Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Juntadeandalucia

juntadeandalucia.es

Discovered 2026-09-28 16:00 UTC
Est. attack date 2026-09-28
Country ES
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Organization with 198 emails extracted. Domain: juntadeandalucia.es

Infostealer activity detected by HudsonRock

Compromised Employees: 2216

Compromised Users: 54882

Third Party Employee Credentials: 930


External Attack Surface: 200


Infostealer Distribution

Exposure Report
by ParanoidLab
391333
Passwords
5320 critical
21875
Cookies
1242 critical
Last queried 2026-09-28 16:00 UTC

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • juntadeandalucia.in.tmes.trendmicro.eu.
TXT Records
  • 615986673
  • 982949852
  • 727494135
  • trend-micro-v1-domain-verification.f623b21d5ab15e677959445cf72d73eb=712401b1-2fff-4857-aea4-646f20eb3e8c
  • atlassian-domain-verification=cZ9eu9/GJ09ov7XeBi1yZ0lZUPCkxaeEsTtc135NanoKmaCls0Dt3lBJdA8nHd8p
  • google-site-verification=p-VbmtZKqVBrEoozMjTFXmktpTb4bXh5priXT6gcmMc\
  • tvMfbQDsobsHYk0tJYfrTwUTKf5JkQ5kYBNhogwZcVdzA4Gw1TtTTfxeAIqw3DTdWLsKWoFajhPMkb0laqbPnA==
  • sophos-domain-verification=b2200a5729c439554d0b5c94470be2ea3ba30da92fb679628bb7042ff6a7ca2d
  • google-site-verification=p-VbmtZKqVBrEoozMjTFXmktpTb4bXh5priXT6gcmMc
  • 914026014
  • 1646747672455
  • google-gws-recovery-domain-verification=51006176
  • Junta" "de" "Andalucia_73705158
  • 364332394
  • amazonses:H4LKdQ1dSQV1nRXnc0knS+2i54bHiqTXTJmiaHwXE6I=
  • 535601674
  • UH82Pp5wnRpHDhVd0RkXRNFESxPw62+lK5LWkZkaRCs=
  • Junta" "de" "Andalucia_19601220
  • 1646747230765
  • globalsign-domain-verification=JLPQ-t7oH8TNdxfcASNLWW9hBEBMy1tSKvDrOxk5Oe
  • mdt-site-verification=0030422ac31df641742b3b122cae78d04f79423a31eaf924bb75567bf3bc2f63
  • google-site-verification=v6W7OG4fvJ3PLy2gua5YdrF262dl0H41PPZQ59WQIW0
  • 1651859490077
  • 1645711235454
  • 1674130512256
  • 1646747177922
  • v=spf1 include:spf.protection.outlook.com ip4:217.12.27.153 ip4:217.12.27.75 ip4:217.12.26.60 ip4:217.12.26.61 ip4:217.12.27.157 ip4:217.12.27.158 ip4:217.12.27.160 ip4:217.12.27.210 include:spf.juntadeandalucia.es include:spf.tmes.trendmicro.eu -all
  • 451587166
  • apple-domain-verification=j1wOANa404zhlaOr
  • smartfense-domain-verification=AmIyZQ4VgGbzUFUv2qB-_mgK92AF7cUA3oBSjrb970d3Bihz
  • 186872497
  • google-gws-recovery-domain-verification=5077660
Cloud / SaaS Services Detected
Amazon SES/WorkMail Apple Atlassian Sophos

Leak Screenshot:

Leak Screenshot