Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2023-04-08 17:05 UTC
Est. attack date 2023-04-08
Country US

Description:

Founded in 1957 and headquartered in Hollywood, Florida, HEICO is a company that designs, produces, services and distributes products and services to segments of the aviation, defense, space, medical, telecommunications and electronics industries.SITE: www.heico.com Address 3000 Taft St, HollywoodFlorida, 33021, United States

Infostealer activity detected by HudsonRock

Compromised Employees: 7

Compromised Users: 0

Third Party Employee Credentials: 1


External Attack Surface: 3


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • mx0a-004ac301.pphosted.com. Proofpoint
  • mx0b-004ac301.pphosted.com. Proofpoint
TXT Records
  • 0ed1fe018ae9e57e322d1f4053ac546dc889117171
  • google-site-verification=6Cb2-XRMz_UGuuWz3urUT36qKYI0Ja1vu1esQjCeJDM
  • 219ffe93-2efd-4e48-8885-42fb0dacd273
  • teamviewer-sso-verification=d0395d0c2c1e4f80a106291d8944dfaa
  • knowbe4-site-verification=df9dd319399073c91bd48cae4ace1e12
  • _sd6l18jyf34gqsovbk4vz7h9gmov7kf
  • duvabn99sftg2q4240urf7je4a
  • d99044ab-6b50-4450-8dea-3dd1c9983f5e
  • anthropic-domain-verification-jqy5jm=o9vXIbRL9NMGA5e0RN5aL3cyS
  • apple-domain-verification=FHS0XTdJ2cu9EmN8
  • 1grm0pridh9ekvulcd123qg2d7
  • 4579e4ae-a575-4209-b32b-9117a7186f23
  • aaa245ce-3eda-4e12-b2d2-3fb5037a9652
  • ibmid=549e46e2-f3c9-4ea9-8d5e-cc03d0260e8f
  • cisco-ci-domain-verification=74e5c8d281179cb624132a9811e29edf5627d6e2913a29c420ff008d0bb64357
  • openai-domain-verification=dv-dVp8ylNZD6iKZVICiBQ94tHD
  • cisco-ci-domain-verification=99fc5906369451e9b91fe3adc070fd22ac70dbd7547aea08415567868e88d20
  • slack-domain-verification=2mb2iQ1Qtuuxdjxo40GK9Hyuv0AptRtkdiSfxOTs
  • v=spf1 include:spf.protection.outlook.com include:spf-004ac301.pphosted.com include:cvent-planner.com mx:heico.com ip4:97.107.117.251 ip4:205.220.161.127 ip4:205.220.172.87 ~all
  • specops-verification-code=af113ce9-fc40-4a39-b945-29f34fdfe8b1
  • 3kp2s5rohqurdlibdlup1smh1
Cloud / SaaS Services Detected
Apple Slack Anthropic OpenIA Teamviewer KnowBe4 Cisco Proofpoint

Leak Screenshot:

Leak Screenshot