Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Metro Transit

Group: Play

Discovered by ransomware.live: 2023-10-11

Estimated attack date: 2023-10-09

Country: US

Description:

Missouri, United States



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • registrar-abuse cloudflare.com
MX Records
  • usb-smtp-inbound-1.mimecast.com.
  • usb-smtp-inbound-2.mimecast.com.
TXT Records
  • duo_sso_verification=BYrdybGsz6ASg1zhAd0b6U9aTb9rwySjZLYX0ozZ6WTabf9Q13s6pm9QUfeIdSUM
  • kmhbKpn65MMIH49Eh9LejZJLuhr6s2+mKMNGszNk7Ld4ncFc0cHTI5/ghXdxugdQQ/Emc5r45kNKW5pR1Cz/DQ==
  • slack-domain-verification=eTYSmmmdsK1GsNyjNpu3r4km48Vi04MZSYMuJH6Y
  • tracking CNAME api.elasticemail.com
  • v=spf1 ip4:38.56.101.59 ip4:38.65.101.6 ip4:139.60.0.0/22 ip4:44.229.121.55 ip4:148.59.100.16/28 ip4:44.229.121.55 include:spf.protection.outlook.com include:usb._netblocks.mimecast.com include:_spf.elasticemail.com include:_spf.psm.knowbe4.com include:_s" "pf.e2ma.net include:e2ma.net include:sp" "f.mandrillapp.com ~all
  • MS=ms17612083
  • MS=ms62989842
  • MS=ms76993592
  • api._domainkey TXT k=rsa;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCbmGbQMzYeMvxwtNQoXN0waGYaciuKx8mtMh5czguT4EZlJXuCt6V+l56mmt3t68FEX5JJ0q4ijG71BGoFRkl87uJi7LrQt1ZZmZCvrEII0YO4mp8sDLXC8g1aUAoi8TJgxq2MJqCaMyj5kAm3Fdy2tzftPCV/lbdiJqmBnWKjtwIDAQAB
  • docusign=d22e7be5-6082-47b2-9ebb-8fb6cde118ab
Cloud / SaaS Services Detected
Microsoft 365 Slack KnowBe4 Cisco Duo Mimecast DocuSign

Leak Screenshot:

Leak Screenshot