Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2025-12-03
Est. attack date 2025-12-03
Country UK

Description:

N/A

Infostealer activity detected by HudsonRock

Compromised Employees: 10

Compromised Users: 8

Third Party Employee Credentials: 15


External Attack Surface: 10


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • vk45235a9ra@networksolutionsprivateregistration.com
  • domain.operations@web.com
  • ju5rq3jg28s@networksolutionsprivateregistration.com
MX Records
  • mainetti-com-1.fortimailcloud.com.
  • mainetti-com-2.fortimailcloud.com.
TXT Records
  • google-site-verification=Bl7Amp31GsnIjg5cfSyA2_rxvC-ErLR6IAca1BO3H3w
  • duo_sso_verification=HLq1bPKuPTqP8NwKmcJ290k1OJX9ttFKH2vBUB8HcwuxE7VypjqQUDAiKOKFmyVb
  • MS=ms90474319
  • brevo-code:5056451b371d6f96e1fe98c10a5dabf4
  • v=spf1 mx ip4:194.75.60.194 include:spf.protection.outlook.com include:_spf.fortimailcloud.com include:spf-us.emailsignatures365.com include:shops.shopify.com -all
  • MS=6FADEA561833129C2134511A30529BEE370ECB31
Cloud / SaaS Services Detected
Microsoft 365 Shopify Fortinet Cisco Duo

Leak Screenshot:

Leak Screenshot