Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Montreal North

Group: rhysida

Discovered by ransomware.live: 2025-01-04

Estimated attack date: 2025-01-04

Country: CA

Description:

Montreal North Montreal North is a borough within the city of Montreal, Canada. It consists entirely of the former city of Montreal North on the Island of Montreal in southwestern Quebec.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 789

Third Party Employee Credentials: 26


External Attack Surface: 102



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • mona arcinfo.qc.ca
  • equipe.solutions.numeriques montreal.ca
MX Records
  • montreal-ca.mail.protection.outlook.com.
TXT Records
  • google-site-verification=EhosPZ09SNEGgdY9vkwpica9CtrC8a4KqTHuALRNxeM
  • 7108dc36d5da44a599bd6d492f6abdcd
  • MS=ms86589524
  • v=spf1 include:_spf.google.com include:spf.protection.outlook.com ip4:207.96.224.155 ip4:142.243.254.210 ip4:142.243.254.235/32 include:spf_c.oraclecloud.com include:email.campaign-mail-1.com include:ofsys.com ~all
  • cisco-ci-domain-verification=6db86ec315c9dcbf695886347280e7418f04acdc5a02415efec3cfc916a90567
  • google-site-verification=6CsJZTwHf6BhU61fL8ODEuLUyXreNHwq44hYAkGcaYw
  • MS=C7D4A59642B4D30774A6EFE2AA8076A020F04CA0
  • vmware-cloud-verification-ea566088-6a81-4eea-a177-ebe07618972b
  • have-i-been-pwned-verification=5fc18033e6f5f192aac04523f627d699
  • amazonses:sbn6CF70ykJNjYusVdPIttZp++Gl4bAMuOCeHxQH26s=
  • 6ec101c8aa0849f4ae8a429e3e4bb7ff
  • google-site-verification=rWH47l-UllBx0o8nqbYji0KkjjFFu-WhhydMBS0CIBQ
  • apple-domain-verification=HAXwB7kKd1uXb2jP
  • google-site-verification=Yi3Ctph1Qzv4mzP2IVZ8n18Oo4J2lLhM4dYv0eKubhA
  • adobe-idp-site-verification=fc5ce7ca1842c6eec2e8f39402b296526819ee47036433bf7640df27f1900f4b
Cloud / SaaS Services Detected
Adobe Apple Amazon SES/WorkMail Microsoft 365 Oracle Cloud Cisco Have I Been Pwned