Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Four Hands LLC

fourhands.com

Group 0mega
Discovered 2024-01-25 17:30 UTC
Est. attack date 2024-01-25
Country US

Description:

Manufacturing and distributing home furnishing products, retail, design

Infostealer activity detected by HudsonRock

Compromised Employees: 6

Compromised Users: 147

Third Party Employee Credentials: 2


External Attack Surface: 21


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • fourhands-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • apple-domain-verification=Ei8EkQItsSmu9M69
  • anthropic-domain-verification-f9k3jt=nNNOQcCHaQkSmYbemuupjdraI
  • google-site-verification=GBfVgIJs3Pz-DBm5L42KVdFQ6IFSv7woNY_hwjSDO2c
  • google-site-verification=OM8akG0QLQzE4ipkKxlhh5nEM6UmOFOvnyLy0H36GII
  • _nxsg88h4wvpx95pchu94zggdhco2kqs
  • Aqi41+K2KSx9jG5CU5lJczqpnae/SieblZjOMrsUkIoPF5TM+cGXFMETUuePpxsXd5XoEaoV7yUQKabs081k2Q==
  • v=spf1 exists:%{i}._spf.mta.salesforce.com ip4:198.24.36.136 ip4:64.125.192.76 ip4:167.89.86.59 ip4:52.73.203.75 ip4:13.86.154.69 ip4:192.235.99.134 ip4:192.235.99.166 ip4:192.235.99.163 ip4:192.235.99.161 ip4:192.235.99.157 ip4:40.92.0.0/15 ip4:40.107.0." "0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144.0/20 ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149.72.0.0/16 ip4:159.183.0.0/16 ip4:134" ".128.64.0/19 ip4:134.128.96.0/19 ip4:223.165.113.0/24 ip4:223.165.115.0/24 ip4:223.165.118.0/23 ip4:223.165.120.0/23 ip4:199.255.192.0/22 ip4:199.127.232.0/22 ip4:54.240.0.0/18 ip4:69.169.224.0/20 ip4:23.249.208.0/20 ip4:23.251.224.0/19 ip4:76.223.176.0/2" "0 ip4:54.240.64.0/18 ip4:76.223.128.0/19 ip4:216.221.160.0/19 ip4:206.55.144.0/20 ip4:24.110.64.0/18 ip4:64.132.92.0/24 ip4:64.132.88.0/23 ip4:66.231.80.0/20 ip4:68.232.192.0/20 ip4:199.122.120.0/21 ip4:207.67.38.0/24 ip4:128.17.0.0/20 ip4:128.17.64.0/20 " "ip4:128.17.128.0/20 ip4:128.17.192.0/20 ip4:128.245.0.0/20 ip4:128.245.64.0/20 ip4:13.111.191.0/24 ip4:128.245.242.0/24 ip4:128.245.243.0/24 ip4:128.245.244.0/24 ip4:128.245.245.0/24 ip4:128.245.246.0/24 ip4:128.245.247.0/24 ip4:128.245.176.0/20 ip4:136.1" "47.224.0/20 ip4:207.67.98.192/27 ip4:207.250.68.0/24 ip4:209.43.22.0/28 ip4:198.245.80.0/20 ip4:136.147.128.0/20 ip4:136.147.176.0/20 ip4:13.111.0.0/16 ip4:161.71.32.0/19 ip4:161.71.64.0/20 ip4:13.110.208.0/21 ip4:13.110.216.0/22 ip4:13.108.16.0/20 ip4:13" "6.146.128.0/20 ip4:129.77.16.0/20 ip4:13.110.224.0/20 ip4:159.92.157.0/24 ip4:159.92.158.0/24 ip4:159.92.159.0/24 ip4:159.92.160.0/24 ip4:159.92.161.0/24 ip4:159.92.162.0/24 ip4:159.92.154.0/24 ip4:128.245.240.0/24 ip4:128.245.241.0/24 ip4:159.92.155.0/24" " ip4:159.92.163.0/24 ip4:159.92.164.0/22 ip4:159.92.168.0/21 ip4:128.245.248.0/21 ip4:103.151.192.0/23 ip4:185.12.80.0/22 ip4:188.172.128.0/20 ip4:192.161.144.0/20 ip4:216.198.0.0/18 ip4:66.159.240.244 ip4:66.159.238.217 ip6:2a01:111:f400::/48 ip6:2a01:11" "1:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 ~all
  • 0ed1fe018a231654f48da34decb8648bc4c348b599
  • lucidlink-verification=M411EVE5VC3NC1V43P843012HM
  • eGs3C1B/iJvoVcIWqXD9TMgFJJsqCesXot0tiKnCxosTyF5RXqHrFs3C3oWtrNXxBisNA4iTpTagJGypgMIdZA==
  • atlassian-domain-verification=qjgPzvJyIpVM0KvmfsLYJaRr0l9FIGfLJqTM4o3LDohDDNEgtttwaoqslDpBXut2
  • MS=ms43441070
  • docusign=28c6e6e3-e350-44b9-8f2e-b62ec3e49a0a
  • docusign=5cb566ab-8160-4493-bbd5-d7503aae986c
  • google-site-verification=JLkOnKIutRBnwai8pdod-6xH1YNxz1Yc_vPzrOK5H3s
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Anthropic LucidLink DocuSign

Leak Screenshot:

Leak Screenshot