Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo fawry.com

Group: lockbit3

Discovered by ransomware.live: 2023-11-08

Estimated attack date: 2023-11-08

Description:

As the leading provider of e-payments and digital finance solutions, Fawry spearheads accessible, reliable, and high-value propositions for the benefit of millions of banked and unbanked users across the nation.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse namecheap.com
  • cc6ee783d729480fa4454308036b7fb7.protect withheldforprivacy.com
MX Records
  • alt3.us.email.fireeyecloud.com.
  • alt1.us.email.fireeyecloud.com.
  • alt2.us.email.fireeyecloud.com.
  • primary.us.email.fireeyecloud.com.
TXT Records
  • MS=ms43777344
  • MS=ms65974818
  • MS=ms74271513
  • MS=ms87925918
  • v=spf1 ip4:156.200.121.178/32 ip4:156.200.121.179/32 ip4:50.31.62.18/32 include:spf.protection.outlook.com include:_spf.fireeyecloud.com -all
  • B6BItx1ehmJ4tSJtQtsrgEuteLVRHn6oorEYjxnv2UnQh7jAB/4jUs/QgqPpsRk7+NWvl2FY3j16KpZBEHHIzA==
  • MS=ms24447729
  • MS=C76E12097D6A2C4E31699E593B71F7A169E30084
  • kbmmg1aq654v7jsgd63sppt2jn
  • uatv9t3sitgmjtk9mk6bdd0d9l
  • google-site-verification=-72DhlR9b03PIhVqpHdgk9MMmsagc-wJKcdcYTxTjwg
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot