Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Pittsburgh’s Trusted Orthopaedic Surgeons

Group: donutleaks

Discovered by ransomware.live: 2024-05-17

Estimated attack date: 2024-05-14

Country: US

Description:

Hello everyone! We got some not very smart people who was compromise and do not want to protect their clients data. Today here medical company from Pittsburgh(USA):"Pittsburgh’s Trusted Orthopaedic Surgeons" [must be not so trusted as you thought, but okay] Web site: https://www.gpoa.com/ "Pittsburgh’…



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse enom.com
MX Records
  • mail2.gpoa.com.
TXT Records
  • MS=ms96695511
  • facebook-domain-verification=25hb5wuabmzjvha9audahmbb52pxrg
  • q8sccy7wbbxw6h08kxtwvt2kxq30l4nj
  • v=spf1 a:gpoa.com ip4:71.245.184.24 include:spf.mandrillapp.com ?all
  • facebook-domain-verification=vbs54o0d3po1qy6ilh7dx8y9b3bws2
Cloud / SaaS Services Detected
Microsoft 365 Mandrill

Leak Screenshot:

Leak Screenshot