Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Alphv
Discovered 2023-07-26 14:29 UTC
Est. attack date 2023-05-26
Country CA

Description:

Procurri is the only 100% channel focused company in our space that focuses exclusively on partnering with the channel to deliver lifecycle solutions not typically available from the traditional IT channel. Head offices Asia, Europe, USA, Canada.

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 4


External Attack Surface: 1


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuseinstra.com
  • infodomain-contact.org
MX Records
  • procurri-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • google-site-verification=E-oj2eBjoT21hktCay8cey7CxTtI0n0N6JV2OA46dO8
  • amazonses:+4960c7ypVyJ+CcqWIuF13FD3ZlGsSDKe++VILxA+I8=
  • 31t3m6qts68zccyprf70g30w6zwdgbj8
  • v=spf1 ip4:103.13.129.211 ip4:103.13.131.112 include:spf.protection.outlook.com include:infusionmail.com include:spf.mandrillapp.com include:servers.mcsv.net include:_spf.salesforce.com include:6535012.spf10.hubspotemail.net -all
  • 7t541v4qmf5d4c9gfrmlh4dbvv
  • kkmdcqjksspt98k1c0tqjec9mb
  • jqiomjkcmk297m2nhdm14up7a3.
  • v=verifydomain MS=6906991
Cloud / SaaS Services Detected
Amazon SES/WorkMail HubSpot Mailchimp Microsoft 365 Salesforce Mandrill

Leak Screenshot:

Leak Screenshot