Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo gocontec.com

Group: Lockbit3

Discovered by ransomware.live: 2023-05-10

Estimated attack date: 2023-05-10

Description:

first part of data.Contec Holdings provides repair services to satellite, cable & IP based system operators, B2B, B2C, and E-commerce order fulfillment and logistics services, and in or out of warranty repair services for OEMs.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 13

Third Party Employee Credentials: 13


External Attack Surface: 0



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • mx2-us.emailsecurity.app.
  • mx1-us.emailsecurity.app.
TXT Records
  • jg5ldwtlg6ysh5z2k7cyzy11461hmjzk
  • _globalsign-domain-verification=QYuaUjXqIg2BfFBILWkiIqK0tWjAf3loVhPTbpqtjl
  • SJg8ZUcUjc4I/FWUqLStvgtpZ+zHVPsknTOSffIh/Yn0QtLF39vleCU7m7MIyVrl9CaTuy47FuSzSxn8VU8xqw==
  • 6O+5UH6zUmm3hQHST2Qri3vKsPwTfhaocFUtaqaN3s4=
  • MS=ms37561929
  • v=spf1 include:spf.protection.outlook.com include:emailsrvr.com include:servers.mcsv.net include:_spf.odoo.com include:spf1.emailsecurity.app -all
Cloud / SaaS Services Detected
Mailchimp Microsoft 365

Leak Screenshot:

Leak Screenshot