Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Akira
Discovered 2024-12-09 14:59 UTC
Est. attack date 2024-12-09
Country ZA

Description:

Cipla is a global pharmaceutical company focused on agile and sus tainable growth, complex generics, and deepening portfolio in our home markets of India, South Africa, North America, and key regu lated and emerging markets We are ready to upload more than 70 GB of internal corporate docu ments including: personal medical records with used medications, inside financial information, customer contacts with phones and e mails, employees contacts etc.

Infostealer activity detected by HudsonRock

Compromised Employees: 222

Compromised Users: 252

Third Party Employee Credentials: 374


External Attack Surface: 143


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • cipla-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • MS=ms45680848
  • Dcik0GC5DQbfGw493wU9DGhUmtSeENxmtOSqfhRE6Mc=
  • v5fdo7ifb2633aiocs2c6k3j6m
  • NO9SezT1HDluy5oxl7qLIx2gE3TCC5IbUa0AHE9snDF8KavSEWJB1zoow1BoqQbrNCOeqXRU+qa0NXMqQSCkBQ==
  • t0a6o70ekrkhrrfjsq9i2djt9o
  • swisssign-check=Std6t2fQZ691uc4LS4x5N7pSd6DDKeDkMSrkeXh5Wc
  • mr3tbiae5tjjkr0i2vmm7mum0l
  • D699-A3AC-AA2F-5FD0-CAA9-E79C-E15D-2CF3
  • amazonses:VSLJclkvgvafaHNytymEYhSyrTjlLvF6iMIQkhf6Z/k=
  • v=spf1 ip4:20.5.80.155 ip4:20.5.82.25 ip4:13.126.94.72 include:spfcorp.netcore.co.in include:spf.protection.outlook.com include:spf.emailsignatures365.com ~all
  • successfactors-site-verification=MWIyNTEyNmZlZjk4YTNlZTBiMTBiNjY2NmQ4NTk1YmQxMTVkNTVjMDUxNzBmNTVjYTQ1NTRmMjg3OTU5OWMyMg==
  • google-site-verification=3miWviX7YYElk3v7AD0QThqifhO1tzM_ajguFye8AjE
  • _urp3k6u6c8e00u73chncydlc5srsu4a
  • d4m8fb788wb2gd9x2w3ccmgx98z8f8h5
  • msfpkey=55yz6mr65w4mib0crw0yix69d
Cloud / SaaS Services Detected
Amazon SES/WorkMail Microsoft 365