Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Treasury of Cote d'Ivoire

tresor.gouv.ci/tres/

Group Hunters
Discovered 2024-05-13 14:32 UTC
Est. attack date 2024-05-13
Country CI

Description:

Country : Côte d'Ivoire - Exfiltraded data : no - Encrypted data : yes

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 804

Third Party Employee Credentials: 47


External Attack Surface: 15


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • herve.akebouesndi.ci
MX Records
  • ALT2.ASPMX.L.GOOGLE.COM. Google Workspace
  • ASPMX.L.GOOGLE.COM. Google Workspace
  • ASPMX2.GOOGLEMAIL.COM. Google Workspace
  • tresor-gouv-ci.mail.protection.outlook.COM. Microsoft 365
  • ASPMX4.GOOGLEMAIL.COM. Google Workspace
  • ASPMX5.GOOGLEMAIL.COM. Google Workspace
  • ALT1.ASPMX.L.GOOGLE.COM. Google Workspace
  • ASPMX3.GOOGLEMAIL.COM. Google Workspace
TXT Records
  • v=spf1 include:spf.protection.outlook.com ~all
  • MS=32EDD1E805F002FE70EB65AF515F53515861776A
  • MS=ms44870794
  • google-site-verification=nqCBLf0cxAYrrp2c45rHGYW_cQrdh2lCq3bDUgdiN0Y
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot