Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2025-11-26
Est. attack date 2025-11-26
Country CA

Description:

N/A

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 4


External Attack Surface: 1


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • ss2.dsmhosting.net.
  • ss.dsmhosting.net.
  • biopharmaservices-com.mail.protection.outlook.com.
TXT Records
  • VPzrBckgJTSaLXJw2Ug/Bk2wSQez1zZvXw1K6jmiD5Hu81xWH2gzF2f7J75wDdI1psztEhO+TBmaaw4+eZlc5g==
  • euc503if9eca6ub2bu1sd2hnca
  • v=spf1 include:spf.protection.outlook.com include:dsmhosting.net include:servers.mcsv.net ~all
  • MS=ms84915757
  • t1mddq94akvudhnmiki8dcba0q
  • lru67n0pm5mhpk5q93982en7ns
  • knowbe4-site-verification=6b7d96ef032c404f4a2c8ab3781bc256
  • docusign=87b46125-9ee3-4f3d-b292-abefaa1788fd
  • apple-domain-verification=c4YCS6VYKDcVYT8N
Cloud / SaaS Services Detected
Apple Mailchimp Microsoft 365 KnowBe4 DocuSign

Leak Screenshot:

Leak Screenshot