Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo SOCOMEC

Group: stormous

Discovered by ransomware.live: 2023-03-26

Estimated attack date: 2023-03-26

Description:

Socomec is a global energy company that specializes in providing integrated and advanced electrical solutions to medium enterprises. Its products and services include systems design of electric power conversion systems, renewable energy, automatic steering and control systems, protection systems, rides, batteries. The company is characterized by high technology and high quality in its products, and also provides distinguished services in technical maintenance.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • legal safebrands.com
  • info domain-contact.org
  • clientele safebrands.com
MX Records
  • socomec-com.mail.protection.outlook.com.
TXT Records
  • citrix.mobile.ads.otp=i992rn7zexmjyk5vughs0go
  • pardot_86922_*=dc79ba333bd188aec01a5ff0c232d686da08bf48ebead61fc4630dfb8e1ad0b8
  • dMA0J0J+TfP9JLmOz3I+7EgRPdcK8/mgT4N1ljwkgQY=
  • docusign=554fa26b-e497-4599-a6ae-eb8f88a3fac3
  • sending_domain86922=a57158b7b2d24592f1a17470ada19360fe8e79224f2559baaa8ab4d1f16eb96d
  • reachdesk-verification=1qUlF7aL8X7b8V01I9MjknlvkO3sv6eFupYVusdLtgYjR0y1PZFOawvHvrK5FBwB
  • v=spf1 ip4:149.72.203.251 ip4:85.31.192.42 ip4:85.31.193.42 ip4:85.31.193.7 ip4:174.129.245.244 ip4:198.245.81.0/24 ip4:136.147.176.0/24 ip4:13.111.0.0/22 ip4:13.111.52.0/22 ip4:13.111.63.0/24 ip4:13.111.68.0/24 ip4:13.111.72.0/22 ip4:13.111.92.0/24 ip4:1" "3.111.111.0/24 ip4:136.147.182.0/24 ip4:136.147.135.0/24 ip4:199.122.123.0/24 ip4:163.172.146.249 include:et._spf.pardot.com include:spf.socomec.com include:_spf.salesforce.com include:spf.protection.outlook.com -all
  • kYwjlp4tGFk/1Sxk7VjBixXK4lNGiTo+e1ptIKBu2KPoFHXjG8Oq4xpH1ot5X1lyKWRavfRg9+x6yuHfnONrdg==
  • pardot_86922_*=f2dce50df526319614eb52cf42ce430f876e38611fbee52efb0c26f78ba41e39
  • MS=71A12A770EDFC14270EDAB9CFD70E35389F9E64F
  • _globalsign-domain-verification=IPemmyHkjznUDauQX1y99jG57zgOMux924rUCgo4FX
  • atlassian-domain-verification=bIs8FQpSN/ztCHVKjYRkfp98VjviW7fBmHr9eJonGQuCrwiLHdEwpQiWm5mDephU
Cloud / SaaS Services Detected
Atlassian Salesforce DocuSign

Leak Screenshot:

Leak Screenshot