Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

agilysys.com

agilysys.com

Discovered 2024-04-19 11:37 UTC
Est. attack date 2024-04-19
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

agilysys.com

Infostealer activity detected by HudsonRock

Compromised Employees: 6

Compromised Users: 5

Third Party Employee Credentials: 6


External Attack Surface: 10


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • agilysys-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • atlassian-sending-domain-verification=f0a539f7-bd1c-4910-8410-2826adbffe2a
  • 00D36000000uHJy=1TBRn00000001XB
  • Dynatrace-site-verification=437da1b3-02b8-4939-83e9-19ed2737a82d__11lc9ai382eqc2asbugkj3l9og
  • agilysys-domain-verification-pnfkhe=ZfEyzNi8PSfjht112LQI5pHSp
  • openai-domain-verification=dv-ug0Tkajs9i7ThOjBRcx82C9P
  • anthropic-domain-verification-6r03gm=sffWcu3zlHbVFO5IoUUXWqGn7
  • onetrust-domain-verification=4d0139101b664d9586e5d2d5cf8ff399
  • docusign=8a9ff1ee-ab72-4518-885d-6cef9e83691e
  • atlassian-sending-domain-verification=7758c95e-d95d-4db3-8e77-f87c77b1bf47
  • atlassian-domain-verification=NQ5S8AVaNciJOy9bXxw7/O9e7UpWFRSlqwrLPZrR/YjPs037yssBPKHxZbnq8rrY
  • 4ad38aca-e779-44c5-92f4-125947fbb968
  • agilysys-domain-verification-1dny2v=aMaXiMI1ZtwRKaUCP5PPN98Bd
  • q8k9em4girrn9ijsf1lhj0d0cj\010
  • MS=ms68477214
  • Dynatrace-site-verification=72e9b01f-5eda-475f-9b5a-0c2ed1523067__2o314vgl5omik3fqdl08iv3cfv
  • atlassian-domain-verification=XcR3aQxG1QGi2jVyOY2u/U7aW6joJ3A4aTsoIcN106yYAgU4Y5kz2DGps8XTsdgu
  • openai-domain-verification=dv-tyIA4adjXUNwuBRhdXovs83O
  • wiz-domain-verification=1d55822a2bcbd1e51559a18a793ccc93d055176aea12acbf75eaaa7a00589fc2
  • twilio-domain-verification=c026c1ca9b01bed1cc8e393f59d00e9f
  • VtN3bzqFGaLh/AqF1OMwP12v7UQDmqnKaA7MrIWf80/3UwXqV4DHbPwXfVvjg/Z3o1lopmokIcVwMQd4S65aTQ==
  • docusign=cac4b1de-0d51-44bf-8b01-07b6444975fa
  • datadome-domain-verify=5fkpgv7eIA8AQVLiMZS97QEvabaDEccB
  • onetrust-domain-verification=859b93c5a117449aa503552ec6fc8241
  • cursor-domain-verification-hjcvk0=4eTGNcZL2tFUGlie3bvt0rmPR
  • amazonses:1KOR45uZbroKjHwUZMlgLs1lYtcKHs+s7CJpHsbq6Jw=
  • anthropic-domain-verification-0pqay4=jdmgNpWhD6a917VBxF8MgZoWF
  • docusign=a33c12b4-c5df-4571-9f62-542152b09807
  • af5de1fb-9854-44f5-a127-c4886dcdf6b0
  • docker-verification=82700998-e191-4134-8f93-588edf413ba7
  • mongodb-site-verification=rWMA34ls4szByefZiDfGRAZpSL4hHeWh
  • v=spf1 include:aspmx.pardot.com include:spf.protection.outlook.com include:_spf.salesforce.com include:_spf.psm.knowbe4.com include:es._spf.adp.com include:amazonses.com " "include:mail.zendesk.com ip4:167.216.128.0/22 ip4:64.89.44.0/23 ip4:199.33.128.11 ip4:199.33.128.176 ip4:199.33.128.174 mx ~all
  • onetrust-domain-verification=837920a2326c4cb8897c1fc339f307fb
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Docker Microsoft 365 Salesforce Anthropic OpenIA KnowBe4 Zendesk Twilio OneTrust DocuSign

Leak Screenshot:

Leak Screenshot