Watermark

CTI Telemetry

VirusTotal Analysis

Dominio
uw.edu.pl
Registrar
N/A
Motori AV Recap
0
Malevolo
0
Sospetto
33
Non rilevato
61
Innocuo

Acronis [harmless] clean
0xSI_f33d [undetected] unrated
Abusix [harmless] clean
ADMINUSLabs [harmless] clean
Axur [undetected] unrated
ChainPatrol [undetected] unrated
Criminal IP [harmless] clean
AILabs (MONITORAPP) [harmless] clean
AlienVault [harmless] clean
alphaMountain.ai [harmless] clean
AlphaSOC [undetected] unrated
Antiy-AVL [harmless] clean
ArcSight Threat Intelligence [undetected] unrated
AutoShun [undetected] unrated
benkow.cc [harmless] clean
Bfore.Ai PreCrime [undetected] unrated
BitDefender [harmless] clean
Bkav [undetected] unrated
Blueliv [harmless] clean
Certego [harmless] clean
Chong Lua Dao [undetected] unrated
CINS Army [harmless] clean
Cluster25 [undetected] unrated
CRDF [harmless] clean
CSIS Security Group [undetected] unrated
Snort IP sample list [undetected] unrated
CMC Threat Intelligence [harmless] clean
CTX AI [undetected] unrated
Cyan [undetected] unrated
Cyble [harmless] clean
CyRadar [harmless] clean
DNS8 [harmless] clean
Dr.Web [harmless] clean
Ermes [undetected] unrated
ESET [harmless] clean
ESTsecurity [harmless] clean
EmergingThreats [harmless] clean
Emsisoft [harmless] clean
Forcepoint ThreatSeeker [harmless] clean
Fortinet [harmless] clean
G-Data [harmless] clean
GCP Abuse Intelligence [undetected] unrated
Google Safebrowsing [harmless] clean
GreenSnow [harmless] clean
GreyNoise [undetected] unrated
Gridinsoft [undetected] unrated
Guardpot [undetected] unrated
Heimdal Security [harmless] clean
Hunt.io Intelligence [undetected] unrated
IPsum [harmless] clean
Juniper Networks [harmless] clean
Kaspersky [harmless] clean
LevelBlue [harmless] clean
Lionic [harmless] clean
Lumu [undetected] unrated
MalwarePatrol [harmless] clean
MalwareURL [undetected] unrated
Malwared [harmless] clean
Mimecast [undetected] unrated
Netcraft [undetected] unrated
OpenPhish [harmless] clean
Phishing Database [harmless] clean
PhishFort [undetected] unrated
PhishLabs [undetected] unrated
Phishtank [harmless] clean
PREBYTES [harmless] clean
PrecisionSec [undetected] unrated
Quick Heal [harmless] clean
Quttera [harmless] clean
SafeToOpen [undetected] unrated
Sansec eComscan [undetected] unrated
Scantitan [harmless] clean
SCUMWARE.org [harmless] clean
Seclookup [harmless] clean
SecureBrain [undetected] unrated
SOCRadar [undetected] unrated
Sophos [harmless] clean
Spam404 [harmless] clean
StopForumSpam [harmless] clean
Sucuri SiteCheck [harmless] clean
ThreatHive [harmless] clean
URLhaus [harmless] clean
URLQuery [harmless] clean
Viettel Threat Intelligence [harmless] clean
VIPRE [undetected] unrated
VX Vault [harmless] clean
ViriBack [harmless] clean
Webroot [harmless] clean
Yandex Safebrowsing [harmless] clean
ZeroCERT [harmless] clean
desenmascara.me [harmless] clean
securolytics [harmless] clean
Xcitium Verdict Cloud [harmless] clean
ZeroFox [undetected] unrated

0xSI_f33d undetected (unrated)
Axur undetected (unrated)
ChainPatrol undetected (unrated)
AlphaSOC undetected (unrated)
ArcSight Threat Intelligence undetected (unrated)
AutoShun undetected (unrated)
Bfore.Ai PreCrime undetected (unrated)
Bkav undetected (unrated)
Chong Lua Dao undetected (unrated)
Cluster25 undetected (unrated)
CSIS Security Group undetected (unrated)
Snort IP sample list undetected (unrated)
CTX AI undetected (unrated)
Cyan undetected (unrated)
Ermes undetected (unrated)
GCP Abuse Intelligence undetected (unrated)
GreyNoise undetected (unrated)
Gridinsoft undetected (unrated)
Guardpot undetected (unrated)
Hunt.io Intelligence undetected (unrated)
Lumu undetected (unrated)
MalwareURL undetected (unrated)
Mimecast undetected (unrated)
Netcraft undetected (unrated)
PhishFort undetected (unrated)
PhishLabs undetected (unrated)
PrecisionSec undetected (unrated)
SafeToOpen undetected (unrated)
Sansec eComscan undetected (unrated)
SecureBrain undetected (unrated)
SOCRadar undetected (unrated)
VIPRE undetected (unrated)
ZeroFox undetected (unrated)

