Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Colonial Pipeline Company

colonialpipeline.com

Discovered 2023-10-15 14:47 UTC
Est. attack date 2023-10-15
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

Threat actors – they hide amongst us. It is becoming increasingly difficult to differentiate these bad actors from our heroic cyber front-line responders, who work night & day to protect their clients from ever-growing cyber threats. In fact, as we’ll discuss here, some of these threat actors operate under the guise of powerful cyber-security executives.…

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • registrar-abusecloudflare.com
MX Records
  • mxa-00349a01.gslb.pphosted.com. Proofpoint
  • mxb-00349a01.gslb.pphosted.com. Proofpoint
TXT Records
  • v=spf1 redirect=_se2b9eeaa.sdmarc.net
  • MS=ms65247187
Cloud / SaaS Services Detected
Microsoft 365 Proofpoint

Leak Screenshot:

Leak Screenshot