Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Rhysida
Discovered 2024-01-13 11:50 UTC
Est. attack date 2024-01-13
Country US

Description:

Lee Spring Lee Spring manufactures and distributes mechanical springs, wire forms, stampings and fourslide parts worldwide.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 108

Third Party Employee Credentials: 1


External Attack Surface: 23


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • ddfdab9c87714fdca6c9477afa7a328c.protectwithheldforprivacy.com
  • abusenamecheap.com
MX Records
  • us-smtp-inbound-2.mimecast.com. Mimecast
  • us-smtp-inbound-1.mimecast.com. Mimecast
TXT Records
  • zjbyxfdf1j6dp1ghcydy7hqt1fp98pkw
  • BAbnm7Ou/7teEbaxMwfpSGducPU2uPAIgRdtC2zHUK31yAT3K5kQxpAY4ZsGVJnLJMd8qNbkdUxTXy7j+XwL1w==
  • _lf7knmlf97ptqfhbv1lasq67ztx7lu5
  • anthropic-domain-verification-h5zdga=Yy971vDs3Cn9AdT80W7Dgk6Hi
  • bw=m0HjLLmDy97dZXeqIWLQwoV6ZXrWfByvWqtoyp33LgTM
  • google-site-verification=Ajt5L8TESGRL2K4X_oZs3aEjK3HctTaS66wfucWwkdk
  • v=spf1 a ip4:148.170.231.254/28 ip4:103.47.205.174/32 include:us._netblocks.mimecast.com include:_spf.messagegears.net -all
Cloud / SaaS Services Detected
Anthropic Mimecast