Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Hunters
Discovered 2024-02-17 07:40 UTC
Est. attack date 2024-02-17
Country US

Description:

Country : United States of America - Exfiltraded data : yes - Encrypted data : yes

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 22

Third Party Employee Credentials: 9


External Attack Surface: 17


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 5588cfb10d9da5610d6e120b3785e6c1eda95eaf1db6813e5a809c69fff63058psi.org.whoisproxy.org
  • 5588cfb10d9da5610d6e120b3785e6c1a37e69a2ac5dc98d7bd3ed44fdd12013psi.org.whoisproxy.org
  • 5588cfb10d9da5610d6e120b3785e6c186e433a2265ac05c347ea8d7ca4abf76psi.org.whoisproxy.org
  • 5588cfb10d9da5610d6e120b3785e6c1f704d877bac4d4b3c06213160d3e8662psi.org.whoisproxy.org
  • trustandsafetysupport.aws.com
MX Records
  • psi-org.mail.protection.outlook.com. Microsoft 365
TXT Records
  • pardot_320231_*=a3668f3
  • v=spf1 include:spf.protection.outlook.com include:aspmx.pardot.com include:_spf.salesforce.com ip4:216.200.96.210 -all
  • 00D2E0000012gTu=1TBUu00000000JN
  • 00DA0000000H71D=1TBPC000000012X
  • anthropic-domain-verification-8mczeh=AdJOtp7mvFhCZ6g3g4FLVNDB4
  • google-site-verification=_S83kN_gd3c4sA3PgvyDJXObJb4bbwzI31KhHSFneW8
  • pardot857593=44c6ae8894524a4fbe4e83b9eddffb06f7e94efb2715291bc1bbdbc9a163384b
  • pardot857593=a9999efeaa610e0f9f7479120552b82b15c98d9fd3bc737bea1d23be57052898
Cloud / SaaS Services Detected
Salesforce Anthropic

Leak Screenshot:

Leak Screenshot