Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Play
Discovered 2023-01-01 20:19 UTC
Est. attack date 2023-01-01
Country FR

Description:

Fere-Champenoise, France

Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 7

Third Party Employee Credentials: 1


External Attack Surface: 12


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • e.kleincder.fr
  • domaineshexanet.fr
  • l.marchaudhexanet.fr
MX Records
  • de-smtp-inbound-1.mimecast.com. Mimecast
  • de-smtp-inbound-2.mimecast.com. Mimecast
TXT Records
  • MS=ms20238136
  • a:smtp-gw1.silae.fr ip4:5.226.2.176/28 ~all
  • v=spf1 include:spf.protection.outlook.com include:de._netblocks.mimecast.com include:spf.sendinblue.com include:spf.hexanet.fr include:spf.jabatus.fr a:smtp-gw1.silae.fr ip4:5.226.2.176/28 a:smtp.hexanet.fr ip6:2603:10a6::/30 -all
  • apple-domain-verification=2vbRmwQRnVg40GWd
  • hibp-verify=dweb_phuxn3fw63ds1w4w8ap8jqk9
  • MS=ms13573285
  • MS=ms96696083
  • Sendinblue-code:54aeec021d527cb32f6c05a5b8feaf2e
Cloud / SaaS Services Detected
Apple Microsoft 365 Sendinblue Mimecast