Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Ricopia

Group: Thegentlemen

Discovered by ransomware.live: 2026-03-01

Estimated attack date: 2026-03-01

Country: ES

Description:

ricopia.com zoominfo.com/c/ricopia/405953806 Ricopia helps businesses upgrade their technology and work smarter. With over 100 tech experts, they've been helping companies of all sizes get better at digital tools for more than 30 years. They do this by checking how a company works, finding ways to improve technology, and helping teams learn new skills. Big names like ING Direct and BNP Paribas trust Ricopia to make their businesses run more smoothly and efficiently



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@nicline.com
MX Records
  • ricopia-com.mail.protection.outlook.com.
TXT Records
  • scq5ztgsy555f14khtd722ym6d2fp2kn
  • zoho-verification=zb20830165.zmverify.zoho.eu
  • MS=ms35380814
  • brevo-code:8a36bfc1f4896a884a16fabd8cce7465
  • v=spf1 ip4:152.228.227.112 ip4:178.33.161.128 ip4:185.103.36.106 +a +mx +include:spf.protection.outlook.com include:eu.transmail.net include:spf.mandrillapp.com include:eu.zcsend.net ~all
Cloud / SaaS Services Detected
Microsoft 365 Zoho Campaigns Mandrill

Leak Screenshot:

Leak Screenshot