Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-10-03 15:43 UTC
Est. attack date 2025-06-27
Country US

Description:

[AI generated] McDonald's is a global fast-food chain, established in the USA in 1940 by Richard and Maurice McDonald. It is renowned for its hamburgers, french fries, breakfast items, soft drinks, and desserts. Primarily, the business model is based on franchising, operating over 38,700 restaurants in over 100 countries worldwide. The Golden Arches logo is globally recognized.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 3482

Third Party Employee Credentials: 31


External Attack Surface: 100


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • sesmail.mcdonalds.com.
TXT Records
  • globalsign-domain-verification=sQ-XKBfUo5JDJd8xvoOg94ZQ0q4WWtarHMUXPLXva-
  • google-site-verification=EnEJy4OfSOZcfOxa0vglOOBdiZyRTGBoa0jFKvz64hM
  • amazonses:24YzB2l981UTyShDCxFnkb9onqr7EICEKxuiXuT0JsE=
  • amazonses:w61li6pZNv7ThE859iAQ4pB3r+/V0o3raZ+l+MjGGUM=
  • m44vwjmxlvh26mg9nf08qshrn8rzy3s3
  • i3ercugito3yrnvxyidnkrs3ronr4jyy._domainkey.us.mcdonalds.com i3ercugito3yrnvxyidnkrs3ronr4jyy.dkim.amazonses.com
  • atlassian-domain-verification=xr1imvOStLlJuzF56e9Es6XYgxsJ/g37cNaRq9ELyWsnXQwPY/FEiPGXdVFWS4vJ
  • google-site-verification=dWgCJy1wnoMQHUrevkULexZ6C4F67zRJRyhd2BD_0JM
  • v=spf1 include:spf.mailjet.com include:_spf.q4press.com include:amazonses.com include:_spf.tivian.com include:spf.protection.outlook.com include:spf.cashedge.com ~all
  • google-site-verification=IUH4L9-jC3u-HQprdyL6jS-GBE4RgbW59jup9wd8nts
  • google-site-verification=iBg7YjcBWxqMsH0VIfkAY9LwQ9Q6HNstaznRQmt-JBo
  • google-site-verification=8P1qbyxjsZuEtxjuD8vE7jaw73fnw7996n0mmon34wQ
  • facebook-domain-verification=kgdg0z0q8plsrhydjn7cfc4060qs7e
  • _d3o1mforjeyzo5o6hpvgssdka31obmm
  • fcr34w4ydxvjlpfd378b6gy13sp70nl7
  • google-site-verification=rbTHUfWUluMmGA18BckcrPVjVE2u58QQF0CE8DcHjv4
  • google-site-verification=1l2IiUZudhFss5aXQBmrC0xBBRT3SDEZcMHyKrwitWw
  • amazonses:2yrtLrBZnUnx460KXwTUxZ01Ud5ZLaiIxLObRgOROXw=
  • fastly-domain-delegation-00492901-5H2jV3eG3-2025-08-19
  • bu6vtqae5ivnlcygdwdv5tlv3ouelhgc._domainkey.us.mcdonalds.com bu6vtqae5ivnlcygdwdv5tlv3ouelhgc.dkim.amazonses.com
  • m4gcv5ds4osmwyunlxglow4zhbi2av7n._domainkey.us.mcdonalds.com m4gcv5ds4osmwyunlxglow4zhbi2av7n.dkim.amazonses.com
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Mailjet

Leak Screenshot:

Leak Screenshot