Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Pacific Rim Mechanical

prmech.com

Discovered 2025-12-18
Est. attack date 2025-12-18
Country US
City San Diego

Description:

Pacific Rim Mechanical (PRM) is a Southern California-based mechanical contractor (HVAC, Plumbing, Energy Solutions) serving commercial, industrial, healthcare, and biotech sectors since 1987, known for high-quality construction, maintenance, and repair services, focusing on integrity, safety, and long-term client partnerships through expertise and innovation like BIM modeling. Clients: Sony, SpaceX, THERMA LCC, ASML LCC... Laek: 100GB WE HAS COLLECTED SUCH DATA AS: - Confidential documents - Clients Data - NDA - Financial data - Operations - Corporate data - Business Agreements - Development - Drawings And a lot of other VERY IMPORTANT information!

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • us-smtp-inbound-1.mimecast.com.
  • us-smtp-inbound-2.mimecast.com.
TXT Records
  • _wggea0clxvzo36ge39a82dfbk2dynph
  • 1m6kq3qgdndkgnsdcj7wrrtj8ds9q0t9
  • MS=ms21764765
  • 7ryvc797ngnscc2x17m75q2j4h4ky3p5
  • google-site-verification=Z98jLAoezBRYm7u_IBkvJnNPMdZItRbJsvrhSazBZa8
  • teamviewer-sso-verification=0e90182ab237475baf435d757ef5aea6
  • apple-domain-verification=mTmAPTuSSBy4dVzO
  • v=spf1 mx a include:spf.protection.outlook.com include:us._netblocks.mimecast.com ip4:104.40.90.51 ip4:172.233.152.148 ip4:12.79.39.170 ~all
  • _sgco9rrpedpjcfa6ebhpvxkvkvoo5kq
  • google-site-verification=a4h_LsCgIT8SKz7RMG_DMcDnWyZrMc3QLWr7B-ZvdXA
  • msfpkey=6pa1k68tm00tkhrh59yv9eteb
  • autodesk-domain-verification=WzRoQEA23BKpGV1kkY0Z
  • 8IAZ4mNH89hDszkltMz9X32AVyDTW1/pC9nzxayMR1y92QzDP5xPbOov3ZyM34Y67PyeSuiIyBPb2jLahKs/xw==
  • 5jdm535jx75ls826nzsfpkwyr9n7cvll
Cloud / SaaS Services Detected
Apple Microsoft 365 Teamviewer Autodesk Mimecast

Leak Screenshot:

Leak Screenshot