Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

AmerisourceBergen/Censora - MWI Animal Health

mwiah.com

Group Lorenz
Discovered 2023-02-06 17:38 UTC
Est. attack date 2023-02-06

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 55

Third Party Employee Credentials: 1


External Attack Surface: 4


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • mxa-00320f01.gslb.pphosted.com. Proofpoint
  • mxb-00320f01.gslb.pphosted.com. Proofpoint
TXT Records
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
  • wiz-domain-verification=42cda8feeae8c83f2ad1d581db4a7645c07d304d7fb94ad0b09087872e200d59
  • c06f68b0e09947e18a9976734690865b
  • google-site-verification=YHm2qzBkLswehhi7gO-InquDwoBN3wvOwHCIJQQ2A7o
  • sprout-social-c707e08d-1cff-43bb-9201-c189c943a82b
Cloud / SaaS Services Detected
Proofpoint