Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo O'Shea Builders

Group: medusa

Discovered by ransomware.live: 2025-03-29

Estimated attack date: 2025-03-28

Country: US

Ransom: $ 350,000

Description:

O'Shea Builders (founded in 1902) is a commercial construction-services provider in Illinois with offices in Springfield and Peoria. O'Shea Builders provide general contracting, construction management, design build, civil and building maintenance services. O'Shea Builders corporate office is located in 3401 Constitution Dr, Springfield, Illinois, 62711, United States and has 137 employees. The total amount of data leakage is 120.50 GB



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • osheabuilders-com.mx1-na.mailanyone.net.
  • osheabuilders-com.mx2-na.mailanyone.net.
  • osheabuilders-com.mx3-na.mailanyone.net.
TXT Records
  • v=spf1 ip4:104.152.198.126 ip4:52.1.234.206 ip4:52.70.152.226 ip4:54.165.79.164 ip4:103.47.205.238 include:spf.mailanyone.net include:spf.protection.outlook.com include:sendgrid.net include:clientfeedbacktool.com -all
  • v=verifydomain MS=9003078
  • miro-verification=28f46ec849be5bb6fe61e1d49d6fe5d7ddab42f0
Cloud / SaaS Services Detected
Microsoft 365 Miro SendGrid

Leak Screenshot:

Leak Screenshot