Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Orrick, Herrington & Sutcliffe

orrick.com

Discovered 2026-02-23 22:46 UTC
Est. attack date 2026-02-23
Country US

Description:

Founded in 1963 and headquartered in San Francisco, California, Orrick, Herrington & Sutcliffe is a co…

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 3

Third Party Employee Credentials: 8


External Attack Surface: 13


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • us-smtp-inbound-1.mimecast.com. Mimecast
  • us-smtp-inbound-2.mimecast.com. Mimecast
TXT Records
  • 2ekcon4vuou0ifn15vp2ru85lm
  • smartsheet-site-validation=TfyxM2IGIHWC1g73DSno2O3kLU0YQoXZ
  • typ11vn1pc28thcq3kch8wcpc61j5vnp
  • neat-pulse-domain-verification-kNm4JZM=e9e252f4-f6c5-465a-aad8-2bf247c7d056
  • MS=ms16409965
  • den9h922tjpc2f6271fm6dol53
  • 62jljn9ti77eeal3clnvgb6mva
  • logmein-verification-code=df652fc8-ff45-46d5-8f61-fd4f97055898
  • dropbox-domain-verification=hgewtxwi6e3e
  • jamf-site-verification=PRtpyuOrCgWJnveix8YG-w
  • l7ht4ndolh6il2drs1m9902pjj
  • 0E798EB93310DF2D7948348C67DB99B98137DFC11CAC7DC9BAE61156072241F8
  • apple-domain-verification=oKMNJLU0MMbuEp68
  • apple-domain-verification=rMUenylaaWX8-DHCQq3bnXaLC6P7A2c-d6BV6G_-r3M
  • _juvwvccrjdrgrx2zsmupdn2vfxqypl9
  • insomnia-validation=f603c1edfaec4715b5fbdc7acbc0bf0317b1d92652b6503d9a65cb5073f096f4
  • gLZuzzhU48IWubVTdTgi+j5AP/Kdss7KeUbSZ2Kf3RwhUgTo642wqOryWW/JJKNBn5VQqbDGB1tr/N4wEWDFZw==
  • docusign=3b817953-ffb8-45a2-9f69-fe9746b475aa
  • nmieucmajnmqmmhqq0pjub31tk
  • v=spf1 include:spf.orrick.com include:spf.protection.outlook.com include:us._netblocks.mimecast.com include:sharepointonline.com -all
  • ZOOM_verify_e1j9Qg51gvytW1GPvmB6T2
  • google-site-verification=b0Zc86S4AhnIK3_lC8Au4aj8CSAnfHALZ0JEkYibuqI
  • docusign=5eb057e3-f74b-4db6-bef8-8ccc556a4974
  • cisco-ci-domain-verification=27d06adda51787d8391bc3b8b531430220e909312377a98fa20319b030a947f4
  • YJ92g341JUvrCHc9t/FtOdlBTMRyZYFxUn6ISAtaSwrInCRrIKe+cgFmre67awSfvWbM9kSm8UzEleagwSca7w==
  • intersight=e20a35b5cf26230a4b59c63371211f22a07abafc544d54f7f7c9711e79376057
  • o42f9utqlm9899sl43gmo80t8i
Cloud / SaaS Services Detected
Apple Dropbox Microsoft 365 Box LogMeIn JamF Cisco Mimecast DocuSign Zoom