Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2025-11-05
Est. attack date 2025-11-05
Country FR

Description:

N/A

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domini@serverplan.com
  • abuse@serverplan.com
MX Records
  • francehopital-com.mail.protection.outlook.com.
  • deltamx01.esvacloud.com.
  • deltamx02.esvacloud.com.
  • mail.eelimedia.it.
TXT Records
  • google-site-verification=1wixCk0OFh_JA6HP2itMMhG4_1ApA_4Tei_0UxtAyxI
  • pardot1031311=602ac3c54f47184a70985370652184e93dcdf8504f78a5cdf4afcd982f14bd2b
  • sending_domain1031311=11750ceca0a1667a7534f3ba508ec62d9d5f7d20a26537da067e596ce4af6efe
  • v=spf1 include:_spf.mlsend.com include:spf.protection.outlook.com include:spf.esvacloud.com\194\160include:aspmx.pardot.com include:spf.mandrillapp.com ip4:95.174.21.213 ip4:95.174.21.214 ip4:46.28.0.61 -all
  • MS=ms84873377
Cloud / SaaS Services Detected
Microsoft 365 Salesforce Mandrill

Leak Screenshot:

Leak Screenshot