Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Hunters
Discovered 2024-02-17 07:40 UTC
Est. attack date 2024-02-17
Country US

Description:

Country : United States of America - Exfiltraded data : yes - Encrypted data : yes

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 22

Third Party Employee Credentials: 9


External Attack Surface: 17


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 110c0d7e3c1252c7825e3009d1292c7f49d9ba60bb5594fd552b8f0f140f05capsi.org.whoisproxy.org
  • 110c0d7e3c1252c7825e3009d1292c7f54e799de14c4add36fdc62c44f7ae90fpsi.org.whoisproxy.org
  • 110c0d7e3c1252c7825e3009d1292c7f817e1ccede86344947de403a0dbc15e2psi.org.whoisproxy.org
  • 110c0d7e3c1252c7825e3009d1292c7fe39bc3a2472e900ed195f237ce58915dpsi.org.whoisproxy.org
  • trustandsafetysupport.aws.com
MX Records
  • psi-org.mail.protection.outlook.com. Microsoft 365
TXT Records
  • pardot_320231_*=a3668f3
  • v=spf1 include:spf.protection.outlook.com include:aspmx.pardot.com include:_spf.salesforce.com ip4:216.200.96.210 -all
  • 00D2E0000012gTu=1TBUu00000000JN
  • 00DA0000000H71D=1TBPC000000012X
  • anthropic-domain-verification-8mczeh=AdJOtp7mvFhCZ6g3g4FLVNDB4
  • google-site-verification=_S83kN_gd3c4sA3PgvyDJXObJb4bbwzI31KhHSFneW8
  • pardot857593=44c6ae8894524a4fbe4e83b9eddffb06f7e94efb2715291bc1bbdbc9a163384b
  • pardot857593=a9999efeaa610e0f9f7479120552b82b15c98d9fd3bc737bea1d23be57052898
Cloud / SaaS Services Detected
Salesforce Anthropic

Leak Screenshot:

Leak Screenshot