Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Fog
Discovered 2025-03-06 01:47 UTC
Est. attack date 2025-03-05

Description:

Extract from The 19 biggest gitlabs

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 1

Third Party Employee Credentials: 1


External Attack Surface: 7


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mxb-00103a01.gslb.pphosted.com. Proofpoint
  • mxa-00103a01.gslb.pphosted.com. Proofpoint
TXT Records
  • 00D500000006sro=1TBVR0000000085
  • 00DTH000005I7RZ=1TBTH00000002oD
  • 00DVE000007F2Or=1TBVE000000023R
  • DirectFedAuthUrl=https://ciena.okta.com/app/ciena_pwcentrafederated_1/exk24kamuedchTxer0h8/sso/saml
  • adobe-idp-site-verification=034210a15b8e70e227fdf3fe74f1c7f7781ba62892475a6977d4787a8b2c74c1
  • atlassian-domain-verification=RPsyuqOa19vjyzRBqf4i+0PK0yjbRTK/rieRabLpFh5hIjSt2UuqLCYYnnuhczWU
  • docker-verification=91caf02d-2a4e-4660-bab6-2dc25cb1ca19
  • facebook-domain-verification=bo37bxthrb0413pvjc7lj4sy1jezji
  • google-site-verification=dPyynkTuvaGcKoiJrFZ5K5tc0yrjPswDCfpWmXlvcwo
  • google-site-verification=pMS-A_ODJN5iAyKsWdNPWn1ZfqgcyVicaMU4vvcTXoo
  • miro-verification=1669f9fbb641794a54eddb964bd1fe572e89959c
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
Cloud / SaaS Services Detected
Adobe Atlassian Docker Miro Proofpoint

Leak Screenshot:

Leak Screenshot