Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Ryuk
Discovered 2020-03-20 00:00 UTC
Est. attack date 2020-03-20
Country GB

Infostealer activity detected by HudsonRock

Compromised Employees: 22

Compromised Users: 39

Third Party Employee Credentials: 61


External Attack Surface: 47


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • finastra-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • google-site-verification=7LO2rGNhi709eWxUqnJOiHyJX9_FqHAkRpazUsNBP8I
  • google-site-verification=-mVMo-Oo3V_YRM7daVSDwXPMOugRQFumQNjm_byHQkM
  • drift-domain-verification=7e49e17d8e7de7c27350c40eb26ba621997d127ca1340625eab4e2369465cccb
  • docker-verification=bee18490-4da8-4cce-9492-614658fdfcf2
  • adobe-idp-site-verification=e39df00ef08c1385e3278a583ce1f0355c7a541f6e974f4083b27d473791eafe
  • h1-domain-verification=oLizj8xtHKbp7Vwsa4F8F2q5KhQUApbPBknmFoMitUyUH4kD
  • atlassian-domain-verification=R1QwOI4aGpIa6kBOobWB516pVKg9b8MJT0zacarUWaiz7xVPUpCEEDDJYE7xHXAW
  • ibmid=8d0d82e1-ba72-4fe9-8c89-a704589d4d79
  • msfpkey=4chox428w8wl37wweu1gezvoo
  • docusign=d5323118-1c58-4133-a451-1b85af55dbed
  • docusign=9e663461-070f-4365-96a3-d484595dbbc7
  • atlassian-domain-verification=TfzG6YMIMj050/Me2oT0WrUTLLZQLEJMivUPhVx8THS5nt6zuR2VJmtqIL3a8BKt
  • google-site-verification=TDw9xnhuI-5NkvAv4L0betkh27CsMj0_od2xe7JapTE
  • MS=ms15095011
  • cisco-ci-domain-verification=368195510479174aadbd6ff5b26fbea35ca57de1ef4f0dad1a92fc08d08407c5
  • v=spf1 include:_spf1.finastra.com include:_spf2.finastra.com include:mailsenders.netsuite.com include:mktomail.com include:spf.protection.outlook.com include:_spf.salesforce.com ~all
  • apple-domain-verification=xaWOwvbI1mfMO15t
  • docusign=fdadff6f-b19a-42e8-9ca0-92e71e39ad7c
Cloud / SaaS Services Detected
Adobe Apple Atlassian Docker Microsoft 365 Salesforce Marketo Cisco DocuSign