Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Travis County Sheriffs Officers Association

traviscountytx.gov

Group Royal
Discovered 2023-01-26 17:24 UTC
Est. attack date 2023-01-26
Country US

Description:

Travis County Sheriff's Officers Association is a company that operates in the Government industry.

Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 21

Third Party Employee Credentials: 4


External Attack Surface: 23


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • email.abusetraviscountytx.gov
MX Records
  • mxb-001a5d02.gslb.pphosted.com. Proofpoint
  • mxa-001a5d02.gslb.pphosted.com. Proofpoint
TXT Records
  • ed6hFcclRvEK9HO3EsBnCvUFe2PoldjI0Nb7JSaSJ/nmgmXobQl+8WPcz3r0F+1ptfOuMV8rs6S5neSWD8J4rA==
  • ca3-47c23cadacb04752a1d88d21d0ff3185
  • MS=ms15275189
  • atlassian-domain-verification=YI1XkhA7dQCowXwEk2cPtfSD6j8mFBuZAI8FmakuCVrjpfmjFXkRFupzGPQyaOTB
  • infoblox-domain-mastery=ac7039b797291403455a67f270d79e0d52e59cb74c40e54a3ad388a2083e09b69c
  • google-site-verification=7rZKInpGZlFYKYOBHenTF6LcwIdlepZaJqOM9hOAdYE
  • apple-domain-verification=aWpEdmbbhLS78GSE
  • v=spf1 include:spf-001a5d02.pphosted.com ip4:198.214.208.27 ip4:198.214.211.71 ip4:167.89.9.126 ip4:65.99.240.242 include:spf.protection.outlook.com include:_spf.legalserver.org include:_spf.salesforce.com a mx a:mail.hecorp.com ~all
  • canva-site-verification=44TmnYCWkvGAs8t2TTXLMw
  • smartsheet-site-validation=Bj4MYWekhDiciRL1kP7Pj0lkUHXp7Oyg
  • google-site-verification=W98zbZgLDpXX6CgAZ6YAnj6ZcRc1r1N03EtoEX3G498
  • MS=ms96830217
  • docusign=14daeba0-6ff4-4ec5-a769-3bca0e84a099
  • paloaltonetworks-site-verification=253c50f2219444f7d746b781b94982d9297fc289e00f1cc11621018cbba7b9a8
  • mjcwrwp23bltqvv7lz0v5j0hyx5s77nn
  • twilio-domain-verification=d4cbade8ba32745a953c8e8990794e76
  • cisco-ci-domain-verification=21c401f1847522c30afc80ebee103884f5b4000193a8848e667daff8062968b9
  • jamf-site-verification=Epjzddu8TLD5cY1zBzBJaA
  • docusign=74750e17-2b4c-45f6-9b3e-183d0fb3d61c
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Salesforce JamF Cisco Twilio DocuSign Proofpoint