Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo OGI Groupe

Group: Worldleaks

Discovered by ransomware.live: 2025-12-19

Estimated attack date: 2025-12-18

Country: FR

Description:

[AI generated] N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 1

Third Party Employee Credentials: 0


External Attack Surface: 2


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • support support.gandi.net
  • f67193806804f9bc611fb662dd657c6c-1683358 contact.gandi.net
  • noc gandi.net
MX Records
  • g54.altospam.net.
  • t19.altospam.com.
TXT Records
  • v=spf1 ip4:82.64.45.16 ip4:109.190.95.108 ip4:188.165.49.27 ip4:185.8.77.85 include:spf.protection.outlook.com include:_mailcust.gandi.net include:ser" "vers.mcsv.net include:_spf.oktey.com include:spf.EU.exclaimer.net include:spf.zoho.eu include:eu.transmail.net include:spf.hornetsecurity.com -all
  • BhGbUOeG6iTy7uDLm0GlI8S4heLqHoQL2U5uNa4NdeaMc0zMVo1OpU4sPa5X8kqeezZKf1D5XUu2i9ZhifzhNA==
Cloud / SaaS Services Detected
Hornetsecurity

Leak Screenshot:

Leak Screenshot