Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Hunters
Discovered 2024-02-17 07:40 UTC
Est. attack date 2024-02-17
Country US

Description:

Country : United States of America - Exfiltraded data : yes - Encrypted data : yes

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 22

Third Party Employee Credentials: 9


External Attack Surface: 17


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • trustandsafetysupport.aws.com
  • 18f9adb920ec478bee7e210ba50850363c76fc031324220878ab26d5a1e82643psi.org.whoisproxy.org
  • 18f9adb920ec478bee7e210ba5085036b904b56918b1672885304e28dcdef744psi.org.whoisproxy.org
  • 18f9adb920ec478bee7e210ba5085036296a400b6fbd9d63712a519ed52b7be1psi.org.whoisproxy.org
  • 18f9adb920ec478bee7e210ba5085036dcd65b7ac2b04002585faedc072baba0psi.org.whoisproxy.org
MX Records
  • psi-org.mail.protection.outlook.com. Microsoft 365
TXT Records
  • pardot857593=44c6ae8894524a4fbe4e83b9eddffb06f7e94efb2715291bc1bbdbc9a163384b
  • pardot857593=a9999efeaa610e0f9f7479120552b82b15c98d9fd3bc737bea1d23be57052898
  • pardot_320231_*=a3668f3
  • v=spf1 include:spf.protection.outlook.com include:aspmx.pardot.com include:_spf.salesforce.com ip4:216.200.96.210 -all
  • 00D2E0000012gTu=1TBUu00000000JN
  • 00DA0000000H71D=1TBPC000000012X
  • anthropic-domain-verification-8mczeh=AdJOtp7mvFhCZ6g3g4FLVNDB4
  • google-site-verification=_S83kN_gd3c4sA3PgvyDJXObJb4bbwzI31KhHSFneW8
Cloud / SaaS Services Detected
Salesforce Anthropic

Leak Screenshot:

Leak Screenshot