Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Play
Discovered 2023-09-18 20:45 UTC
Est. attack date 2023-09-18
Country US

Description:

Arizona, United States

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 10

Third Party Employee Credentials: 1


External Attack Surface: 1


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • e08dbe91395bf8c30d1a315d812f44e928bd34f0af08f348193bcf83d03c441artafleet.com.whoisproxy.org
  • e08dbe91395bf8c30d1a315d812f44e9500dfaaba1c19f82f644ac00f5454b25rtafleet.com.whoisproxy.org
  • e08dbe91395bf8c30d1a315d812f44e93a7b273cbd7b1d6d7b156eaa1ea230certafleet.com.whoisproxy.org
  • e08dbe91395bf8c30d1a315d812f44e9e5f40ffc05a5d255415af6867ea34e78rtafleet.com.whoisproxy.org
  • trustandsafetysupport.aws.com
MX Records
  • rtafleet-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • apple-domain-verification=yA39qS8rfeS9nC8D
  • firebase=xerifleet
  • google-site-verification=KKIGPxoB9El8NTAy6oarROjx7j8MenEOITCsJZNfBQc
  • google-site-verification=Lnzzf5rL48i8NqkJJOguu7BXUow2BzRvdeJRGWBBJs0
  • google-site-verification=_z2ltKr940s1QWGnqrLovjdK_G-WgeWi3xYz_vKxxvQ
  • stripe-verification=33f04b2d3ab2ce1bcdf05d73ac6e54ce2b4d4061029040ff37970dac0ff82cae
  • v=spf1 include:_spf.rtafleet_com._d.easydmarc.pro ~all
  • ZOOM_verify_IdDMccr63TSKQPOc64MpGK
  • anthropic-domain-verification-gv6zr4=JLtKa4KDXO4WXFWyM0MtMRJcv
Cloud / SaaS Services Detected
Apple Stripe Anthropic Zoom

Leak Screenshot:

Leak Screenshot