Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

SONY.COM

SONY.COM

Group Clop
Discovered 2023-06-23
Est. attack date 2023-06-23

Description:

Sony Group Portal - Home

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@cscglobal.com
MX Records
  • mxb-001d1709.gslb.pphosted.com.
  • mxa-001d1709.gslb.pphosted.com.
TXT Records
  • 00DWe000001Yqmn=1TBWe00000004bV
  • YzcX/ANAcVb1c6oLNOXQzniFpgGypdlowJHvEvmRuqyhkvEsdv/zFQuiZuYakJL3xpHMmttCjOvNqxz3g+LFeg==
  • 00DWG000004ARsf=1TBWG00000005cQ
  • 00D55000000AU1R=1TBWF00000007O6
  • atlassian-domain-verification=J8IuFHzPA35SrowKp4YTkNaH2y55875Vd4ajfcdSaa8IwFnHFgwDVXn/7ah4zKLQ
  • 00D3h00000669Bv=1TBa600000000Pp
  • atlassian-domain-verification=r5fb2FayUvo8fOgFJFJEBAo2HglGDiEdGr/UdZm4wa442MjFHSZIWre0rbN1X01l
  • 00D6C00000010N1=1TBWF00000007Xn
  • traction-guest=cdf7c589-6dec-4726-a5cf-63b199033f64
  • MS=ms30214679
  • 00DWF000004plvW=1TBWF0000000B1t
  • duo_sso_verification=OCP7uIMPOgLi1G6lzhe7ytJ1mlBnCnegPoARYrbP5iaQz1lbBdgKOs7mxHqm6pMC
  • 00DWG0000048OkV=1TBWG0000000989
  • cisco-ci-domain-verification=63d5c7eae53960e203dc78b5f8df051547793ec65388f2b6c981213444854fa2
  • atlassian-domain-verification=eYbBPmkmHnq2Q12ZTfOxAq/iVMZaGO6bpwCblWnl3ZB0V9FIkHCbT0BZlRCT1hwG
  • amazonses:uiKa9HJAcBY9FnqDkcA2neYsNY7672GwLqmefcFcEeo=
  • atlassian-domain-verification=n7x5LmVD/gQIr0wswuMn6UPVWrFJHl7XYQPlf1T1RNdwdq87KoCz150IKaBFTBI4
  • adobe-sign-verification=b4a30c4f74bb611dce0e5d515054481c
  • amazonses:OfVkq/yn1d+o09tdXhxkoHbIGCNeP8aYj3amzwACQ3c=
  • k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDBfF8XiPmS/aLbBcNnixpRclWpr1Z0MY4Hy9h3oW4VF6XDJaKhmTWkaOvKIv3ZMQyjIrbpmBwL0xiyy3F88HwPi9tA7POXgpsl12W3EXu2qzOHhMvpT7VZC0vFArz3H1djX3+4UGixZyt14lrXEvgd9TE9cJs2/RXdF0Joosx74QIDAQAB
  • docusign=3122656f-b5f7-497b-8782-4907222b538a
  • 0ed1fe018ab8b5050c7c8341b7b8894557d2554815
  • 00DWF000006yay1=1TBWF0000000Bzb
  • 00DWF00000BLrhJ=1TBWF0000000Kmk
  • smartsheet-site-validation=bKd1dTuQ8acbZh57Q5DDRrTEaI0qI2SW
  • atlassian-domain-verification=waYuW8HMlUW/U3Dv4MxS16bX0nEfYNpuqW5c18LpYhqHUi280snd3mDAQFwjkAzx
  • 00D3J0000008lPt=1TBWF00000007Hj
  • adobe-idp-site-verification=cff4ddad-a01e-4226-a77f-8c081cde0aee
  • vizcom-domain-verification-krvt38=pNKLWPMfyeYHIB1ynoblsznrX
  • 00DIo000000LPcZ=1TBfU00000001SM;00DIk000000LHlF=1TBfd00000001c1;00D0w0000000UON=1TBfd00000000jB;00DIm000000LPaE=1TBBU00000004gL;00DIm000000LPd2=1TBBA00000000EX
  • google-site-verification=zfXryc1xAcIFps86mXmIJrDtpsur406Wn-pOMSS0i5w
  • atlassian-domain-verification=wQ8HCOCZf3qKkVA9AJLbklKI2Vg3gLMCLGjitCRrWNPdK2uOnnud6x8IJ8KES8BC
  • 00DWF00000BLrsb=1TBWF0000000Ihh
