Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

SHELL.COM

shell.com

Group: Clop

Discovered by ransomware.live: 2022-12-22

Estimated attack date: 2022-12-22

Description:

Shell Global


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • shell.com-Tech@anonymised.email
  • abuse@comlaude.com
  • ipladmin@shell.com
MX Records
  • shell-com.q-v1.mx.microsoft.
TXT Records
  • m5pH6XJm/UMzxV/TutADz4Kl0dboUJHh7180cCyD/p+5RBHj33/LSdiPFjnEXWGPQez+uElLZVAfeeP1vorhog==
  • hcp-domain-verification=8b8626010d390830e0af71dc9445743231a89e755f783804897c7df5950de525
  • atlassian-domain-verification=SfYQMaMissomX90WfR7MoGF8l6LQeuVp45SNlq07qdo9gatpSy/F69CAfUMOaztE
  • 516mkaajq1ufta49cd6qs4gqjn
  • 5rd5scsii7robjjqc7kc18nmjs
  • mixpanel-domain-verify=61dfbc63-3e0f-4b53-ad62-26977e529056
  • lpjr2mkhmby7w5dydndfvxc0lk98llb0
  • h28ra7n9j438lmumemkatjbdel
  • 5cl4k0oed72ehkvoa10v4ipn6o
  • q1mksk7p1p6byn9g81hwy0y014126d9z
  • duo_sso_verification=PTDBTnybb8VK0vk02mkuBA75Yqyu0KOZQdxiJL6h55TcM2QmTETmUz13zXyYNqup
  • docusign=47717a16-0808-482b-b670-362c050ee218
  • onetrust-domain-verification=1ac702ebcb2d40dca863857f087cf057
  • openai-domain-verification=dv-yjC9VWvOIxJjQxOMtFY8vZpx
  • fastly-domain-delegation-594378-0ZM4amkwMltEWmCIidYB-04-2023
  • google-site-verification=2RWUzwfEqaFFEu-YXOetJGyDYW_jM1QzfbK63hd_Qec
  • n8i8ceak50h50tllaatr3edhkf
  • 9kycgg9dv494rjqt1nnd06cqq2x8b7ft
  • pardot877962=43d42d10d8972bd081c2e637e06a677cbb3a07406ed9297e6b4c23f3a07a44e4
  • oibinbof2ldrrk8f0o03qhovu5
  • zsxkjt0l3138n4yz86g77689kw28g261
  • ltllqqbtqhhw684mg24g3dwwnq3jw37w
  • x7idUCqz9nWCEY0CcyH2/URUlRj3Hzo9Vfm8JmQdziLc1EEjjy+rRjBGMqI0Nn47Ru8/sDAOvHiuOZQ96IbeYQ==
  • 83784732hy
  • k5lebgsivjqnpekbv0jq81r910
  • google-site-verification=ePLLCG-tbcqjAQ9frNo-D8FcR6e4AjSNDKg5gFYFJi0
  • 3x493h89c0dxsgjwwsr7h9msc7p2g5k3
  • ba371u8b1vl9131qrk0f1frm3h
  • tpiqi03rt46c6iunqptc9gh0vs
  • pardot905062=487588ed2945ae95200b9905ecdda8e918ff69e755d759e7e6b5ae533363edc1
  • atlassian-sending-domain-verification=7b25cdbd-c3f5-4d35-acb4-0fff16852411
  • 67479A2E9D885B37AF8FB5868B275E3D4DB9DF445459E4F7C03373132488AF84
  • B0CF2F5A020200D38923562A57ACC4492AB96072A79F72B463D68009ED7B789D
  • 54z1dw6s66pmp64pmq1tbtz13f2r4l3l
  • R0IGT1MG1NUTSAYSH4CRX58HXZ9LXWIOV068SSV8E
  • 48pskkhqnt6obu4n92vl3a7am1
