Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

The Estée Lauder Companies

estee.com

Group Alphv
Discovered 2023-07-26 14:08 UTC
Est. attack date 2023-07-18

Description:

The Estée Lauder Companies Inc. is an American multinational cosmetics company, a manufacturer and marketer of makeup, skincare, fragrance and hair care products, based in Midtown Manhattan, New York City. It is the second largest cosmetics company in the world after L'Oréal.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 15

Third Party Employee Credentials: 100


External Attack Surface: 3


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • whoisrequestmarkmonitor.com
  • abusecomplaintsmarkmonitor.com
MX Records
  • mxb-001a2001.gslb.pphosted.com. Proofpoint
  • mxa-001a2001.gslb.pphosted.com. Proofpoint
TXT Records
  • google-site-verification=RJ2bFg2ItNS38ICZj-ei3aXuXvShkf-zUMirHDs7tVM
  • google-site-verification=rE_Hcf8nLc1S-ZrZccM-dHTG2jM51dsfESY7LAmv50s
  • twilio-domain-verification=76874f9162c953881f324f8b25fb4ab4
  • flexera-domain-verification-dhrwydnklyycmlvj
  • cisco-ci-domain-verification=1938d59a521381095a702906795574e8e74b2d6543a8101d3ca3cd94128d9c97
  • _amazonses=tmIGidbDuNIzWDWj03HaHE3gS5LZaochdNgLnM1Tv2g=
  • airtable-verification=ce88e92ff7ffa24ce311788a46c9568a
  • flexera-domain-verification-tpwzohsioyfvcccm
  • adobe-idp-site-verification=2d625dc3-2d25-4f2b-b28f-54fd924a5002
  • apple-domain-verification=VkkzphuvBOzBJVRY
  • teamviewer-sso-verification=81bef4a24c94475e94a87ebcade541e6
  • A5hjj0GCy8cPn1o+rQTUYZLBWch1PEsCp83lAoSaocw=
  • apple-domain-verification=ZpiDi7x8Q2nlQOCH
  • MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCgZJX33AlnQkGf2mKq6KjBqiZ4wf1ceXFB7MsPEtARDrziePYHdTgHM/++pXltgosr1YWkhBSvnaNVewiDlG8u0
  • _pingoneemail=50422868-b014-40fb-9267-61d8b45bcb04_8b09759a-5942-4d0c-b115-f5d9023c98fc
  • k0cGRm7SvQcCOrg8tFJc9sEeh68tzjGudEZsXzRZhBWA0lKVQe2JUmEifwVCVn3WI/Cc0fPT5eicGABSvv5RQQ==
  • jkeT0S/B0YxYEZy/OwkrIOVyGuEQEp5XfZxrpKMcMeyLWNhQxNQ7kscTkcu+uXswpSNTcorBn1YSLAtQYDzz+g==
  • M/+Sgqe+vRh0PD2x3XRXekJOUf6n0MiZaCuYGKYiDvs=
  • MS=ms30753306
  • _amazonses=A5hjj0GCy8cPn1o+rQTUYZLBWch1PEsCp83lAoSaocw=
  • openai-domain-verification=dv-IhQfRPuaPdSbte4lAL5jmrJL
  • 384939272-475350928
  • logmein-verification-code=37b4ddcb-6682-44cd-bbc9-d881f6002987
  • onetrust-domain-verification=18053e6d27f34a15a61b6a6d16eaa76a
  • neat-pulse-domain-verification-VZX76qv=bb044b59-bc64-44f6-be26-d5bf5e3659ca
  • shopify-verification-code=Olen4s7CKkJguMpzetml52S8YaTY6v
  • 50422868-b014-40fb-9267-61d8b45bcb04_8b09759a-5942-4d0c-b115-f5d9023c98fc
  • apple-domain-verification=zW32rKLTueo2CwHf
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all
  • 7977d3704c39276ec3c349e928ee4414
  • tmIGidbDuNIzWDWj03HaHE3gS5LZaochdNgLnM1Tv2g=
  • airtable-verification=7977d3704c39276ec3c349e928ee4414
  • smartsheet-site-validation=yVla-jBmPM3iTqqiKWihWDxU_B-ayUoO
  • onetrust-domain-verification=7626a08c0da643dab87d6c3719af3879
  • _pingoneemail=bb7f86da-06e5-4dea-a07c-6267815cbf59_3819efdf-b56a-49ec-8366-65a09a37d7d9
  • wrike-verification=MjU2MDQ2MTpjNDRhZGZhN2ZhMmFjMzMwN2UzNWU3OTg5ZWVkZmY5ZTZjNjQ3MzI1NWY3YmU2MTZlNDM4ZmIwMmE4MTc2Yzky
  • Figma-domain-verification=aea0a39b9c353297a93e3880b7e5fa1bbcf4f205231842902dc10f44b4ea7224-1718394463
  • _amazonses=M/+Sgqe+vRh0PD2x3XRXekJOUf6n0MiZaCuYGKYiDvs=
Cloud / SaaS Services Detected
Adobe Apple Amazon SES/WorkMail Microsoft 365 OpenIA LogMeIn Teamviewer Flexera Cisco Twilio OneTrust Proofpoint

Leak Screenshot:

Leak Screenshot