Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

mundo-r.com

mundo-r.com

Discovered 2023-05-15
Est. attack date 2023-05-15
Country ES
City Zaldibar

Description:

3TB of data downloaded. Financials, legal documents, customer, employee, and more. Also, about 100gb of euskaltel.com data was downloaded from this network. These will be published in the next post.R cable Spain is an operator of telecommunicat...

Infostealer activity detected by HudsonRock

Compromised Employees: 517

Compromised Users: 3858

Third Party Employee Credentials: 537


External Attack Surface: 180


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@interdominios.com
  • contact@privacyprotect.org
  • info@interdominios.com
MX Records
  • mxl.mundo-r.com.
TXT Records
  • globalsign-domain-verification=0DBD6F71DC0E4D8B123C8F253600F665
  • j3lxxpjfv4ykbldl3yf0lh313t794kz4
  • globalsign-domain-verification=E95DF849BC3D75C0C2F9CE447137A19D
  • google-site-verification=oxwlcrqwxa8lvpnj50j4tvqxythkbynr1bghml5lauu
  • dtm-domain-verification=xUu8hN_VP2hMeBAJ1OC1zEeawJpZzbCRnTthPjLNESY
  • v=spf1 mx include:spf.hornetsecurity.com ip4:212.51.32.0/23 ip4:213.60.252.118 ip4:212.142.145.30 ip4:212.142.145.31 ip4:212.142.145.32 ip4:212.142.145.37 ip4:213.60.113.180 ip4:212.142.144.0/27 ip4:217.168.2.92 ip4:212.51.43.219 -all
  • globalsign-domain-verification=31E6E91C685E1504BA2C9CACF175B172
Cloud / SaaS Services Detected
Hornetsecurity

Leak Screenshot:

Leak Screenshot