MX ALT2.ASPMX.L.GOOGLE.COM
TXT google-site-verification=emEHyVA9-mgt7vuyQxn9pPuyUHJ-Y3O_eC0v9db_8RI
MX ASPMX.L.GOOGLE.COM
TXT v=spf1 ip4:193.0.65.128/27 ip4:193.0.72.2 ip4:193.0.72.144 include:_spf.google.com -all
NS arwena.nask.waw.pl
NS ns1.net.icm.edu.pl
TXT google-site-verification=9bxiqefMY9pOwsk0p9aTflYRgk2BpB-Rmh35GjlL3sc
TXT google-site-verification=BxTj-GBfIWLtL_SxtzjTowFvVJjGl9Yu9VDvLlqvdJ8
NS ns1.uw.edu.pl
TXT google-site-verification=zj1ZJZ-lHoMsuNDCOmyfKcVRY8DkWZKukZWx4v1n1M0
MX ALT1.ASPMX.L.GOOGLE.COM
NS ns2.uw.edu.pl
TXT ZOOM_verify_FPq5Vq6mA5vDC7Xr14n5W6
NS ns2.net.icm.edu.pl
A 193.0.115.152
SOA ns1.uw.edu.pl
TXT google-site-verification=bqgMVFeuUu77cbQfjeOTda3O7CBEvMf0s-jP1gcKLz8
TXT MS=9B6B4F4D1E13DCD9C42DA37212BC9C7CDBBD9E40
TXT mojecertpl-site-verification-SHTg1QJlG3L1OfActZVGYVwLbZyydQN1
NS wask.wask.wroc.pl
TXT HARICA-aqRkL4h1GFy3qBuPdXP

Emesso da:
GEANT TLS RSA 1
Intestato a:
uw.edu.pl
Valido dal:
2025-05-13 09:00:07
Valido fino al:
2026-05-13 09:00:07

Infostealer analysis by HudsonRock

2780
🧠 Dispositivi infetti
2741
🌐 Utenti compromessi
39
πŸ§‘β€πŸ’Ό Dipendenti compromessi
66
πŸ”‘ Password aziendali
4885
πŸ”‘ Password users

Raccoon 233
Vidar 83
Generic Stealer 616
Acreed 6
Mystic 3
CRYPTBOT 11
RedLine 782
StealC 117
UNKNOWN 34
Atomic 3
Ficker 3
Azorult 68
Lumma 666

https://logowanie.uw.edu.pl 16
https://it.jira.uw.edu.pl/servicedesk/customer/portal/6/user/login 9
https://logowanie.uw.edu.pl/cas/login 9
https://webmail.chem.uw.edu.pl 5
https://gp.vpn.uw.edu.pl/global-protect/login.esp 5
https://***.uw.edu.pl/*******/****/***********/*******.*** 4
https://***.uw.edu.pl/**/****/***** 4
https://***.uw.edu.pl/*****/****/******** 4
https://******.****.uw.edu.pl/****** 3
https://****.uw.edu.pl/*******/*******/*******/*** 2
https://***.***.uw.edu.pl/*******/***/*****.*** 2
https://*********.uw.edu.pl/********/******** 2
https://*****.*********.uw.edu.pl*****/*****.*** 2
https://****.uw.edu.pl/****/**/ 1
https://********.uw.edu.pl/***/****/*****.**** 1
https://***.uw.edu.pl/**/****/*****/ 1
https://******.uw.edu.pl/ 1
https://**.****.uw.edu.pl/***********/********/******/**/****/***** 1
https://*****************.**.uw.edu.pl/********/**************.*** 1
https://**.uw.edu.pl/***/****/*****.**** 1
https://**.****.uw.edu.pl/*****/*****.*** 1
https://*****.***.***.uw.edu.pl/*****/*****.**** 1
https://*********.uw.edu.pl/***/************************************************* 1
https://****.uw.edu.pl/****/** 1
http://***.***.uw.edu.pl 1
https://*********.uw.edu.pl/***/************************************************* 1
https://******.****.uw.edu.pl/*****.*** 1
https://**.***.uw.edu.pl/*****/*****.***.**.***.**/***/**/*******/***/******/******/****/**************.**** 1

