Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Sonda

Group: Medusa

Discovered by ransomware.live: 2023-04-03

Estimated attack date: 2023-04-03

Country: CL

Description:

SONDA, a Chilean multinational IT company headquartered in Santiago, is the leader of digital transformation in the region with more than 13,000 employees, presence in 11 countries and implementation of solutions in more than 3,000 cities.It is the biggest in the sector of Information technology in Latin America.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • sonda-com.mail.protection.outlook.com.
TXT Records
  • WuS3Z7QyIpKaXFI4WRz+d5Mlby/LIsNQMhiHtRii1F8ZqcDiCHW2DrtEt0iczQ/3GxwlLKLkba/ouYX84VYcBw==
  • openai-domain-verification=dv-M9Nq4iLtsbDXI0yJd2iOpOgL
  • cisco-ci-domain-verification=5d7a6fc45f2caae237891fa65d8f46ad9a566c5f88908e950ef6f25d1ca29f9f
  • sendinblue-code:6d953b6c7367cf00dff807a467a2460b
  • duo_sso_verification=4z9pxTLv1BX1RBdhT6aEhSKrQxJKnLzHjOiULu6DqqsJuOgobuP7XWnQ5IXCFg0l
  • google-gws-recovery-domain-verification=46702604
  • _globalsign-domain-verification=0JKRyqptfPGq7Htm7YNX1VNqu-AiTjJvCw1Vk1A2Gk
  • v=spf1 mx include:spfa.sonda.com include:spf.protection.outlook.com include:servers.mcsv.net" " include:u11877660.wl161.sendgrid.net include:spf.mindfree.cloud include:_spf.salesforce.com include:sonspf.sonda.com -all
  • GOOGLE-SITE-VERIFICATION=RZLRSJFO8IVLMCXHUPJGUGPSQV3DJDWWVCQWQVKHHKG
  • cisco-ci-domain-verification=48e6c993605c048fcdc8f45b9d252da84c0def4ee10ecc7a31cbc6e534cb853f
  • _a36x5iyr1658p57i9fgv5ygrlxjtfk4
  • adobe-sign-verification = 252ff1533ecadda820f0183617614212
  • _globalsign-domain-verification=k7sbwMGor0_SMflg30z9nF15rM8GvwsT1oxXUsCmye
  • _globalsign-domain-verification=eKnQa8pxi5TPVxB_lDJdJnTTO-hCzslaUcKjUerVIc
  • _globalsign-domain-verification=bv0YwWlMb301wUWRc42oqNodj6LE6QzWXndArd897i
  • MS=ms10168002
Cloud / SaaS Services Detected
Mailchimp Microsoft 365 Salesforce Cisco SendGrid Cisco Duo

Leak Screenshot:

Leak Screenshot