Watermark

CTI Telemetry

VirusTotal Analysis

Infostealer analysis by HudsonRock

76
🧠 Dispositivi infetti
24
🌐 Utenti compromessi
52
πŸ§‘β€πŸ’Ό Dipendenti compromessi
168
πŸ”‘ Password aziendali
59
πŸ”‘ Password users

RedLine 36
Lumma 34
Raccoon 32
UNKNOWN 12
StealC 12
Vidar 2
Azorult 2

https://mymails.chetu.com/owa/auth/logon.aspx 89
https://mfa.chetu.com:9251/authorization.do 20
https://backbone.chetu.com 6
https://mymails.chetu.com/ 5
https://mymails.chetu.com 5
http://β€’β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’β€’β€’β€’β€’β€’β€’.β€’β€’β€’β€’ 4
https://β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’β€’β€’-β€’β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’%β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’.β€’β€’β€’β€’ 4
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com 3
https://β€’β€’β€’.chetu.com 3
https://β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com 3
https://β€’β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’β€’β€’β€’β€’β€’β€’.β€’β€’β€’β€’ 3
https://β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’β€’β€’-β€’β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’%β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’.β€’β€’β€’β€’ 2
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/ 2
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 2
https://β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com 2
http://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/ 1
http://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’β€’β€’.β€’β€’β€’β€’ 1
http://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/ 1
https://β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/ 1
https://β€’β€’β€’.chetu.com/ 1
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/ 1
https://β€’β€’β€’.chetu.com:β€’β€’β€’β€’/β€’/β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.β€’β€’ 1
https://β€’β€’β€’.chetu.com:β€’β€’β€’β€’/β€’_β€’β€’β€’β€’β€’β€’β€’β€’_β€’β€’β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’β€’β€’β€’β€’β€’β€’.β€’β€’β€’β€’ 1
http://β€’β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’.chetu.com 1
https://β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com 1
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’-β€’β€’β€’β€’-β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com 1
https://β€’β€’β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’ 1

https://downloads.chetu.com/index.php/login 51
https://downloads.chetu.com/index.php 3
https://downloads.chetu.com 3
https://download.chetu.com/index.php/login 2
https://backbone.chetu.com/human-resources/lists/hr%20payroll/allitems.aspx 1
https://β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’β€’β€’-β€’β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’/β€’β€’%β€’β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’.β€’β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’β€’β€’.chetu.com/β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’/β€’β€’β€’β€’β€’β€’β€’β€’.β€’β€’β€’β€’ 1

McAfee VirusScan 1
360 Total Security 1
None 1
Windows Defender 16
Not Found 25
McAfee Firewall 1
Windows Defender [ON] 1