Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Future Generali

futuregenerali.in

Group Medusa
Discovered 2025-10-04 10:32 UTC
Est. attack date 2025-09-27
Country IN

Description:

Future Generali India is a joint venture between the global Generali Group and Indian partners, offering both life and general insurance. It provides a wide range of products including motor, health, travel, savings, and protection plans. Backed by Generali’s 190+ years of expertise, it combines global standards with local reach. The company emphasizes customer-centric solutions, digital innovation, and strong bancassurance partnerships, especially after Central Bank of India’s stake. Its vision is to actively protect and enhance people’s lives, with goals to double premium growth by 2030. Challenges include high competition, regulatory caps, and low insurance penetration in India. company is headquartered in Unit 801 & 802, 8th Floor, Tower C, Embassy 247 Park, L.B.S. Marg, Vikhroli (West), Mumbai — 400083, Maharashtra, India. 4,068 Employees The total amount of data leakage is 386.8 GB

Infostealer activity detected by HudsonRock

Compromised Employees: 98

Compromised Users: 1506

Third Party Employee Credentials: 68


External Attack Surface: 113


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • apac-tldadminendurance.com
MX Records
  • futuregenerali.in.tmes-in.trendmicro.com.
  • mxa-00aab002.gslb.pphosted.com. Proofpoint
  • mxb-00aab002.gslb.pphosted.com. Proofpoint
TXT Records
  • workplace-domain-verification=119a187b-17bf-40ea-abaa-53ebc4468ccd
  • google-site-verification=PsqPLx1op_nE-kl2Ifg895E1rhglIcUOcOfFZ46TBhs
  • _globalsign-domain-verification=GXWIhLAukuaU4Yq5aQpE2WbBfpgpw3meZTOseJfJiq
  • gNLE1UKkOYNkvLnLPCAFvgA68yLeDeYc+gYaAo3bgIw=
  • globalsign-domain-verification=6pskjkLF36F5IV46sqFm3h3Ud_UFiyonlEwUGu0eQj
  • globalsign-domain-verification=gmVscgGMb7_vB1lp4ni6WHw_-5p4daq3rtMbJKmxLx
  • google-site-verification=aMEBvxFZ9qpjOlBB8XLfqlZQUB41JjNyv0dfQFZrvEw
  • google-site-verification=bAVa-WjgeKB41voabWe8yLlUYZuw8_uqx_4gIuJS-ug
  • globalsign-domain-verification=vnMO4_1O1WtQfbUZK8nt1EeJBMnLoVwNJWGxmoeFfj
  • _globalsign-domain-verification=SJYgDH3P3qywehspO__8pJT3hg4l69xn3Qk6C2BtS6
  • _globalsign-domain-verification=qG-jeWdsrQoJrUQDY4DClGYaL8qJSuTdklOIkI-qYk
  • google-site-verification=gQn0bozC5wfDQsIioYB4_r5zrFS-QNYuTxJgzamzuRE
  • tmes=df7713d108e421a731b774339737bcdf
  • U/zYeX/20hO8QoLT9EiIs11GrJwNaIBaY39zUo4DG98=
  • apple-domain-verification=1rwI0ismc03GLSsI
  • _globalsign-domain-verification=8eIsfeZH0BhOvPP8mUSEWRN16AbpnYZN_azC2_lgOn
  • MS=ms50362642
  • _globalsign-domain-verification=P0HeRy40D7WCLVmU9k9lXGoAhNnV2r325fJFtDnc_-
  • v=spf1 ip4:180.179.141.2 ip4:180.179.141.14 ip4:180.179.32.211 ip4:180.179.100.33 ip4:185.31.132.230 include:spf.protection.outlook.com include:ocmail.in include:spf.falconide.com include:amazonses.com include:spf.tmes-in.trendmicro.com include:614015a2.s" "pf2.netcorecloud.net include:_spf-dc44.sapsf.com include:in-iwc-spf.icewarpcloud.in -all
  • google-site-verification=vFV8TuIeogerLUJ6SKP_Os-c74RiMh7cEtekjiwwlyU
  • google-site-verification=0hgd8zUM0q1Tle4Du8gL40FnLO3yCkeLBr0b87i2VJ4
  • globalsign-domain-verification=QQOZfWFIgvM3CYoOW5x8sCSefzpUJMpyPnrxD4GgKj
  • google-site-verification=LFpJ2otSYF3yTiUX7yJE98rEf6k74mn0b6Db_linhqc
  • successfactors-site-verification=OTNjYmVhODE0MjhmNzQ3ZGU5M2Q2MzQxZWUxZWJhODNkYWExZmIyYzVmNDA1NjI1OTQzMTlhOWZmMGU0NmQ2Zg==
  • tmes=e25c05d0efc40ca527713a7c05512ac4
  • globalsign-domain-verification=H5bctsSy0mKcrqa6ggHdtiYsIAPhvDgaRANKWkkYE4
  • Z5FpTfSNUjLRskXGDZureVyYgqbxx6pqOqee2Y+AMXI=
  • _globalsign-domain-verification=jkoNOLqQpznuGA-aXhWkFvKEzcEYdTtw32NGWyMgV5
  • globalsign-domain-verification=qJpKX56Fu9gGeQkSobt2HiNWRkShellIo_fWpmhpZe
  • google-site-verification=GDjp5RRNAZ_ZbUwYq0Nvo5U1AF2u-xLTl9JLndIEbXA
  • _globalsign-domain-verification=vl5QT1hf_EFA9mJ41UU7zhULD1nILVlkSB8Fiqgb9o
  • F44XM2KhQHcatW2cBwmuP0shTvXDNf99RHeTXl6faY0=
  • 3gYioN07gHBMb+Bkcw4ywdMO0b++eg5LfuN6iMWEZ6zUEglcW3dW0a9iMGfRef098VHoSO65nfMwvuhSHXu5ZQ==
  • globalsign-domain-verification=94o8M9Lub43Q6tOTvVIl6qh17-Bnhx8Aj9gOWuKGQ0
  • k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDED/4KBpQBK0GnY/8TFm/J6zVmkEoXGJWl/6bBy+yUp5pC8aghKbos2gRv0YYCUBs1r9faQJ9Uhlj4wX6ihQxy3YLMq2fi/cHqvUyI8+Zg33Mu4nB4fKGbbb0uUuPN8H5uW6D9ybnJN8vx6B+Rw7EEcDsbZu2fbAx0U3qJSCSsJQIDAQAB
  • wso2-domain-verification:CiIMeahVuB3ndHZ
  • TXT Value: successfactors-site-verification=MThiNTc2ZDUxZTlhMmUxZDhiMmJiNjY0YjcxY2VlNGJhNDQ3NjBiODUyMGM2MGZkNDkzZDQ3ZGUxYmY5YmUwNw==
  • CDDbkyPmBQih6a7cLomuGBESRsyd2t23tcLULHhJGi0
  • YF/mLCcDjvXWbWl3TYwE5ritjx9z04Q82m5vtvX5vBM=
  • aQt3u0ZG225S26Jhd74/HoP+/CdeLi35TeItQBrnfF7jHtKW6x0kFRtJEG/LYg71cPk7489oMgzd7p2KNJN34w==
  • google-site-verification=ZtIE6mbL6QheJ-_YO-Zd8pRB6UwY0rkYK73ppVX1Nuk
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail Global Sign Microsoft 365 TrendMicro Proofpoint

Leak Screenshot:

Leak Screenshot