Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

GARRETTMOTION.COM

GARRETTMOTION.COM

Group Clop
Discovered 2023-07-26 20:42 UTC
Est. attack date 2023-07-26
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

Garrett Motion / Turbo Technology / Electric & Hybrid / Connected Vehicle

Infostealer activity detected by HudsonRock

Compromised Employees: 7

Compromised Users: 697

Third Party Employee Credentials: 11


External Attack Surface: 70


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • whoisrequestmarkmonitor.com
  • abusecomplaintsmarkmonitor.com
MX Records
  • garrettmotion-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • mongodb-site-verification=32xADDLnHhbSKPMuNU069J4PIb3tbPrt
  • google-site-verification=5kP3cy6Vtp-FZF1pJBolyTxuZGh2YoarsKKROasJ76c
  • docker-verification=b7158ff5-4435-47cb-a8f3-3d409ec7adf2
  • paloaltonetworks-site-verification=8a342d50488cd1716ee1adf83cff76f478694ebd5620e431a2868a64f202695a
  • cursor-domain-verification-ewsc1h=uZBwocSyLjTv8T12ADsJgT2G9
  • paloaltonetworks-site-verification=04ba0cb3fc1d55ff4e019e5efc77c5e507178a25b064a0d6e60e27c979ed3f66
  • v=spf1 include:spf.protection.outlook.com include:spf_c.oraclecloud.com include:_spf1.garrettmotion.com include:_spf2.garrettmotion.com include:_spf3.garrettmotion.com include:_spf.salesforce.com include:amazonses.com -all
  • google-site-verification=GTN6NUseK8aH3yyP0uUCgFPjqJmnthnBV0zVOvFnQNI
  • atlassian-domain-verification=fzzO6Zwmp8DvfMjeh3hPkBwdsWfcmpagbY/6CQmN7IIPhMUyci8kfvrGMOOc45C5
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Docker Salesforce Oracle Cloud

Leak Screenshot:

Leak Screenshot