Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2022-12-29 20:33 UTC
Est. attack date 2022-12-29
Country BR

Description:

The São Paulo Metropolitan Train Company is a commuter rail system owned by the Secretariat of Urban Transportation of the State of São Paulo. It was created in 1992 with the merger of several railways in Greater São Paulo, Brazil.

Infostealer activity detected by HudsonRock

Compromised Employees: 160

Compromised Users: 324

Third Party Employee Credentials: 84


External Attack Surface: 137


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • cptm-sp-gov-br.mail.protection.outlook.com. Microsoft 365
TXT Records
  • 3NL3ZRFLFIXHA1YQRE2QQCN2T1JIQMSOKD49UYLF
  • tvFnLESksnHRapWto8qQyD+5SX3kFxNuv6OBPf8RUeeQngafbMqztmE0C/d/3d6EjzIKBE+FceftXUyBvBGJ5Q==
  • UIG3Oq7wchHM4d5LiEQGVkQb7GkxMyOq5Mws11vcxDuL6t3WgTXlYwI8l258s6x1CoiuR4uU9EG3ltSrpsF8+w==
  • globalsign-domain-verification=2123D0F1F1161E029C64B90EB773E126
  • v=spf1 mx ptr ip4:200.196.234.64/28 ip4:201.55.47.0/25 include:spf.protection.outlook.com -all
  • MS=ms65721300
Cloud / SaaS Services Detected
Microsoft 365