Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Hunters
Discovered 2024-02-17 07:40 UTC
Est. attack date 2024-02-17
Country US

Description:

Country : United States of America - Exfiltraded data : yes - Encrypted data : yes

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 22

Third Party Employee Credentials: 9


External Attack Surface: 17


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • ee946d6a3b5321e7a19dae6c5f062cac1f66491ba0724a17a0f5e88da320f0b9psi.org.whoisproxy.org
  • ee946d6a3b5321e7a19dae6c5f062cacc30a1abc9bb38ec71011db498456a953psi.org.whoisproxy.org
  • ee946d6a3b5321e7a19dae6c5f062cac0c6b9ca74ac65944eb1026a19a8e4777psi.org.whoisproxy.org
  • ee946d6a3b5321e7a19dae6c5f062cac084d3c773b4d1ac0753f7320fbd6a26cpsi.org.whoisproxy.org
  • trustandsafetysupport.aws.com
MX Records
  • psi-org.mail.protection.outlook.com. Microsoft 365
TXT Records
  • v=spf1 include:spf.protection.outlook.com include:aspmx.pardot.com include:_spf.salesforce.com ip4:216.200.96.210 -all
  • 00D2E0000012gTu=1TBUu00000000JN
  • 00DA0000000H71D=1TBPC000000012X
  • anthropic-domain-verification-8mczeh=AdJOtp7mvFhCZ6g3g4FLVNDB4
  • google-site-verification=_S83kN_gd3c4sA3PgvyDJXObJb4bbwzI31KhHSFneW8
  • pardot857593=44c6ae8894524a4fbe4e83b9eddffb06f7e94efb2715291bc1bbdbc9a163384b
  • pardot857593=a9999efeaa610e0f9f7479120552b82b15c98d9fd3bc737bea1d23be57052898
  • pardot_320231_*=a3668f3
Cloud / SaaS Services Detected
Salesforce Anthropic

Leak Screenshot:

Leak Screenshot