Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo federalbank.co.in

Group: apt73

Discovered by ransomware.live: 2024-12-20

Estimated attack date: 2024-12-20

Country: IN

Description:

Indian bank. 637895 lines CUSTOMERNAME CUST_ID_N FNAME DOB PAN_NO MNAME LNAME AGE SEX FATHERNAME SPOUSENAME DRIVINGLICENSENO PASSPORT...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 66

Compromised Users: 4066

Third Party Employee Credentials: 36


External Attack Surface: 113



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • susheel netlynx.com
MX Records
  • federalbank-co-in.mail.protection.outlook.com.
TXT Records
  • amazonses:iiLwAozC5CCe4Y+OVbOFXoEKAH6RHodCn13aThuurjA=
  • google-site-verification=ZcrQE4q8wfY6NAFRLTLc8mlDj93_fnTkNEcbodL92JI
  • cisco-ci-domain-verification=2f5a6197451ea3f005cc2f72c36ccde42208998af18fa5729bca5ff17e19de86
  • KMcAREnZxDhg/0JyckuUU7WPI4Djj7/6YdBVFCB7Oyoklw8wRTCuA1mBA8dmGmADj0nK8adhshYCYLNrtDG0AQ==
  • v=spf1 mx ip4:121.243.127.70/32 ip4:115.113.10.233/32 ip4:61.95.168.121/32 ip4:210.212.233.217/32 ip4:125.18.129.11/32 ip4:103.74.181.41/32 ip4:103.74.181.42/32 ip4:103.74.183.43/32 ip4:103.74.183.33/32 ip4:43.254.161.107/32 ip4:115.248.49.221/32 ip4:111." "93.153.118/32 ip4:103.74.181.39/32 ip4:167.89.65.156/32 ip4:103.74.181.35/32 ip4:103.74.181.36/32 ip4:124.247.203.101/32 ip4:115.240.150.11/32 ip4:118.185.188.13/32 ip4:115.241.231.15/32 ip4:103.74.182.12/32 ip4:103.74.182.13/32 ip4:103.74.182.14/32 ip4:1" "03.74.182.24/32 ip4:103.74.182.25/32 ip4:103.74.182.26/32 ip4:103.74.182.27/32 ip4:103.74.182.28/32 ip4:103.74.182.29/32 ip4:103.74.182.30/32 ip4:103.74.182.21/32 ip4:103.74.182.22/32 ip4:103.74.182.23/32 ip4:121.243.127.66/32 ip4:61.95.168.118/32 ip4:14." "143.1.8 ip4:61.95.173.34 a:mailgate.federalbank.co.in a:mailgatedr.federalbank.co.in include:spf.protection.outlook.com include:_spf.campaigns.federalbank.co.in -all
  • amazonses:bS2RHgOJWSiahPWfWRhyXb84zl4gMj8uJMM3UlzYh+Y=
  • MS=ms89389002
  • t71pivrrqqp1kc8bnvhh6gkeff
Cloud / SaaS Services Detected
Amazon SES/WorkMail Microsoft 365 Cisco

Leak Screenshot:

Leak Screenshot