Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Memorial Sloan Kettering Cancer Center

mskcc.org

Group Meow
Discovered 2023-12-12 11:40 UTC
Est. attack date 2023-12-12

Description:

PREVIEW

Infostealer activity detected by HudsonRock

Compromised Employees: 18

Compromised Users: 300

Third Party Employee Credentials: 44


External Attack Surface: 118


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • mxa-00402601.gslb.pphosted.com. Proofpoint
  • mxb-00402601.gslb.pphosted.com. Proofpoint
TXT Records
  • MS=ms94440000
  • ca3-7da0f410f9624f4fae6dcf9ccf2ccf2e
  • 84hfoNCXMXbobC6IakYhylHcFzCCgMoChanTwGjYowx7Mk0aI0DKYxkuGvTvju/wfAPcO4qIY1axbA16idPOTw==
  • 09beb289-12ab-4d91-b48a-56585266d6da
  • openai-domain-verification=dv-K76wjzuTvBlAVFvXmhJpM2OL
  • adobe-idp-site-verification=b348fbab6c3af396a18ab2a10a3a3b2092f18873f86c4150435b40e375842bde
  • google-site-verification=z2NGRYKRpbnRMIzWWkZ1ezmDMmvbBLCirDnYS5v2i50
  • google-site-verification=mAHvMdCSp4-YCyLxxkP_KQVF5UbMYXrr8Sy_Cq0PdiI
  • atlassian-domain-verification=LUmLCJicpzD1/2UaFdML8EcVmwMq6hykxzT105XMkZlZTW31UPIaEobSaEvqVXrr
  • _szd489l5b2ii8knrmkao1k66ywuimh7
  • 84hfoNCXMXbobC6IakYhylHcFzCCgMoChanTwGjYowx7Mk0aI0DKYxkuGvTvju
  • _a267vzbfqca2m2dnvteurthnb173zdj
  • cloudhealth=25ce480b-5ef6-4089-9a08-878db39248fb
  • miro-verification=ba02fcfe3dabdbc013b11c3d8e8949be390d7c3f
  • google-site-verification=6N-oHNsc3XUO64UNuffVXtsc7KglnuAiPQ8vvWtqFWs
  • docker-verification=6ae93dd3-5b71-4ec2-875f-fbd494a2b483
  • 86435eeb-c8c2-4772-a535-4404caf56b47
  • hcp-domain-verification=1db8cc011f1d1dc467a792f9f14ecaf6ae44baf9ef9ce2b1b3a8715d76df7935
  • facebook-domain-verification=ygb8f6jzej7p4hpt2aguwoh9eoewmg
  • apple-domain-verification=IqHHmIMLJ1dLOwu9
  • Qn_8WduwfHYY2A6hPFowkIsSJQ
  • google-site-verification=WIIRq9nA7ImTqR0zMB_f3h-ugfgUV-E5ujfppEkbUh8
  • v=spf1 include:spf5.mskcc.org include:spf6.mskcc.org include:spf.protection.outlook.com include:spf-00402601.pphosted.com a:b.spf.service-now.com a:c.spf.service-now.com a:d.spf.service-now.com exists:%{ir}.%{v}.arpa._spf.mskcc.org ~all
  • ciscocidomainverification=57151d093a777cee26b3577ddaa91efd6fc7e1c53d65da5a2ef0e73c409a7c44
  • q/U6tr8sT4oxToSxJChIQQFOV4iexKXqbNKqA1hnZk2G0EbouOhfuttWCPq+q+fKb84PCgWcBkSpYsxdxP53WA==
  • 1WzLav0IwSShm-pgwKOm
  • hosting-site=msk-jh-production
  • flexera-domain-verification-vwuhxezcrfbmpuhz
  • apple-domain-verification=cuaqvRNebK151eag
  • google-site-verification=fKJxdl0vsJDL1Y_H655_5YHJr6_ZbPYVd_cQT1mzTqc
  • jamf-site-verification=3cVPbLvIYlifplNbe6bhnw
  • adobe-sign-verification=25ba5e7affb87dfdc04356730be8992
Cloud / SaaS Services Detected
Adobe Apple Atlassian Docker Microsoft 365 OpenIA Miro Flexera JamF ServiceNow Proofpoint

Leak Screenshot:

Leak Screenshot