Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.danareksa.com

Group: Stormous

Discovered by ransomware.live: 2025-11-06

Estimated attack date: 2025-11-06

Country: ID

Description:

VPN access to the company’s internal network is provided


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 49

Third Party Employee Credentials: 9


External Attack Surface: 20


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • compliance_abuse webnic.cc
  • reg_14795180 whoisprotection.cc
  • adm_14795180 whoisprotection.cc
  • tec_14795180 whoisprotection.cc
MX Records
  • mr02.danareksa.com.
  • md1.danareksa.com.
  • md2.danareksa.com.
  • danareksa-com.mail.protection.outlook.com.
  • maildana.danareksa.com.
  • maildana2.danareksa.com.
  • mr03.danareksa.com.
  • mr01.danareksa.com.
TXT Records
  • v=spf1 a mx a:danareksa-com.mail.protection.outlook.com a:maildana2.danareksa.com a:maildana.danareksa.com ip4:103.87.152.250 include:spf.protection.outlook.com include:spf.mandrillapp.com a:mr01.danareksa.com" " a:mr02.danareksa.com a:mr03.danareksa.com ~all
  • bl6hl0trs6qrs1nglgrq8lj2g6
  • jijn52o96e4nktit74573t743m
  • Persero Danareksa
  • MS=ms98684713
  • eem1ll11aphun0v891s78qptkc
  • v=DMARC1; p=none; rua=mailto:dmarc@danareksa.co.id; ruf=mailto:dmarc@danareksa.co.id;
  • MS=ms74609122
  • jm0wS2GFVkIkZrvUdpFg+15OSLFW+THhsanHVX2lKrHrarPgnFmiigljVPDAo7hOLLzC6+Lue6AnGVBuhZzR9g==
Cloud / SaaS Services Detected
Microsoft 365 Mandrill