Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Banco Hipotecario del Uruguay

Group: Crypto24

Discovered by ransomware.live: 2025-10-03

Estimated attack date: 2025-10-03

Country: UY

Description:

We have exfiltrated over 700GB of most sensitive highly sensitive customer PII, financial/accounting records, legal/contracts, property/title documents, credit and risk files, market/trading operations data, and IT/security configuration information.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 588

Third Party Employee Credentials: 1


External Attack Surface: 24


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • bhu-net.mail.protection.outlook.com.
TXT Records
  • c74d3561f6d5ec3d5357b11c3b03154f51d8d757c3aece2880bb5740aa3b942
  • 9075bc294f0446e4a6f4e6cd0b9c0580778d83aaaec2fec333c967e5b115d04
  • 4b0e8f15a7b3b95e026ca59141e2c5d995fb29b080315c84ecd92473bf2f8232
  • 2dcaffab9437802895fd2fe6a1439659f1d0ca11e1ccbbdda92a752d200b37d
  • v=spf1 mx include:spf.protection.outlook.com -all
  • 4126a56afb071f755a10a39381f6299cf48a758b5326ab5ab771a4bd9237e9b
  • brevo-code:a15d740b3be569330d3c24398dd3f658
  • 899217577c64cfb39a7fb9fe81033bee107cf9ed61dec449c59a67eae6ea197
  • faafc4cdebea25890ec965d1676b36899fbb6f12a6cb9ca9137212a9ea8b8a3
  • 1e99bb776a4be036086b743439a4de78428c65e7dd33c5f3f6019d6204ae879
  • 59a005f897c05fd94cfd172faa3ef640bff2d4917c3499cc719fdd944c05efb
  • c2eb185f3cd2701cc6d016bda033db5fb36756efa14ed0085b4706ab9459080
  • MS=FB9C7336090898B3F1BEB6CD5068AD1B88C95312
  • MS=ms83009033
  • c43a7480ee8535e88db035e2e16ea25c895fb042155706dbcffa991962e015cf
  • 50f2033fb43c9ed5f9c6d8948f488abd524719e5fce6721b03e77cc4c728aa
  • 33773faebbe0123f4296ae2ed8432eaaf9052d6d8010ff107ef0d2447516c820
  • MS=ms51464957
Cloud / SaaS Services Detected
Microsoft 365