Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

BECHTEL.COM

BECHTEL.COM

Group Clop
Discovered 2025-11-21 12:56 UTC
Est. attack date 2025-11-21
Country US

Description:

[AI generated] Bechtel Corporation is a global engineering, construction and project management company. It operates in various sectors including infrastructure, nuclear, security, environmental clean-up, oil, gas and chemicals, mining and metals. Founded in 1898, the US-based company is one of the most respected in its field, with projects in more than 160 countries. Bechtel provides design, management, procurement and construction services and is privately held.

Infostealer activity detected by HudsonRock

Compromised Employees: 38

Compromised Users: 1646

Third Party Employee Credentials: 186


External Attack Surface: 115


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mxb-00399f02.gslb.gpphosted.com. Proofpoint
  • mxa-00399f02.gslb.gpphosted.com. Proofpoint
TXT Records
  • docusign=95f2dc95-6e35-4feb-9bf3-86dc7371e608
  • fSjj4aMF7d3MI+erzH4EhJEWdNbF9NzWiW8jxSU1aGOJg4vOVOY1X/h/F6cXQXh0mAWNZUodOLoRzpeQDCX80g==
  • v=spf1 ip4:147.1.154.111 ip4:147.1.234.176 ip4:147.1.234.177 include:spf-00399f02.gpphosted.com -all
  • u5pEpMQuf+DEaOfrphjxoLLy9SYCXmAhH0msVGQlrUcaJGbGfYHaWcMXNxAnsz1uK4oLJmq9S3eSaPrT1T7abg==
  • ru03csDcZuwjK99yJEHHcq1T2WPtuiR3r0zBYJZp756ECXjOEUuHBWjeG49xiS3TXHlTLtztaDN5JjKafmYw2A==
  • YmVjaHRlbA==
  • pexip-ms-tenant-domain-verification=a246a6ca-35e2-4636-93b0-2c7660fe15eb
  • google-site-verification=eUJoWNRvyRHTKIZmha4wxwOpoy4QKKTkFD0MHAPfqs0
  • _z9nv0ir894x3l4vx8mkqrjghvgvltpy
  • xq9HN+gokt9FTdRemRrCtAi5yqE0swPMku/YN/mjceIPcYQc4cW0Dc79O1z7lV2qA+SMXOrigRhiQodIgix3yw==
  • apple-domain-verification=oNSq4MlVOEpdUdGs
  • smartsheet-site-validation=SMpXZSuuif6LXwGiyeDdCrQJRitkmw1K
  • atlassian-domain-verification=lm9vet5oLT6QuFGFgSHnoV8bqQdC+esF5NB6ERELMAR2nhnaK7ZwKJbzkmOMUOYg
  • _U8NOqjcULm2hiXmTTV2
  • A4VkqixrXUQ3n4kGWJHuhV2xX9Gt2qQXIVbIuXwV5DgxP/iuaGuJTXHruzddur6aic+0yEjofhADwmPm+tvSjA==
  • google-site-verification=s_QuInBgB2VB5nMEbAAyBonK0tYa9WpIjJN0Yz5iYQk
  • wRhieipxgdPQxJ4P+kU8a11byaCicn/CncXyxBRYy3oOcAh9cpOASrFZs3srPyRm8CWvROSfcBHsK4iKt2a0Ww==
  • notion-domain-verification=bYTiSsok897wSjb2R0ZfRk7bT0D1EbdQxGsK61ZG7ND
  • google-site-verification=1z0Gz3oxZPQlruBqPnOiazxowU2WarIHkAFeD7Kxfzs
Cloud / SaaS Services Detected
Apple Atlassian DocuSign Proofpoint

Leak Screenshot:

Leak Screenshot