Finding CF-3017
Low exposure on staging.meridianenergy.example
Mark in progressFalse positive
LowFalse positive
EmployeeDetected 2026-07-11 16:19Seen 6× across sourcesCredential evidence
Passwords are masked — full values require reveal permission- Identity
- [email protected]
- Login URL
- https://staging.meridianenergy.example/login
- Password
- Tk1••••••
- Matched asset
- staging.meridianenergy.example
- First seen in log
- 2026-07-09
Infected device
- Device
- WIN-D2K4P7X
- Operating system
- Windows 10 Pro 22H2
- IP at capture
- 198.51.100.62
- Country
- Brazil
- Infected at
- 2026-07-09 14:18
- Antivirus
- Defender (active)
Source block
- Block
- BLK-88186
- Stealer family
- Lumma
- Posted
- 2026-07-09 08:41
- Channel
- Telegram cloud-of-logs
- Lines in block
- 1,638
Related findings
Triage timeline
2026-07-11 16:19 · System
Finding created from stealer block and matched to asset staging.meridianenergy.example
2026-07-11 16:19 · System
Severity set to Low based on asset criticality and credential context
2026-07-11 09:30 · A. Analyst
Status changed to False positive
Awaiting next analyst action