Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo blr.com

Group: Ransomhub

Discovered by ransomware.live: 2024-11-22

Estimated attack date: 2024-11-14

Country: IN

Description:

[AI generated] BLR.com is a company that provides compliance and training solutions for businesses. They specialize in delivering resources and tools to help organizations stay compliant with regulatory requirements in areas such as human resources, workplace safety, and environmental management. Their offerings include online training courses, webinars, publications, and software designed to streamline compliance processes and enhance workplace productivity.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 132

Third Party Employee Credentials: 5


External Attack Surface: 62



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • us-smtp-inbound-2.mimecast.com.
  • us-smtp-inbound-1.mimecast.com.
TXT Records
  • k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDGoQCNwAQdJBy23MrShs1EuHqK/dtDC33QrTqgWd9CJmtM3CK2ZiTYugkhcxnkEtGbzg+IJqcDRNkZHyoRezTf6QbinBB2dbyANEuwKI5DVRBFowQOj9zvM3IvxAEboMlb0szUjAoML94HOkKuGuCkdZ1gbVEi3GcVwrIQphal1QIDAQAB;
  • fg6034of3epn7c1k5hgt4pktdf
  • v=spf1 include:o6g3y3x1bn.powerspf.com -all
  • MS=ms81236458
  • openai-domain-verification=dv-lsegBDBF2op9UgWyTWfZrRON
  • ppoj4u7p9t3998ssuhuin7g9hh" " 9t9r349f24v5bmejqn8s7fu4r9
  • 7nu7bekotcd9j5f1pka462jk6d
  • sending_domain648023=39c623bcf070e54a7df72dfae0a2eb7f034baddd273ae2cb4e25c43d66b0ce61
Cloud / SaaS Services Detected
Microsoft 365 Mimecast

Leak Screenshot:

Leak Screenshot