  • cisco-ci-domain-verification=221d305d2b1221f9d96ea9cde0d89df2a2ddc44fef8454a724e1a22dd27bd782
  • 00D2i0000008eKi=1TBWF00000007BG
  • 00Ddn000002K0HF=1TBdn00000005Kg
  • smartsheet-site-validation=8UHPs3KZLjpUj8xeJcFXQYzakQm_V7Aa
  • 00DWG000003GOFx=1TBWG0000000Cdt
  • 00Ddq000005tB6P=1TBdq0000000Ikx
  • include:5133606.spf02.hubspotemail.net
  • 00Ddh000000n7A1=1TBdh0000000Aqc
  • facebook-domain-verification=rn9nh6m7g7sxesufnk7gufxr7pht73
  • apple-domain-verification=HBPp89XmNImI9Qwc
  • 00D6D0000008arA=1TBBS00000002Y5
  • 00DAz000008a8yX=1TBAz00000006Bx
  • smartsheet-site-validation=6_otSYK33LBHB3hGD4yvBCRC3K36fKfy
  • apple-domain-verification=nb7VlmdSF87vwM2c
  • ZOOM_verify_rEu3V6YvT3iT4iHJy6N2TQ
  • SSI-BOX-verification=3005070
  • Dynatrace-site-verification=1babd889-fadb-4ff7-8463-0980d5597143__9c12rjohn2l0ijdaaalvihrite
  • atlassian-domain-verification=CGwx36EaSg2BdGXaayaYz5HvMnQFyPmGSixHPOLfvIQyCIbQ7OaJaP5JyptT40bO
  • 00DWF000006X7Qf=1TBWF0000000EXf
  • mgverify=11d18dfff6511cf00d0a1d5d7e1f6a0a2fcd0f2a554de658fa5b069b947fec18
  • mindmanager-verification=2cb8b923f6d897035b2f7d5d73cc0e61690f625cef67ad7cdd39a19428709148
  • onetrust-domain-verification=07d2af6be3aa4cdc99ebe26e053cdd18
  • fastly-domain-delegation-sony-323730-2020-12-07
  • 00DWK000003CdyL=1TBWK0000000Ax3
  • 00D280000018Q2y=1TBRB0000000Aqc
  • 00Ddl000004Jkw5=1TBdl0000000Xjx
  • _6be4o7b553lh0g4k3rz70s6pblav0zl
  • 00DWG00000191fR=1TBWG00000005Nu
  • 00DP0000000Gvsm=1TBWF00000008X3
  • 00DWG0000034J2L=1TBWG0000000DgP
  • intersight=e96be0bed3c84c3117ce32993955e9a8179f4a21ef59509de20f1b5beb03b23b
  • 00DWG000003GQ0F=1TBWG0000000905
  • cloudhealth=ef6859d5-232b-4ff0-8811-ded26d79e7ee
  • stripe-verification=e3c5cc73ce14364162038aa39a921d6ad8cd17b95c69d1e35ebe7d776f416c27
  • v=spf1 include:amazonses.com include:spf.protection.outlook.com include:spfa.sony.com ip4:121.100.43.221 ip4:185.136.188.108 ip4:185.136.189.108 ip4:121.100.43.225 ip4:121.100.43.226 ip4:139.60.152.0/22 ip4:148.105.8.0/21 ip4:160.33.101.112/28 ip4:160.33." "194.224/28 ip4:160.33.194.232 ip4:160.33.194.233 ip4:160.33.194.234 ip4:160.33.194.235 ip4:160.33.96.128/28 ip4:185.132.182.190 ip4:185.132.183.11 ip4:185.183.30.70 ip4:198.2.128.0/18 ip4:205.201.128.0/20 ip4:208.74.204.0/22 ip4:212.100.250.11 ip4:212.100" ".250.16/29 ip4:37.188.101.80/28 ip4:46.19.168.0/23 ip4:5.61.115.112/28 ip4:5.61.115.80/28 ip4:5.61.115.96/28 ip4:5.61.117.112/28 ip4:5.61.117.80/28 ip4:5.61.117.96/28 ip4:52.222.62.51/32 ip4:52.222.73.120/32 ip4:52.222.73.83/32 ip4:52.222.75.85/32 ip4:54." "186.193.102/32 ip4:83.138.165.68/31 ip4:91.207.212.191 ip6:2607:fd28:0102:1:1::/80 