Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo avril.ca

Group: blackbasta

Discovered by ransomware.live: 2025-01-11

Estimated attack date: 2024-12-12

Country: CA

Description:

Avril Supermarché Santé, an independent health food supermarket chain based in Quebec, Canada. Founded in 1995, Avril aims to promote a healthy lifestyle by making natural and organic products accessible to everyone. The company operates multiple stores across Quebec and offers a wide range of products, including groceries, supplements, beauty items, and ready-to-eat meals.SITE: www.avril.caADDRESS: 11 rue Évangéline Granby, Quebec, J2G 6N3 Canada.TEL#: 1-844-375-6446ALL DATA SIZE: ≈550gb+ 1. Financial data, Accounting 2. Human Resources 3. Personal employees documents 4. DirectionMagasin 5. Marketing & etc…


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 102

Third Party Employee Credentials: 1


External Attack Surface: 35



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • reg.ca-admin gandi.net
  • Please ask the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Other contacts of the queried domain name
  • abuse support.gandi.net
  • 258f4ed9f076eb7538365044214a72f1-4692776 contact.gandi.net
  • b66e9658d2621cde562c104488e52d83-5306412 contact.gandi.net
  • a8aead4b1f8b2ce9c0bf00229dd8fc21-5306415 contact.gandi.net
MX Records
  • avril-ca.mail.protection.outlook.com.
TXT Records
  • facebook-domain-verification=nchbttzykfdav2whfq4ncds5drkxz0
  • google-site-verification=QNVpzqzxY6NkLOXckfO_ct7ZKgGmVeYIBwqpjOuIMXY
  • v=spf1 include:_spf.mailersend.net ip4:184.95.215.17 ip4:209.222.234.158 include:spf.protection.outlook.com include:amazonses.com include:servers.mcsv.net include:mail.zendesk.com include:maintenancedirecte.net -all
  • MS=ms40526823
  • _globalsign-domain-verification=5lNBDnOokdPVeXAz9O3eR7r3QWQhhzOwB5yzyGj6lf
  • _l3f2hvthq6iomii0iizjj1zs065p8c0
  • _wewr9oqj56u5yi3sjtw0tiy7mh24a1o
Cloud / SaaS Services Detected
Amazon SES/WorkMail Microsoft 365 Zendesk

Leak Screenshot:

Leak Screenshot