  • twilio-domain-verification=0178223b1df951657aa3e1e2def8991a
  • 11dbh9792bdd7no2j47o1265g5
  • jef44p27d386qk9drqed3tkr0g
  • e4h8i4ka4ur4bgkhng7c11mg24
  • evfrn1hmhnajl0hv7c1gooepp9
  • d97c7xwpcymczhpklm1dpr1xr6fn3yzb
  • k6tpym151cnp6p3p3b6bh9f5659y990g
  • 134hl1ope1i9kk2kbl6t8ihbp5
  • 1p2lou31bk4i8ceh274d0ouef
  • jkq27atp8e1b2k0cgt219uhdo4
  • pardot270112=15e5e42b1e301512adf3e51a8a7605206daec3bc1aa68afa18f90b2c8634424d
  • j1e32iga06qkpukb87v0g0eqp0
  • odfm9m1iu24t0poric4590mu79
  • vv1k4qk64kn9nqaab0nalhekka
  • muvfg8qupf7tveph8up5k72o7r
  • 7ftggy6w4c5bp3w6ljt8rv9h5dsvbd7r
  • obli3jldc5kg9eskcdv7p4oejl
  • docusign=ebc4433c-7318-4b65-b3cf-c4d01acf5b55
  • f24h05gua5o5ltd5nmt7e3tj43
  • i782jj352nhalrah0528vlmij0
  • adobe-idp-site-verification=2dcd60bb-a70f-4f4c-9832-e36e4f08745e
  • jfz9hgryxw3rs6d1xq4ctlvqdxkx0rnj
  • vfccitpee3sp44qvsgscnd1lpq
  • hcp-domain-verification=c1780cf85dee1d22876a0131e4642ee4998ba9e794102457bb7565fb27c46a94
  • bw=ByUMJFZWrkr5cE3IR5PdTjBbqxK91zzHO+N4SQLbcrRB
  • 52e9uve0stsqgoioc8fpnvq89p
  • mongodb-site-verification=QT1Vu4DO1Q6VWQPepOCIJXiHj26PZoIu
  • duo_sso_verification=WojFyyjSjqR6aEVhlNeJGxsEbub6J7DLeiA8y88ZatRECfEEkqjYaFmWwg1tuiHY
  • 8x9rgzz3pvy6nz9g9470084k519f27vk
  • v=spf1 exists:_i.%{i}._h.%{h}._o.%{o}._spf.shell.com include:_spf.shell.com include:_spf1.shell.com include:spf.protection.outlook.com include:_spf.salesforce.com -all
  • pardot995622=e4aba6e693244a7e777d31ca2819641fd25d0de16992d173b52ec081d3d9da52
  • rhbd09fq696qpol8fvjdktjir6
  • smartsheet-site-validation=yjjK074dTIEOnWIeLdErssobXkT14tjg
  • formstack-domain-verification=7182f5bd68e108664a843725ce0b1bbe
  • mindmanager-verification=46eaa26621e4955c1675b55d446c6d03325f458b59a465f898d42924010e7286
  • 9v7lgkl5vn6qu138hnacm87m7d
  • pardot905062=71d2bb6db75d59f8fea2bdccf42eea2b1426982c29442de37411d334fb48dffd
  • sh040c523rvkjb2e2vdmnm2hqj
  • becmf9keiapknkqktt5kcdsk4u
  • ji7u4e1cp654qvcjfjh2no28jg
  • rur9jt6ktbsj1ohcq8950b8ss5
  • acnv83d9hq898cmdur04r2pkd1
  • p3ov9rvqqu3nd1uhobfus9gnmg
  • f24l12r2mrp3xtc42pjgh0zz2sd51tyt
  • nw8j50tn89gmp884nly0s70tlqbcf8cx
  • mongodb-site-verification=p5sfueWDgHybEayDekRFIQaqQYpRucfZ
Cloud / SaaS Services Detected
Adobe Atlassian Salesforce Twilio OneTrust Cisco Duo DocuSign

Leak Screenshot:

Leak Screenshot