Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo chempartner.com

Group: lockbit3

Discovered by ransomware.live: 2023-02-13

Estimated attack date: 2023-02-13

Description:

281 GBContents of downloaded information: company analytics, project information, reports, information on drug supplies, etc.AboutUs: Over the past twenty years, ChemPartner has evolved from the pure chemistry service provider to a research inn...



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • DomainAbuse service.aliyun.com
MX Records
  • chempartner-com.corpsmtp.net.
  • cnc.biz-email.net.
  • chempartner-com.corpsmtp.cn.
  • mail.biz-email.net.
TXT Records
  • globalsign-domain-verification=DOYnvsO5jdxRXEEML6h5pP2Uv9zovgo-Q-g-H58tAG
  • v=spf1 mx ip4:116.246.25.160/28 ip4:222.71.122.218 include:_s.corp-email.com include:spf.protection.partner.outlook.cn include:_spf.salesforce.com -all
  • sending_domain981092=8c7805819a8d9ae2d4778a6ed8008ef6734fee3eaa0c03c8834c81f352685801
  • MS=46377B85D82461C38F0526BC71EA7480557B8F6C
  • google-site-verification=aVANZ5DqEthQ8TBOwP5vE5YWx8Szna7qtqtGEVzBdBU
Cloud / SaaS Services Detected
Salesforce