Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Scania.com

Scania.com

Group Teamxxx
Discovered 2025-08-04 21:25 UTC
Est. attack date 2025-08-03
Country SE

Description:

[AI generated] Scania is a leading Swedish company that specializes in the production of heavy trucks, buses, and other commercial vehicles. It is also known for manufacturing diesel engines for heavy vehicles and marine and industrial applications. Founded in 1891, Scania has numerous subsidiaries and operates in over 100 countries, providing innovative transportation solutions focused on sustainability and efficiency.

Infostealer activity detected by HudsonRock

Compromised Employees: 116

Compromised Users: 1617

Third Party Employee Credentials: 195


External Attack Surface: 157


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • cluster2.eu.messagelabs.com.
  • cluster2a.eu.messagelabs.com.
TXT Records
  • 924e01d0-6dab-499d-902e-ceecf3a54072
  • _globalsign-domain-verification=orpPsqtpwYDX8Z1B8O46J3RXDLBWSR8PSbxHE1NH1J
  • docker-verification=6d925cfa-fbdd-4622-87d3-6b3dbefcc36f
  • atlassian-domain-verification=YL3HRreMhgrmGFdBdH/GWEqtj7DNYs6CI2N/w6ixRir2N9dXYcIWVxb8E/moLTlp
  • o5NqOzUyPzHA7eksD+MsD/cIiuOz+jCAA8V+h5yXVBM=
  • sign-in-app-verification=pe-5TnMRopNbC5Dus_ahDXW8losNLqFlRm3A2_SzVnE
  • 51/onVAIsN5gb3YCbaNZI6fU1QO/zB+28Y9sN/VTbXGz4HHCiLg98JoqUVHpo485cbLSLNJmVP7AdV+P0vfUFw==
  • modusign=01GJYF0F3V5C2Q5RTXD9XK98PP
  • _globalsign-domain-verification=IciSKoYhci2sYm5g6b-ddeohiloIEoSubMpoV1G8Je
  • openai-domain-verification=dv-U0ywfhqEsTvaLIRQXSqnS3GC
  • MS=ms77612244
  • adobe-idp-site-verification=868f105e2d05671c7283e198c2663c0b6ae13eef5096e3c3f348dbcea756b758
  • flexera-domain-verification-xxicofqsvgsefeph
  • v=spf1 ip4:20.76.228.226 include:spf.messagelabs.com include:aspmx.pardot.com include:servers.mcsv.net include:spf.protection.outlook.com ~all
  • _globalsign-domain-verification=ryREIdjfeM3vDvOgamIFeorT3dkYhiyvYlRH0-fDTJ
  • cJdPVsjlKOhYqnV69F8V7LWoq8+uKQ4Aj1j/MhSOL9c=
  • docusign=b07fa50d-1c4e-49fe-b99b-708abf3c4642
  • monday-com-verification=zoLJpU40YEEYKF05RgzZksnZeXBjFKT5DXYde0m_KgI
  • flexera-domain-verification-ggirhoekbxibxqtu
  • google-site-verification=p5XPzJYJkLLPu7Ic-AdWpMbzu0XqQndQ0j1xf9151VI
  • google-gws-recovery-domain-verification=68691363
Cloud / SaaS Services Detected
Adobe Atlassian Docker Global Sign Mailchimp Microsoft 365 OpenIA Flexera DocuSign

Leak Screenshot:

Leak Screenshot