Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Akira
Discovered 2023-08-28 13:02 UTC
Est. attack date 2023-08-28

Description:

Intertek is an international provider of quality and safety services to a wide range of global and local industries. In the pack of more than 300Gb of data you can find all set of information: personal documents, business partners info, confidential agreementsand reports. There is also information about their US affiliate Professional Service Industries.

Infostealer activity detected by HudsonRock

Compromised Employees: 408

Compromised Users: 414

Third Party Employee Credentials: 289


External Attack Surface: 189


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mxa-0025c601.gslb.pphosted.com. Proofpoint
  • mxb-0025c601.gslb.pphosted.com. Proofpoint
TXT Records
  • openatts a=dns-did; p=did:ethr:0x0c782f9CD6c6c05b86cb80f30Ae9d66aDf297A28#controller; v=1.0;
  • 63E643793D53A701F7386851693888A0E3B8A13CA34BF9806BA13C72AA90C98D
  • ibmid=ef17d089-7e6f-4ab3-83ca-2abace050c12
  • 3d28d3da-df3a-43dc-9ba2-613fb61c83fe
  • 00d1t000000fotseac
  • n1w3n8687tdg007vcsqlkwg3gs9gsh96
  • a0f3c90f-d278-4d52-b4fd-2495f4f34076
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com include:_spf0.intertek.com include:spf.protection.outlook.com include:spf.mandrillapp.com include:_spf.salesforce.com -all
  • intersight=9c54208a6794df2ad1ae645f733ea6e8757aa243761cd29202915280afa9cc5c
  • 1DFBEC3B36FAB4DE16E21890930C768249331A44751A349C2049B98487EF81AE
  • 0C625BBA84
  • UtXXjYpUMTFQodYACnTSiDAuGWDyT1aY2SxrcI3nYhy32jejYC8RoQuXeFX/jx6CCeqxl3QBCewAjjohc57lKA==
  • google-site-verification=TxqzEpuoFgXPjFsV0VHRxQRJ2MALtLadnNCHV4B15NA
  • atlassian-domain-verification=n42FalmrEeWU0AgMtDWZMaRpsCBs5SpjiqR2X3Nd8Ljijb7ymzETN6qp7BBwVvUP
  • ibmid=8af66f8f-d4ed-4156-9b97-d6769ad34928
  • ahrefs-site-verification_3a8ecaa82452b321cc41d09a40ba52a32de3cb210b1da49939b950cc09fbb8e1
  • openatts a=dns-did; p=did:ethr:0x0c782f9CD6c6c05b86cb80f30Ae9d66aDf297A28#controller; v=1.0
  • 4CB3DE03F6C0434CCF229D3FF0E02242F2FCC7313DAFF316089F964CE621E1A9
  • ms-domain-verification=7db63f74-2898-4f75-8021-2e4660135307
  • atlassian-domain-verification=Aq8y4oq2W3xZLe9aHwCsRAICHTDZswAFArkkC/BiqAGVMl1iDY1gAZ17LzAJpcZ8
  • nintex.5d07a7c46563f80d96073eb1
  • brevo-code:62dfcc8797dffc77e12389b7c45ffbc1
  • MS=ms39099776
  • ec45124c-04af-4a7e-a8b7-3d2be50627d1
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Salesforce Mandrill Proofpoint