Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Orange (mobile operator)

Group: nefilim

Discovered by ransomware.live: 2020-07-04

Estimated attack date: 2020-07-04

Country: FR


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 39

Compromised Users: 98292

Third Party Employee Credentials: 0


External Attack Surface: 106


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • administration nordnet.com
  • gestionndd francetelecom.biz
  • technical lerelaisinternet.com
MX Records
  • smtp-in2.orange.fr.
  • smtp-in.orange.fr.
TXT Records
  • _jeir5ugkuot4k8j459z89zvql1b9kxx
  • google-site-verification=c4OfrczLMSJm4DyV_ROkN-H3IoVB-up0QI0FfErDj2Y
  • google-site-verification=9xjSUpzPfzPK-jOBA3a4tFB3I_yybuVsWQ4QjMRrKfk
  • google-site-verification=wVfmItsRg98bVMcfUEzmeLzPIkoxoD2yHupbXNHa76M
  • facebook-domain-verification=z5whlxjhtfyfgqgchltv10zt2rebiz
  • v=spf1 include:_spf_gp.orange.fr include:spffed-ip.orange.com include:_spf_other.orange.fr ~all
  • google-site-verification=zln0xRnfIitq6AoSLlrmTWXxbuZUGh3uH5_9Y-iOZ2Q
  • yahoo-verification-key=U2/MmC96KMRjrERLKLLC5cYnFPRFfJ70a7XZ/lhTQN4=
  • _dmarc.collecte-mobile.orange.fr IN TXT " "v=DMARC1;" "p=quarantine;" "rua=mailto:collecte-mobile.orange.fr@dmarc.postmarkapp.com\"\
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.