Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

trugreen.com

trugreen.com

Discovered 2024-05-21 00:40 UTC
Est. attack date 2024-05-03
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

TruGreen is a full-service lawn care provider focused on delivering high-quality, tailored solutions to both residential and commercial customers.SITE: www.trugreen.com Address : 1790 Kirby Parkway Forum II Suite 300 Memphis, TN 38138 USAALL DATA SIZE: ≈850gb 1. Corporate data 2. Personal users data 3. Payroll, financial & etc…

Infostealer activity detected by HudsonRock

Compromised Employees: 25

Compromised Users: 887

Third Party Employee Credentials: 4


External Attack Surface: 7


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • smtp-2.truadm.gmis.att.net.
  • smtp-3.truadm.gmis.att.net.
  • smtp-1.truadm.gmis.att.net.
TXT Records
  • d365mktkey=56a7f3dlevehfcgu37x3ruvc8
  • vr2kfitel01hbkgne0fsk0goah
  • _globalsign-domain-verification=yykX0BEfZyNaTQIOQm-yPH9zT0bzt7ugvs4O3pj0Iy
  • qo6horcb6vleqe44fk9of0pm0g
  • google-site-verification=oC-7AMOJjlfAT4N70hH9mJ00U2Ypn8kewhKFc6OuFvs
  • pmrkgjcgp1h8j1avbr9duv92gu
  • google-site-verification=2xI99Otc8ahKohzOJtwaYUZD2JDoUcBq8Scgq-j55UU
  • 5mdu6436crfns2b3ieijn8f732
  • 5LAESQ5KV7M5829TPI8D2O2QHP
  • d365mktkey=3ft9d4ga4m0bfox3yod8ham14
  • d365mktkey=z18eb16cz11cek76a2966i76
  • af8h1u5j5scj5r7roo27pjn73b
  • E11950AB36378BF2346EE8093A0B1F4F841E4467F04F6C67C40373B9F3E2B288
  • ucsgncql1a5ibm74q0c7l57ag
  • d365mktkey=3wc446glt10aso5hgj0voluia
  • 5aq0fpk574v5gjirmhvfp41f6a
  • _lmtf28axuc9laqnqxct0qar4uhb4oaj
  • l9gkqtirjft63qk0u51toe3hb
  • v=spf1 a ip4:207.166.92.11 ip4:207.166.95.11 ip4:207.166.101.207 ip4:207.166.104.207 ip4:208.115.113.186 ip4:208.115.96.41 a:mail.securenotifier.com a:mail2.securenotifier.com include:cvent.com include:spf.protection.outlook.com ~all
  • _7lg22xqtir356og298t2moe5urggvf6
  • _2ett3vw2jmooll9jzzs90sejle4lwbi
  • d365mktkey=5g8skikg66h3pdrfcs0loyyj0
  • facebook-domain-verification=qjvm82vrw3jv3elgpdu6aytvvu67z7
Cloud / SaaS Services Detected
Global Sign

Leak Screenshot:

Leak Screenshot