Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Consorci Sanitari Integral

csi.cat

Discovered 2024-04-22 12:46 UTC
Est. attack date 2022-10-11
Country ES
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

Consorci Sanitari Integral (CSI) is a healthcare consortium based in Catalonia, Spain Leaked data size: 52.47GB.

Infostealer activity detected by HudsonRock

Compromised Employees: 14

Compromised Users: 168

Third Party Employee Credentials: 5


External Attack Surface: 39


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusenominalia.com
MX Records
  • csi.in.tmes.trendmicro.eu.
TXT Records
  • PDQ-633225
  • apple-domain-verification=dh0cpS7M4oni0VUu
  • X7MUtx9XV/g6z64XFHIvZUFCCYthkumiXJSWDE25LUyYxBNkQDSd9kDk0V5x6MAZHM8t7IRri16qXixf/EXUNA==
  • msfpkey=6de4mnlsuemvndf33ig9vbud8
  • atlassian-domain-verification=WjzvimUEYGgjXW77IQeg18uiZhk2TpPbFNjjMbGDKLba6m7cjhdLcl9RUfPHKVOa
  • v=spf1 mx a ip4:89.6.176.9 include:spf.tmes.trendmicro.com include:spf.opinat.com include:spf.protection.outlook.com -all
  • MS=8C2218F3CFAED00AF4F46686DE0D9DBDDC23DC7A
  • google-site-verification=igyGWWQDSPcgi1X857vLx69ogfYyDPuPO0QvbQC8sbc
  • atlassian-sending-domain-verification=e002d67a-40e9-426a-9240-186cd1857e88
  • google-site-verification=DEZj638A2VSPbptP8tn9Kf5Lz9t1LXNIALd0nzbN30M
  • tmes=f86af360065d67b42170a41889688de9
Cloud / SaaS Services Detected
Apple Atlassian TrendMicro

Leak Screenshot:

Leak Screenshot