Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

casepointcom (UPDATE)

casepoint.com

Group Alphv
Discovered 2023-07-26 14:28 UTC
Est. attack date 2023-05-30
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

We have over 2TB of very sensitive data, lawyers, SEC, DoD, FBI, Police and more.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 13

Third Party Employee Credentials: 4


External Attack Surface: 3


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • trustandsafetysupport.aws.com
MX Records
  • casepoint-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • google-site-verification=e0wriGzzIm_zHNAOPWmLOQG-sJvP_9ojA-cJDgOrDQg
  • asv=9cd0d1b68acc60690525946f8d63b567
  • zoho-verification=zb38747037.zmverify.zoho.com
  • 642bzpy0kd5v5fkf70xnj5n1z3xxl9yy
  • google-site-verification=ImqMKtxWlGm2JvUCqOcYhS-N7JHlG247_EU-Pra-nFI
  • D51B7D66E9
  • MS=30CED4E9FA6986DA0C9A470B8DDF7DEE9CF3FAF8
  • _globalsign-domain-verification=myuoZnZpKfF5rYNz0xH6HX0Z5stU1Zlfm3F-X9CQJJ
  • oedq76saiallq9wc7idtq8qryu9jnsr8
  • globalsign-domain-verification=7700E772399345D12C7DB93789A3C217
  • jamf-site-verification=JD-IwuhKDTFuvB7BIZkXUA
  • google-site-verification=LM0baGxUeyxIIQ_0B4ByTp2qHll__4Y0hnwUjM5jRkc
  • MS=ms93611685
  • site24x7-signals-domain-verification=1f59a82cbf40ed1c913eb2c66511ecbe
  • _globalsign-domain-verification=aZbB5DG6BilvhRoBGsX4DXN1bkeXYLv1WH-Ck8Tsde
  • google-site-verification=Ru2UlUgZHH_qbyTQzkstD5429R4lPMWXUcDmCjUPXms
  • cywetadns-domain-verification=b9e8023263296806c2529fe7e50a54d3
  • D1D80034FD
  • ms-domain-verification=596fa3cf-f914-4606-8864-a100115af4b7
  • MS=ms20094822
  • v=spf1 ip4:64.125.48.179 ip4:38.101.76.200 mx include:spf.autopilothq.com include:_spf.salesforce.com include:_spf.google.com include:mail.zendesk.com" " ip4:3.93.157.0/24 ip4:3.210.190.0/24 ip4:18.208.124.128/25 ip4:54.174.52.0/24 ip4:54.174.57.0/24 ip4:54.174.59.0/24 ip4:54.174.60.0/23 ip4:54.174.63.0/24" " ip4:129.213.161.164 ip4:129.213.186.234 ip4:150.136.214.119 ip4:129.213.169.163" " ip4:108.179.144.0/20 ip4:139.180.17.0/24 ip4:141.193.184.32/27 ip4:141.193.184.64/26 ip4:141.193.184.128/25 ip4:141.193.185.32/27 ip4:141.193.185.64/26 ip4:141.193.185.128/25 ip4:143.244.80.0/20 ip4:158.247.16.0/20 ip4:216.139.64.0/19" " ip4:23.21.109.212 ip4:23.21.109.197 ip4:52.49.235.189 ip4:54.172.84.90 ip4:147.160.167.0/24 ip4:203.112.132.100 ip4:103.181.101.2" " ip4:38.68.201.66 ip4:208.185.225.66 ip4:38.101.76.200 ip4:64.125.48.179 ip4:20.175.228.184 ip4:103.181.101.2 ip4:203.112.132.100 ip4:38.32.130.170 ip4:209.249.209.146 ip4:38.104.101.242 ip4:38.120.135.35 ip4:216.200.231.226 ip4:38.32.96.255" " include:spf.protection.outlook.com -all
Cloud / SaaS Services Detected
Global Sign Microsoft 365 Salesforce JamF Zoho Campaigns Zendesk

Leak Screenshot:

Leak Screenshot