Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo sfr.fr

Group: apt73

Discovered by ransomware.live: 2024-11-23

Estimated attack date: 2024-07-12

Country: FR

Description:

SFR is a French telecommunications company. It is both the second oldest mobile network operator and the second largest telecommunications company ...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 173

Compromised Users: 90342

Third Party Employee Credentials: 0


External Attack Surface: 128



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domaine sfr.com
MX Records
  • smtp-in.sfr.fr.
TXT Records
  • v=spf1 ip4:93.17.128.0/24 ip4:198.2.187.67 ip4:52.36.127.248 ip4:86.64.210.3 ip4:86.64.210.5 ip4:86.64.210.19 ip4:86.64.210.79 ip4:86.64.210.153 ip4:86.64.210.154 ip4:195.62.75.16/29 include:spf1.sfr.fr -all
  • wx3qzvclgn9075dqtzxpp4k8t4m1502k
  • amazonses:p3HEkN0C4HX+XaWp6Rgs/GpmpPORzsoT0FmM8USlpEA=
  • y80jphtqhqxyzt3yb2pbs6bd5qh746zf
  • google-site-verification=teCIeQ6AHM1F2yezbALmddwx96XhkHX1E3YP8byc_X0
  • yahoo-verification-key=m6zLtCjZ6lAoaRF7osG44BTHuAE1aYmW5Y0yfs+a+a4=
  • yahoo-verification-key=+y0ZvV+ZIJH5a65pOIppQhrDQS2uVyBATH52KTcn/DY=
Cloud / SaaS Services Detected
Amazon SES/WorkMail

Leak Screenshot:

Leak Screenshot