Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2025-11-26 10:49 UTC
Est. attack date 2025-11-26
Country CA

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 4


External Attack Surface: 1


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • biopharmaservices-com.mail.protection.outlook.com. Microsoft 365
  • ss.dsmhosting.net.
  • ss2.dsmhosting.net.
TXT Records
  • v=spf1 include:spf.protection.outlook.com include:dsmhosting.net include:servers.mcsv.net ~all
  • VPzrBckgJTSaLXJw2Ug/Bk2wSQez1zZvXw1K6jmiD5Hu81xWH2gzF2f7J75wDdI1psztEhO+TBmaaw4+eZlc5g==
  • docusign=87b46125-9ee3-4f3d-b292-abefaa1788fd
  • lru67n0pm5mhpk5q93982en7ns
  • knowbe4-site-verification=6b7d96ef032c404f4a2c8ab3781bc256
  • MS=ms84915757
  • t1mddq94akvudhnmiki8dcba0q
  • apple-domain-verification=c4YCS6VYKDcVYT8N
  • euc503if9eca6ub2bu1sd2hnca
Cloud / SaaS Services Detected
Apple Mailchimp Microsoft 365 KnowBe4 DocuSign

Leak Screenshot:

Leak Screenshot