Group:
Ransomhub
Discovered by ransomware.live: 2024-11-01
Estimated attack date:
2024-10-27
Country:
Description:
[IA generated] OBE.com is a company specializing in providing advanced online business solutions and digital services. It focuses on assisting businesses in enhancing their online presence through innovative technology and strategic digital marketing practices. The company is known for its expertise in web development, e-commerce solutions, and data-driven marketing strategies, aiming to drive growth and efficiency for its clients.
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 10
Third Party Employee Credentials: 2
External Attack Surface:
4
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- obe-com.mail.protection.outlook.com.
- smartsheet-site-validation=5-tX5T7Z4HkfL_1WSmeaMAYzQRy3qSdm
- _45l3yypudta7215c49fbx2advbt8q0p
- logmein-verification-code=X2uk8Jy6wWW5yb52phr4XjivF
- atlassian-domain-verification=FyTvzpft79IdZ/SnaN3xYb02qh0fpoTXxgcDb3JXzUOTfMk5TtgzKgJUMFia/bh4
- y3j97fp209knt681brnz0rcvfyssqg6f
- GrtLpOLfr89
- 0ed1fe018a543c72bcf80341559b059b2bf9b1865c
- docusign=c5519b38-b1c2-4225-a2a6-2110744a376a
- _cofwq7uy7v7f28dltltnz3zv8to3b2t
- 3fGruA8tZZg+z1lOQ6jCEqjG2/xypBq9P3ed/Ku8Q3Q0h/GARm3slEk3IEljnQB0UxtaVulvnBwEN6L0UJx4aQ==
- v=spf1 " "mx " "ip4:184.175.145.162 " "ip4:184.175.145.189 " "ip4:209.64.25.247 " "ip4:52.44.151.164 " "ip4:208.118.229.82 " "ip4:184.175.145.171 " "ip4:52.1.14.157 " "ip4:107.20.210.250 " "ip4:3.17.124.102 " "ip4:74.118.245.71 " "ip4:74.118.247.30 " "ip4:149.72.231.47 " "ip4:149.72.196.66 " "include:usb._netblocks.mimecast.com " "include:amazonses.com " "include:_spf.ultipro.com " "include:spf.protection.outlook.com " "include:servers.mcsv.net " "include:_spf.psm.knowbe4.com " "include:_vccnets.8x8.com " "-all
- ibmid=6793d9fc-71ad-4185-9d66-e1a9742bd2e4
- p9c6lkbkqfb6o8npdiehe7k8nh
- google-site-verification=KjmbADaK8sZEjK1Ygg7Q3n_AlmPYE263-L2q2QSV1tA
Cloud / SaaS Services Detected
Atlassian
Amazon SES/WorkMail
Mailchimp
LogMeIn
KnowBe4
Mimecast
DocuSign
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.