Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo alfa.com.co

Group: Akira

Discovered by ransomware.live: 2025-02-04

Estimated attack date: 2025-02-04

Country: CO

Description:

Extract from Taking stock of 2024 Part 2


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 55

Third Party Employee Credentials: 13


External Attack Surface: 18



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • admin hello.co
MX Records
  • aspmx3.googlemail.com.
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • aspmx.l.google.com.
  • alt3.aspmx.l.google.com.
  • alt4.aspmx.l.google.com.
  • aspmx2.googlemail.com.
TXT Records
  • v=spf1 ip4:190.255.35.91 ip4:190.255.35.90 ip4:35.231.108.82 include:_spf.google.com include:spf.mailjet.com include:spf.zoho.com include:transmail.net include:_spf.embluemail.com ~all
  • MS=8157DBE71A77D1C61B9A5430C7B328450F1A10FB" "MS=ms25091195
Cloud / SaaS Services Detected
Microsoft 365 Zoho Campaigns Mailjet