ip6:2607:fd28:0102:3:300::/80 ip4:101.231.129.3 ip4:101.231.129.4 ip4:3.93.157.0/24 ip4:3.210.190.0/24 ip4:18.208.124.128/25 ip4:54.174.52.0/24 ip4:54.174.57.0/24 ip4:54.17" "4.59.0/24 ip4:54.174.60.0/23 ip4:54.174.63.0/24 ip4:139.180.17.0/24 ip4:141.193.184.32/27 ip4:141.193.184.64/26 ip4:141.193.184.128/25 ip4:141.193.185.32/27 ip4:141.193.185.64/26 ip4:141.193.185.128/25 ip4:143.244.80.0/20 ip4:158.247.16.0/20 ip4:108.179.1" "44.0/20 ip4:66.159.233.15 ip4:66.159.234.91 ip4:66.159.233.14 ip4:66.159.234.90 ip4:66.159.232.89 ip4:143.55.149.237 ip4:66.159.233.25 ip4:66.159.234.101 ip4:101.231.129.43 ip4:216.139.64.0/19 ip4:211.125.130.0/24 ip6:2001:cf8:0:b0::/64 -all
  • 00DWG000002XHIf=1TBWG0000000DAC
  • 00DV9000003xfIL=1TBV900000008qQ
  • 00D10000000YqLf=1TBdc000000046t
  • stripe-verification=35ba23934a707a07c4c9be6e43adc627d3cb801a293fdb8ca7bc5a940d9c853d
  • 00Dfd000001lWn4=1TBfd00000000Cv
  • 625a9ec4-6651-49b8-8c83-74133987095f
  • 00DWF00000BLrcT=1TBWF0000000JQr
  • 00DN0000000DziC=1TBBE00000003qk
  • atlassian-domain-verification=952mPCXTF37KezRl6E/Bi2/ZatxPM1gKFPIf4MXehRtaz9DKajMnwKdtPvWhDT0/
  • airtable-verification=7e3b774835059c30d789beabb4a07435
  • status-page-domain-verification=t7crx8w5wb4b
  • webexdomainverification.ELPM=7682f227-dbc9-4df9-ae72-7649e05b521f
  • docusign=877ac654-f0e6-4bc6-a293-49c26778da82
  • 00DWF0000081Ulp=1TBWF0000000Ixp
  • 00DWF000005oadJ=1TBWF00000009kr
  • 00DWG000004FIjt=1TBWG0000000ALx
  • atlassian-domain-verification=ODIyKwRoeJmcccZvbpjcODmGQO8JB3slQhtNIaT/hatqwr4uUiBM/7ufgDe7YrOD
  • 00DWF000004xt9R=1TBWF0000000J5t
  • notion-domain-verification=zBpkBDL5tfCR1bTR8MKJbNbS9N1JU836BxnUDg5HDPW
  • 3107e583-6c54-414f-8708-dadd2b68db17
  • MFC=2c04db9e-a7b5-4b3c-a971-b8dbf1e148b3
  • vQmLLyL7EiCbLfmJNXSAa4CPvnWFHN6cAKmXtcETJbzKpwymXUQgnlIlaSlVd7JFTH2Rd4OeM2Fa1tg0gSZIuA==
  • atlassian-domain-verification=v4FZr2rkZY1PR7ZAEJ/xabaYK0R3alTg14hy8n0MJFRgpptZtebzQeaul0IQ6Hzj
  • notion-domain-verification=be3uo8AorliA1f8sISmIWqJxGWhSGQKgTWhKhkHahR6
  • apple-domain-verification=t838FSLg4LjXckfk
  • cursor-domain-verification-2m4vw3=BswYxH6hytFYk3sXuD4TPwmKW
  • atlassian-domain-verification=/PaoSe8zbFJuWVCT7GftJBGp94eYcxfj63DrEJ1FwO9TWOypzG5iRIPdvIuayCEg
  • _tl13flz107h4rbful1ic34v8450rf60
  • google-site-verification=j1FfNnOllL0QdFSzHNHnHAcWV_54Kbd_bURGKTK3y4s
  • atlassian-sending-domain-verification=95aaa013-d4f7-44cb-9fa0-2d8acc713d7e
  • adobe-sign-verification=d9afcd8ad833d41a47f92fec1bf30bf5
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail HubSpot Microsoft 365 Stripe Cisco OneTrust Cisco Duo DocuSign Proofpoint Cisco Webex Zoom

Leak Screenshot:

Leak Screenshot