Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Bertani Trasporti Spa

bertanitrasporti.it

Group 8base
Discovered 2024-02-28
Est. attack date 2024-02-28
Country IT

Description:

Bertani Trasporti Spa is a road and rail transport company based in via Camillo Benso Conte di Cavour 58, in Castiglione delle Stiviere, in the province of Mantua, in Italy. For over 90 years, we have been dealing with mobility in the broadest sense of the term.bertanitrasporti.it

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 10

Third Party Employee Credentials: 7


External Attack Surface: 10


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • esva.bertanitrasporti.it.
  • esva2.bertanitrasporti.it.
TXT Records
  • v=spf1 mx a ip4:194.243.25.57 ip4:194.243.25.35 ip4:194.243.25.37 ip4:194.243.25.38 include:spf.protection.outlook.com include:spf_c.oracle.com include:spf_a.oracle.com include:spf_c.oraclecloud.com include:eu.rp.oracleemaildelivery.com -all
  • android-enroll=https://ldcsa.bertanitrasporti.it/rtc/srvivepm/MDM/api/v1/enroll/AndroidEnroll
  • 30wjP0BwiHAs4pgMPkRgJraYBppeEN7DCQwVU2yogr55ANYxKJ/+Wcru0ukCZvEJ4PJZYP81ugFYOPbVTyGNtg==
  • MS=ms58660491
  • MS=ms14890957
Cloud / SaaS Services Detected
Microsoft 365 Oracle Cloud

Leak Screenshot:

Leak Screenshot