Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Lynx
Discovered 2024-11-26 14:46 UTC
Est. attack date 2024-11-25
Country AE

Description:

PASSPORTs, FRESH DOCUMENTs, PERSONAL INFORMATION

Infostealer activity detected by HudsonRock

Compromised Employees: 19

Compromised Users: 35

Third Party Employee Credentials: 68


External Attack Surface: 16


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • eu-smtp-inbound-1.mimecast.com. Mimecast
  • eu-smtp-inbound-2.mimecast.com. Mimecast
TXT Records
  • dropbox-domain-verification=84bgpmjy9afl
  • K6wVdAupeQEISl8UMRqB56EXEsySAQS8Lvr2svkY0ROynnQ3Dc1idBJap8GXwGVzAdMpMbBOQXzvvQbM05l0xg==
  • v=spf1 ip4:94.200.203.26 ip4:94.200.203.78 ip4:35.244.180.124 ip4:94.56.98.26 ip4:151.253.96.60 ip4:3.29.190.251 include:eu._netblocks.mimecast.com include:spf.protection.outlook.com include:spf.emailsignatures365.com include:spf2.gmg.com -all
  • google-site-verification=iTpDnj44dectOGkl-w3YFKa1Mxbm_3NPj5Xn6Wa5i-w
  • 56x1dkg77b9zpmfkhkxg9sh588s3k42b
  • google-site-verification=HQLgYo_63FpTdRH-ffKFpV2-mpYM03VyZLyT1ow8itQ
  • knowbe4-site-verification=9c958f6d9e2f1009e0128889d9b88ea3
  • globalsign-domain-verification=9f56d6ef56dee363dfaa667da921b4cd
  • google-site-verification=-A3myZ7r1tJFdqBBUEPXgVxynfjq5sw00jHmBFcMsRY
  • globalsign-domain-verification=23EC86B12BDF1EBC5B884DFBF7642395
  • hbl7tqh9lgk0f2s089nxm0ybkqhzk39z
  • MS=ms44838977
  • atlassian-sending-domain-verification=c8a99230-18c2-414a-96c9-e7a719e37608
  • k3gqh7d3tuaqng4u48dolrjvaq
  • MS=50849BE3129D15E6CF6625FE68C53CA278782A96
  • _jlvb4q31gxhz2ljr3cq86yvpqwyd05a
  • google-gws-recovery-domain-verification=49219843
  • workplace-domain-verification=S7HqkSPByYeRSe8VX283BoYrRcgyUX
  • z7mpf95rqmhrdb5ndm1fqm0969hb6qwr
  • _z84t67k48h53c04e37ca7say2jkrivh
  • globalsign-domain-verification=E1CDA02257FC2251552A67068F4C09DE
Cloud / SaaS Services Detected
Dropbox Microsoft 365 Box KnowBe4 Mimecast

Leak Screenshot:

Leak Screenshot