Skip to main content
Meridian Energy
Request a Demo

Finding CF-3017

Low exposure on staging.meridianenergy.example

Mark in progressFalse positive
Back to findings
LowFalse positive
EmployeeDetected 2026-07-11 16:19Seen 6× across sources

Credential evidence

Passwords are masked — full values require reveal permission
Login URL
https://staging.meridianenergy.example/login
Password
Tk1••••••
Matched asset
staging.meridianenergy.example
First seen in log
2026-07-09

Infected device

Device
WIN-D2K4P7X
Operating system
Windows 10 Pro 22H2
IP at capture
198.51.100.62
Country
Brazil
Infected at
2026-07-09 14:18
Antivirus
Defender (active)

Source block

Block
BLK-88186
Stealer family
Lumma
Posted
2026-07-09 08:41
Channel
Telegram cloud-of-logs
Lines in block
1,638

Related findings

Triage timeline

  1. 2026-07-11 16:19 · System

    Finding created from stealer block and matched to asset staging.meridianenergy.example

  2. 2026-07-11 16:19 · System

    Severity set to Low based on asset criticality and credential context

  3. 2026-07-11 09:30 · A. Analyst

    Status changed to False positive

  4. Awaiting next analyst action