Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

belfius.be

belfius.be

Group Killsec
Discovered 2024-09-05 23:15 UTC
Est. attack date 2024-09-05
Country BE
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Belfius Bank, founded in 1996 and headquartered in Brussels, Belgium, provides banking services.

Infostealer activity detected by HudsonRock

Compromised Employees: 13

Compromised Users: 54

Third Party Employee Credentials: 5


External Attack Surface: 26


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mail.belfius.be.
TXT Records
  • dw3f352yw2n8csnsk1qzbfmf7z9hsqk5
  • globalsign-domain-verification=s1T78T2LoUhvaqLnytrtkikYkuNrzYpX7XdXKiH867
  • google-site-verification=21mOJj1BOtnPFeNsCEf5sqZPptcmiXW9SH-BcVD8Avg
  • _brjo6s0l2b8kmxh9s0dcfaytm23t4nj
  • google-gws-recovery-domain-verification=55479146
  • miro-verification=fed5e6f4926ba0cefa65c1a512f9f795d586d134
  • _4qnxkc2agwi4sgbbtl071b7m4xebzkx
  • adobe-idp-site-verification=5f542e21-dcba-45b4-9c19-ee31f6d24c0d
  • _h35qujgl8as6pq3yn7tjasfa3vzuruj
  • _i4yk5aopwqrgc6sy3edz9m4fd3uxrxr
  • paloaltonetworks-site-verification=5e7434416082b43a7139d710d5182413527b2be22c6d02e6444dbfee46c891fe
  • QuoVadis=08faf705-a7f0-48d6-8886-401441d94d94
  • onetrust-domain-verification=7fe7901e64e44dd0b8ceadf80949a27b
  • have-i-been-pwned-verification=6419316d3960281afb9577ab54216dbe
  • apple-domain-verification=rSgTvU8ijCgmkemW
  • 0fllzymzmpjzhhhp4lkb31sn4jz8m4q2
  • _globalsign-domain-verification=YhwEbv70TlLfHv_syA4fVw5ABAqZ76Q5E7su0PGnAr
  • _gmddbf773witg3pv7371vueuxv0lo70
  • v=spf1 ip4:141.96.0.129 ip4:212.63.232.3 ip4:31.193.177.229 ip4:31.193.177.236 ip4:62.72.101.114 ip4:188.64.79.0/24 ip4:188.93.102.215 ip4:79.174.133.61 ip4:185.18.8.253 ip4:85.158.111.74 include:spf.mandrillapp.com include:servers.mcsv.net" " include:spf.mailjet.com include:spf.flexmail.eu include:sendgrid.net include:_spf.cmail.ondemand.com -all
  • MS=ms16040564
  • QuoVadis=493aaff4-9d19-4f82-a615-2c9b677ee82a
  • onetrust-domain-verification=1c6d2dbcf44c4dbebea19ebbeea126ab
  • 3wv276b97g1lvphr0hjnvpxs9llyldww
  • tr76hh1j7xy3l8kw41smr8v5vqz5t25w
  • globalsign-domain-verification=Yz16rsv99unNpPc-F3ZIJgFhuPy40FSanrJxfZ1-UW
  • cm.com-domain-verification=019744a8-fcd4-7407-91f7-1adaa66be2bf
  • google-gws-recovery-domain-verification=71434632
  • google-site-verification=jGGsflG7MQkybhEytlLqo53N4x3wh_D_dAUkfX6Xhxw
  • successfactors-site-verification=YjA2NjUyZTRjNzRkODk4Yzg0MGRjNzYyZjViNTYxNzU3MGVjNWU5M2FjNjcwMmEyMDU5NDJkYjBjZDAwYzA1OQ==
  • google-site-verification=Corl1Gn3t9BY8JXOEFPfD8lpvW8zc1URrORicAqAw58
  • QuoVadis=536e02ed-7221-4972-8511-9919aed61daf
  • globalsign-domain-verification=-DBRuFg_Z8b5iVtCMiGxSE1B3L-jH2H9PrbdkjaP7X
  • xr8lx9clpm0z4kqtfxksp0jrl3msxwjd
  • google-gws-recovery-domain-verification=54609390
  • r0by0m7r6p47ngsgpxbrc24zrt2l49gq
Cloud / SaaS Services Detected
Adobe Apple Global Sign Have I Been Pwned Mailchimp Mailjet Mandrill Microsoft 365 Miro OneTrust SAP Success Factor SendGrid

Leak Screenshot:

Leak Screenshot