Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

uga.edu

uga.edu

Group Clop
Discovered 2023-06-14 20:22 UTC
Est. attack date 2023-06-14
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

UGA

Infostealer activity detected by HudsonRock

Compromised Employees: 95

Compromised Users: 1421

Third Party Employee Credentials: 634


External Attack Surface: 151


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • No MX records found.
TXT Records
  • google-site-verification=zwncZ6G2jDsaF3OeQztWytnTzTz2WWPeKghso_jAPmI
  • Foxit-domain-verification=45b5f5c2615965c20ca4aab810e74cb5
  • brevo-code:cfa92b6a811325c57a586de9b893f676
  • amazonses:H8rIXKMAw9ljXAiKFbQCELD15iE+XIEOQyX+oWMcGr8=
  • brevo-code:1a1686b8b2045fd87b379b3495066b91
  • d365mktkey=0b9d6i6xF2m320TUtQiIzUYSNpW3Gj2ybCP12kiTsWwx
  • v=spf1 include:_spf.mlsend.com include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:_spf.qp-mail.com include:spf.protection.outlook.com ~all
  • smartsheet-site-validation=8Ncxe6hlB8-aDOBDBp64Lu46AmXKXmvX
  • sending_domain555812=3304d8eab997a478be9ab3f09a33a20e1905b4b3abef16f69a6bf82f090df882
  • openai-domain-verification=dv-LP1MjyPoR1m3TqgPu0l57YKm
  • jamf-site-verification=kqKOZmPM_pRLVx6hlcqSMg
  • e2ma-verification=nr4ab
  • dfacb6fb-9598-4684-815e-c053426bab30
  • atlassian-domain-verification=rZPHO8vvAWCWQbD8d3xvAqFOytZ/wDnX4WMvx5gLR4g69Bu4gsiiHGp4SjJ4poyh
  • d365mktkey=YjcbfV14vrqxM23dyVvRxi8wEuaPmwFaxFkigxn2m58x
  • apple-domain-verification=s7lypSmtIRNEf43n
  • asv=c7519f930ae5823a397f54de28c3f60b
  • adobe-idp-site-verification=1ab6cb17-3551-4869-9296-fb097a240ce6
  • brevo-code:59b3a18744d24f960bd78166f34f87c5
  • ms-domain-verification=deabb3d5-5c1a-4e57-b38e-98c74f1558b8
  • anthropic-domain-verification-dqf2ca=qAuRuABK5Lxa2QkcH4NHhcZ4I
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Anthropic OpenIA JamF

Leak Screenshot:

Leak Screenshot