Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo synertrade.com

Group: cactus

Discovered by ransomware.live: 2024-10-16

Estimated attack date: 2024-10-16

Country: FR

Description:

<p>Software.<br><br>“SynerTrade is the global Source to Pay solution with over 650 customers and managing over $600 Billion in spend. SynerTrade is a leading international provider of cloud-based procurement solutions for the digitalization of companies’ procurement process.”<br><br>Website: <a href="https://www.synertrade.com/">https://www.synertrade.com/</a><br><br>Revenue : $42M<br><br>Address: 1120 Avenue of the Americas Fl 4, New York City, New York, 10036, United States<br><br>Phone Number: +49 89 122 8 722-0, +33 1 41 67 30 00<br><br><mark class="marker-yellow"><strong>Download link #1:</strong></mark> &nbsp;<a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/SynerTrade/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/SynerTrade/PROOF/</a><br><br><mark class="marker-yellow"><strong>Mirror:</strong></mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/SynerTrade/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/SynerTrade/PROOF/</a><br><br><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:</strong></mark> Personal identifiable information, database backups, corporate confidential documents\contracts\correspondence, projects, customer confidential data, etc.</p><p><img src="/uploads/220216_Binkau_David_Personaldaten_b21aec391e.png" alt="220216 Binkau David Personaldaten.png"><img src="/uploads/edited_Internal_Penetration_Testing_April_2024_107e249d25.png" alt="edited_Internal Penetration Testing - April 2024.png"><img src="/uploads/Blueinfy_Web_App_Sec_Report_KONE_KSMP_v1_0_8653abc926.png" alt="Blueinfy_Web_AppSec_Report_KONE_KSMP_v1.0.png"><img src="/uploads/180614_Eberhard_Aust_identity_card_passport_e193bb1c5a.png" alt="180614 Eberhard Aust identity card +passport.png"><img src="/uploads/180928_DBT_DTAG_Synertrade_fully_signed_e246797f00.png" alt="180928_DBT_DTAG_Synertrade_fully signed.png"></p>


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 558

Third Party Employee Credentials: 0


External Attack Surface: 102



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse namebay.com
MX Records
  • synertrade-com.mail.protection.outlook.com.
TXT Records
  • pin5ructs5blhbak6qmkp0khak
  • jvre5rntn9dk49kgo7li8ndjdv
  • vr1ue6lcmha80eim6afirtkhhf
  • atlassian-domain-verification=RdokmdWkFmuJCwt851Hx7ZhDxaAITbM4Fm0/L4cVQBflCQ/ESWHzhDmCVElwU9JC
  • rovag_verification_token=42E1FB74FFBE44B4B4683ABBD4F5E682
  • pstiurfja493dfhjuuo9oam8kl
  • v=spf1 a:synertrade.com include:spf.protection.outlook.com include:spf.mailjet.com ip4:213.95.223.20 ip4:35.214.63.201 ip4:213.95.243.154 include:zcsend.net include:eu.zcsend.net include:spf.zoho.eu include:zoho.eu include:eu.transmail.net -all
  • brevo-code:2b815f90d682200202b3782b32ac9ebc
Cloud / SaaS Services Detected
Atlassian Zoho Mail Mailjet

Leak Screenshot:

Leak Screenshot