Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.usmba.ac.ma

Group: GDLockerSec

Discovered by ransomware.live: 2025-01-24

Estimated attack date: 2025-01-24

Country: MA

Description:

8MB


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2148

Compromised Users: 6827

Third Party Employee Credentials: 3279


External Attack Surface: 198



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • contactns inwi.ma
  • admin-ns meditel.ma
  • technicalns inwi.ma
MX Records
  • ALT1.ASPMX.L.GOOGLE.COM.
  • ALT2.ASPMX.L.GOOGLE.COM.
  • ALT3.ASPMX.L.GOOGLE.COM.
  • ALT4.ASPMX.L.GOOGLE.COM.
  • ASPMX.L.GOOGLE.COM.
TXT Records
  • google-site-verification=SbN1VqFkE2YwXG9dGdvtCqlO1YM36GRb68QtTM5htXQ
  • google-site-verification=wjpcSEok1_HCrYsl3XQtTueF0u1tpBCmsQMM1i8WMOU
  • MS=2C2B48E967B67E87DD1B44E10B4DBF7F9287A737
  • v=spf1 include:spf.mailjet.com include:_spf.google.com ~all
Cloud / SaaS Services Detected
Mailjet

Leak Screenshot:

Leak Screenshot