Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo www.fecrwy.com

Group: Lynx

Discovered by ransomware.live: 2025-12-23

Estimated attack date: 2025-12-23

Country: US

Description:

The Florida East Coast Railway freight rail system located along the east coast of Florida. It is a rail provider for PortMiami, Port Everglades, and Port of Palm Beach. FECR connects to the national railway system in Jacksonville, Florida, to move cargo originating or terminating there. Based in Jacksonville, Florida, FECR provides end-to-end intermodal and carload solutions to customers.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 3


External Attack Surface: 1


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • fecrwy-com.mail.protection.outlook.com.
TXT Records
  • v=spf1 ip4:148.233.4.38 ip4:192.227.139.132/32 ip4:74.117.192.0/22 ip4:69.18.219.0/24 include:spf.protection.outlook.com ip4:67.207.87.142/32 ip4:206.81.12.226/32 ip4:200.52.78.2/32 ~all
  • cisco-ci-domain-verification=3cc7bbf29dc51f6d5bc57a27153f4ce5dd03ca1774871f202ab360d4b6e9582b
  • 4otic2a2ebegsdc3gki98mock5
  • lPpjwpeLV4RsqZmhA9i6mQSTmfT7/Z76vSN8JpmqpTeg4vf9hsNmmz2yVriYrhrGPasXXlvRMYNdas4OB+atkQ==
  • knowbe4-site-verification=93cac9afb1db4e8ccbe769eea629f85a
  • 1WBYB728J7X5UMZ4ORL65NW8R82TNYHDTT4R7XIV
  • 6smekmnu8vidn387ffl0rnlj0k
  • p4df2fio7vds0b0n8rarfis77t
  • dnbcbhsckv8pl3ie3gqkf6p8e4
  • MS=ms30535351
Cloud / SaaS Services Detected
Microsoft 365 KnowBe4 Cisco

Leak Screenshot:

Leak Screenshot