Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Cambian Group

caretech-uk.com

Discovered 2023-02-11 15:54 UTC
Est. attack date 2023-02-11

Description:

Includes data from Care Tech Holdings PLC (parent holding company, caretech-uk.com) & ByTheBridge.co.uk & Cambian Group. A billion dollar mega-corporation and British orphans, what could go wrong?

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 25

Third Party Employee Credentials: 3


External Attack Surface: 12


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • caretechuk-com02b.mail.protection.outlook.com. Microsoft 365
TXT Records
  • v=spf1 include:spf.protection.outlook.com include:_spf.careshield.com ip4:213.212.96.93 ip4:94.229.167.37 ip4:213.143.144.20 ip4:89.187.86.17 ip4:37.128.132.100 ip4:78.31.108.198 ip4:94.229.167.29 ip4:80.6.91.150 include:servers.ebsnd.com a:mailuks.avs.ci" "vica.com a:mailukw.avs.civica.com include:spf.zohomail360.eu -all
  • MS=ms44518737
  • azQ+GtTWGfVJLolld3/aZtccjdUZ1mskFm3NPaW6ZPJ2nCGAPQ9x5jBfhxJH8Y5IK0Ct4i1Gurlstx+nhSYdAw==
  • C0A4R59901
  • apple-domain-verification=AuhPdVUWtNijkS6C
  • mh3lmdlnrm6hrip2l5k16tuuaf
  • duo_sso_verification=BVTeMVeFiONLReAz3GUgeD3sphgO64C6ejI9KaLaSDz0gHr88wewT4LeTXn3HgHD
Cloud / SaaS Services Detected
Apple Microsoft 365 Cisco Duo