Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

itt.com

itt.com

Discovered 2024-04-19 12:08 UTC
Est. attack date 2022-10-23
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

itt.com

Infostealer activity detected by HudsonRock

Compromised Employees: 9

Compromised Users: 13

Third Party Employee Credentials: 14


External Attack Surface: 13


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mx2.hc2313-10.iphmx.com. Cisco/IronPort
  • mx1.hc2313-10.iphmx.com. Cisco/IronPort
TXT Records
  • globalsign-domain-verification=3C0AE977C9A41A3666922699EEFB996F
  • 9CpzIHJTQBHshVgsePik5lhFzsKEloyLMHTDzlbSbrytfYnpneBV2s7cGcyaJ3CmhzCFz3VZtkI/qhM6PSaEIw==
  • ciscocidomainverification=722f6e004aff4ad1941d108b8647a80510033906eb225ac48ef5843284dcc089
  • docusign=0b8301ee-e6e7-4ffe-91d5-09a17c038284
  • docusign=a848c6de-9589-4d62-9349-03afa087cd77
  • v=spf1 exists:%{i}.spf.hc2313-10.iphmx.com mx a:email.itt.com ip4:199.253.126.5 include:spf.protection.outlook.com include:spf.braintreegateway.com include:_spf.salesforce.com include:_netblocks.icims.com -all
  • duo_sso_verification=yOqUeEgoL0bTGqcv9wPUV7VU4pNxWV9mk83fYxDAdNaxLSF2O55LcavDYCUedg7z
  • zvbt75z.ng.impervadns.net
  • atlassian-domain-verification=d8tAjOZaIN088mIROSrQYrnedO6nGPf7lm4KbMjdkuZeH8D0fbNKup7Huyh11NFJ
  • openai-domain-verification=dv-PkWaoRj7tkFGUWebQVUrciJK
Cloud / SaaS Services Detected
Atlassian Salesforce OpenIA Cisco Duo DocuSign

Leak Screenshot:

Leak Screenshot