Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo SISTRAN Consultores

Group: blacknevas

Discovered by ransomware.live: 2025-09-01

Estimated attack date: 2025-09-01

Country: MX

Description:

538k files1.1TBlisting data https://gofile.io/d/r8a9GVThe company specializes in providing IT services, software development, and consulting solutions, primarily focused on the insurance industry.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 59

Compromised Users: 11

Third Party Employee Credentials: 2


External Attack Surface: 17


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse easyspace.com
MX Records
  • mail.sistran.com.
  • sistran-com.mail.protection.outlook.com.
TXT Records
  • google-site-verification=aV_mw4LBPh5nJBM3HmbAnZZcp7NJ3NYCUoBqVpLVwt4
  • v=spf1 mx mx:mail.sistran.com include:spf.protection.outlook.com ip4:200.10.99.45 ip4:200.70.58.146 ip4:200.10.99.15 ip4:200.10.99.15 ip4:200.10.99.20 ip4:200.10.99.46 ip4:200.10.99.2 ip4:200.10.99.25 ip4:190.104.233.56 ip4:200.10.99.6 include:spf.fromdop" "pler.com -all
  • MS=ms70815258
  • ZtIaDai+iRRJTVUVsbBwR0+4HtmaVp6ak7mXhuowTCPJ0zfNkBOZFyKPPplbMivtMWM112tXo6GSfAzYTtS5hw==
  • include:spf.fromdoppler.com -all
  • u0cj8img0bb9iu7e1hdktghqvn
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot