Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

DRIVEANDSHINE.COM

driveandshine.com

Group Clop
Discovered 2022-12-22 20:02 UTC
Est. attack date 2022-12-22
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

Home - Drive & Shine

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • us2-smtp-mx1.titanhq.com.
  • us2-smtp-mx2.titanhq.com.
TXT Records
  • apple-domain-verification=OC77LOFg6JtBq1UH
  • google-site-verification=1Re3DUKlSfoYKgLLqEXjnKbFrEqkFbtfrk_OSGtSxtk
  • google-site-verification=AemtGCcKB8UBOzFaTUmlhAWWyJn7fEDGpLKlmIj3zlI
  • google-site-verification=oVOFcGldC-W73USr6bHr-VPi75vjJssKC-6sqj_Qtzg
  • google-site-verification=q2JaKOsAuBGpGW2nVEOn9HHNbXE94RNJ5XwjxflOOOw
  • v=spf1 ip4:15.235.9.145 ip4:104.218.146.10 ip4:173.167.158.200/29 ip4:64.40.106.50 ip4:35.208.50.175 ip4:198.2.128.0/24 ip4:198.2.132.0/22 ip4:198.2.136.0/23 ip4:198.2.145.0/24 ip4:198.2.186.0/23 ip4:205.201.131.128/25 ip4:205.201.134.128/25 ip4:205.201.1" "36.0/23 ip4:205.201.139.0/24 ip4:198.2.177.0/24 ip4:198.2.178.0/23 ip4:198.2.180.0/24 include:sendgrid.net include:spf.protection.outlook.com include:spf.myconnectwise.net include:_spf.wddonline.com -all
  • MS=ms31958930
Cloud / SaaS Services Detected
Apple Microsoft 365 SendGrid

Leak Screenshot:

Leak Screenshot