Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Boldon James

fortra.com

Discovered 2025-01-29 14:29 UTC
Est. attack date 2025-01-29
Country GB

Description:

Data classification that keeps you secure, compliant, and in control. Data is everywhere and protecting it is becoming more difficult than ever. Fortra’s Data Classification enables you to establish a policy-driven foundation that helps you identify and classify sensitive data at creation, in motion, or at rest and apply the right security policy to protect it. We have 500 gb of company data in our hands. We have in our hands the source codes of their programs supplied to protect government files.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 20

Third Party Employee Credentials: 4


External Attack Surface: 9


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 16f25c593dceed6e5c6e57213e5a7129534bd8d36e9890076d345242d1a45581fortra.com.whoisproxy.org
  • trustandsafetysupport.aws.com
  • 16f25c593dceed6e5c6e57213e5a7129db6824bb2ac0fa862de9e4b6fb6a68dbfortra.com.whoisproxy.org
  • 16f25c593dceed6e5c6e57213e5a71292033f265247fd414db7ffad683c0e985fortra.com.whoisproxy.org
  • 16f25c593dceed6e5c6e57213e5a71293260f54fa59b9ff637019a3d4d7c508ffortra.com.whoisproxy.org
MX Records
  • seg1.helpsystems.com.
  • seg2.helpsystems.com.
  • seg3.helpsystems.com.
  • seg4.helpsystems.com.
  • awsseg01.helpsystems.com.
  • awsseg02.helpsystems.com.
TXT Records
  • stripe-verification=8B9EB48D6B2904129860BF11D5F31702BC51341BB36A5F00981C12EEF133870A
  • v=spf1 exists:%{i}._i.%{d}._d.espf.agari.com include:%{d}.36.spf-protect.agari.com -all
  • MS=ms98980933
  • Salesforce DP2 = 00Ddp000001W6ZZ=1TBdp00000006iB
  • apple-domain-verification=lnoWYqdaV8zD4Nso
  • atlassian-domain-verification=FlPvCFEcbTsq0mvRmWSwZwTDscv/P9mB9LmZbCkbqmF0g5bdGAMTpCZiDuBkfQud
  • docker-verification=7e2efb00-a614-4da5-9411-bae549c1f1e6
  • figma-domain-verification=5332a435b4d4c03d04af48520295ddd485eb9b3bcd0e0c1b47c800807065012b-1730173779
  • google-site-verification=0w_hB91LVWGLJhDu2e3sByFQRVGihaITtA6nm6zisqI
  • google-site-verification=fQBEUBFRHc31FJnS3YXSdHFf5EguM3r9IxCggtv-edQ
  • jetbrains-domain-verification=c29textvucst2p9e0ct242aj0
  • msfpkey=3er5se178yybgl4qu7706k837
  • salesforce-prod-verification=00Da5000015FRLr=1TBaZ0000000HQf
  • salesforce-uat-verification=00DWC000006eUFF=1TBWC0000000MdF
  • smartsheet-site-validation=J4pFbH1Eettz2EmQUfjUkPfkVrPY7ujd
Cloud / SaaS Services Detected
Apple Atlassian Docker Microsoft 365 Stripe

Leak Screenshot:

Leak Screenshot