Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Groupseco.com

Group: ransomhub

Discovered by ransomware.live: 2024-10-25

Estimated attack date: 2024-10-25

Country: BE

Description:

Groupseco.com is a company specializing in security solutions and services. They offer a range of products, including surveillance systems, access control, and security management software. The company focuses on providing tailored solutions to meet the unique needs of businesses and organizations, ensuring safety and operational efficiency. Their expertise spans various sectors, with an emphasis on innovation and reliability.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 0

Third Party Employee Credentials: 2


External Attack Surface: 7



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse ascio.com
MX Records
  • groupseco-com.mail.protection.outlook.com.
TXT Records
  • HDTsbf9T6/LYHvYZViO7chA7tGjCJacAKWoYRdTiW9Jzoz/QTK+oJMh+3zaafVPQgtBqx2Whun5JJXOKYkmViw==
  • n6de8Maibp0qcjz79B5ZIlwOS4o5o+6DDzsC49/XmYG/ZTfzYKGBCqiNwJP/XOnM1RcUJTuDqU0Gay3EUx5Ifg==
  • google-site-verification=X8-aJNoUe3jseX6jKkEPCKS3WwxwRjQhQUPCKrpa5x8
  • v=spf1 ip4:217.117.41.81 ip4:194.78.157.10 ip4:212.88.238.226 ip4:82.143.118.114 ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.105.8.0/21 ip4:103.28.42.0/24 ip4:146.88.28.0/24 ip4:163.47.180.0/22 ip4:203.55.21.0/24 ip4:204.75.142.0/24 ip4:27.126.146.0/2" "4 ip4:167.89.0.0/17 ip4:168.245.0.0/17 ip4:82.150.225.79 ip4:171.17.133.140 include:amazonses.com include:sharepointonline.com include:spf.protection.outlook.com include:smtpw.cytric.net -all
  • MS=ms18595143
  • apple-domain-verification=ipOtmJVxImmSHivu
  • 5VFZp8OjxPETPonyNO9LX7ZtL4eteIl0nkPg4j7/wPRRvAfd+3Mbdcxs1QcqWdtMYsqZ950ro5gG9LrcMksTfQ==
  • globalsign-domain-verification=ZmOWepAriGiElvHOa_MhySlzGeHD7ivdPUZ0sf7rs-
  • google-site-verification=5kVe-dAG8M2ya5YwqYu0uI_tbMOV2pswYmGJ14I2hVo
  • atlassian-domain-verification=rQnW7TnYSkC2gQnnKtsb+PM0uZoQtbQB/fMEJzyCyinqeEAIbW87P7N2+pnjL2TV
  • teamviewer-sso-verification=566b25a19c094cffb40124ff10289565
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail Microsoft 365 Teamviewer

Leak Screenshot:

Leak Screenshot