Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ATSG, Inc

Group: Bianlian

Discovered by ransomware.live: 2024-11-09

Estimated attack date: 2024-11-09

Country: US

Description:

ATSG, Inc. was founded in 1994 as an IT solution provider with an initial focus in the enterprise networking arena.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 12

Third Party Employee Credentials: 9


External Attack Surface: 5



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • us-smtp-inbound-2.mimecast.com.
  • us-smtp-inbound-1.mimecast.com.
TXT Records
  • vW+NqGFitmQzxpnSrWZ+7KIcNz9u6fPXtupi4ljN8yjHuOggmv74/QHUaCC24oV7Gk434cTCp0pTMN98cwTEcA==
  • cisco-ci-domain-verification=61813aeba0023570de2439d5d3cb2d503e0dba9cd01de0203e763ae6b692a35
  • cisco-ci-domain-verification=39394610157ba9ef75578d024f1be31992f653ea76e8f7a2305196411420c536
  • v=spf1 include:aspmx.pardot.com include:_netblocks.mimecast.com include:_spf.salesforce.com include:spf.protection.outlook.com ~all
  • atlassian-domain-verification=NKytmM73c1HTERd23nvN3MAsovcmyHUlqn0u4baP99dfiDEgcMmVOalseut89FPo
  • nintex.63d2cbf84bdba082a5c15231
  • loej4ihovihsh4beoapnu2hjqj
  • google-site-verification=9mLA9KDHV7K0kZlkqB3XEvfz5C97ZyZ-Reo57MukxzE
  • 93r1lbq6e1dvob7cmg7k95dbi0
  • sending_domain420812=1b7c2705a275ba90dca2a937cdeb1a4725ea3a3f9764ff59ef7c869c749e9ddc
  • 0ed1fe018a6c457f021ed7488896f8d3bb9678670e
  • 186ha47dqeju6hirfc0o2uumqg
  • google-site-verification=O-63K0DLlrORiKyDqZ8D1BPWI7yj3ozu2DDk-o7oNAM
  • pardot420812=c8c842aa3418bda393679329c7525b5328b1118a3f55f56160e123406028e5d3
  • 7nhii4hj84r367oi620sn8b7ld
  • cisco-ci-domain-verification=5de3495d94f16ff18d50c138fea7a4e5f677eb7f9c81318e073c35179bb6905e
  • MS=ms66599736
  • qoo8110avf56n95rqc5sfugovq
  • docusign=c7f5200c-1fd0-41b2-9f40-4006d6e89af1
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Salesforce Cisco Mimecast DocuSign

Leak Screenshot:

Leak Screenshot