Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-10-05 12:13 UTC
Est. attack date 2025-10-05
Country CA

Description:

Terex Environmental Group is a leading Canadian consulting firm providing environmental technical guidance and regulatory liaison. We develop environmental programs with purpose that are technically sound and specifically designed for the energy sector. Our approach to planning and execution of environmental programs is tailored to client requirements and ensures alignment with regulatory frameworks.

Infostealer activity detected by HudsonRock

Compromised Employees: 11

Compromised Users: 83

Third Party Employee Credentials: 61


External Attack Surface: 66


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • whoisrequestmarkmonitor.com
  • abusecomplaintsmarkmonitor.com
  • hostmasterterex.com
MX Records
  • terex-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • smartsheet-site-validation=3Ql5om8H1N5n0JzBbKjEu4VAEVDyPNcH
  • google-site-verification=HalF4j4lOdwHUFWSDt4j07HYLJlYYyVcsNVu9pDEOec
  • google-site-verification=QCnlGkinTWh7KUigqNfN9qqXXakS2IFnKvhs1eVtFBw
  • pexip-ms-tenant-domain-verification=7c0afcc9-16c4-459f-99de-233502f180ef
  • neat-pulse-domain-verification-2XpmDVM=739ddd23-6aba-46c0-9d6a-5151cf50e0d6
  • UTc0yNF5uFaVwJX97KTkNEYmV70g87wdXIZTRWz4iH5ov5kdMK92RQL5HtzLC4bsEm9DlE1z2rq/letm1rlIaQ==
  • atlassian-domain-verification=nojasmd7rtmrJVDkAAN8CbrfRaMB4IL2nPG/A54xzouv7befqRx9hcCfJB4okvIN
  • v=spf1 a ip4:51.145.182.33 include:spf1.terex.com include:_spf.salesforce.com include:amazonses.com include:rp.oracleemaildelivery.com include:spf.protection.outlook.com include:et._spf.pardot.com ip4:20.16.85.137 a:c.spf.service-now.com ~all
  • MS=ms29744092
  • MS=ms95808419
  • apple-domain-verification=9pSxNbWIIJdHnw4t
  • MS=BF50ACAA7E32B6D33F8F721C94E2EF50E549A8AF
  • facebook-domain-verification=ih3eljbsr8yfebnqq0gqwyxubzvo8e
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail Microsoft 365 Salesforce ServiceNow

Leak Screenshot:

Leak Screenshot