Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Idaho National Laboratory

inl.gov

Discovered 2023-12-08
Est. attack date 2023-11-26

Description:

nuclear research, nuclear power, power plant

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • whoisresponse@inl.gov
MX Records
  • inl-gov.mail.protection.outlook.com.
TXT Records
  • atlassian-domain-verification=od2sGjYYu9B4eUc21tzf3kDn4BPatp/Q7aoDXLkX8tYjQ5ry//qB3ze2jSRrdM3o
  • v=spf1 mx ip4:134.20.0.0/16 ip4:141.221.0.0/16 ip4:155.248.8.180 ip4:64.74.237.230/31 ip4:216.147.212.20/30 ip4:169.145.39.240/29 ip4:157.133.167.152/29 ip4:18.98.16.200/29 ip4:167.89.0.0/17 ip4:168.245.0.0/17 ip4:199.255.192.0/22 ip4:199.127.232.0/22 ip4" ":54.240.0.0/18 ip4:69.169.224.0/20 ip4:23.249.208.0/20 ip4:23.251.224.0/19 ip4:76.223.176.0/20 ip4:54.240.64.0/18 ip4:76.223.128.0/19 ip4:216.221.160.0/19 ip4:206.55.144.0/20 ip4:24.110.64.0/18 include:servicenowservices.com include:spf.protection.outlook" ".com include:docebosaas.com include:rp.email.oci.oraclegovcloud.com include:spf_usgov.oraclecloud.com ip4:147.154.59.192/26 ip4:147.154.123.119 ip4:170.52.3.228 ip4:192.29.143.169 ip4:159.112.165.64/26 ip4:192.29.42.231 ip4:129.149.37.192/26 ip4:158.178.2" "19.192/26 ip4:158.179.11.192/26 ip4:170.52.4.253 ip4:147.154.14.34 ip4:81.208.187.192/26 ip4:204.216.114.64/26 ip4:158.180.181.192/26 ip4:158.179.135.64/26 ip4:79.72.112.64/26 ip4:64.181.146.64/26 ip4:216.131.131.240/28 ip4:141.145.63.16/28 ip4:129.152.95" ".16/28 ip4:129.152.79.16/28 ip4:207.127.109.192/26 ip4:151.104.48.26 ip4:151.104.61.235 ip4:84.235.196.192/26 ip4:84.235.197.192/26 ip4:84.8.179.64/26 ip4:159.13.87.0/26 ip4:129.148.11.192/26 ip4:207.127.107.192/26 ip4:147.154.255.192/26 ip4:192.29.216.19" "2/26 ip4:146.56.127.192/26 ip4:192.29.91.192/26 ip4:204.216.119.192/26 ip4:129.153.243.192/26 ip4:147.154.189.192/26 ip4:141.145.79.16/28 ip4:129.148.219.192/26 ip4:129.157.31.16/28 ip4:207.211.139.192/26 ip4:155.248.28.128/26 ip4:155.248.119.192/26 ip4:1" "55.248.115.192/26 ip4:129.149.63.192/26 ip4:192.29.172.192/26 ip4:207.127.72.64/26 ip4:192.29.207.192/26 ip4:192.29.232.192/26 ip4:192.29.137.192/26 ip4:204.216.127.192/26 ip4:192.29.178.192/26 ip4:129.149.22.192/26 ip4:79.72.22.64/26 ip4:79.72.39.64/26 -" "all
  • notion_verify_ERqTkvk}8]fsC*cKQ#mYN6:+iNqeQ]KKj^hEi.*t5!psD@HB@]*?!0v#YMEfY8L8]Z0D9_
  • atlassian-domain-verification=6U/1fd6Bbwdw8qzk5aTaSvrIo3lLH1Ivd355o6jDaeFiINJwToAoF5gwj3zl9syF
  • amazonses:3CymOYzKBXZuZuX9oYSP192J7bmNOBDu6agp3e6vPDc=
  • 4d37c79b-7300-4fa5-927a-522edf04a147
  • box-domain-verification=be0668c027ba299345e331b3505673e9d272b849aced80d00e434c12e97e3545
  • apple-domain-verification=KKP9pOcaIqOfhiE2
  • adobe-idp-site-verification=1e4ef6af758bb11c452de2c4e4c0ea6b5d6e41ab336b2db3f43d6f5799cc4391
  • ca3-b209afef2e8f43ce848ca23655faecf5
  • autodesk-domain-verification=nik9W0uosWOHaYYT6eVC
  • docusign=811d3974-1fa4-44f1-a7ee-9243489cdd11
  • asv=24baee9e703b55865d7a5a023915cde0
  • meltwater_sso_20210219_T3-4848
  • figma-domain-verification=897959671d0e27b3f806dfb75d3fd0ef33888d6d80d05c8bd50420cc70a75738-1761840393
  • openai-domain-verification=dv-qvtW8cGGr8fQGKzu5Fp31Kp7
  • facebook-domain-verification=lsfqiowkmlx6gen6drirxigvy8dgf8
  • atlassian-sending-domain-verification=1e84621d-6336-42f2-96c6-1e46dc126072
  • mandrill_verify.cl4xGps9dMyZIC8MS8obBg
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Mailchimp Box Autodesk DocuSign

Leak Screenshot:

Leak Screenshot