Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo ehdd.com

Group: Incransom

Discovered by ransomware.live: 2025-02-20

Estimated attack date: 2025-02-20

Country: US

Description:

Founded in 1946, EHDD seeks to create built environments that enhance our culture, honor the natural environment, and respect and delight the people who use them. Headquartered in San Francisco, EHDD serves clients around the world in Aquariums, Museums and Science Centers, Education, Corporate Office, Mixed-Use Development, and Government. EHDD is a Top 10 AIA COTE honoree, and featured in " The Habits of High-Performance Firms, Lessons from frequent winners of the AIA COTE Top Ten Award.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 4

Third Party Employee Credentials: 0


External Attack Surface: 1



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • ehdd.com.1.arsmtp.com.
  • ehdd.com.2.arsmtp.com.
TXT Records
  • a27qips1j5t0bptkvmb7jf5k50
  • e18ha6e6bokr7nn4bp50ipajnt
  • MS=ms64158633
  • aab539190800c4fdfcf7aaa6da34ee3c
  • google-site-verification=6ylo45KfYM9bNlieDqofkLun_0GNfwNTlngdNe04rGg
  • mqearfa16tr0dcm78quhchn84g
  • v=spf1 include:spf.protection.outlook.com include:spf-westus.emailsignatures365.com ~all
  • duo_sso_verification=nFwRXhINOmNyRdwYRCmQOZ4GhYbi43bBu4yiB70owj1c67s7u3uS76JU1qCXowOh
Cloud / SaaS Services Detected
Microsoft 365 Cisco Duo

Leak Screenshot:

Leak Screenshot