Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Medusa
Discovered 2023-04-03 12:45 UTC
Est. attack date 2023-04-03
Country CL

Description:

SONDA, a Chilean multinational IT company headquartered in Santiago, is the leader of digital transformation in the region with more than 13,000 employees, presence in 11 countries and implementation of solutions in more than 3,000 cities.It is the biggest in the sector of Information technology in Latin America.

Infostealer activity detected by HudsonRock

Compromised Employees: 1968

Compromised Users: 459

Third Party Employee Credentials: 958


External Attack Surface: 200


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • sonda-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • _globalsign-domain-verification=bv0YwWlMb301wUWRc42oqNodj6LE6QzWXndArd897i
  • adobe-sign-verification = 252ff1533ecadda820f0183617614212
  • MS=ms10168002
  • GOOGLE-SITE-VERIFICATION=RZLRSJFO8IVLMCXHUPJGUGPSQV3DJDWWVCQWQVKHHKG
  • WuS3Z7QyIpKaXFI4WRz+d5Mlby/LIsNQMhiHtRii1F8ZqcDiCHW2DrtEt0iczQ/3GxwlLKLkba/ouYX84VYcBw==
  • google-gws-recovery-domain-verification=46702604
  • _a36x5iyr1658p57i9fgv5ygrlxjtfk4
  • _globalsign-domain-verification=cb-R38-3T0YKlP9OYq3P0nivn6Qp92pXlkSKoA1p_t
  • _globalsign-domain-verification=eKnQa8pxi5TPVxB_lDJdJnTTO-hCzslaUcKjUerVIc
  • _globalsign-domain-verification=0JKRyqptfPGq7Htm7YNX1VNqu-AiTjJvCw1Vk1A2Gk
  • cisco-ci-domain-verification=5d7a6fc45f2caae237891fa65d8f46ad9a566c5f88908e950ef6f25d1ca29f9f
  • openai-domain-verification=dv-M9Nq4iLtsbDXI0yJd2iOpOgL
  • sendinblue-code:6d953b6c7367cf00dff807a467a2460b
  • _globalsign-domain-verification=k7sbwMGor0_SMflg30z9nF15rM8GvwsT1oxXUsCmye
  • anthropic-domain-verification-js5s35=6GwUGCGlzifHHl6RWySjIcGYa
  • cisco-ci-domain-verification=48e6c993605c048fcdc8f45b9d252da84c0def4ee10ecc7a31cbc6e534cb853f
  • duo_sso_verification=4z9pxTLv1BX1RBdhT6aEhSKrQxJKnLzHjOiULu6DqqsJuOgobuP7XWnQ5IXCFg0l
  • v=spf1 mx include:spfa.sonda.com include:spf.protection.outlook.com include:servers.mcsv.net" " include:u11877660.wl161.sendgrid.net include:spf.mindfree.cloud include:_spf.salesforce.com include:sonspf.sonda.com -all
Cloud / SaaS Services Detected
Global Sign Mailchimp Microsoft 365 Salesforce Anthropic OpenIA Cisco SendGrid Cisco Duo

Leak Screenshot:

Leak Screenshot