Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo moi.gov.ly

Group: Killsec

Discovered by ransomware.live: 2024-10-16

Estimated attack date: 2024-10-16

Country: LY

Description:

The Ministry of Internal Affairs of Libya (وزارة الداخلية الليبية) is the interior ministry of Libya. The Ministry is headquartered in Tripoli.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 11

Compromised Users: 14

Third Party Employee Credentials: 4


External Attack Surface: 7



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domains nic.ly
  • hamouda it.moi.gov.ly
MX Records
  • _dc-mx.6b4f4d5c5692.moi.gov.ly.
TXT Records
  • _lcilb1qhxy0w29flg72v1fwkqgyokdm
  • v=DMARC1;p=none;sp=none;adkim=s;aspf=s;pct=100;fo=1;rf=afrf;ri=86400;rua=mailto:musab.yousef@moi.gov.ly;ruf=mailto:musab.yousef@moi.gov.ly
  • v=spf1 +a +mx +ip4:62.240.36.40 +ip4:62.240.36.36 +ip4:156.38.58.11 +include:spf.protection.outlook.com -all
  • z8c1rrfj1g9x7g3rslyyrht7ywln83l2
  • _42nos8sokyy4fnyb10qdds0q7x0p7yb
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot