Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

goldstarfinancial.com

goldstarfinancial.com

Discovered 2026-09-23 18:20 UTC
Est. attack date 2026-09-23
Country US
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

[AI generated] N/A I don't have reliable, verified information about a specific company operating at "goldstarfinancial.com." There are multiple businesses that have used similar "Gold Star Financial" naming conventions in different jurisdictions (this is a fairly generic name used by mortgage brokers, lending companies, and financial services firms in various countries), so I cannot confidently confirm which specific entity this domain refers to, its current operational status, ownership, or verified business details without risking inaccurate attribution. If you can provide additional context (such as the specific country, registration details, or services advertised on the site), I can help assess it more accurately. Alternatively, if this is for threat intelligence purposes, I'd recommend verifying details through domain registration records (WHOIS), business registries, or regulatory filings relevant to

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 9

Third Party Employee Credentials: 4


External Attack Surface: 11


Exposure Report
by ParanoidLab
958
Passwords
73 critical
3
Cookies
0 critical
Last queried 2026-09-23 18:20 UTC

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • goldstarfinancial-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • v=spf1 include:us._netblocks.mimecast.com include:spf.protection.outlook.com ip4:207.46.163.247 ip4:74.126.9.238 ip4:72.52.238.74 ip4:207.158.48.193/26 ip4:209.216.210.32/28 ip4:198.37.147.129 ip4:34.102.239.211 include:support.zendesk.com include:amazons" "es.com include:mailgun.org ~all
  • google-site-verification=b6oNM4n-Gd-62bzfTw9W5MX96R6y1PoiM0w7LdaQgI0
  • google-site-verification=ELPagBaqH-wP_Sq3JMTHmq0RvFu3Mpc6Rs_qPa88NDA
  • globalsign-domain-verification=n6HxR3qPkGraF4-n69rBDmm5VdXfRHvAzhntbOLJqU
  • MS=ms78367846
  • apple-domain-verification=ZSxw_BliViS--FTXpLDzLDp5QnslZWEc-deFV3rt_S0
  • globalsign-domain-verification=3k_szoLqFxWpyMUly53XhNzX32tYzSTA2O1D2MpUrB
  • 0ed1fe018ad6faa38146aa44e091c504
  • finicity_partner_id:2445583511316
  • ZOOM_verify_LXAW6fSOTzSm8uG1gotW0w
  • fnrpedfcgcfjed8suhnchoafpq
  • finicity_partner_id:2445583511159
  • MS=ms82546106
Cloud / SaaS Services Detected
Apple Mailgun Microsoft 365 Mimecast Zoom

Leak Screenshot:

Leak Screenshot