Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Everest
Discovered 2025-11-10 22:19 UTC
Est. attack date 2025-11-10
Country BE

Description:

[AI generated] AGFA, short for AktienGesellschaft für Anilin-Fabrikation, is a multinational company that develops, manufactures, and distributes analogue and digital imaging systems and IT solutions. The company's history traces back to 1867 in Berlin, Germany. The company operates in four divisions: health care, graphic systems, materials, and glass. Products include systems for radiology, cardiology, hospital and clinical care, printing and publishing industries.

Infostealer activity detected by HudsonRock

Compromised Employees: 27

Compromised Users: 3

Third Party Employee Credentials: 25


External Attack Surface: 6


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusereportkey-systems.net
  • abusekey-systems.net
  • infodomain-contact.org
MX Records
  • agfa-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • google-site-verification=S9LmGqZ35uWKrMXWJtL7rHbDXo6rPqBC_gvNx_tuVQg
  • spf2.0/pra include:spf.flexmail.eu ?all
  • atlassian-domain-verification=1crEnZ/lw/EKowaTkonft45rzmXxQ0inEhzNeOubHraFRzfck8sCvDSxOMfe9dXI
  • v=spf1 ip4:134.54.0.0/16 ip4:208.76.6.0/24 ip4:62.70.39.128/27 ip4:62.72.103.25 ip4:62.72.103.250 ip4:67.30.130.0/26 ip4:59.84.174.120/30 ip4:217.7.144.170 ip4:80.154.4.226 ip4:188.64.79.0/24 ip4:64.106.173.0/25 ip4:192.69.130.0/24 ip4:193.201.138.36 " "include:spf.flexmail.eu include:spf.clearslide.com include:servers.mcsv.net include:spf.protection.outlook.com include:_spf-sfdc.successfactors.com include:_netblocks.act-on.net " "ip4:82.192.79.97/27 include:spf.trustit.eu include:_spf.cmail.ondemand.com ip4:212.99.44.69/32 ip4:212.99.44.71/32 " "ip4:199.255.192.0/22 ip4:199.127.232.0/22 ip4:54.240.0.0/18 ip4:69.169.224.0/20 ip4:23.249.208.0/20 ip4:23.251.224.0/19 ip4:76.223.176.0/20 ip4:54.240.64.0/18 ip4:76.223.128.0/19 ip4:216.221.160.0/19 ip4:206.55.144.0/20 ip4:24.110.64.0/18 " "ip4:103.23.64.2 ip4:103.23.65.2 ip4:103.23.66.26 ip4:103.23.67.26 ip4:148.139.0.2 ip4:148.139.0.31 ip4:148.139.1.2 ip4:148.139.1.31 ip4:148.139.104.16 ip4:148.139.104.17 ip4:148.139.105.16 ip4:148.139.105.17 ip4:148.139.124.21 ip4:148.139.124.22 " "ip4:148.139.124.23 ip4:148.139.124.24 ip4:148.139.125.21 ip4:148.139.125.22 ip4:148.139.125.23 ip4:148.139.125.24 ip4:148.139.142.17 ip4:148.139.142.18 ip4:148.139.142.19 ip4:148.139.142.20 ip4:148.139.143.17 ip4:148.139.143.18 ip4:148.139.143.19 " "ip4:148.139.2.2 ip4:148.139.3.2 ip4:149.96.1.26 ip4:149.96.13.2 ip4:149.96.132.2 ip4:149.96.133.2 ip4:149.96.14.2 ip4:149.96.194.2 ip4:149.96.195.2 ip4:149.96.2.26 ip4:149.96.220.2 ip4:149.96.221.2 ip4:149.96.5.2 ip4:149.96.5.209 ip4:148.139.143.20 " "ip4:149.96.5.3 ip4:149.96.5.6 ip4:149.96.5.7 ip4:149.96.6.2 ip4:149.96.6.209 ip4:149.96.6.3 ip4:149.96.6.6 ip4:149.96.6.7 ip4:199.91.136.26 ip4:199.91.136.28 ip4:199.91.137.2 ip4:199.91.137.26 ip4:199.91.139.145 ip4:199.91.139.22 " "ip4:199.91.139.23 ip4:199.91.139.24 ip4:199.91.140.26 ip4:199.91.140.28 ip4:199.91.141.145 ip4:199.91.141.22 ip4:199.91.141.23 ip4:199.91.141.24 ip4:37.98.232.12 ip4:37.98.232.2 ip4:37.98.232.26 ip4:37.98.234.2 ip4:37.98.235.2 " "-all
  • MS=ms87248394
  • google-site-verification=h_VaPRcNlNHpq-7F9aBdSPC9iVoPyZ9uVlFPNOJu2Ls
  • google-gws-recovery-domain-verification=61924044
  • adobe-idp-site-verification=d17c66ff895e2a84f8be2367ea6efa9fa059043151c0071f4d533bf5caac27d0
  • 88cjr6avru5qs31s5rd0llb7o7
  • google-site-verification=2zp0xvt7-7LnVaQF8XWpv9xLLJbbN4j5WbCi41E1SsA
  • miro-verification=43b21aa6bb419480b306689972410b2542c8f956
  • d365mktkey=Ax4AjA1bgao2XdAmKN6xbcEooEwrncyQXPxDQPi4LkIx
  • v4tdu9gkvb8d7m0pmjdqs9ch43
  • cisco-ci-domain-verification=cbe587ae121d956e1a791b5b9708eacb8bf5db659c6f4264f4c6881b284d45d
Cloud / SaaS Services Detected
Adobe Atlassian Mailchimp Microsoft 365 Miro Cisco

Leak Screenshot:

Leak Screenshot