Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-12-28 21:47 UTC
Est. attack date 2025-12-28
Country DE

Description:

Klingele Paper & Packaging Website: www.klingele.com WE HAS COLLECTED SUCH DATA AS: - Confidential documents - Clients Data - NDA - Financial data - Operations - Corporate data - Business Agreements - Technology - Total: 450GB And a lot of other VERY IMPORTANT information!

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 9


External Attack Surface: 1


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuseionos.com
  • dataprivacyprotectedionos.de
MX Records
  • klingele-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • docusign=e5c91845-899c-4325-b389-9766c1f89191
  • MS=E279D223B46DE3F74CDD32C143ADD0145B8D2D20
  • klingele.com,zqRvpMVsfZGPVQtP6ORqTwa4BEAdb/NDG81Qg7DO+tqB1aDLviLfqdR8pmrtKtZAr1hAw9G2FEOTqN116o/Ukw==
  • atlassian-domain-verification=DLHxEbV87Fh7qSZjhLtYQQ3dtJyp5gJomEHvYcnVBge8lBdkL0PXsx7b7JLvePQ8
  • google-site-verification=5OrcQJCf182QLr2s4JmUOle8vzq7dn951fUJwlLto6k
  • _4e03itaidvf47kbp99qas7kdr4n86ks
  • _b44ih9whddzgxrufa53e6al3vr78eln
  • v=spf1 a:mail.klingele.com ip4:145.253.154.82 ip4:185.173.21.12 ip4:3.67.54.56 ip4:34.107.8.58 ip4:212.227.17.10 ip4:85.10.251.246 include:spf.protection.outlook.com include:spf.exclaimer.net include:_spf-dc55.sapsf.eu include:_spf.jpberlin.de -all
  • Wr9GuvwFH4sWXAUbiuTT2INpuY9Z02OTWyHzntpuhjM=
  • apple-domain-verification=TTL9Ep9WZiADvX2F
  • _globalsign-domain-verification=O5AsHJydnTbaKJxMh_P1nXJ4gcs923jbVSiRKY4FgN
  • 2023050210425417zd5eq4fzm5bwdsn27uhadt2vicyht4wf29f165n7dmci3p9i
  • docusign=4522a12b-33e0-439e-bfb6-5e89c36a22de
  • MS=ms67938871
  • zqRvpMVsfZGPVQtP6ORqTwa4BEAdb/NDG81Qg7DO+tqB1aDLviLfqdR8pmrtKtZAr1hAw9G2FEOTqN116o/Ukw==
  • _globalsign-domain-verification=k2Rx8ZbqIwBA4pAyvefZUFa6GEavY0iztqnrwv6rj2
  • bw=jTuQE3O5d3c/+ZNYhUmpkhsT+WKb2D5uRY1fdR/D1tgi
Cloud / SaaS Services Detected
Apple Atlassian Global Sign Microsoft 365 DocuSign

Leak Screenshot:

Leak Screenshot