Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

erco.co.il

erco.co.il/

Group Toufan
Discovered 2023-12-22 02:45 UTC
Est. attack date 2023-12-22
Country IL

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 21

Third Party Employee Credentials: 5


External Attack Surface: 4


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • avielerco.co.il
MX Records
  • mx2.hc1311-82.c3s2.iphmx.com. Cisco/IronPort
  • mx1.hc1311-82.c3s2.iphmx.com. Cisco/IronPort
TXT Records
  • IO3wlTdvSP6/sHeAcNMyddW5eUPmWf4Fmb22+wfTqWL6YcLoAJET3u++v3Nbf6j2Q+YbMymMRo73o7f7wn/NsA==
  • v=spf1 exists:%{i}.spf.hc1311-82.c3s2.iphmx.com ip4:62.219.184.131/32 include:inforumail.com include:spf.protection.outlook.com include:u22373052.wl053.sendgrid.net include:spf-de.emailsignatures365.com -all
  • MS=ms32240468
  • kcPVVt5XNf6y0mgi/hovQgw7OWmbcUvdApx1CuG2B/lhA1O3UfLFMMVshu7bzBRGU48Bmkas8L1TjB2WeDAiMA==
Cloud / SaaS Services Detected
Microsoft 365 SendGrid