Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2023-03-26 15:04 UTC
Est. attack date 2023-03-26
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Socomec is a global energy company that specializes in providing integrated and advanced electrical solutions to medium enterprises. Its products and services include systems design of electric power conversion systems, renewable energy, automatic steering and control systems, protection systems, rides, batteries. The company is characterized by high technology and high quality in its products, and also provides distinguished services in technical maintenance.

Infostealer activity detected by HudsonRock

Compromised Employees: 29

Compromised Users: 35

Third Party Employee Credentials: 31


External Attack Surface: 24


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • infodomain-contact.org
  • clientelesafebrands.com
  • legalsafebrands.com
MX Records
  • socomec-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • cOkn55jVg+4zZnZgSiHblWG9AkFE2b/VwMiuZZx5DkIPVoJ9gho/s4jFAQeay92sf97ihUKgSD+/40zq3oCXpw==
  • citrix.mobile.ads.otp=i992rn7zexmjyk5vughs0go
  • atlassian-domain-verification=bIs8FQpSN/ztCHVKjYRkfp98VjviW7fBmHr9eJonGQuCrwiLHdEwpQiWm5mDephU
  • _globalsign-domain-verification=GKfOtAUx0WY1L_k-zVDCaVB-UarksiGc4MDrPW2ny3
  • kYwjlp4tGFk/1Sxk7VjBixXK4lNGiTo+e1ptIKBu2KPoFHXjG8Oq4xpH1ot5X1lyKWRavfRg9+x6yuHfnONrdg==
  • IvZzZH2dQo+8ThsNREFmYjH/MkSQ6YBfgvCaRUX50zr66i49lEeUQ4gU5bPLccYofLGYMmNJadozg/ESEVYnFw==
  • canva-site-verification=526tC5V4BLqlbaRkUcG8SA
  • dMA0J0J+TfP9JLmOz3I+7EgRPdcK8/mgT4N1ljwkgQY=
  • docusign=554fa26b-e497-4599-a6ae-eb8f88a3fac3
  • pardot_86922_*=f2dce50df526319614eb52cf42ce430f876e38611fbee52efb0c26f78ba41e39
  • pardot_86922_*=dc79ba333bd188aec01a5ff0c232d686da08bf48ebead61fc4630dfb8e1ad0b8
  • v=spf1 ip4:149.72.203.251 ip4:85.31.192.42 ip4:85.31.193.42 ip4:85.31.193.7 ip4:174.129.245.244 ip4:136.147.176.0/24 ip4:13.111.0.0/22 ip4:13.111.52.0/22 ip4:13.111.63.0/24 ip4:13.111.68.0/24 ip4:13.111.72.0/22 ip4:13.111.92.0/24 ip4:13.111.111.0/24 ip4:1" "36.147.135.0/24 ip4:199.122.123.0/24 ip4:163.172.146.249 ip4:198.245.81.0/24 ip4:13.111.0.0/16 ip4:136.147.182.0/24 include:spf.socomec.com include:amazonses.com include:_spf.salesforce.com include:spf.protection.outlook.com -all
  • reachdesk-verification=1qUlF7aL8X7b8V01I9MjknlvkO3sv6eFupYVusdLtgYjR0y1PZFOawvHvrK5FBwB
  • _globalsign-domain-verification=6T7pXUHUfELFFZNA9THml3FB-CETvOIxsdCJZtOlDs
  • MS=71A12A770EDFC14270EDAB9CFD70E35389F9E64F
  • sending_domain86922=a57158b7b2d24592f1a17470ada19360fe8e79224f2559baaa8ab4d1f16eb96d
Cloud / SaaS Services Detected
Amazon SES/WorkMail Atlassian DocuSign Global Sign Salesforce

Leak Screenshot:

Leak Screenshot