Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Cactus
Discovered 2023-07-20 12:48 UTC
Est. attack date 2023-07-20

Description:

Imagination is an independent experience company with 12 offices worldwide. We specialise in designing experiences which change how people feel, think and act.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 0

Third Party Employee Credentials: 9


External Attack Surface: 0


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 4f639e79be0c71cfb8238d55237e8a8197a1b601f0e74df19334f4ef9a807fd6imagination.com.whoisproxy.org
  • 4f639e79be0c71cfb8238d55237e8a810b67a2561fec2099a1ac12a5e76138efimagination.com.whoisproxy.org
  • trustandsafetysupport.aws.com
  • 4f639e79be0c71cfb8238d55237e8a81c96bb7375afca5ff82c971b48f044e4cimagination.com.whoisproxy.org
  • 4f639e79be0c71cfb8238d55237e8a8199161c614fed67fcbe2fb44037458c6dimagination.com.whoisproxy.org
MX Records
  • alt4.aspmx.l.google.com. Google Workspace
  • alt1.aspmx.l.google.com. Google Workspace
  • alt2.aspmx.l.google.com. Google Workspace
  • aspmx.l.google.com. Google Workspace
  • alt3.aspmx.l.google.com. Google Workspace
TXT Records
  • docusign=b1833283-7882-4e41-8ab8-523b3ee5b054
  • google-site-verification=ELieoMWD1vm4NlZwUrL8KJu71AttfS6jH6erv-2n4r8
  • google-site-verification=jVaWty86659yPH6mMwBRK3IMvS3CyElRGpuosAlJ21k
  • google-site-verification=xJ2PeRD9HHsVpRpzeQoOLXIAYwWdlRjx2ZN69imOWBE
  • jamf-site-verification=8KKALelaw3J3muuOBMsxhg
  • v=spf1 include:_spf.google.com include:servers.mcsv.net ~all
  • 3ck5qnds338sipup2585du5pg7
  • apple-domain-verification=xBwcCMF0lsdlzX0Q
  • atlassian-domain-verification=9n1dZGcUH6pRCe7Y05hglbJorE1XG6B/6c07JYJz/ZYVvxWvqnK5kzASmpRXzQ8F
  • detectify-verification=28a76893cc012e8ca9224dd29cec638c
Cloud / SaaS Services Detected
Apple Atlassian Mailchimp JamF DocuSign

Leak Screenshot:

Leak Screenshot