Watermark

CTI Telemetry

VirusTotal Analysis

Infostealer analysis by HudsonRock

33
🧠 Dispositivi infetti
16
🌐 Utenti compromessi
17
πŸ§‘β€πŸ’Ό Dipendenti compromessi
33
πŸ”‘ Password aziendali
49
πŸ”‘ Password users

RedLine 44
Lumma 12
Raccoon 4
StealC 2

https://mail.fm.gob.ar/owa/auth/logon.aspx 21
https://intranet.fm.gob.ar/wordpress/login 6
http://soporte.fm.gob.ar/osticket/upload/login.php 2
https://recibo.fm.gob.ar/reset-password/4791588f5af860300a5f2a31e9c6228d3bebcf6ae6b33b476d0dd18575a399bb 1
https://recibo.fm.gob.ar/login 1
http://β€’β€’β€’β€’β€’β€’β€’.fm.gob.ar/β€’β€’/β€’β€’β€’β€’β€’β€’.β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’β€’β€’.fm.gob.ar 1

https://recibo.fm.gob.ar/login 25
https://nubefm.fm.gob.ar/index.php/login 5
https://proveedores.fm.gob.ar/reg_prov/altausr.php 5
https://nube.fm.gob.ar/index.php/login 4
https://nubedemo.fm.gob.ar/index.php/login 2
https://β€’β€’β€’β€’β€’β€’β€’.fm.gob.ar/β€’β€’β€’β€’β€’_β€’β€’β€’β€’β€’β€’β€’β€’_β€’β€’β€’β€’.β€’β€’β€’ 2
https://β€’β€’β€’β€’β€’β€’.fm.gob.ar/β€’β€’β€’/β€’β€’/β€’β€’β€’/β€’β€’β€’ 2
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’.fm.gob.ar 1
http://β€’β€’β€’β€’β€’β€’β€’.fm.gob.ar/β€’β€’/β€’β€’β€’β€’β€’_β€’β€’β€’β€’.β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’.fm.gob.ar/β€’β€’β€’β€’β€’_β€’β€’β€’β€’β€’β€’β€’β€’_β€’β€’β€’β€’.β€’β€’β€’ 1
https://β€’β€’β€’β€’β€’β€’.fm.gob.ar 1
https://β€’β€’β€’.fm.gob.ar/β€’β€’β€’/β€’β€’/β€’β€’β€’/β€’β€’β€’ 1

None 1
Windows Defender 3
Not Found 4