Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

fosterfarms.com

fosterfarms.com

Discovered 2023-02-22 13:36 UTC
Est. attack date 2023-02-22

Description:

Change the negotiator.He's obstructing the deal and denying the facts and the obvious obvious. And doesn't want to use valid insurance!Here are scans of insurance documents from the network of companies:http://lockbitfile2tcudkcqqt2ve6btssyvqwl...

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 2

Third Party Employee Credentials: 1


External Attack Surface: 2


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • registrar-abusecloudflare.com
MX Records
  • mxa-001de901.gslb.pphosted.com. Proofpoint
  • mxb-001de901.gslb.pphosted.com. Proofpoint
TXT Records
  • google-site-verification=iZKxWwVo8v0UAWWrn3PNXgGsJUa6Hi-qsO5XS7xpajs
  • n6p10q6e604tgah2h3el045sjg
  • psg2lcamevdkivb5j10vpss2gj
  • smartsheet-site-validation=G-l8iU3_AhL2fUqjMrtoIeby-TTxl-b7
  • twilio-domain-verification=b816b8f110ea37dbb84555ee6bbf204c
  • uw4CFrzI5wpzlSladaljUL2l/NYTUHAI0jW9RisWjcpwjjZ+kqt0Gnj/7FIOYuXjGbk8hH6hiI20o9sLWyPR6w==
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
  • vmware-cloud-verification-0a5acb51-fb28-4928-85ab-c3590ab07e12
  • 13lle7egbl07m1bouckokcjvqq
  • 6llp2lr7q36k2furds24ia3v9m
  • 7t2u2n7i36sqghu9k1555fp2f2
  • MS=ms80109893
  • anthropic-domain-verification-n7bx14=dnrp8j5Tmgn4mng2x7Cdd9H4Z
  • apple-domain-verification=f41sN82eKX25RmX6
  • dkh9sdl0ruor5reuud5r39j8j4
  • docker-verification=14df7062-4325-4234-b914-512714f6d64c
  • docusign=97d9b369-2144-42f6-b049-60534baa69f6
  • docusign=c6d1c184-be3a-401e-b5b7-9616e3103d65
  • etv8vtaoi21k684m8pku8aagfn
Cloud / SaaS Services Detected
Apple Docker Microsoft 365 Anthropic Twilio DocuSign Proofpoint