Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

etisalat.ae

etisalat.ae

Discovered 2024-02-16 15:07 UTC
Est. attack date 2024-02-16
Country AE
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Emirates Telecommunications Group Company PJSC, doing business as etisalat by e&, is an UAE state-owned telecommunications company. It is the 18th largest mobile network operator in the world by number of subscribers.

Infostealer activity detected by HudsonRock

Compromised Employees: 290

Compromised Users: 12919

Third Party Employee Credentials: 170


External Attack Surface: 147


FortiBleed Exposure Detected

This domain's FortiOS SSL-VPN credentials were exposed via the "FortiBleed" leak (CVE-2022-40684).


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mail2.etisalat.ae.
  • mail.etisalat.ae.
TXT Records
  • yQ9vOf8hxu27f5GxhWNfBM3FbKrvEKk7T3vvmKnPN+eqSAciNg3CmsLNKgZ8RmRHJgc1NPv6r8fn1BbBRsoEyQ==
  • ZFa5HCbmiuO+LAvhd+FQ9w339/htoQbgKzGVOx1temXze796MyJS/7vxEZYzqzkUCPQuDoBFoTM4us4U3K+A1A==
  • apple-domain-verification=lxGgyECSAubjpg4M
  • 9944226bb7324b43bf4954fe8dd8ae3c
  • MS=ms76976897
  • MS=ms42600708
  • docusign=0707d111-9848-448f-a669-15fcf00fa36e
  • docusign=1ec09fed-13a5-4b73-b02e-2dd77f765a63
  • VISA= 5D86A5B6B2DE1B40820EDB3BFB0711D5
  • VISA= EAD33090A2AE2FEFD5C0CCD0928D4FBF
  • VISA= B45285D9E98E0CBD325E93EC965FB65A
  • v=spf1 ip4:151.253.143.89 ip4:151.253.143.78 ip4:195.229.238.169 ip4:195.229.238.170 include:_etbulk.etisalat.ae include:_eimrspf.emirates.net.ae include:spf.protection.outlook.com -all
  • cisco-ci-domain-verification=300db9dab18e977ac0f70404807b600efe04d242ac2ae081d6d12ed606a7b56
Cloud / SaaS Services Detected
Apple Cisco DocuSign Microsoft 365

Leak Screenshot:

Leak Screenshot