Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

MECHANICSBANK.COM

MECHANICSBANK.COM

Group Clop
Discovered 2023-07-26
Est. attack date 2023-07-26

Description:

Mechanics Bank - Mechanics Bank

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@cscglobal.com
MX Records
  • mx2.hc2799-10.iphmx.com.
  • mx1.hc2799-10.iphmx.com.
TXT Records
  • bw=HNb376b8g3tDv3GgwatHyQPfRerBPOFHdZVUpXKgZ1bn
  • v=spf1 include:mechanicsbank.com._nspf.vali.email include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:stspg-customer.com ~all
  • adobe-sign-verification=a634f716a6dc2f2b34b8bf3b456350fd
  • status-page-domain-verification=bd1pszd8tmv1
  • _fd8mj1mg5wvbavotj1mv95g0ssp16dj
  • globalsign-domain-verification=81D33A7A2FDE919FC3064A5C95714620
  • docusign=1179e839-049f-4350-8aee-6185fe9455e2
  • smartsheet-site-validation=CV41codrJsQorDUe8dfzaf-harbM_Avq
  • \"v=spf1 include:amazonses.com ~all\
  • cisco-ci-domain-verification=4d551a9b814fb353d7c0982892edd14c17f8e5b4e09c3b2ae47dc5d821bc0875
  • s0llgw1l8jl1ny8n1smcdcb9z4zcg3n0
  • globalsign-domain-verification=584B56D899B2727E998DF40B89A3A8CB
  • MS=ms19839287
  • apple-domain-verification=cRfE70cCw7_oWkvEJik4X-9Cg1vMWICWcLfsLJhsTOg
  • jRQJC2H+KDmsDUhKRsGhy6s3O7Xyci+nsS4cQ+nSnagacQRLRPAjAbkPdWD7qLq/Rwpl3jmqPuMr4kzYF6kL3Q==
  • google-site-verification=5qFSZTz9MZN7eKmBcJ_tG2yuTOfF3pEwqgGJgXL_-ic
  • globalsign-domain-verification=A1094B855AD90164CFFD10EF7C383613
  • google-site-verification=-6z31GQoeu5655i3MwEuGjqHf6HDlcSMhyiJNLpKnLk
  • _6ra7oddcfj24lu06hco24txbmv28e96
  • apple-domain-verification=Hkg2Vp6PfJtLyKHs
  • omnissa-connect-verification-5665e9f7-f223-49a5-8978-25d1791e1170
  • _g67skulckvj9tsfi2sl6qjoc9x9xze1
  • anthropic-domain-verification-90pnax=Bi5ejjcv0RDGbYBH2qxNgJut3
  • google-site-verification=4nhJ3l17qWXuepaz74tSFyeRCap62wGX9W0V_wRdX5o
  • GnJXuul8FO5Iaad7wZAg4UFE5xIxRXrHFgl/VMwINrgQE0uHYqHurOJZ9vClesHusI2EI2SPg8tNt1yP0KniAQ==
  • globalsign-domain-verification=60908ada27efa5e4ee21b7797972ffae
  • intersight=dbc69485ad8b393190e481f398ff391c03a9a779d68e382e32b57480e5592f8e
  • MS=F9200FCCC183F98CE870379CCAC69DBD9FA1AAA5
  • globalsign-domain-verification=37E0E508504705B12E3E56980A502218
  • docusign=04f31323-3c58-497a-9ff3-ad759190ba72
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail Microsoft 365 Cisco DocuSign

Leak Screenshot:

Leak Screenshot