Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo www.grohe.com

Group: ransomhub

Discovered by ransomware.live: 2025-01-22

Estimated attack date: 2025-01-22

Country: DE

Description:

[AI generated] Grohe is a leading global brand for complete bathroom solutions and kitchen fittings. The company is headquartered in Germany and provides an extensive line of products that includes faucets, showers, thermostats, and flush systems. With a reputation for quality and innovation, Grohe blends advanced technology with premium design to deliver high-performance, water-saving products. The company emphasizes sustainability and durability in its designs.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 11

Compromised Users: 350

Third Party Employee Credentials: 13


External Attack Surface: 101



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse corehub.net
MX Records
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • alt3.aspmx.l.google.com.
  • alt4.aspmx.l.google.com.
  • aspmx.l.google.com.
TXT Records
  • v=spf1 ip4:212.144.97.207 ip4:212.144.97.208 include:spf.protection.outlook.com include:_spf.google.com -all
  • MS=ms56341533
  • MS=ms99458227
  • apple-domain-verification=QOrSpNcsGp0Hfeun
  • docusign=3b99eba4-6986-4582-9c74-f8603b4bf113
  • facebook-domain-verification=q9wpwbbymrp7sgb06o429zrrcf6poy
  • google-site-verification=KaRmtEQ77wxudSXjmxxs2w3H_7lNaC2uJuMTc-ghZCs
  • WSpu/H6D8U/jrcjDQvH2CGXUUI2VdngUjUesulMyrUa7RuP69BeGzy8jV2ZoyOppLXo8wFPTI/VduXFButscrQ==
  • jhKGBHd1zPAYzh3ehDyk3nTznIW09KDqYaYLyGHS4p0aWmBZurY7zn61AKFyNxvEqnQ5WvSp2ZpxOOWy+0ISyQ==
  • adobe-idp-site-verification=c1f2b664a9ba524f4846bb507cd1b13add3dee04f3861bda1734e0d169c3755c
Cloud / SaaS Services Detected
Adobe Apple Microsoft 365 DocuSign

Leak Screenshot:

Leak Screenshot