Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Discovered 2023-10-11 19:01 UTC
Est. attack date 2023-10-11
Country ID
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

PT Pelabuhan Indonesia (Persero), trading as Pelindo, is Indonesian state-owned port operation company that offers an integrated port service throughout Indonesia.

Infostealer activity detected by HudsonRock

Compromised Employees: 171

Compromised Users: 2296

Third Party Employee Credentials: 139


External Attack Surface: 125


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • pelindo-co-id.mail.protection.outlook.com. Microsoft 365
  • _dc-mx.0e66c33be24f.pelindo.co.id.
TXT Records
  • v=spf1 mx ip4:103.41.110.38 ip4:103.41.110.121 ip4:103.41.110.122 ip4:103.41.110.123 ip4:149.96.221.2 ip4:103.219.76.7 ip4:103.214.99.171 ip4:103.19.80.130 ip4:103.19.80.196 ip4:103.244.245.5 ip4:103.19.80.226 ip4:103.19.80.225" " ip4:103.19.80.205 ip4:103.19.80.242 ip4:103.19.80.247 ip4:103.19.80.248 ip4:103.41.110.141 ip4:103.219.76.6 ip4:149.96.220.2 ip4:103.19.81.194 ip4:103.19.81.195 ip4:103.19.81.196 ip4:103.214.99.130 ip4:103.19.80.166 ip4:103.19.80.168 ip4:103.19.80.247" " mx:secmail.pelindo.co.id include:spf.protection.outlook.com include:_spf.excellent.co.id include:spf.tmes-sg.trendmicro.com ~all
  • MS=ms57697005
  • _ukv8axu99oe9nc1cbbj8mnldv00tyvt
  • dlh5mkql225gsk7mkzdr65qbymd9r8x8
  • google-site-verification=icquW_8356jxy304NlNC7kav9vIJYCDQxq9xxkSpmQo
  • hRUa9jYFpSq/jDjD8CuGxIRgJsETqgSQ0upucNflCyNxZRe/6Jjo5K52dcG26n/6diZv2a34XuYWtgAFhBdsaQ==
  • spf.tmes-sg.trendmicro.com
  • trend-micro-v1-domain-verification.a5757c174ade67139cab74bbf7b467c7=2d25f006-6fca-42ec-ba54-caebcb3ff1b3
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot