Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

communisis.com & paragon.world

communisis.com

Group Lynx
Discovered 2025-01-15 13:03 UTC
Est. attack date 2025-01-09
Country GB

Description:

With a passion for PROGRESSION we make lives better

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 3

Third Party Employee Credentials: 10


External Attack Surface: 4


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • communisis-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • j7nj0jkb9aoe19ocqkm79fi4br
  • apple-domain-verification=ofhsdnH3FGQjLDD8
  • DirectFedAuthUrl=https://login.microsoftonline.com/62128841-cfe1-4c2e-940a-78fd9a4ae217/saml2
  • yb2z7twxsxnrrk3j2pg14f0s3zs8zycv
  • MS=msXXXXXXXX
  • MS=ms95663352
  • wtbTJFiiG67yTZVkvAODgrvwL9AXJqRvBF+hHXVLHLKqMy5vP+wkcLuYdMIWxmUDSfvKXmzi+ZZy27vIZJE6Gg==
  • zoho-verification=zb65254370.zmverify.zoho.uk
  • atlassian-domain-verification=/fnoFA15nbL0wtr2n3SOsKSWgnkOhwDXLUrwvzSe/YAZOQDtXytttui24QV3dCa9
  • v=spf1 mx ip4:144.21.49.44 ip4:152.67.148.35 ip4:213.212.84.157 ip4:213.212.115.135 ip4:18.196.215.67 ip4:52.166.22.204 ip4:213.212.84.190 ip4:185.136.190.88 ip4:185.136.190.188 include:spf.protection.outlook.com include:aspmx.pardot.com include:144274418" ".spf04.hubspotemail.net include:sendgrid.net ~all
  • docusign=368dfdd1-d87c-4ac2-b4ea-cacb3cadbe94
  • u4v67eehv688bgnpv3tinj1p53
  • pardot591211=13cb148013ede09d089392994e661012b6191700239439f077993210745893e0
  • jp9mc18q2o48qhkl9mvn2mi7t
  • MS=ms10006971
Cloud / SaaS Services Detected
Apple Atlassian HubSpot Microsoft 365 Salesforce Zoho Campaigns SendGrid DocuSign

Leak Screenshot:

Leak Screenshot