Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Babuk
Discovered 2020-10-25 00:00 UTC
Est. attack date 2020-10-25
Country GB

Infostealer activity detected by HudsonRock

Compromised Employees: 57

Compromised Users: 158

Third Party Employee Credentials: 60


External Attack Surface: 76


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 2qaaarfncpnhidp.email
  • abusesafenames.net
  • hostmastersafenames.net
MX Records
  • serco-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • v=spf1 ip4:168.245.49.105/32 ip4:54.240.30.198/32 ip4:54.240.30.199/32 ip4:52.56.103.10/32 ip4:52.56.102.31/32 ip4:35.177.105.167/32 include:spf.protection.outlook.com include:_spf-dc2.sapsf.com include:aws.us1.spf.staffbase.com include:spf.hosted.jaama.c" "o.uk include:spf.topdesk.net include:ipreomail.com include:eskerondemand.com a:mail.hertfordshire.gov.uk -all
  • j3pqch14l4ly104spx4bp9kw23sm2kfz
  • d365mktkey=SVQBZZfrdMmmuHyjTFB05bgAegQkADWtT0GARV0Ux54x
  • JkxMxl+6PCHDsjO54WeggFc40s+h04mhBOWLXccEqQA2j2q/XejbSCBY4q7QY2tQolLlTuOo3kj86LwEWnIYLQ==
  • d365mktkey=JEcuKQcUc8HYcgDfeRVH8S5e40vlfho6dFxb67xIL1ox
  • _pw22no9e1p9gektyd9jaemb5hcx9olp
  • apple-domain-verification=QEMOXn51uk2YRUd3
  • d365mktkey=qdwhl2yvWRqe1xdsnuKWxPzkPZv5xxze02AHllp3yOEx
  • d365mktkey=i6aFmxnROfYNgDpPz8a9HQSjtCFUyFi2C6nUfsxWfXwx
  • msfpkey=7eu7y8n942gkoiwrbwk3k8r2y
  • access-domain-verification=9cf916a122ed5369aa3644483883393780418d4753d31019c5ab580a48d43425
  • miro-verification=fe93d81f2e79f94fe43839fe175b823481ef54d6
  • docusign=f68fcb26-338e-4be9-9b0a-8853e2d0eb17
  • d365mktkey=cQmulkYEgxEAJvLDraml3mRJOyn0Vp0YibHGxDvFXK8x
  • _wu3fhqaxmhiwz1cpg9p2jw5wtfjuw45
  • Serco
  • d365mktkey=MNcsFP3eofTEk5ok8xqISQxBf0uvVSbig8CBTPOxmRAx
  • box-domain-verification=947ffa11d9b85ff523c6b3765e5f0cf2c87ae74352b70dbe71104ebf0953695f
  • atlassian-domain-verification=qSLeaosPqdoFnmcgEclgQh4QcfhJ29DkvMPIE8wAKnigw/tz5IDx2sJrYsg2Tv1W
  • d365mktkey=N8pmeSdCmFlldPAe6VKZ5ZCSmiqblIKDsOXxTU7xkeMx
  • d365mktkey=q1wtE6DMA1nW0KmKhNj6wRxaexo4OitfaZoperxCdQ8x
  • teamviewer-sso-verification=63b287cc33b14f7eb087509e421fc816
  • paloaltonetworks-site-verification=15c445503fcf0d0334e0eef5aebfc48325207aa63575c7ac3ff968097cb3b0ff
Cloud / SaaS Services Detected
Apple Atlassian Box Miro Teamviewer DocuSign