Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Klehr Harrison Harvey Branzburg

klehr.com

Discovered 2025-05-06 18:15 UTC
Est. attack date 2025-01-14
Country US

Description:

Law Firms & Legal Services

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 0

Third Party Employee Credentials: 1


External Attack Surface: 0


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • d338929b.ess.barracudanetworks.com. Barracuda
  • d338929a.ess.barracudanetworks.com. Barracuda
TXT Records
  • mnvogqotvoalhbnomdgu3m6be6
  • jpzx8pnk7nbh285c4j2gfvf2sr6btvrs
  • 3ncprmtrdtxy4k17ksr0w408wt2f07v6
  • ppe-2dd3f4873add3e72ef8e
  • l87dr1j59slt9wvzw4s8dvryh8wl3jjp
  • 7b7w3lsj3npk4g44q029g5lk7szl10jf
  • MS=ms77579218
  • _mh9fo8misiyz6nvt5o2lhw298ds8nru
  • d8s7vwj9g41920sbcn092grnbf7d7xfg
  • v=spf1 ip4:141.162.101.25 ip4:4.78.153.13 ip4:172.255.48.66 ip4:199.116.132.73 ip4:50.254.175.61 ip4:173.61.98.95 ip4:66.161.237.8 include:spf.protection.outlook.com include:spf.ess.barracudanetworks.com include:ccsend.com include:spf.US.exclaimer.net ~al" "l
  • ghpdx1s2cflyqrf02ktglq4g746xbcjr
  • 3rtv3mljxp2ddhst3vflnwctp8j72mcr
  • bm0zjc9m68qwvh7yltj0mr08gd0m81v6
  • google-site-verification=AUzzlzHj2wf9STHaxBtioGg1IwEQaUdHtpmb8pwdgoU
  • _1reprv93v34ir3d6bd83vioja1wsskq
  • ts8mcnxtp83chf9zd61zcmbvxgb9vjkx
  • 9ymbmg971lh5vndz1zqy19sr947wm51y
  • bkv879hsqjf1ljpdh9glgwp0sqd6zp14
  • f2bmvk78nrylv01h7ch5xfkp6r76lfvc
Cloud / SaaS Services Detected
Microsoft 365