Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-06-10 22:23 UTC
Est. attack date 2025-06-10
Country PE

Description:

The leading pharmaceutical laboratory in Peru, present in eight countries and with more than 3,600 employees.

Infostealer activity detected by HudsonRock

Compromised Employees: 27

Compromised Users: 63

Third Party Employee Credentials: 12


External Attack Surface: 21


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • medifarma-com-pe.mail.protection.outlook.com. Microsoft 365
TXT Records
  • google-site-verification=eYSq8MeTnvK4b1k-TrFTzT6Q2v8-nbF4sm0NQA26KAU
  • v=spf1 mx ip4:200.48.84.0/24 ip4:44.205.106.155 ip4:10.100.1.17 ip4:190.187.120.184 ip4:190.187.184.138 ip4:200.4.207.19 ip4:5.83.0.0/16 ip4:185.98.0.0/16 ip4:193.53.0.0/16 ip4:20.121.56.28 ip4:147.204.152.42 ip4:54.233.101.39 ip4:52.67.34.111 ip4:148.102" ".48.10 ip4:200.37.165.74 include:spf.perucloud.pe include:spf.protection.outlook.com include:_spf.embluemail.com ~all
  • cisco-ci-domain-verification=1cce2e6cec89ac416ab70895350988c7f707f136390b578270845da895cf6230
  • MS=ms77084197
  • MS=ms42803909
  • apple-domain-verification=hOIgc9n1vH3gSblF
Cloud / SaaS Services Detected
Apple Microsoft 365 Cisco

Leak Screenshot:

Leak Screenshot