Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

SAFILOGROUP.COM

SAFILOGROUP.COM

Group Clop
Discovered 2023-07-26 20:48 UTC
Est. attack date 2023-07-26

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 21

Third Party Employee Credentials: 8


External Attack Surface: 8


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • whoisrequestmarkmonitor.com
  • abusecomplaintsmarkmonitor.com
MX Records
  • safilo-mx2.esvacloud.com.
  • safilo-mx.esvacloud.com.
TXT Records
  • google-gws-recovery-domain-verification=68936419
  • google-site-verification=MWUIwbNxWpQPTUnRmVJjW4vNo7iQnz74_v6vAkTx7Os
  • adobe-idp-site-verification=c4b268beb1a879d27289538155d75882e7fa1735e36f5ae624a1cba78ab78712
  • v=spf1 ip4:212.131.146.4 ip4:195.81.177.18 ip4:88.34.104.43 ip4:89.202.144.122 a:hybrid.safilo.com include:spf.protection.outlook.com include:sharepointonline.com -all
  • MS=ms58652348
  • jamf-site-verification=mNiSTOtZuAQ6o0cGEEeyTA
Cloud / SaaS Services Detected
Adobe Microsoft 365 JamF

Leak Screenshot:

Leak Screenshot