etude-villa.fr
blackbastaThis record tracks a ransomware attack claimed by the blackbasta group against etude-villa.fr. It collects the publicly disclosed attack details — sector, location and timeline — as published on the operator's leak site and indexed by Breach House.
Window Zero
EXPOSURE GAPWindow Zero is the time the breach stayed in the open before anyone said so — the gap between when the attack was first discovered on the operator's leak site (t1) and when it was publicly disclosed (t2). The wider this window, the longer victims, staff and customers were exposed with no warning.
Attack Summary
Etude Villa Florek - legal servicesSITE: www.etude-villa.fr Address 18 Rue Néricault Destouches 37013 Tours FranceFULL DATA SIZE: 43gb 1. Finance 2. Accounting 3. Confidentiality 4. Customer Files 5. Users dataNETWORK: ETUDEVILLA-------------------------DOMAIN ADMINS------------------------- admin Admin de réseau adminabsi admininfra Administrateur OGMI SBSMonAcctetudevilla.local\admin @bsi37300 etudevilla.loca\administrateur @bsi37300-------------------------DC------------------------- VM-01-VILLA.etudevilla.local 192.168.36.203 Windows Server 2019 Standard-------------------------SERVERS------------------------- VM-03-VILLA.etudevilla.local 192.168.36.205 Windows Server 2019 Standard HYP-02-VILLA.etudevilla.local 192.168.36.212 Windows Server 2019 Standard VM-04-VILLA.etudevilla.local 192.168.36.206 Windows Server 2019 Standard VM-02-VILLA.etudevilla.local 192.168.36.204 Windows Server 2019 Standard HYP-03-PRET.etudevilla.local Windows Server 2019 Standard HYP-01-VILLA.etudevilla.local 192.168.36.202 Windows Server 2019 Standard VSRV-TOURS-DATA.etudevilla.local Windows Server 2016 Standard SRV-HPRV-villa.etudevilla.local Windows Server 2016 Standard VSRV-TOURS-DC.etudevilla.local Windows Server 2016 Standard VSRV-TOURS-RDS.etudevilla.local Windows Server 2016 Standard SERVTSE.etudevilla.local Windows Server 2008 R2 Standard SERVSYM.etudevilla.local Windows Server 2008 R2 Standard SERVEUR.etudevilla.local Windows Server® 2008 Standard FE
Leak Screenshots
SAMPLEProof-of-breach screenshots the operator posted from the stolen data. Previews are redacted and locked — the originals are available on HaveIBeenRansom.