Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo usherbrooke.ca

Group: lockbit3

Discovered by ransomware.live: 2023-12-07

Estimated attack date: 2023-12-07

Country: CA

Description:

Université de Sherbrooke is a public Roman Catholic university located in Quebec, Canada.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 286

Compromised Users: 829

Third Party Employee Credentials: 177


External Attack Surface: 162



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • mona arcinfo.qc.ca
  • dns-contact-adm listes.usherbrooke.ca
  • dns-contact-tech listes.usherbrooke.ca
MX Records
  • usherbrooke-ca.mail.protection.outlook.com.
TXT Records
  • google-site-verification=ERHJsgKP9njueqa0plNaREsCXOo7UAwQltTtzZaimwE
  • heyhack-verification=60e53c1b-9538-4718-9ed8-59206e72a364
  • x0eaUInP
  • apple-domain-verification=Ve0EraxiYyBlKOMO
  • cisco-ci-domain-verification=6ecca4c26dafc0dfa2451f30153c17f69ad3855efacf023c245d694d547f2736
  • 4navblN1S0Gb8raNb8+EFg2NLqQMWgJ5MdT+zvPpfoJQpSXx8WtJG+PgKPfZry7ZO1/EIZuMAcXHIxPC7DUe6g==
  • atlassian-domain-verification=utA/e3nHoQclvRDrWofDoqelpfAjLij5zayLyzDmIjyeAXfUONa2bU/uK/VScJFj
  • v=spf1 include:spf.protection.outlook.com ip4:132.210.0.0/16 a:b.spf.service-now.com a:c.spf.service-now.com a:d.spf.service-now.com include:_spf2.usherbrooke.ca -all
  • have-i-been-pwned-verification=4dbb8eb4a078ac7051d3413a4b406437
  • atlassian-domain-verification=KIawDggp2e8lRxjYmbfreN02qarxvhuiWA0Jn1czuxtfaCRC5A2vQzfQpuCLzcAz
  • MS=ms60417001
  • 7VUQvEQmO2tY3HhuMvZufgjXA3x7BiWbBP14Yf+mZIG4MqjK2i905FMQvP5othEZn45gwtK0RkidW2tps/+4tg==
  • D29FcOwl
  • facebook-domain-verification=rbzvtw4q7zpld9gfgk7hudehdi0zxn
  • druide-validation-domaine=a9eDA1E89f620c79878420CCc7D35130
  • google-site-verification=QaV5N6vkzh_n5iEYv1j58TMQsH9oznj_9MdVX1a7gCU
  • intersight=6e7408f804a759ac837099938e8034c5f51c12ef374d745ff8fa5a2f6f838994
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Cisco ServiceNow Have I Been Pwned

Leak Screenshot:

Leak Screenshot