Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Universite Paris Sud

Group: ransomhouse

Discovered by ransomware.live: 2024-10-09

Estimated attack date: 2024-08-11

Country: FR

Description:

The university is a unique network of five faculties, three university technical institutes (IUT), five schools, two associate member universities and seven national research organisations. They have come together to work towards a shared ambition: to combine their strengths to create a leading scientific cluster for research, education, student success and innovation, with the hopes of contributing to the development of a fairer society. As France's top university and one of the world's top 20 best universities, Université Paris-Saclay covers the fields of science and engineering, life and health sciences, and human and social sciences.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 81

Compromised Users: 7

Third Party Employee Credentials: 166


External Attack Surface: 119



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • support ovh.net
  • infogerance campus-paris-saclay.fr
  • ohhtd914f415uh5jt8yg v.o-w-o.info
  • tech ovh.net
MX Records
  • mx1.u-psud.fr.
  • mx2.u-psud.fr.
TXT Records
  • apple-domain-verification=XRAG02xPdzORElnO
  • nintex.661f9825227161a9791845e8
  • DirectFedAuthUrl=https://adfs.universite-paris-saclay.fr/adfs/ls/
  • d3820042f0694c4ab38bd6714615b35d
  • google-site-verification=vUpHSgZs2bvw1of43sdGjuPCHydF5HkXxGYF33p4V80
  • MS=A8AAAAD643DF5E8CDC7B89FA2DFFF84542BE116E
  • vdpf54xs9xkc5hvtwlddpqy5jmc0rl9m
  • MS=ms97138953
  • IrnP6m/egnlzG4pdqvTv+qGIb3E=
  • v=spf1 mx ip4:129.175.213.0/25 ip4:129.175.213.128/32 ip4:129.175.212.64/29 include:spf.protection.outlook.com include:spf.saclay.cblue.be ~all
Cloud / SaaS Services Detected
Apple Microsoft 365

Leak Screenshot:

Leak Screenshot