Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo MICHELIN.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: FR

Description:

[AI generated] Michelin.com is the online platform for the Michelin Group, a leading tire company founded in 1889, based in Clermont-Ferrand, France. The company is renowned for his contribution to the tire industry, including the invention of the radial tire. Apart from manufacturing tires for various kinds of vehicles, Michelin also provides travel assistance, publishing maps and guides, and operates in more than 170 countries worldwide.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 64

Compromised Users: 3387

Third Party Employee Credentials: 305


External Attack Surface: 114


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse cscglobal.com
MX Records
  • de-smtp-inbound-2.mimecast.com.
  • de-smtp-inbound-1.mimecast.com.
TXT Records
  • v=spf1 include:spf.mailjet.com include:spf.sendinblue.com include:sendgrid.net include:cust-spf.exacttarget.com include:de._netblocks.mimecast.com include:44151349.spf03.hubspotemail.net include:spf-008a4301.pphosted.com include:spf-008a4302.pphosted.com" " ip4:193.228.157.119 ip4:62.210.79.21 ip4:64.95.144.196 ip4:52.169.188.148 ip4:201.94.128.0/20 ip4:141.194.36.41 ip4:141.194.36.42 ip4:52.22.10.189 ip4:52.70.196.131 ip4:52.71.64.190 ip4:52.71.20.6 ip4:72.4.119.8 ip4:52.205.191.224/27 ip4:104.208.163.42" " ip4:213.32.108.33 ip4:141.194.36.43 ip4:182.18.163.19 ip4:37.157.8.26 ip4:37.157.8.27 ip4:43.228.187.74 ip4:43.228.185.67 ip4:198.181.201.15 ~all
  • brevo-code:f15df8a444d091fbc01d5bed7a695503
  • brevo-code:394c0938defd07c7d32264104daa2049
  • Sendinblue-code:320d7a0a1776887db9640f8121c59c7a
  • UPMMtSA6InOCHobmgB8z+xlQyU8=
  • brevo-code:0c90471082a3b2462dc9671368d4f56f
  • mongodb-site-verification=yVC7moEiA8vYgm0kKNzFWh54vnZFhgCi
  • facebook-domain-verification=wps16fhtfncnugax62f974k93b33m4
  • brevo-code:c914b59e7f282b7bd6be6707d3d410c1
  • google-gws-recovery-domain-verification=42357351
  • brevo-code:0b871975985644473df73dce17148313
  • brevo-code:67f6623ea0044093109c2520fd2c79e6
  • brevo-code:4225d9ab9830b3df7f4a6aaf6d554d06
  • _alw31bezmifq57qa6derdc8c8fwhokv
  • google-site-verification=2pArBQooz7jOEYIlJJd8aIk3bQkzzEDtYm3rFbfqqYc
  • adobe-idp-site-verification=5325327a-4b7a-46bb-bc1d-f929aa0046e1
  • google-site-verification=-KD-hQ117iq2xq0T59Dhtv9nP4D2JHU1JY-WIUQBbdU
  • mandrill_verify.jpqgR8_udPPbGdibnAGcSA
  • MS=ms68566304
  • atlassian-domain-verification=fTuV4RMI2ROPmmpfXvaNTJP2wVZ8wHbIatbyBId5eeZumWuBr1nKxl0iJfK71LJa
  • brevo-code:91c1c04f1ce59b3265ec91944a8343de
  • miro-verification=489e201f4ac755cb66fe5fae3d4a531f5b473fa3
  • adobe-sign-verification=d1856e9dfc1d0dfacf3c6b0bcd1b564a
  • adobe-sign-verification=5b2b13ebabc32a55b4c4af32c203f9d
  • _x7ifm9dj3wk3d2tf3hht44e2ckwiyt2
  • vmware-cloud-verification-fae8eec6-4301-493f-b903-5035577b7d6a
  • brevo-code:12986ff77994e3b05ad793f9315ca49e
  • google-site-verification=K-TB4ZRS1_Xn0KdnIVdIhLca4xZBOCulQaqr8henj6I
  • brevo-code:8e6392d950a67d8430ca290610ca6cfe
  • brevo-code:96a41c6d73a3b493e3790f789402b22a
  • cisco-ci-domain-verification=5155b7cf4e81dab53704cb8e8bbfec96101a4768a4840fb95ecf3ca57e081f49
  • brevo-code:9f8cbcbe07537030c9311060a71a96a0
  • brevo-code:09b3609550913589ba7302525deafc5f
  • apple-domain-verification=XiN3L0je5aGwO4YF
  • google-site-verification=wKJo0iMF_DdMecpelgRpMgaHIjETpIOS74mawV566Lk
  • brevo-code:7ca8cc06dfe6fda15f4ffeb9a0fdb3e2
  • brevo-code:259bc6f2bd045d00362685c01614cab9
  • brevo-code:42560fbcd317952d1a90f3dbb95f8642
  • google-site-verification=bR44xxoM8l6qWeP8J5KY8-yjGRyw0ngayiQ_qN8kotI
  • brevo-code:61942c2ee054ab5265a78d06ec4136eb
  • google-gws-recovery-domain-verification=44223348
  • brevo-code:25cd1c6b43792ff04d2f58440a857320
  • adobe-sign-verification=7d0f4ee51e8cc8218a0d47de7ad6ecf5
  • brevo-code:ba0a6f95595289aa887adc5b2ef2bcce
  • google-site-verification=Ob6eYGno8ceAOTHHlVlm1R2qNCMNpSGJCrY-v-gwlgA
  • brevo-code:93f289e363f8f5ee27b599ce69412ed1
  • cisco-ci-domain-verification=305faf4ed2622c895a0ab9a323c1daa095429bb63746109813da28ff0e0bca4c
Cloud / SaaS Services Detected
Adobe Apple Atlassian HubSpot Mailchimp Microsoft 365 Miro Cisco Mailjet SendGrid Sendinblue Mimecast Proofpoint

Leak Screenshot:

Leak Screenshot