Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Hafa

Group: Thegentlemen

Discovered by ransomware.live: 2026-02-06

Estimated attack date: 2026-02-06

Country: SE

Description:

hafa.fr zoominfo.com/c/hafa/458792496 Lubricants designed by experts to always go further. This is the HAFA Pioneering Spirit. Since 1953, HAFA has demonstrated its ability to renew itself and accompany you towards ever-greater performance. A single partner with a range of lubricants that meets all my needs. For me, it's HAFA. Hafa offers product ranges that cover all professional uses and simplifies the management of your lubricant needs.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 0


External Attack Surface: 1


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • support@ovh.net
  • blzo4y6g4sznln1t0kn6@s.o-w-o.info
  • tech@ovh.net
MX Records
  • mx-mibc-fr-10.mailinblack.com.
TXT Records
  • google-site-verification=U9SGojG0qsrJF9Q0FLbk2SxZNiPZgFfpLRKoONh6YcQ
  • v=spf1 a mx ip4:93.92.104.0/21 ip4:146.255.170.174 include:spf.protection.outlook.com include:spf-eu.letsignit.com include:spf.mailinblack.com -all
  • brevo-code:20efbd2c38328f68db19e31befc1d078
  • 2e9be397fcb96b4e227d7f498ea2dbef
  • MS=ms98340421
Cloud / SaaS Services Detected
Microsoft 365 Mailinblack

Leak Screenshot:

Leak Screenshot