Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2023-03-27 17:17 UTC
Est. attack date 2023-03-27
Country BR

Description:

A company of the Stone Co group, Linx is a specialist in retail technology and leader in the management software market, with a 45.6% retail market share, as attested by the IDC. All of our expertise is focused on retailing for and for people, connecting the individual to the ease, intelligence and desired experience from the online to the offline world.

Infostealer activity detected by HudsonRock

Compromised Employees: 569

Compromised Users: 1171

Third Party Employee Credentials: 282


External Attack Surface: 200


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • smtp.linx.com.br.
  • linx-com-br.mail.protection.outlook.com. Microsoft 365
  • linx-com-br.mail.eo.outlook.com. Microsoft 365
  • mx3.linx.com.br.
  • mx2.linx.com.br.
  • smtpcorp.linx.com.br.
  • smtpprinter.linx.com.br.
TXT Records
  • brevo-code:20507743cede40d5fe44832b2aa3b193
  • gevvk0r9hb5e1e8te7dr7ubu94
  • jddoqn1e7rdbbnurt7i3gakesq
  • mongodb-site-verification=rLwK7RHjK3XcjlIsMHFgsfDjTFB6V1MY
  • site24x7-signals-domain-verification=06ec1c6d91a9100e83805e72d9e8e85f
  • v=spf1 ip4:52.165.23.159 ip4:13.67.190.160 ip4:186.251.88.11 include:spf.protection.outlook.com include:sendgrid.net include:_spf.rdstation.com.br -all
  • atlassian-domain-verification=aB1E30ph0ugJVay8b9ITUTH5oHI0QX2FJAMaacXQ6Ob5vju3xe5d8s6pzM8YTNPP
Cloud / SaaS Services Detected
Atlassian SendGrid

Leak Screenshot:

Leak Screenshot