Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo VISEO

Group: fog

Discovered by ransomware.live: 2025-02-19

Estimated attack date: 2025-02-19

Country: FR

Description:

Extract from Gitlabs: Next TI, VISEO, Hochschule Trier - VISEO is a global technology company offering digital transformation services, including customer experience, modern ERP cloud systems, supply chain management, finance transformation, custom development, and data analytics & AI, to help businesses optimize processes and enhance customer interactions.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 11

Compromised Users: 18

Third Party Employee Credentials: 39


External Attack Surface: 23



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse support.gandi.net
  • 023b556dab8a4770ffe50a3845b6613f-1817013 contact.gandi.net
  • 400e43d2b3db9bd066e7cb2d812d558c-666951 contact.gandi.net
MX Records
  • viseo-com.mail.protection.outlook.com.
TXT Records
  • miro-verification=00239d2df47994434bf1250b2c787f671e2e48d0
  • google-site-verification=63Hy1S2qm2y-QSQke4G-JgTJKYaoGdSe7SjWPWGs_w4
  • google-site-verification=RvIFqLGNUT7v_yIYdfPD_GwIQcfgzrZ4yViyBH8HokQ
  • v=spf1 include:spf.protection.outlook.com include:_spf.salesforce.com include:amazonses.com include:servers.mcsv.net include:aspmx.pardot.com include:_spf-dc33.sapsf.eu a:smtp.al-pi.net ip4:77.225.103.117 -all
  • docker-verification=8a9067bb-762d-4c0f-914b-5d761af4bae4
  • apple-domain-verification=r8g4OLoPSZU8nDSS
  • pardot36282=71269289a3dacf57a9912650e56cc5e373405e83cc4982ac3197db30f11c3c71
  • google-site-verification=PajRyqBgZhsjIx0WmOLn-NchblRFH5hWtDBUHlel4FU
  • pardot853223=8530c1561d5e7ca89589c480fcc1fb8a77a9368ea8fb11a4f9463e0209c96b30
  • pardot952042=5698dc813e24352326b62cbca36b1a127968e372bbdba9165b701e22162ee8bb
  • onetrust-domain-verification=8ec5988404e440609a4c1184203e6efb
  • docusign=0425c970-133d-4874-aa99-09cc44492daf
  • MS=ms79359505
  • sending_domain853223=ebb2effddcb1a9afc84e38f837bbe17502cf2811b215a552e2a315c2e8257502
  • jamf-site-verification=cY4zRaEoZUB4EWO5hVjazQ
  • atlassian-domain-verification=JXJtkKyAHsVaHQMeg1pJ2mL4FU4QDOI/nTdSiHhEkgvp6ymoIvAP1rOrm2W/H1Rz
  • google-site-verification=hYb65CRS6Tzlq-aP5vWhXiBPqPxAQn3hix_UMAJSfJo
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail Microsoft 365 Salesforce Miro JamF OneTrust DocuSign

Leak Screenshot:

Leak Screenshot