Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

guyer.com.uy

guyer.com.uy

Discovered 2023-08-31 23:42 UTC
Est. attack date 2023-08-31
Country UY

Description:

Attention!Due to incompetence of Guyer&Regules law firm's IT staff, I managed to infiltrate this company and steal a large archive of confidential client data weighing just under a terabyte. This archive contains data of many clients, including leg...

Infostealer activity detected by HudsonRock

Compromised Employees: 5

Compromised Users: 37

Third Party Employee Credentials: 1


External Attack Surface: 18


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • eu-smtp-inbound-2.mimecast.com. Mimecast
  • eu-smtp-inbound-1.mimecast.com. Mimecast
TXT Records
  • ct3q80316r4aodio6kvpn5rnjp
  • v=spf1 ip4:179.27.167.117 ip4:201.221.13.195 ip4:190.64.72.162 ip4:201.221.13.196 ip4:190.64.208.218 ip4:72.5.52.192/26 ip4:70.42.174.0/24 ip4:74.217.129.0/24 include:_netblocks.mimecast.com include:spf.protection.outlook.com -all
  • 3p9l9o3uqjv5om64o19rre9hee
  • LSS9cZ3S5VqIiN8n4Mpv4ntvnfJCsMDcZJ3+yX87inUY9LP3mX8WsZ1zWHGxegLtOvK6n7YRVcbR0nxUhIjO0w==
  • atlassian-domain-verification=6GyRbHxsxQ30n3ZWqsJ7415uS00V8aa5CL6UDcFFVWuTFIkyROSc5S5YbTb2z9nD
Cloud / SaaS Services Detected
Atlassian Mimecast

Leak Screenshot:

Leak Screenshot