Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ORU Mabee Center

Group: rhysida

Discovered by ransomware.live: 2025-01-24

Estimated attack date: 2025-01-24

Country: US

Description:

ORU Mabee Center ORU is a liberal arts university with programs for every interest, from business and biology to engineering, computer science, nursing, criminal justice, theology and ministry, and more! More


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 32

Compromised Users: 135

Third Party Employee Credentials: 77


External Attack Surface: 44



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • us-smtp-inbound-2.mimecast.com.
  • us-smtp-inbound-1.mimecast.com.
TXT Records
  • v=spf1 include:us._netblocks.mimecast.com ip4:205.143.139.214 ip4:205.143.139.217 ip4:63.101.54.51 ip4:66.151.109.0/24 include:spf.protection.outlook.com " "ip4:205.143.139.224 " "include:aspmx.pardot.com include:servers.mcsv.net ip4:165.193.85.0/24 include:spf.dynect.net ip4:198.187.196.100 ip4:198.187.196.130 ip4:172.27.16.23 include:a._spf.brightspace.com ip4:72.50.228.113 ip4:139.60.0.0/24 ip4:139.60.1.0/24 " "ip4:139.60.2.0/24 ip4:139.60.3.0/24 ip4:34.210.12.74 ip4:67.228.34.32/27 ip4:173.236.20.0/24 ip4:192.92.97.0/24 ip4:108.178.6.0/24 ip4:52.128.40.0/21 " "ip4:216.235.195.0/24 " "ip4:208.117.49.214 " " include:_spf.mlsend.com include:amazonses.com -all
  • e2ma-verification=u91eb
  • tumu58pq88h0drgbvsdllm55u4
  • google-site-verification=9PKMpLJXFINcQAvUoQMMCJbS0B_9SgiTQeo4HJ8M5RU
  • google-site-verification=OAiRU0KK-oHLMEC0rbH8lO0GV7NiQQBbqu7pCklrL24
  • GPXFpQFbhHu/G10zjtDrU7MbDGYhVlNqtEy3J861bSV0bVJ9jg8s2nZtMvnDs5r/J2BM0pdVFsneMjmogw8Yng==
  • pardot_187052_*=5df7e9945a460794b8247ac177cdf9845b6841ca9d59dc2872a3e76e8b74ee64
  • apple-domain-verification=zBx6bAH5gZ3iGbSF
  • view-oru
  • o3krl7qc60dek80sj4hrgleq1e
  • have-i-been-pwned-verification=b3b646669eb20f31fd31d16fa75de47e
  • U0W76TZECDPO4PHD0DEORC8DJI1S9GMIVYCINOAH
  • google-site-verification=zg-MRkY-nfdmbk5n0ismwLyoaWC2O70nVMjxblnnIaA
  • pardot_187052_*=0a6819beb17b1ddb8fb009cfe8b658e404c84474ca102d28a2b91ff00caf8780
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail Mimecast Have I Been Pwned

Leak Screenshot:

Leak Screenshot