Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

51talk.com

51talk.com

Discovered 2025-03-18 18:38 UTC
Est. attack date 2025-01-30
Country PH
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

A lot of interesting info: 1G - 51TalkActivity_backup_2025_01_25_030001_1281267.bak 1G - 51TalkNewStaff_backup_2025_01_25_030001_1281267.bak 1G - 51TalkOA_backup_2025_01_25_030001_1437541.bak 9G - 51TalkOAtask_backup_2025_01_25_030001_1281267.bak...

Infostealer activity detected by HudsonRock

Compromised Employees: 60

Compromised Users: 3208

Third Party Employee Credentials: 50


External Attack Surface: 136


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • DomainAbuseservice.aliyun.com
MX Records
  • mx1.qiye.aliyun.com.
  • mx2.qiye.aliyun.com.
TXT Records
  • v=spf1 include:_spf.mlsend.com include:spf.qiye.aliyun.com -all
  • google-site-verification=4epKg8f-ZAfyWmTe7EvqGAOOY941CgVprSjr9zFThYw
  • _globalsign-domain-verification=up0arwtVObwQHBtwXZQCtDRa2eSGRD8btljUwukLzk
  • mailerlite-domain-verification=69a2edc0063db47d70e18a8bd2669ca31268ae30
Cloud / SaaS Services Detected
Global Sign

Leak Screenshot:

Leak Screenshot