Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo OnePoint Patient Care

Group: incransom

Discovered by ransomware.live: 2024-09-15

Estimated attack date: 2024-09-12

Country: US

Description:

One Point Patient Care (OPPC) founded in 1965 and headquartered in Tempe, Arizona, is a national, hospice-focused pharmacy providing delivery, mail-order and Pharmacy Benefit Management (PBM) all under one service umbrella.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 2

Third Party Employee Credentials: 2


External Attack Surface: 0



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • smtp1-mke.securence.com.
  • smtp1-msp.securence.com.
TXT Records
  • v=spf1 ip4:10.10.0.26 ip4:72.44.199.214 ip4:167.89.0.0/17 ip4:208.117.48.0/20 ip4:50.31.32.0/19 ip4:198.37.144.0/20 ip4:198.21.0.0/21 ip4:192.254.112.0/20 ip4:168.245.0.0/17 ip4:149.72.0.0/16 ip4:159.183.0.0/16 ip4:223.165.113.0/24 ip4:223.165.115.0/24 ip" "4:223.165.118.0/23 ip4:223.165.120.0/23 ip4:3.222.0.24/29 ip4:198.21.4.52 ip4:167.89.31.27 ip4:167.89.127.244 ip4:44.192.35.0/24 ip4:3.120.181.200/29 ip4:35.159.219.224/28 ip4:18.199.180.160/27 ip4:3.7.25.40/29 ip4:13.127.153.86 ip4:52.66.154.99 ip4:13.12" "7.210.61 ip4:3.25.47.0/29 ip4:3.93.157.0/24 ip4:3.210.190.0/24 ip4:18.208.124.128/25 ip4:54.174.52.0/24 ip4:54.174.57.0/24 ip4:54.174.59.0/24 ip4:54.174.60.0/23 ip4:54.174.63.0/24 ip4:108.179.144.0/20 ip4:139.180.17.0/24 ip4:141.193.184.32/27 ip4:141.193." "184.64/26 ip4:141.193.184.128/25 ip4:141.193.185.32/27 ip4:141.193.185.64/26 ip4:141.193.185.128/25 ip4:143.244.80.0/20 ip4:158.247.16.0/20 ip4:216.139.64.0/19 ~all
  • google-site-verification=8kGVUBsjmMEgTwllkvZH0zAgyFxQCYiXPRkSFTjS_a4
  • MS=ms25688408
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot