Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Akira
Discovered 2024-07-11 16:33 UTC
Est. attack date 2024-07-11
Country FR
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

SIGMA is a California based, leading manufacturer of luxury & bes poke custom faucets, shower systems & accessories. Projects infor mation, some employee data, payments details. Everything will be uploaded soon.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 16

Third Party Employee Credentials: 8


External Attack Surface: 11


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 9ba12c1151c3bdac32b963734a5631e2-766584contact.gandi.net
  • nocgandi.net
  • supportsupport.gandi.net
MX Records
  • sigma-fr.mail.protection.outlook.com. Microsoft 365
TXT Records
  • have-i-been-pwned-verification=c0ca0ad365817bb5c51df648903da668
  • google-gws-recovery-domain-verification=43154476
  • google-site-verification=szIThm4NWPOWFbhZPvHA3LEevZW3VVUVcZSUEzgHkGI
  • ZlGOu7Ttoulqp8Vei7BWQG0Z6sI=
  • google-site-verification=vx6YZeyR13Y2f3vD7mvkygAxtzce6t52n1_l9Whn6b8
  • pardot_153941_*=0f5cf8571164fcd2b8f1c2f3d39dc05f71498b01e527dfb8d96e9987cc997f3a
  • msfpkey=4l8ou5mnu0y62i8w7q0k6w3d9
  • msfpkey=ycyaetiskqpmall07p8itqvq
  • Kj37l6HoowgsGpR0uA8QTlrIiueMVJZo
  • docusign=7710c515-e202-4dfa-8952-f3d466fc80f4
  • msfpkey=387rcsn1u364c65ja38ozoehu
  • apple-domain-verification=6oREfW0BeghvrVGd
  • atlassian-domain-verification=c4CgMu6OdGePlf3z3iRwuWXvEYFOwkUW+xQKDxAyO25QtFwLlJSvbqOLb6/FNhnF
  • v=spf1 include:spf.mailjet.com include:aspmx.pardot.com include:_spf.activetrail.com include:spf.protection.outlook.com include:spf.joinmyit.com include:_spf.salesforce.com -all
Cloud / SaaS Services Detected
Apple Atlassian Salesforce Mailjet DocuSign Have I Been Pwned