Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-10-03 15:41 UTC
Est. attack date 2025-09-07
Country US

Description:

[AI generated] Home Depot is the largest home improvement retailer in the United States. It is a one-stop-shop for tools, construction products, and various services. The company caters to do-it-yourself (DIY) customers, professional contractors, and the construction industry. It offers installation services and tool and equipment rental in addition to selling a litany of home improvement items.

Infostealer activity detected by HudsonRock

Compromised Employees: 42

Compromised Users: 55870

Third Party Employee Credentials: 104


External Attack Surface: 150


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • exchanger2.homedepot.com.
  • mxa-000e6608.gslb.pphosted.com. Proofpoint
  • mxb-000e6608.gslb.pphosted.com. Proofpoint
  • mx0a-000e6608.pphosted.com. Proofpoint
  • exchanger1.homedepot.com.
  • mx0b-000e6608.pphosted.com. Proofpoint
TXT Records
  • google-site-verification=3NvwcCmI2tiaqvhxEx918MCg-AfY9OOwxB3NpSQwTjw.
  • ciscocidomainverification=2a19d56e7ed441cd6cd10c84d904c0f8828fba1455df76c984284b5d85fa5c2e
  • atlassian-domain-verification=xqfqkDq+B7CyObHlKTiLqquR1QTlpKQeek64YJoRwFWeUm0Tihwqz8GA0enUIHSs
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ip4:148.163.149.217 ip4:148.163.153.207 include:mail.zendesk.com ~all
  • ms-domain-verification=1851d99d-d9bb-4eb8-b800-8e86a71b0fcc
  • adobe-idp-site-verification=3fbd7a09e2fe24031aad0a4a8c68e8242e227010cef9e40aeebcf4bc7addb8a0
  • OSIAGENTREGURL=https://mdm.homedepot.com/athena/enrollment/athenaiosenroll.aspx
  • mk-org-sso-967a2df0-7b8d-405b-b414-4627a3d6311e
  • bv-domain-verification=e51f90f4244f97973230f42f1a8485fc03995b331b6a856ee883e72624c85d3d
  • hj-ownership=a4r4Ms7CqBFe1WU
  • liveramp-site-verification=C7ahcr0qXYCzwhdiK-pcYbtLNhwzEvcgbvbgjovyRy0
  • google-site-verification=94tM-sDACvy_JNGSU6fp8GOaI6k5OuzXZN8PPYCtdRI
  • google-site-verification=dtvgbq00CxnP6nJC7dgLEOVtLcoKKXtdj90AImFCbuM
  • 18aa0eb980e5432c9ac85035050b628
  • pardot757373=218869be8ba439583983ba0ae0f7bfe67956ead606a3deb3f20bdfc1fd42b8cd
  • pendo-domain-verification=6163daa5-67e0-4c5d-9607-d97d6a0c9ab4
  • google-site-verification=wpZpi9YRPHBYFY7AfQOaVZSOnXuiN_LYpOsuCJRiEyQ
  • Dynatrace-site-verification=5218cc8f-b799-466b-81e2-151902ea9493__b7hius6gka10pcd61m5vcgio0c
  • b93b75bb-c0c7-445c-89eb-8560cef8dba9
  • vmware-cloud-verification-e1ffc876-3a8b-4242-94c1-9e8db12d03f1
  • onetrust-domain-verification=9be9c479e03f424d939ac18286224476
  • smartsheet-site-validation=UQZXQ9whIKMhr-lD3a9QxQbUGhnacn2o
  • ms-domain-verification=3a3a542a-71c8-45ad-ab04-7152bfba2a64
Cloud / SaaS Services Detected
Adobe Atlassian Salesforce Zendesk Bing Webmaster OneTrust Proofpoint

Leak Screenshot:

Leak Screenshot