Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

terra#####

teradata.com

Group Clop
Discovered 2024-12-24 23:05 UTC
Est. attack date 2024-12-24
Country US

Description:

Presumed victim name: Teradata - Cl0p announcement. We have data of many companies who use cleo. Our teams are reaching and calling your company and provide your special secret chat.

Infostealer activity detected by HudsonRock

Compromised Employees: 125

Compromised Users: 2376

Third Party Employee Credentials: 124


External Attack Surface: 170


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • teradata-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • atlassian-domain-verification=UV1o5dMrgUgLBMndABjoc4MsBqAk2OjTBxnN4X0idax2UuL8l7HvLwoX9tuiNdrx
  • QcnxhgmKMY3WYFIj87EttTuIaUCb33wUCloeB6pjLUGzMuJ9tu4Jj3ZjoIXm0iTdkZmjKDKuvK741XxPcir3Pw==
  • AD74-90FF-2E7E-8737-9F51-5C5B-006D-7AF4
  • ms-domain-verification=e9e363cc-f9c5-475d-a984-a3df933e3c20
  • facebook-domain-verification=kzmts5dhn0z1gnpwnz5v3bhwecdscz
  • drift-domain-verification=22146589078dbb1cddbbf38f8d2d614ee92fab06506ba737a65baaeb1378ed5b
  • google-site-verification=fmJDviNhYt67WnpBiAiXExKYhXH2itsdvp652bhJJsQ
  • miro-verification=cb0b54eeeadc517a617a4141b1f1db427cb5ccce
  • google-site-verification=y7EXJ1EJCuriZMcRrPYqkT324KGOGjGGSsAiQtmuVB8
  • jamf-site-verification=CUqUxDL5x8AFEVNU9yfY0A
  • v=spf1 include:dq7adb8023.powerspf.com ~all
  • _61fyo70hta0vkppqhmg3kcnylnrkre3
  • OSSRH-82627
  • paloaltonetworks-site-verification=8182e9cf0fde1d6dd320e2ffcd0a21293165416dd39f959990653eab56d1d4f9
  • pendo-domain-verification=b8dd700f-5242-41ee-b39d-1cb1f00a031b
  • smartsheet-site-validation=M5TwzQmOsKUxOhCMT-2uB-J6kqZFRr-s
  • atlassian-domain-verification=vsDbe2LEMbTXJznCxJrV9uLMlJ2zfyC+ARQuJPVutqpN7-K9Gz2+EHhlvO2ce7WV
  • docusign=eeacc179-90fd-40ac-8eea-464f72165407
  • webexdomainverification.DUVK=04d73953-960e-46d5-9de4-3d4b1a7fde9a
  • apple-domain-verification=5u2jHePu1fMeg2nv
  • flexera-domain-verification-adlvhtrkvepizlfq
  • docusign=709e68c2-aed8-4596-99e0-ba0cbe44b0ab
  • browserstack-domain-verification=ca924e29-22ed-4527-aaa5-0a5a24e4478b
  • docker-verification=e0eb7ed3-269f-42fe-9344-94371757174f
  • Dynatrace-site-verification=44197d14-ff5f-495d-8281-daa32fda86ee__1ef9jiclo12uikdq06a8t46uol
  • anthropic-domain-verification-8jbq3n=tkiqNnHOeW06tKg4Tc0QX7k7p
  • google-site-verification=OjkpFdMVZbr3ADSOzrR0NNzU2GiJGCEj8gwsDxcAm1M
  • XJIS6nRtkfNpVs7FktgjXqQTxN8vlPzuigVwezS1Ap1I4I/V72e4moWwLncvgkHonVVNaetwoyAXRnN/HE3U5Q==
  • vmware-cloud-verification-e9066857-1412-4f2e-a16b-e94d689e0581
  • GUID:3059c2fe-8c4a-4458-bfa9-4f26de365af8
  • MS=ms87085747
  • 58835d48125ec4feaa67eec4b584bb860e33b7de5b5634ae7cb1259cdb9310e9
Cloud / SaaS Services Detected
Apple Atlassian Docker Microsoft 365 Anthropic Miro Flexera JamF DocuSign Cisco Webex

Leak Screenshot:

Leak Screenshot