Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo https://geodis.com

Group: Alphalocker

Discovered by ransomware.live: 2024-04-18

Estimated attack date: 2024-04-18

Country: TH

Description:

GEODIS Thai Ltd. came under attack! All SQL bases of the company are available! We think there's a lot to see!GEODIS is a leading worldwide provider of customized transportation, warehousing, global logistics, and supply chain solutions. We unlock value in a complex and evolving world.Read more ⇒


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 26

Compromised Users: 867

Third Party Employee Credentials: 93


External Attack Surface: 0



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • legal safebrands.com
  • info domain-contact.org
MX Records
  • mxb-0020e701.gslb.pphosted.com.
  • mxa-0020e701.gslb.pphosted.com.
TXT Records
  • pJRUij0mKnTthFmDngPQJi2r90QgVluEK6j8UnQDW+tkD1OJ3+Kcq1BaC5pLXiiRyH3XdoSlWO5s5T0FdhAxIw==
  • intersight=a269c5849574ef5e1d2884478c18744805f63459a22bb0ba932abd17405a888a
  • ibmid:85c870eb-bf6c-4491-9e8d-6446e98b8729
  • ca3-6f3bd2a33e3b47f29c4391c50c81265b
  • intersight=041d76513f63e417bb2052617897e5cc2c4c12dd2719622f6cb5f13efc9d7b54
  • 51B1-EFF4-FBE1-EACE-47A2-FCEB-22C7-F202
  • google-site-verification=TWWM776XxlkvPMAVqrQoQwBg580Y92jPixQaVTGBsnU
  • postman-domain-verification=af5f827d0dcb0dccb4dc2ead9e62b9e5be0a725def a7241af8bf35725436e894ea58ec75a0ad7fb2894ba808927d92eac52e951d316f785998867862f3b1df70
  • MS=ms62091021
  • cisco-ci-domain-verification=16bf98f83980cf8bd7bc73f73efb43a7ef7a4d5c4b18045dd9d3d87aee2257bb
  • apple-domain-verification=J1MVfkeZ0lMzlQ9h
  • pardot698723=13d8985f8812c09027f8e10d59a7b5d4f844034d4d071443343152e494cdd71d
  • google-site-verification=EShC2ycb2GEIxvQRj-6fgE2BRftHwRb5ZtyPGoQwFhs
  • google-site-verification=F1iY6s6XpmmVuIo3l_SuFX-zBSM1jKIhc0cFdqp1FZ4
  • Dynatrace-site-verification=7a9f0055-d47d-4953-8e18-caee9d2c20d1__kroraglaioq7n7jvpc4a3rh9mf
  • DomainVerification=PJ88AF0JAM0V1B6NG3R7KWIL7YU3PX83GSBYJKXPFSFEGR9OBA8036APCA6OOZN1
  • v=spf1 include:spf.geodis.com. -all
  • F597-B9CD-2B45-C02C-C42E-4EDA-E987-CEA8
  • G0E0O90464
  • google-site-verification=GcMZ3vMAXLYY94i7ri_5cbzAwKUVeHT7dfD9bhjUmag
  • D-TRUST=QFFRVI8KPVMXB8FYEABW3JN
  • mongodb-site-verification=Pl4KrG88SKlAALiK2rTG1bQAgeYBWGJL
  • docusign=40ca4ac9-d1ab-4917-a3e7-000fc296a527
  • apple-domain-verification=9xzt0nEaXz5fsWqY
  • atlassian-domain-verification=kIMgTPMktY55msbBp5zcKyh6pCdgyAGu5QJZb4LMO9qt0oAH+hp1GozQqijEVxAV
  • google-site-verification=amDgHLcOnL-SZ_NcNG8_2-vuC2M3-wEkUgWWLZc63sc
  • MS=ms61420384
  • teamviewer-sso-verification=a91a3b0d2d1c4ed18bdb6704179f71e2
  • docusign=89c9fe80-3679-4097-957b-f16de2a8cf6c
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Salesforce Teamviewer Cisco DocuSign

Leak Screenshot:

Leak Screenshot