Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Corporación BJR

bjrimport.com

Group Akira
Discovered 2024-12-10 13:06 UTC
Est. attack date 2024-11-16
Country MX

Description:

BJR Corporation is engaged in selling motorcycle spare parts and accessories based on providing excellent after-sales service, the reby achieving market recognition. We are ready to upload more than 25 GB of internal corporate docu ments including: contact numbers and e-mail addresses of employe es and customers, inside correspondence, internal financial docum ents, passports, confidential documents etc

Infostealer activity detected by HudsonRock

Compromised Employees: 64

Compromised Users: 37

Third Party Employee Credentials: 1


External Attack Surface: 16


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusespaceship.com
MX Records
  • aspmx3.l.google.com. Google Workspace
  • aspmx.l.google.com. Google Workspace
  • aspmx4.l.google.com. Google Workspace
  • aspmx5.l.google.com. Google Workspace
  • ALT4.aspmx.l.google.com. Google Workspace
  • ALT3.aspmx.l.google.com. Google Workspace
  • alt2.aspmx.l.google.com. Google Workspace
  • aspmx2.google.com. Google Workspace
  • alt1.aspmx.l.google.com. Google Workspace
  • gw6065.fortimail.com.
TXT Records
  • MS=ms18105793
  • ivi0dm3j4p7jok8d8gp49l5qdt
  • 8b8n1ki2hpc3rpgobnmjmkqent
  • 4p01mli31v5jkvgbcqe1m41du
  • MS=8D00EAE02B68F7EB1CB21DA1AE771C7AE0012E44
  • _globalsign-domain-verification=1zfWCBQrNsOe487C637XPXgN1Ylms-lKG3pcqbGsRw
  • google-site-verification=DEyQoq6zkHcmy_sZJ1qJsMOpvxOgEuunrU5DgPOzNRo
  • google-site-verification=AX4Hy5Jv-YkLODChBGPAtW23_rZPdA2aMICwssohlTk
  • v=spf1 +a +mx +ip4:104.225.130.2 include:relay.mailchannels.net +ip4:104.225.130.6 +ip4:69.73.154.77 +ip4:69.73.180.8 +ip4:69.73.180.8 +ip4:66.246.252.136 +a:dawson.nswebhost.com +mx:bjrimport.com +include:dawson.nswebhost.com -all
  • 6b6okcpiqjeihrk2p5mobb92o2
Cloud / SaaS Services Detected
Global Sign Microsoft 365