Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2022-12-29 20:33 UTC
Est. attack date 2022-12-29
Country BR

Description:

The São Paulo Metropolitan Train Company is a commuter rail system owned by the Secretariat of Urban Transportation of the State of São Paulo. It was created in 1992 with the merger of several railways in Greater São Paulo, Brazil.

Infostealer activity detected by HudsonRock

Compromised Employees: 160

Compromised Users: 324

Third Party Employee Credentials: 84


External Attack Surface: 137


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • cptm-sp-gov-br.mail.protection.outlook.com. Microsoft 365
TXT Records
  • tvFnLESksnHRapWto8qQyD+5SX3kFxNuv6OBPf8RUeeQngafbMqztmE0C/d/3d6EjzIKBE+FceftXUyBvBGJ5Q==
  • v=spf1 mx ptr ip4:200.196.234.64/28 ip4:201.55.47.0/25 include:spf.protection.outlook.com -all
  • MS=ms65721300
  • UIG3Oq7wchHM4d5LiEQGVkQb7GkxMyOq5Mws11vcxDuL6t3WgTXlYwI8l258s6x1CoiuR4uU9EG3ltSrpsF8+w==
  • 3NL3ZRFLFIXHA1YQRE2QQCN2T1JIQMSOKD49UYLF
  • globalsign-domain-verification=2123D0F1F1161E029C64B90EB773E126
Cloud / SaaS Services Detected
Microsoft 365