Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

nfe.fazenda.gov.br

fazenda.gov.br

Group Killsec
Discovered 2024-09-29
Est. attack date 2024-09-29
Country BR

Description:

The NF-e Portal aims to provide information about the Electronic Invoice (Nota Fiscal Eletr�nica), coordinated by ENCAT and developed in partnership with the Federal Revenue of Brazil. Its purpose is to transition from paper invoices to electronic invoices, which have legal validity for all purposes.

Infostealer activity detected by HudsonRock

Compromised Employees: 42

Compromised Users: 112226

Third Party Employee Credentials: 25


External Attack Surface: 111


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • colaboragov-mx-balancer.prod.mlicloud.com.
TXT Records
  • globalsign-domain-verification=F5B078BD7E9ECE8CB12C64C959E70D3B
  • MS=3A675C959BF25AF96C7C723CE423D9F1358CC6BB
  • dtm-domain-verification=4Z2ntA_CMx31vQLwf336iemIoKehskEHK7A3e7pu3do
  • MS=ms62161753
  • MS=ms18664459
  • v=spf1 ip4:161.148.21.192/26 ip4:161.148.50.192/26 ip4:200.152.40.96/32 include:spf.protection.outlook.com include:spf.mlicloud.com -all
  • MS=ms69708081
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot