Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

TELOS.COM

TELOS.COM

Group Clop
Discovered 2023-06-19 15:40 UTC
Est. attack date 2023-06-19

Description:

Telos Corporation - Solutions that Empower and Protect the Enterprise

Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 0

Third Party Employee Credentials: 1


External Attack Surface: 7


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • fe4120447c3d698641ceb7bdaa389762daa20968e4da99f051ac76df0e594278telos.com.whoisproxy.org
  • fe4120447c3d698641ceb7bdaa389762350eb3cd53994798b8b68891f014004atelos.com.whoisproxy.org
  • trustandsafetysupport.aws.com
  • fe4120447c3d698641ceb7bdaa3897622f02ca11eb0f2ed2384d68fae6653899telos.com.whoisproxy.org
  • fe4120447c3d698641ceb7bdaa3897629daac968978a5a38c99c31b4e54e98eftelos.com.whoisproxy.org
MX Records
  • mxa-00060b01.gslb.pphosted.com. Proofpoint
  • mxb-00060b01.gslb.pphosted.com. Proofpoint
TXT Records
  • 97cb9gvvdkdpdkxmv8r3q3hc0svzq1c1
  • _rx6hobth7u3o0s1vrzd2dfq69ais10w
  • apple-domain-verification=dROAL0IpFrn3vJk4
  • atlassian-domain-verification=JS4hX68BckZBCdbae76Pyyy3WXGhvnJkHhhffM1ODWpUiYS0ZrkVk8zj4g9QS0u5
  • cisco-ci-domain-verification=6190e8e5a4366f37000ba1e8d65431fe855a92fd277bd68eb9d6a5957be541e9
  • docusign=44f11633-d24f-4a36-8010-a3e1cea0ff7a
  • docusign=8dac9cfb-c00e-4ba7-95ce-5f6d3ccca9b9
  • duo_sso_verification=gMGEmMLpCpOlqY9lBCPU9R21Enz2xqWOtMgAoLKTqCsHRnUtfxeX2MBkRurPJfRn
  • google-site-verification=5YVXUlabUfVlbFc2tixX1lR2-9Pt3-oE3yaAnAKV-Fw
  • have-i-been-pwned-verification=dweb_xi7buc3z8jrkkt1lfkkgp7b1
  • sending_domain311471=a28eff6383cea5a77e84e395f05be2dc23e830ae9447a9288466d180ee513f91
  • slack-domain-verification=5ZYrc5LlapxUTIXePdJ5zn3kV0rPJS7b1vmbCctq
  • v=spf1 mx a ip4:18.252.149.110 ip4:15.200.201.90 ip4:198.252.228.15 ip4:198.252.228.220 ip4:198.252.228.233 include:spf-00060b01.pphosted.com include:aspmx.pardot.com include:_spf.salesforce.com ~all
  • 66z65tqtxzvnqlnzcjyt7nspcmnssp1d
Cloud / SaaS Services Detected
Apple Atlassian Salesforce Slack Cisco Cisco Duo DocuSign Have I Been Pwned Proofpoint

Leak Screenshot:

Leak Screenshot