https://logowanie.uw.edu.pl/cas/login 685
https://nowewyrazy.uw.edu.pl/register 676
https://irk.uw.edu.pl/en-gb/auth/login 471
https://irk.uw.edu.pl/pl/auth/login 388
https://irk.uw.edu.pl/osoby.php 224
https://***.uw.edu.pl/*****.*** 219
https://*********.uw.edu.pl 180
https://***.uw.edu.pl 177
https://*****.***.***.uw.edu.pl/*****/*****.**** 160
https://********.***.uw.edu.pl*****/*****.*** 142
https://*****.***.uw.edu.pl/****/***** 140
https://*****.***.uw.edu.pl/***.*** 127
https://***.uw.edu.pl/*****/****/******** 107
https://***.uw.edu.pl/**/****/*****/ 76
https://*****.uw.edu.pl/***/***** 75
https://***.******.uw.edu.pl/**/****/***** 71
https://******.**.uw.edu.pl/*****/*****.*** 60
https://*********.***.uw.edu.pl*****/***/***.*** 55
https://***.uw.edu.pl/*****/****/*****/ 48
https://****.**.uw.edu.pl/******** 46
https://*********.***.uw.edu.pl/*****/*****.*** 44
https://*****************.***.uw.edu.pl/*****/*****.*** 38
https://*********.***.uw.edu.pl/*****/******.*** 35
https://*****.uw.edu.pl 35
https://***.uw.edu.pl/********/***** 33
https://***.******.uw.edu.pl/*****/****/***** 32
https://*********.uw.edu.pl 32
https://***.uw.edu.pl/*****.*** 31
https://******.**.uw.edu.pl/**/****** 28
https://***.uw.edu.pl/**/****/******** 25
https://***.******.uw.edu.pl/**/****/*****/ 24
https://****.**.uw.edu.pl/********/********/*********** 24
https://****.**.uw.edu.pl/****/*******/***** 24
https://*****.***.uw.edu.pl*****/****/***** 22
https://********.***.uw.edu.pl***** 22
https://*****.***.uw.edu.pl/******/***** 21
https://******.**.uw.edu.pl 20
https://******.****.uw.edu.pl/*****/******.*** 20
https://***.******.uw.edu.pl/*****/****/*****/ 19
https://****************.***.uw.edu.pl/*****/******.*** 19
http://***.**.uw.edu.pl 19
https://*********.***.uw.edu.pl 18
https://*****.***.uw.edu.pl 18
https://*********.***.uw.edu.pl/**/******** 18
https://***.uw.edu.pl/***********.*** 17
https://********.***.uw.edu.pl***** 17
https://*********.uw.edu.pl/*************/*****/*****/******* 17
https://********.uw.edu.pl/*****.*** 17
https://*********.uw.edu.pl 17
https://***.uw.edu.pl/ 15
https://*****.***.uw.edu.pl/*****.*** 15
https://******.***.uw.edu.pl 15
https://*****.*********.uw.edu.pl***** 15
https://*****.***.***.uw.edu.pl 14
https://*****.***.uw.edu.pl/******/************/***.****.*****.******.*********.******.************************ 14
https://******.****.uw.edu.pl/*****/*****.*** 14
https://*********.uw.edu.pl/ 13
https://**********.uw.edu.pl/********/ 13
http://***.**.uw.edu.pl/**********/*****/****************/********* 13
https://****************.***.uw.edu.pl/*****/*****.*** 13
https://****.***.uw.edu.pl/********* 13
https://***.**.uw.edu.pl/******/*********/*****.**** 12
https://******.**.uw.edu.pl 12
https://*********.***.uw.edu.pl 12
https://******.**.uw.edu.pl/**/***** 11
https://****.uw.edu.pl/*****.***/****/****/******** 11
http://****.***.uw.edu.pl/ 10
https://********.uw.edu.pl/*****.*** 10
https://**********.**.uw.edu.pl/***** 10
https://***.***********.uw.edu.pl/**/****/***** 10
https://******.****.uw.edu.pl/*****/*****.*** 9
http://****.***.uw.edu.pl 9
https://***.uw.edu.pl/****.*** 9
https://**********.uw.edu.pl 9
http://******.****.uw.edu.pl/*****/*****.*** 8
https://*****.***.uw.edu.pl/******/************/***.****.*****.******.*********.******.************************ 8
https://*************.***.uw.edu.pl/******/*****/*****.*** 8
https://***.******.uw.edu.pl 8
https://***.***.******.uw.edu.pl/**/****/***** 8
http://***.***.uw.edu.pl/****.*** 8
https://**.uw.edu.pl/*****/*****.**** 7
https://***.***.uw.edu.pl/*****/*****.*** 6
https://********.**.uw.edu.pl 6
http://**.****.uw.edu.pl/*****/*****.*** 6
http://***.****.uw.edu.pl/********.*** 6
https://******.****.uw.edu.pl 6
https://*********************.uw.edu.pl/******* 6
https://*****.***.uw.edu.pl/***/**/*******/***/******/******/****/**************.**** 6
http://**********.uw.edu.pl/******** 6
https://********.***.uw.edu.pl 6
https://***.******.uw.edu.pl/********/***** 6
https://***************.***.uw.edu.pl/*****/******.*** 5
https://*****.***.***.uw.edu.pl/******/***** 5
https://****.**.uw.edu.pl/********/ 5
https://*********.***.uw.edu.pl/ 5
https://***.***.******.uw.edu.pl/*****/****/*****/ 5
https://***.***.******.uw.edu.pl/**/****/*****/ 5
https://*****.uw.edu.pl/****/***** 5
https://******.***.uw.edu.pl/*****/*****.*** 5
https://*****.***.uw.edu.pl*****/******/************/***.****.*****.******.*********.******.************************ 5

Not Found 10
ESET Security 1
Windows Defender 7
ESET Zapora 1