Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Memorial Sloan Kettering Cancer Center

mskcc.org

Group Meow
Discovered 2023-12-12
Est. attack date 2023-12-12

Description:

PREVIEW

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • mxa-00402601.gslb.pphosted.com.
  • mxb-00402601.gslb.pphosted.com.
TXT Records
  • adobe-idp-site-verification=b348fbab6c3af396a18ab2a10a3a3b2092f18873f86c4150435b40e375842bde
  • _a267vzbfqca2m2dnvteurthnb173zdj
  • docker-verification=6ae93dd3-5b71-4ec2-875f-fbd494a2b483
  • facebook-domain-verification=ygb8f6jzej7p4hpt2aguwoh9eoewmg
  • hosting-site=msk-jh-production
  • ciscocidomainverification=57151d093a777cee26b3577ddaa91efd6fc7e1c53d65da5a2ef0e73c409a7c44
  • _szd489l5b2ii8knrmkao1k66ywuimh7
  • ca3-7da0f410f9624f4fae6dcf9ccf2ccf2e
  • Qn_8WduwfHYY2A6hPFowkIsSJQ
  • 84hfoNCXMXbobC6IakYhylHcFzCCgMoChanTwGjYowx7Mk0aI0DKYxkuGvTvju
  • v=spf1 include:spf5.mskcc.org include:spf6.mskcc.org include:spf.protection.outlook.com include:spf-00402601.pphosted.com a:b.spf.service-now.com a:c.spf.service-now.com a:d.spf.service-now.com exists:%{ir}.%{v}.arpa._spf.mskcc.org ~all
  • flexera-domain-verification-vwuhxezcrfbmpuhz
  • apple-domain-verification=IqHHmIMLJ1dLOwu9
  • adobe-sign-verification=25ba5e7affb87dfdc04356730be8992
  • 86435eeb-c8c2-4772-a535-4404caf56b47
  • google-site-verification=fKJxdl0vsJDL1Y_H655_5YHJr6_ZbPYVd_cQT1mzTqc
  • 09beb289-12ab-4d91-b48a-56585266d6da
  • 84hfoNCXMXbobC6IakYhylHcFzCCgMoChanTwGjYowx7Mk0aI0DKYxkuGvTvju/wfAPcO4qIY1axbA16idPOTw==
  • cloudhealth=25ce480b-5ef6-4089-9a08-878db39248fb
  • google-site-verification=WIIRq9nA7ImTqR0zMB_f3h-ugfgUV-E5ujfppEkbUh8
  • openai-domain-verification=dv-K76wjzuTvBlAVFvXmhJpM2OL
  • hcp-domain-verification=1db8cc011f1d1dc467a792f9f14ecaf6ae44baf9ef9ce2b1b3a8715d76df7935
  • miro-verification=ba02fcfe3dabdbc013b11c3d8e8949be390d7c3f
  • google-site-verification=6N-oHNsc3XUO64UNuffVXtsc7KglnuAiPQ8vvWtqFWs
  • jamf-site-verification=3cVPbLvIYlifplNbe6bhnw
  • apple-domain-verification=cuaqvRNebK151eag
  • atlassian-domain-verification=LUmLCJicpzD1/2UaFdML8EcVmwMq6hykxzT105XMkZlZTW31UPIaEobSaEvqVXrr
  • 1WzLav0IwSShm-pgwKOm
  • MS=ms94440000
  • google-site-verification=mAHvMdCSp4-YCyLxxkP_KQVF5UbMYXrr8Sy_Cq0PdiI
  • google-site-verification=z2NGRYKRpbnRMIzWWkZ1ezmDMmvbBLCirDnYS5v2i50
  • q/U6tr8sT4oxToSxJChIQQFOV4iexKXqbNKqA1hnZk2G0EbouOhfuttWCPq+q+fKb84PCgWcBkSpYsxdxP53WA==
Cloud / SaaS Services Detected
Adobe Apple Atlassian Microsoft 365 Miro Flexera JamF ServiceNow Proofpoint

Leak Screenshot:

Leak Screenshot