Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo SOCOMEC

Group: Stormous

Discovered by ransomware.live: 2023-03-26

Estimated attack date: 2023-03-26

Description:

Socomec is a global energy company that specializes in providing integrated and advanced electrical solutions to medium enterprises. Its products and services include systems design of electric power conversion systems, renewable energy, automatic steering and control systems, protection systems, rides, batteries. The company is characterized by high technology and high quality in its products, and also provides distinguished services in technical maintenance.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • info@domain-contact.org
  • legal@safebrands.com
  • clientele@safebrands.com
MX Records
  • socomec-com.mail.protection.outlook.com.
TXT Records
  • citrix.mobile.ads.otp=i992rn7zexmjyk5vughs0go
  • v=spf1 ip4:149.72.203.251 ip4:85.31.192.42 ip4:85.31.193.42 ip4:85.31.193.7 ip4:174.129.245.244 ip4:198.245.81.0/24 ip4:136.147.176.0/24 ip4:13.111.0.0/22 ip4:13.111.52.0/22 ip4:13.111.63.0/24 ip4:13.111.68.0/24 ip4:13.111.72.0/22 ip4:13.111.92.0/24 ip4:1" "3.111.111.0/24 ip4:136.147.182.0/24 ip4:136.147.135.0/24 ip4:199.122.123.0/24 ip4:163.172.146.249 include:et._spf.pardot.com include:spf.socomec.com include:_spf.salesforce.com include:spf.protection.outlook.com -all
  • pardot_86922_*=dc79ba333bd188aec01a5ff0c232d686da08bf48ebead61fc4630dfb8e1ad0b8
  • kYwjlp4tGFk/1Sxk7VjBixXK4lNGiTo+e1ptIKBu2KPoFHXjG8Oq4xpH1ot5X1lyKWRavfRg9+x6yuHfnONrdg==
  • docusign=554fa26b-e497-4599-a6ae-eb8f88a3fac3
  • dMA0J0J+TfP9JLmOz3I+7EgRPdcK8/mgT4N1ljwkgQY=
  • pardot_86922_*=f2dce50df526319614eb52cf42ce430f876e38611fbee52efb0c26f78ba41e39
  • _globalsign-domain-verification=nmPVZ9J9Z8xkqD2bMJvxD9aoNqcZHlharvEQoSOjiq
  • _globalsign-domain-verification=IPemmyHkjznUDauQX1y99jG57zgOMux924rUCgo4FX
  • sending_domain86922=a57158b7b2d24592f1a17470ada19360fe8e79224f2559baaa8ab4d1f16eb96d
  • atlassian-domain-verification=bIs8FQpSN/ztCHVKjYRkfp98VjviW7fBmHr9eJonGQuCrwiLHdEwpQiWm5mDephU
  • reachdesk-verification=1qUlF7aL8X7b8V01I9MjknlvkO3sv6eFupYVusdLtgYjR0y1PZFOawvHvrK5FBwB
  • MS=71A12A770EDFC14270EDAB9CFD70E35389F9E64F
  • canva-site-verification=526tC5V4BLqlbaRkUcG8SA
Cloud / SaaS Services Detected
Atlassian Salesforce DocuSign

Leak Screenshot:

Leak Screenshot