Finding CF-3041
Critical exposure on portal.meridianenergy.example
Mark in progressFalse positive
CriticalNew
EmployeeDetected 2026-07-14 06:12Seen 1× across sourcesCredential evidence
Passwords are masked — full values require reveal permission- Identity
- [email protected]
- Login URL
- https://portal.meridianenergy.example/login
- Password
- Vk3•••••••••
- Matched asset
- portal.meridianenergy.example
- First seen in log
- 2026-07-13
Infected device
- Device
- DESKTOP-4QK7M2
- Operating system
- Windows 11 Pro 23H2
- IP at capture
- 203.0.113.87
- Country
- Germany
- Infected at
- 2026-07-12 21:34
- Antivirus
- Defender (disabled at capture)
Source block
- Block
- BLK-88412
- Stealer family
- RedLine
- Posted
- 2026-07-13 03:12
- Channel
- Telegram cloud-of-logs
- Lines in block
- 1,832
Related findings
Triage timeline
2026-07-14 06:12 · System
Finding created from block BLK-88412 and matched to asset portal.meridianenergy.example
2026-07-14 06:12 · System
Severity set to Critical — corporate SSO portal with valid session cookies in the same log
2026-07-14 06:13 · System
Email notification sent to SOC distribution list
Awaiting next analyst action