Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Aegea Group companies

aegea.com.br

Group Royal
Discovered 2022-12-23 08:56 UTC
Est. attack date 2022-12-23
Country BR

Description:

Founded in 2010, Aegea is one of Brazil’s largest private sanitation companies. In each town it operates, it takes more health and quality of life to the population, always respecting the environment and local culture. Today, more than 21 million people are served in 154 cities across Brazil.Aegea manages sanitation assets through full or partial common concessions, sub-concessions and public-private partnerships (PPPs) and manages public concessions in the entire water cycle, i.e., supply, collection and treatment of sewage according to the profile and needs of each town.

Infostealer activity detected by HudsonRock

Compromised Employees: 15

Compromised Users: 223

Third Party Employee Credentials: 37


External Attack Surface: 63


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • aegea-com-br.mail.protection.outlook.com. Microsoft 365
TXT Records
  • zoho-verification=zb13664661.zmverify.zoho.com
  • MS=ms27864159
  • MS=ms41150703
  • 54a6d3d5-bb92-43db-bc70-4974d665a6fd
  • 4dp9en7jh8ajg2hscgrk0mg5fl
  • jgchband0dhkvo53usdjr6akm4
  • _globalsign-domain-verification=WWL_wRur0gYgThILAaH0CJGuVry2B4jZZDlvgxer0F
  • docusign=999eef89-98b3-46d4-a2c6-2ad688a05ff3
  • caf-verification=be5fb704401a590f14f184f8a3e63d2a7850a64e37b9af073cba2ed30d407342
  • facebook-domain-verification=ffre4o3c2vd49adm5l0u8uphb9s2yk
  • cl36g5uulsefoq5gaikg2faarn
  • c43c9hkuujo5ocqm6vkmiifqup
  • rbqr0fk46fr9hmfu4950o9aap5
  • _279kuj20atc1n9y80fi6bpcypjig3d4
  • _nmmr570gjj4zt39yb7zbbgf46dmw5uv
  • cisco-ci-domain-verification=67d3d7caf8f0160c74d24e5d1ab7de8c5ac39bb49b5d569b18fd62897c43f171
  • docusign=525a7d68-dfd1-436c-b12d-2c8ad257f1a2
  • MS=613A4D0B796554E67D0832D21AE36FE0D7FD5940
  • v=spf1 ip4:189.125.18.0/27 ip4:200.186.245.174 ip4:189.125.19.237 ip4:149.72.179.145 ip4:74.249.28.173 include:spf.protection.outlook.com include:mail.zendesk.com include:rp.oracleemaildelivery.com include:amazonses.com -all
  • dc7jhs6309mme36qftfpmj2dq8
  • HEvMihewcRlzSKIpCY0ocBMxnCE1bN+WFg6owUdKP7tv8GEqW/dPPTQKeFHqpWOieXTG6caeK1UGGSnUssTAmw==
  • MS=ms63798814
Cloud / SaaS Services Detected
Amazon SES/WorkMail Global Sign Microsoft 365 Zoho Campaigns Zendesk Cisco DocuSign