Discovered
2025-02-27
Est. attack date
2025-02-27
Country
Description:
[AI generated] TIMKEN.COM belongs to The Timken Company, a global manufacturer of bearings and related components and assemblies. Based in the USA, it offers engineered bearings and power transmission products used in various industries, including automotive, aerospace, and energy. Besides, it provides services like lubrication management and powertrain rebuild. With over a century of experience, Timken's innovative solutions are designed to improve efficiency and reliability.
Infostealer activity detected by HudsonRock
Compromised Employees: 9
Compromised Users: 159
Third Party Employee Credentials: 8
External Attack Surface:
90
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- mxb-0058d601.gslb.pphosted.com.
- mxa-0058d601.gslb.pphosted.com.
- globalsign-domain-verification=65DB3831C5B7838D880D271C273A2523
- traction-guest=afbee9d5-af3d-4351-a9ed-883b1ffaba6a
- H8azwsnjILbbKkqXAV/RSNkL4uPYwE6GAPP/+lxAF2mkX/cO8QDCgJQSeDGnt7b5K8um+nJ2xSdg3OsTnuxHrA==
- globalsign-domain-verification=11963f891d99a5b0df57ae1fc8264b58
- ms-domain-verification=21ecbaad-f15e-43b9-975e-a031d5043ee8
- webexdomainverification.4C675B8AFB06B136E053AB06FC0A3F65=0de9914f-6b9f-4ef1-8a7a-8d825099a442
- globalsign-domain-verification=4541d5c62333364a85542184093d1d6d
- globalsign-domain-verification=681F34A6DE7837ACC112C268663A090B
- 314A-21F9-1FD4-7F30-4004-AF88-38DE-1BC1
- globalsign-domain-verification=10EAB77377470E2E7E810FDE8EA2C7A1
- globalsign-domain-verification=11963F891D99A5B0DF57AE1FC8264B58
- W1SPuzgLbXkLF7QiMy371u443USsaF5BKCtrxQFRqVaXoj+0hC+WOWuA5aZ6elXt6o4+99BhzsQzHesWKgBVlg==
- apple-domain-verification=9E9sCGzHF0ptw0zX
- google-site-verification=yhX_bLUreG4I9oPFcQ9FXCOaXng6S0tGm7nTw8K7jAA
- smartsheet-site-validation=LqvS91_Wq_vIZ4RAMCy2WjJKE6jW2tHn
- e2ma-verification=1it
- MS=ms48258293
- v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
- atlassian-domain-verification=59ahFzKk8Dp/5NudffwOabVN0RLYn1ZYUrGdPOvraJyBhXv/SpuVm2ai2uSlScTr
- cisco-ci-domain-verification=5bdb9c2eeec34d71522a1131909bae2cd7e9c3390021d06150454d5682a7f7ba
- zYAOmZ3n4dLLNkGlD9cHHip9Oit8hkdD46+PVj1ap/CS0Q/u3svQuJG4KnniqaR4cDIA49Vy03g9CRDQCsgNXA==
- amazonses:DQ7rmlS9nKRdSlwQvZoc+CBycBp0D77YfQTbJb6aRIs=
- globalsign-domain-verification=AD0CC15FEEC993038513E9F39D8FCEE8
Cloud / SaaS Services Detected
Apple
Atlassian
Amazon SES/WorkMail
Microsoft 365
Cisco
Proofpoint
Cisco Webex
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.