Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Fromm (FrommBeauty.com)

frommbeauty.com

Group Fog
Discovered 2024-10-18 17:02 UTC
Est. attack date 2024-10-18
Country US

Description:

16 GB

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • cluster1.us.messagelabs.com.
  • cluster1a.us.messagelabs.com.
  • mail.frommbeauty.com.
TXT Records
  • MS=ms98770879
  • v=spf1 mx include:spf.mandrillapp.com include:aspmx.pardot.com include:spf.messagelabs.com include:as400.frommonline.com ~all
  • gl8hvnoimafbedc998u5ovbe9d
  • duo_sso_verification=V8R2450oyCWUkGTdlf3er1760xMSeeC0XScsDRkEm2I5KzO2NXOReZJU0ChjnDD4
  • pardot874221=ca0a1f8981d10f2e9c9db5417264dbdeed199db8e7f9b1449caaf1b1e8f9112c
  • n76qchhv5of8hojh2u9anote7o
  • ns0uh81u0e0ovm2hjbiqnf8e8u
  • 83ugjk4c920b99ef8buk73m98
Cloud / SaaS Services Detected
Microsoft 365 Salesforce Mandrill Cisco Duo

Leak Screenshot:

Leak Screenshot