Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

John R. Wood Properties

johnrwood.com

Group Medusa
Discovered 2024-04-08 19:17 UTC
Est. attack date 2024-04-08
Country US

Description:

Founded in 1958, John R. Wood Properties is a global real estate company headquartered in Naples, FL. John R. Wood Properties corporate office is located in 9130 Corsea Del Fontana Way, Naples, Florida, 34109, United States and has 1,242 employees. The total amount of data leakage is 1.07 TB

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 1

Third Party Employee Credentials: 4


External Attack Surface: 2


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • infodomain-contact.org
  • trustandsafetysupport.aws.com
MX Records
  • spam.johnrwood.com.
TXT Records
  • MS=ms84952812
  • amazonses:1Bcr5+K2Jh93UC1qH5u7BRZ+ecfiCCeOhRm0a4wsYfI=
  • atlassian-domain-verification=GkML2HXYiXtlGUjBADZIIDCXLipNfXZLqe3+BQy8urDh9k+JUoXO81XYY1GNZe7E
  • docusign=8cc3965e-98cf-4db5-9497-54567ee24f90
  • google-site-verification=plCtSD0Jmu2i7p7QMk9rhER6iiaTCFjfDdTWeeg0xHs
  • kb1gad3t2ne1glvk3n8a835hmk
  • kkWeH5<y!XaMtvvqY2%NTzrUkM%kA[cf" "google-site-verification=RAUdiMpYIqkeBY7Icv9w81aZ0JN0GHlI9NvuuAPfSW0
  • logmein-verification-code=4d904639-7290-4887-bfa7-7485c4465849
  • qoa5c72jd4a5jb4ipvs5qbhpuj
  • r19mc2jd6e09821fqd8o531nj5
  • v=spf1 a ip4:207.126.101.0/24 ip4:192.237.158.166 ip4:209.61.151.173 include:spf.protection.outlook.com include:_spf.lwolf.com include:sendgrid.net ~all
  • 7ljdh27u52cai2hdfflijvhsrq
  • 86p0lneq51kbemcsj8f696mo6o
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Microsoft 365 LogMeIn SendGrid DocuSign

Leak Screenshot:

Leak Screenshot