Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

recope.go.cr

recope.go.cr

Group: Ransomhub

Discovered by ransomware.live: 2024-12-12

Estimated attack date: 2024-12-09

Country: CR

Description:

[AI generated] RECOPE, or the Costa Rican Petroleum Refinery, is a state-owned enterprise responsible for importing, refining, and distributing petroleum products in Costa Rica. As the primary entity managing the country's fuel supply, RECOPE plays a crucial role in ensuring energy security and supporting economic activities. The company focuses on sustainability and efficiency, aligning with national energy policies and environmental goals.

Infostealer activity detected by HudsonRock

Compromised Employees: 8

Compromised Users: 29

Third Party Employee Credentials: 25


External Attack Surface: 8



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mxb-00a04401.gslb.pphosted.com.
  • mxa-00a04401.gslb.pphosted.com.
TXT Records
  • v=spf1 ip4:201.193.217.180 ip4:201.193.217.182 ip4:201.207.40.229 ip4:201.192.237.44 ip4:201.193.197.75 ip4:201.193.217.177 ip4:35.166.157.42 ip4:201.192.237.53 include:_spf.google.com include:spf-00a04401.pphosted.com ~all
  • MS=2BA0703F3381E2C5BE32EBC320CCFD05D7A01930
  • jmilvd8ct293oo64m273jt86km
  • kvs3ocbvgou51pa1hrifl0s1lb
Cloud / SaaS Services Detected
Proofpoint

Leak Screenshot:

Leak Screenshot