Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Aeris Energy

Group: hunters

Discovered by ransomware.live: 2024-11-23

Estimated attack date: 2024-11-23

Country: BR

Description:

Country : Brazil - Exfiltraded data : yes - Encrypted data : yes


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 71

Third Party Employee Credentials: 52


External Attack Surface: 22



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mxb-0060da01.gslb.pphosted.com.
  • mxa-0060da01.gslb.pphosted.com.
TXT Records
  • _globalsign-domain-verification=0E14gUkbXhyXVOUIiECyjA2UN8DosjQlsurXCV9w1D
  • _globalsign-domain-verification=vle3FUPWP0b9XrDb1vl-CzGPxacJm299q6lzARJuNs
  • _globalsign-domain-verification=vzDf-QiF26rF5rKdyld1uujpQn-YKzT3cYi462D9w8
  • v=spf1 ip4:201.57.120.51/32 ip4:205.220.175.86 ip4:205.220.163.87 include:spf-0060da01.pphosted.com include:spf.protection.outlook.com include:_spf.rdstation.com.br a:mxa-0060da01.gslb.pphosted.com a:mxb-0060da01.gslb.pphosted.com ~all
  • MS=ms62939920
Cloud / SaaS Services Detected
Microsoft 365 Proofpoint

Leak Screenshot:

Leak Screenshot