Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Ouro Verde (ouroverde.net.br)

ouroverde.net.br

Group Fog
Discovered 2024-12-17 12:34 UTC
Est. attack date 2024-12-17
Country BR

Description:

4 GB

Infostealer activity detected by HudsonRock

Compromised Employees: 9

Compromised Users: 268

Third Party Employee Credentials: 9


External Attack Surface: 41


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • ouroverde-net-br.mail.protection.outlook.com. Microsoft 365
TXT Records
  • onetrust-domain-verification=0d6ce1cfc73e45cdb88bee3da15d883e
  • r6e7k5mf52fkjugb7mj1d8oqm2
  • docusign=b7ddeec3-8c70-4704-b50f-223ad240641a
  • atlassian-domain-verification=S3tV5hI8ju9riBhcOisv8kex/CSqUvHxsbaH8AnixVVelNfx5Oym2jhF5/6dgSJR
  • google-site-verification=BF5FFf-Cyr3pxECVmPr7w-zTArzPPv-mHc7JABPF-ss
  • IM5pkCoQ6vckx4gQibqu9iY/hyDWmbRkScZro8iV/2iqmbr3JL/XHceG/Feb+wQcrvlRp8Y3YlIS7rifc8DrZA==
  • cloudflare-verify.ouroverde.net.br IN TXT '952493223-454427443'
  • facebook-domain-verification=y2bq6zz0e13ud06e5pfvtr22a31esl
  • nedl3Fs8oIKnjnoPUeyAoblZWg53eDXbufDFn8mjnbg
  • MS=ms72204292
  • GrdvoJESQlCk4_9O2ABqnT89Tssq4J464oSIfopvXBY
  • BZTqZAL1LlzTM64K7jmOyAAjn-YzTjPaoqF4ntQEWj0
  • tsc7t0o7430lk2furc97o0pp96
  • v=spf1 ip4:201.35.35.57 ip4:201.35.35.58 ip4:189.125.140.193 ip4:189.125.140.254 include:spf.protection.outlook.com include:_spf.salesforce.com include:production.na01.ouroverde.demandware.net include:em5585.ouroverde.net.br -all
  • google-site-verification=bAauL0LbNbVk0LpYkfsL5Wt6ipO58ZHjDORVGscTyiM
  • MS=ms98941529
  • production.na01.ouroverde.web.demandware.net
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Salesforce OneTrust DocuSign

Leak Screenshot:

Leak Screenshot