Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

GIGATRON.RS

gigatron.rs/

Group Qilin
Discovered 2023-02-20 15:16 UTC
Est. attack date 2023-02-20
Country RS
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Gigatron downloaded data overview: From 172.31.244.50: DB backups of shops: G1-G69, G88, G89 From 172.31.248.10: DB backups: CTRetail_backup CTRetailWSRepl_backup GigatronWMS_Sync_backup From 192.168.2.144: employee disability ...

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 7758

Third Party Employee Credentials: 2


External Attack Surface: 100


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • inbound-smtp.eu-west-1.amazonaws.com. Amazon SES
TXT Records
  • google-site-verification=fDn53oEUEflQxHyZyjTK-EipeBx1G5f457asn2OZB98
  • v=spf1 ip4:109.94.103.102 ip4:109.94.103.104 include:amazonses.com include:_spf.ha.rs a mx -all
Cloud / SaaS Services Detected
Amazon SES/WorkMail

Leak Screenshot:

Leak Screenshot