Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2024-09-15 15:59 UTC
Est. attack date 2024-09-15
Country MU

Description:

https://www.emtel.com Emtel is a leading telecommunications...

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 215

Third Party Employee Credentials: 6


External Attack Surface: 26


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • mx1-bdr.emtel.com.
  • mx1-asn.emtel.com.
TXT Records
  • google-site-verification=2bAYQhEdUAsDcPjDIYBEP2893ejx4hnU_pOxOSBb5MI
  • google-site-verification=K9xQQk_Qgi2U9tYRxkLc2GFlCXVpoXOCiDgilQYylP4
  • pardot1052403=6be0420fc60a6c8726fea110f7cfde42d84959c7f814ee84172d38706630acf7
  • google-site-verification=YgCeQlQogKAIvxXrnlH1nEP7E_zs5e0KI5FLBJWK9vI
  • google-site-verification=RIWVmc2zOKQp6h6OxziiW26JkcrrvQ0UTiP3VQVtVe0
  • v=DKIM1;t=s;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3RkGwzNcMQcfE+e7rpUP1PzkVP9M6JDQZ870RUohqRtHncAKydr2WK2twj7kjts71K3KOUEOmDSmzKPrPMhPncL0vBep+bopjBwCajRPxcTXjkim8Vtih6MzI8DfhkSgVGXmOazeoEnR/k5OZYW8Digt/L1PmRKC/tzBDfi2V0ORPrH4wmBrzZTk6Jzz3ZuzJwe5O" "jeH9iQ4u+dVonn2uLDz9d4S3xWlPdeYWBRaoW1Dh7BNRAQbJy9a8LK6OJJNwf0oTlYg0dlAHrNMceOI +2UIppBqrkYudJ6Shjc4hbvfqtWjiGh29LGldBOkJ5s0/hDiRxJjOjgIASa0mRkuiwIDAQAB
  • v=spf1 a:smtp-asn.emtel.com a:smtp-bdr.emtel.com a:iron1.emtelworld.com a:smtp.emtelworld.com a:mx10-asn.emtel.com ip4:196.192.81.130 ip4:196.192.81.95 ip4:196.192.81.9 ip4:196.192.81.65 ip4:105.235.157.230 mx include:_spf.salesforce.com exists:%{i}._spf." "mta.salesforce.com -all
  • MS=2B1820C540774D6B1E044800427BA6C3267D9860
Cloud / SaaS Services Detected
Salesforce

Leak Screenshot:

Leak Screenshot