Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Macomb Group

Group: Blackbasta

Discovered by ransomware.live: 2023-03-08

Estimated attack date: 2023-03-08

Description:

Welcome to The Macomb Group! We’re proud to be a leading wholesale distributor of pipe, valves and fittings for the Midwest region and beyond.Founded in 1977 and acquired by the current owners in 1991, The Macomb Group has differentiated itself from competitors by continually expanding our operations to provide unbeatable specialty services, a huge inventory, energy-efficient solutions, and exceptional customer service.We pride ourselves on being a family and friend oriented business which started long before 1991. Our CEO Bill McGivern and Executive Vice President Keith Schatko first met while playing little league together. Years later, as fate would have it, both Schatko and McGivern were working at what was then known as Macomb Pipe & Supply to help pay for college tuition. Although they knew they wanted to become business owners, they also knew how important warehouse operations were to the success of a company so they learned all they could. They started by sweeping floors, packing orders, familiarizing themselves with the products and working the sales counter. When the time came, McGivern and Schatko, together with then-partner Doug Howe purchased the company.SITE: https://www.macombgroup.com Address 6600 East 15 Mile RoadSterling Heights, MI 48312Phone: (586) 274-4100Fax: (586) 274-4125



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • d171316b.ess.barracudanetworks.com.
  • d171316a.ess.barracudanetworks.com.
TXT Records
  • hvrv0intbl5lnvkeahjl30on50
  • s7ckkkibrtfufsd7u8uiphc384
  • 26pn349gpjkf8jbc4gaa5tlmar
  • v=spf1 include:spf.protection.outlook.com include:spf.ess.barracudanetworks.com a:mail.macombgroup.com include:50587571.spf08.hubspotemail.net include:mail.zendesk.com include:spf.postalsrv.aldrichsolutions.net ip4:149.72.39.215 ip4:149.72.182.166 -all
  • pa1e548erllsohlrrfcfvlcgvf
  • op7d1mmu31ogi2vjguctuv4jrh
  • 8dfafcsas3hpepb9to9glo4n89
  • duo_sso_verification=R1l6yNjXC2VPYxsKlHS1CLCa5yI9HZmmhnZ5SaaTqLBo7xKmvjTzCN1MxW4XZJay
  • google-site-verification=PDJbpzE6IhXHI8BFzWWQJ2Z9lePKeetDEpoG5TEVpkU
Cloud / SaaS Services Detected
HubSpot Zendesk Cisco Duo

Leak Screenshot:

Leak Screenshot