Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

aristopharma.com

aristopharma.com

Discovered 2022-12-24 10:53 UTC
Est. attack date 2022-12-24

Description:

1 part of:750GB, Personal folders of key employees, all infrastructure\personal data\accounting, etc.Md. Azharul Islam_6581 36gb - Senior Executive,Production at Aristopharma Ltd. Md. Rubel_10790 4gb - Executive, Production at Aristopharma Ltd...

Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 3

Third Party Employee Credentials: 13


External Attack Surface: 4


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • aplsysadminaristopharma.com
  • abuse-contactpublicdomainregistry.com
MX Records
  • mx1.agni.com.
  • mx2.agni.com.
TXT Records
  • v=spf1 ip4:162.214.73.110 +a +mx +ip4:142.4.30.250 +a:smtp.agni.com +a:smtp.agnimail.com +a:mail.aristopharma.com +ip4:119.148.10.131 +ip4:116.68.193.114 ~all
  • v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDWd+N2qDoFu5bdeTfziw5LMhCGQQFZXBnUP5SiJ0ST8MSxniJxFNkiNwG9cKM06U8rIHd5JvbaF6ola9iFU0B+eCl7XgRSKhgtHmyg71QVfqoIEyIcEt8L7ISuJkYZoE3mICl4b7847fG4hhiaCXcmxzVRj6sy9/k3+1Noq98AOQIDAQAB;
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.