Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Empresas Públicas de Medellín

epm.com.co

Group Alphv
Discovered 2023-07-26 16:18 UTC
Est. attack date 2022-12-26
Country CO

Description:

The bylaws in force for EPM E.S.P. are contained in Decision 12 of 1998, as amended by Decision 32 of 2006. It operates in the water (and sewerage), electricity and gas sectors. It is legally empowered to also act in the telecommunications and garbage collection sectors.

Infostealer activity detected by HudsonRock

Compromised Employees: 569

Compromised Users: 7261

Third Party Employee Credentials: 196


External Attack Surface: 200


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • adminhello.co
MX Records
  • epm-com-co.mail.protection.outlook.com. Microsoft 365
TXT Records
  • v=spf1 mx include:spf.protection.outlook.com ip4:200.13.232.48 ip4:201.220.30.120 ip4:201.220.30.121 ip4:190.71.139.85 ip4:200.122.253.37 -all
  • Nombre/Host/Alias:@Valor/Respuesta/Destino:google-site-verification=Z4IV5PuxxXnQJnxcewAaAHSC6rMxNvmnIi10inKMjos
  • google-site-verification=Rfg0OIQnDAMlYhMmasNE-4Lnw3Fisx-zNjaEm39BoFA
  • _w39xhtxmkdwehk1gvv52bxepemufo5l
  • fastly-domain-delegation-fddelt782931-6-26-24
  • apple-domain-verification=lkTYEUndFTnKt7Lu
  • f2DYyEC3UVqJnZhcf4F3WxVoV9b8RR2n8hqMjHxZX/EFLvkpptIPx63sPrBwA3HmU+EEXcCltDPvFOAnZ9CqsQ==
  • google-site-verification=AnKYzS448KnyIw8s1rpQ6NcwSm-4dTw_-LP7CmnLoNw
  • h4IenSdnczOHAMuNOgnVoF3gktZCDgsH/rhqSvuq3370KoGzBrOiWlvUY7eah/3B77rYBiSOH2EweYZcgxM3BQ==
Cloud / SaaS Services Detected
Apple

Leak Screenshot:

Leak Screenshot