpmXpS_M
  • atlassian-sending-domain-verification=0505887d-819c-4c71-af35-26e7d177dc6d
  • 00D5C000000NaEX=1TBDy0000008OIG
  • atlassian-domain-verification=9AbTKYHbel9piDES8kfPa2Ka3a1JYmOJodM1sIMzAfapUsPOuNe7rwMRULE/CYk2
  • 61d5f5f80d6bf887a2564c455390870bf4fd67e93a5c90f397a41503054354e7
  • 00D4x000002ypGt=1TBKY0000004CB9
  • 00DA0000000Yox5=1TBHu00000000AG
  • twilio-domain-verification=36b432cfb143bed6a253e0f090b56626
  • sending_domain1111462=da458d0a13e4b1eeccd52a6e0a1cf7deda68b13f34603e1e31ab712f0348083e
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com a:smtp-out-colo.dmz.fedex.com -all
  • cargowise.tnt.co.nz._report._dmarc.fedex.com
  • 00DhP0000003dBJ=1TBhP00000000Xt
  • DirectFedAuthUrl=https://purpleid-stage.oktapreview.com/app/purpleid-stage_pwcssonew_1/exk2m3wzdrvU62uDc0h8/sso/saml
  • 00D24000000e4jU=1TBJ6000000wk74
  • 00DKj000000CLKF=1TBKj000000Cag7
  • sending_domain1055723=7a1448f46fb95d110d480dd7632b6fde6532bc2bc1113fbd1aa0ba47a21aa749
  • logmein-verification-code=f904b56f-b087-492b-925b-22172822e8df
  • ZmVkZXg=
  • cargowise.tnt.com.au._report._dmarc.fedex.com
  • 00D3k000000v7jg=1TBKY000000Kyjg
  • 2906633
  • 00D20000000lGYh=1TBJ60000004CFz
  • pardot1111462=e9d4498ce8a56f18fb624efcf36264a34beece2194e6ac483f46dbbd8d4e1836
  • 9d0ccc37-5edd-4435-8d02-a6208810418a
  • 00D1a000000YRuH=1TBHs000000CaRW
  • 00D53000001HP64=1TBDe000000001O
  • 00D3000000082Hq=1TBKe000000PAsc
  • IPXqui76z33ZxMRSsxNMDO3F2tpitdJyhChBbaZWoMc
  • apple-domain-verification=NjJQLKgI2BdfWarO
  • 00Dj0000000HiO8=1TBKZ000000XZCa
  • google-site-verification=meHzK89GMNZhtA3h7DUbSEP-wTvRO69zdMzxpip91QQ
  • fedexfreight.com._report._dmarc.fedex.com
  • 12ebed63-f283-4dee-a4a2-ae658768cb04
  • 00D24000000KXww=1TBJ6000000sY1p
  • yahoo-verification-key=Bawf5IxzT5NHEsy6PRcWGGm8xft14xfXgRuYY69tWT4=
Cloud / SaaS Services Detected
Apple Atlassian Salesforce LogMeIn Twilio Proofpoint

Leak Screenshot:

Leak Screenshot