Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Al Tamimi Law Firm

Group: medusa

Discovered by ransomware.live: 2023-05-19

Estimated attack date: 2023-05-19

Country: AE

Description:

Founded by Essam Al Tamimi in 1989, Al Tamimi & Company has become the largest law firm in the Middle East with offices in Bahrain, Egypt, Iraq, Jordan, Kuwait, Oman, Qatar, Saudi Arabia and the United Arab Emirates. The firm employs more than 360 lawyers and has over 720 staff in total.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse easydns.com
MX Records
  • eu-smtp-inbound-1.mimecast.com.
  • eu-smtp-inbound-2.mimecast.com.
  • tamimi-com.mail.protection.outlook.com.
TXT Records
  • MS=ms36174556
  • fireflies-verification=01JZ2EKS7HK61HH7S4R5N8SZM2.ffverify.fireflies.ai-request-verification=2025-07-01T07:35:52Z
  • ZOOM_verify_lIkR-vLYS62H-JK6uzqL9A
  • sendinblue-code:43ea70075cc8716f39ae4f83677fe3a3
  • logmein-verification-code=526baf7d-b9bd-4155-82dc-fa1fb7b5881e
  • ItYbV0btgdG+FKfFAStsaWiolPcHtdWW3Wxu4RjqTimj7fx1aV5Tu9izXL+GU18oP+mkc3Ah12ZVJmtySlahrg==
  • f09a80ed-7776-4824-89bf-65208f801ece
  • v=spf1 ip4:83.111.236.139 ip4:83.111.236.140 ip4:85.222.150.208 ip4:85.222.150.209 ip4:85.222.150.210 ip4:85.222.150.211 ip4:85.222.150.212 ip4:85.222.150.213 ip4:85.222.150.214 ip4:85.222.150.215 ip4:85.222.150.216 ip4:85.222.150.217 ip4:85.222.150.218 i" "p4:85.222.150.219 ip4:85.222.150.220 ip4:85.222.150.221 ip4:85.222.150.222 ip4:85.222.150.223 ip4:134.213.80.12 ip4:31.222.146.101 ip4:94.236.70.181 ip4:193.223.100.56 ip4:184.106.20.184 ip4:184.106.20.185 ip4:184.106.20.186 ip4:184.106.20.187 ip4:184.106" ".20.188 ip4:184.106.20.189 ip4:184.106.20.190 ip4:184.106.20.191 ip4:85.222.150.238 ip4:85.222.150.230/30 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/14 ip4:104.47.0.0/17 ip4:20.216.56.12 ip4:137.116.240.241 ip4:20.216.14.254 ip4:20.229.26.233 ip4:5" "2.238.78.88/32 ip4:13.95.173.250 ip4:20.74.138.141 ip4:20.74.158.67 ip4:20.74.187.164 ip4:51.4.72.0/24 ip4:51.5.72.0/24 ip4:51.5.80.0/27 ip4:20.47.149.138/32 ip4:51.4.80.0/27 ip4:136.143.188.0/24 ip4:136.143.184.0/24 ip4:135.84.80.192/26 ip4:135.84.82.0/2" "4 ip4:8.39.54.0/23 ip4:204.141.32.0/23 ip4:136.143.182.0/23 ip4:204.141.42.0/23 ip4:8.40.222.0/23 ip4:65.154.166.0/24 ip4:199.67.84.0/24 ip4:136.143.188.0/24 ip4:135.84.80.0/24 ip4:135.84.82.0/24 ip4:117.20.43.11/32 ip4:136.143.184.0/24 ip4:135.84.81.0/24" " ip4:135.84.83.0/24 ip4:136.143.160.0/24 ip4:165.173.128.0/24 ip4:135.84.82.0/24 ip4:136.143.161.0/24 ip4:147.160.167.0/26 ip4:52.49.201.246 ip4:52.49.235.189 ip4:23.21.109.197 ip4:23.21.109.212 ip4:203.76.228.0/22 ip4:103.147.104.0/23 ip4:103.197.16.0/2" "2 ip4:144.217.213.44/30 ip4:167.114.84.252/30 ip4:167.114.197.100/30 ip4:174.138.185.32/28 ip4:198.50.137.108/30 ip4:149.56.192.92/30 ip4:167.114.18.76/30 ip4:54.39.233.188/30 ip4:167.114.10.204/30 ip4:69.10.62.240/29 ip4:216.158.227.192/29 ip4:174.138.18" "5.32/28 ip4:208.73.204.192/29 ip4:167.114.18.76/30 ip4:139.99.214.240/30 ip4:139.99.231.252/30 ip4:139.99.140.228/30 ip4:139.99.190.28/30 ip4:149.56.156.0/30 ip4:51.79.4.144/28 ip4:139.99.214.244/30 ip4:151.80.58.2 ip4:149.56.92.96/30 ip4:162.19.145.168/2" "9 ip4:51.77.93.96/28 ip4:145.239.234.224/29 ip4:51.75.150.128/29 ip4:51.89.15.64/29 ip4:135.125.165.104/29 ip6:2a01:4180:4051:0800::/64 ip6:2a01:4180:4050:0800::/64 ip6:2a01:4180:4051:0400::/64 ip6:2a01:4180:4050:0400::/64 ip6:2a01:111:f400::/48 ip6:2a01:" "111:f403::/48 include:eu._netblocks.mimecast.com include:spf.protection.outlook.com include:_spf.qp-mail.ae include:spf.uae.exclaimer.net include:kallidus-suite.com -all
  • google-site-verification=ppu0A8mWM_e_g5-1_qnX_5lDbFRXq7NALgNQ_lw7J0U
Cloud / SaaS Services Detected
Microsoft 365 LogMeIn Mimecast Zoom

Leak Screenshot:

Leak Screenshot