Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

bankbsi.co.id

bankbsi.co.id

Discovered 2023-05-12 21:55 UTC
Est. attack date 2023-05-12
Country ID

Description:

On May 8, we attacked Bank Syariah Indonesia, completely stopping all of its services. The management of the bank could not think of anything better than to brazenly lie to their customers and partners, reporting some kind of "technical work" being...

Infostealer activity detected by HudsonRock

Compromised Employees: 262

Compromised Users: 3618

Third Party Employee Credentials: 186


External Attack Surface: 123


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • bankbsi-co-id.mail.protection.outlook.com. Microsoft 365
TXT Records
  • af2D1bIFPp5avMZatVJ0x4Oqza7iJv7vNre/uLELLi7cnYE2lDJq3OKWxHVOAVcr
  • v=spf1 a:imsva.bankbsi.co.id a:mailer.bankbsi.co.id a:mailbat.bankbsi.co.id include:_spf.myshn.net include:_spf.salesforce.com ip4:103.28.218.103 ip4:103.23.116.79 ip4:103.23.117.101 ip4:103.23.117.55 ip4:103.23.117.29 ip4:103.23.117.189 ip4:34.101.81.215" " ip4:103.23.117.39 ip4:103.23.117.41 ip4:103.23.117.55 ip4:103.23.117.42 ip4:103.23.117.43 ip4:103.23.117.44 ip4:103.23.117.45 ip4:103.23.117.46 ip4:103.23.117.47 ip4:103.23.117.48 ip4:202.148.18.22 include:spf.protection.outlook.com -all
  • _globalsign-domain-verification=h7s-VAeldFZ9xxfPzI--76FTiEWRN-v5fJ8xmdofbY
  • MS=ms84964308
  • MS=3AEDCC96C12F530060C5C78C31FD0BD7C0C3B8FA
  • GOOGLE-SITE-VERIFICATION=CPC9NQB_C_3_PMUPAPDMAW4DCGCYIBRBWHUE
  • google-gws-recovery-domain-verification=42603732
  • google-site-verification=zIrDYh0eufei3bV0-ZfgUrhpfTbdv8Y0yD6-ATXYUqU
  • dtm-domain-verification=kxnMaZkynlobPXMOXg_y0M1ilZZA-r66F0jrBtCYnV0
  • yahoo-verification-key=vwa+xzllXYoAFLc3DGRPgrGxgisNbgPQjXxl7Pe2VEc=
Cloud / SaaS Services Detected
Global Sign Microsoft 365 Salesforce

Leak Screenshot:

Leak Screenshot