Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Ascom Holding AG

ascom.com

Group Hellcat
Discovered 2025-03-16 00:02 UTC
Est. attack date 2025-03-15
Country CH

Description:

44GB of sensitive data including internal reports, sales documents, confidential contracts, development tools, and source code stolen from Ascom.

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 12

Third Party Employee Credentials: 3


External Attack Surface: 5


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mx2.hc1260-33.eu.iphmx.com. Cisco/IronPort
  • mx1.hc1260-33.eu.iphmx.com. Cisco/IronPort
TXT Records
  • r9ldclk5hzt75rgdb41rjz34nvbly89w
  • d365mktkey=O04Ts8Q4hiwYZUNOAnbM23Z4Wvoq0Sqn1nK2ex1hrzwx
  • d365mktkey=KnXyzzN6OaH3qcd740uxxKxzxF0CxBEwWaVdmMUCTNgx
  • d365mktkey=0aQ3mXI4QH4x7EW01vRmwjGXxwPWjKB1s5x4pdUHSMcx
  • _f3lx0k4o5vh8z171u0st8czckqxwgv2
  • d365mktkey=SXXssW5F1x5LL2PZm2AxHiF9uDvhK2rMRXIAJobLxGsx
  • cqgzxgqjmftlfr42pd0hsxqkd5ww72hn
  • s7p5p706lg3c7smvhl955x57d66fp810
  • msfpkey=265xbdkeklrm9die4qxkydbyw
  • d365mktkey=wNOlKXTYBK3TMWfwn56YTP4J71bakTSkcYw1WMDu8Qsx
  • google-site-verification=F0SD8TfHn_gFGBB28LjaLdCznNFxR0bw9l9RWlMJO-0
  • 81dbbd5c7ae5437e8e6e27c6cd1b0294
  • v=spf1 include:spf1.ascom.com include:spf2.ascom.com include:_spf.afasonline.nl include:_spf.defgo.net include:spf.protection.outlook.com include:aspmx.pardot.com include:spf.crsend.com ip4:91.233.125.0/24 ip4:89.188.72.134 -all
  • remote-domain-verification=185f31ae-9e01-4dd4-a7fd-8f3033686bf4
  • d365mktkey=RGxnNmGkivj8F6CR6NvPNVFI44jiL5xF5xvyowuEX5ox
  • pardot903351=7da41970f3acbea199ce80d360a800dd4c85e35d81827c8e309df69baa66ee19
  • facebook-domain-verification=x9ckob8a4m3o1q5lcw15wcq3x3wy1z
  • google-site-verification=dSur9ythO0vSBkI5qax5pmkvoTyCVxzeVO0EmJKdI9w
  • d365mktkey=7mXX5yH9yJR9wtLh2eiQ1C63GV35lyfwhdeDNLtIvrMx
Cloud / SaaS Services Detected
Salesforce