Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

WESTERNALLIANCEBANK.COM

WESTERNALLIANCEBANK.COM

Group Clop
Discovered 2025-01-24
Est. attack date 2025-01-24
Country US
City Phoenix

Description:

[AI generated] Western Alliance Bancorporation is a leading bank holding company in the US offering retail, commercial, and real estate banking services. Established in 1995, it operates through various divisions and subsidiaries across the nation. Western Alliance Bank provides lending, deposit, treasury management, and online banking solutions to consumers, small to larger businesses, and professional communities.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 12

Third Party Employee Credentials: 1


External Attack Surface: 6


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse@cscglobal.com
MX Records
  • mxb-00209b01.gslb.pphosted.com.
  • mxa-00209b01.gslb.pphosted.com.
TXT Records
  • bgpqs3c5lf0ob9dn6djfvdao82
  • 7ikpgf2ka0bcg0me8giif6r53e
  • 13ppflecij8huaofap5onfprfj
  • 2e51979d-dc09-459e-bda2-05c4faeb43e0
  • d365mktkey=2f9xzbs0840yp9vhxxu1t44bx
  • 6or70g35ujrd20706vrsejdggl
  • _ib2f93g6oc5wt92fo1mhbscyr6c4fw3
  • adobe-idp-site-verification=36995d3c29627d1933076296ad974f0c69a208d106f6271ac77c6fece03a4ca3
  • ecostruxure-it-verification=6adf4119-5d0e-441d-9e18-c34cc4ab5eaa
  • uvb4qnm22tkjnb9anhhe132v52
  • cisco-ci-domain-verification=5972e01b8f80984ad0f4351457811be775bf243379bea99083c52fef0757c9aa
  • atlassian-domain-verification=VQKDj6HpsyLQEKCap0tnB23X2yRVvlFVwZ12UXPr0ad0K3rxRE5R/1igQJzWR71G
  • ac1bjqd0969ra0sf1gffghb4du
  • 0ed1fe018add6fb2d903de48ed9bbd1a7a7dc686e9
  • pco7gtiu3k7ubp0pa6otabb2qs
  • d365mktkey=4jpm8xktnbbjn229a7ndl2i89
  • p3r7s8uapfhq2gr4fche3afmjm
  • _w27ek7t6nsmh9anv1le4qhy7g7id1vj
  • msfpkey=1cgr74erkkjfnlkj3nx5adh6o
  • d9ceih1k8nf3kvrrral9k7htju
  • afb32a3f-e6e4-4668-aca2-5dd79833893e
  • jogbh62n5a6coi8mf5rmtl6ah9
  • infoblox-domain-mastery=e72ed97c2793a6f573b1dd0d25629e217e8bb425f184c981260828c538afbaa528
  • 5hettu6k0k2m25tnjvgr5is2k4
  • v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~all
  • kca1cphk4q7rpnekd4apodeksd
  • MSIRDYm/vU4Ov7LIo+HhYaVmciXWqkVWdMVumoXOqZMtJ1XthcJYV9PaF/0WzAOqCXQMDUkUHtrI0UXQwejvWw==
  • d365mktkey=54yr4aclh2lyd8jz18uawzdat
  • lg7721lqm2gk56f0f86vp0klnj
  • n8he2cng0nem3hejt2ad318tfb
  • knowbe4-site-verification=7771450cdab00a6183a1f60218c17a5c
  • hcp-domain-verification=4c912b6b2430056764238e149e0278e2daffa0f20d724a50e69403a1aee8197f
  • google-site-verification=bgpqs3c5lf0ob9dn6djfvdao82
  • wiz-domain-verification=da3dfe27bc5b21686706040e8587911b7e14f77733212b62d167ecabe78fb86
  • extcasemgmt-site-verification=1478
  • MS=AE928CA8A3D3A988DD02BE37905647A6D875319D
  • f7ftdnuq9t74vh43s698ho2squ
Cloud / SaaS Services Detected
Adobe Atlassian KnowBe4 Cisco Proofpoint

Leak Screenshot:

Leak Screenshot