Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

MICHELIN.COM

MICHELIN.COM

Group Clop
Discovered 2025-11-21 13:05 UTC
Est. attack date 2025-11-21
Country FR

Description:

[AI generated] Michelin.com is the online platform for the Michelin Group, a leading tire company founded in 1889, based in Clermont-Ferrand, France. The company is renowned for his contribution to the tire industry, including the invention of the radial tire. Apart from manufacturing tires for various kinds of vehicles, Michelin also provides travel assistance, publishing maps and guides, and operates in more than 170 countries worldwide.

Infostealer activity detected by HudsonRock

Compromised Employees: 64

Compromised Users: 3387

Third Party Employee Credentials: 305


External Attack Surface: 114


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • de-smtp-inbound-2.mimecast.com. Mimecast
  • de-smtp-inbound-1.mimecast.com. Mimecast
TXT Records
  • adobe-sign-verification=7d0f4ee51e8cc8218a0d47de7ad6ecf5
  • MS=ms68566304
  • brevo-code:61942c2ee054ab5265a78d06ec4136eb
  • _alw31bezmifq57qa6derdc8c8fwhokv
  • google-site-verification=2pArBQooz7jOEYIlJJd8aIk3bQkzzEDtYm3rFbfqqYc
  • _p403623ut54n8hb614inwyyz9urk9k8
  • cisco-ci-domain-verification=305faf4ed2622c895a0ab9a323c1daa095429bb63746109813da28ff0e0bca4c
  • brevo-code:8e6392d950a67d8430ca290610ca6cfe
  • brevo-code:0c90471082a3b2462dc9671368d4f56f
  • apple-domain-verification=XiN3L0je5aGwO4YF
  • google-site-verification=Ob6eYGno8ceAOTHHlVlm1R2qNCMNpSGJCrY-v-gwlgA
  • google-site-verification=wKJo0iMF_DdMecpelgRpMgaHIjETpIOS74mawV566Lk
  • _m7vrrtg99q1x0ehucalf0hkh7r3d0kl
  • _srldc54e6tnsgl24vaxgdtpyw3uwf1f
  • brevo-code:0b871975985644473df73dce17148313
  • v=spf1 include:spf.mailjet.com include:spf.sendinblue.com include:sendgrid.net include:cust-spf.exacttarget.com include:de._netblocks.mimecast.com include:44151349.spf03.hubspotemail.net include:spf-008a4301.pphosted.com include:spf-008a4302.pphosted.com" " ip4:64.95.144.196 ip4:52.169.188.148 ip4:201.94.128.0/20 ip4:141.194.36.41 ip4:141.194.36.42 ip4:52.22.10.189 ip4:52.70.196.131 ip4:52.71.64.190 ip4:52.71.20.6 ip4:72.4.119.8 ip4:52.205.191.224/27 ip4:104.208.163.42 ip4:213.32.108.33 ip4:141.194.36.43" " ip4:182.18.163.19 ip4:37.157.8.26 ip4:37.157.8.27 ip4:43.228.187.74 ip4:198.181.201.15 ~all
  • mongodb-site-verification=yVC7moEiA8vYgm0kKNzFWh54vnZFhgCi
  • adobe-sign-verification=5b2b13ebabc32a55b4c4af32c203f9d
  • brevo-code:12986ff77994e3b05ad793f9315ca49e
  • cisco-ci-domain-verification=5155b7cf4e81dab53704cb8e8bbfec96101a4768a4840fb95ecf3ca57e081f49
  • brevo-code:9f8cbcbe07537030c9311060a71a96a0
  • brevo-code:fe7c2939c9e4dde57d3f5f8afed07fbf
  • Sendinblue-code:320d7a0a1776887db9640f8121c59c7a
  • brevo-code:42560fbcd317952d1a90f3dbb95f8642
  • brevo-code:09b3609550913589ba7302525deafc5f
  • mandrill_verify.jpqgR8_udPPbGdibnAGcSA
  • google-site-verification=bR44xxoM8l6qWeP8J5KY8-yjGRyw0ngayiQ_qN8kotI
  • brevo-code:394c0938defd07c7d32264104daa2049
  • brevo-code:259bc6f2bd045d00362685c01614cab9
  • _x7ifm9dj3wk3d2tf3hht44e2ckwiyt2
  • brevo-code:91c1c04f1ce59b3265ec91944a8343de
  • brevo-code:f15df8a444d091fbc01d5bed7a695503
  • google-gws-recovery-domain-verification=44223348
  • brevo-code:7ca8cc06dfe6fda15f4ffeb9a0fdb3e2
  • brevo-code:ba0a6f95595289aa887adc5b2ef2bcce
  • llama-index-domain-verification-gs2z5n=1gOZhM75DbfBRNoo7v5N7A902
  • google-site-verification=-KD-hQ117iq2xq0T59Dhtv9nP4D2JHU1JY-WIUQBbdU
  • knowbe4-site-verification=faf78adc4602f85a20ff6b5fa91f3683
  • google-gws-recovery-domain-verification=42357351
  • brevo-code:4225d9ab9830b3df7f4a6aaf6d554d06
  • brevo-code:25cd1c6b43792ff04d2f58440a857320
  • adobe-idp-site-verification=5325327a-4b7a-46bb-bc1d-f929aa0046e1
  • adobe-sign-verification=d1856e9dfc1d0dfacf3c6b0bcd1b564a
  • _3daqqjnw82p95xy3hcig0406l4xhrh2
  • _szvmn2edpb704fn9ki7q097t0yurkqu
  • atlassian-domain-verification=fTuV4RMI2ROPmmpfXvaNTJP2wVZ8wHbIatbyBId5eeZumWuBr1nKxl0iJfK71LJa
  • miro-verification=489e201f4ac755cb66fe5fae3d4a531f5b473fa3
  • facebook-domain-verification=wps16fhtfncnugax62f974k93b33m4
  • UPMMtSA6InOCHobmgB8z+xlQyU8=
  • vmware-cloud-verification-fae8eec6-4301-493f-b903-5035577b7d6a
  • brevo-code:93f289e363f8f5ee27b599ce69412ed1
  • brevo-code:e2277458c8e0c736cd799f02d1e64a75
  • google-site-verification=K-TB4ZRS1_Xn0KdnIVdIhLca4xZBOCulQaqr8henj6I
  • brevo-code:c914b59e7f282b7bd6be6707d3d410c1
  • brevo-code:67f6623ea0044093109c2520fd2c79e6
  • brevo-code:96a41c6d73a3b493e3790f789402b22a
Cloud / SaaS Services Detected
Adobe Apple Atlassian HubSpot Mailchimp Microsoft 365 Miro KnowBe4 Cisco Mailjet SendGrid Sendinblue Mimecast Proofpoint

Leak Screenshot:

Leak Screenshot