Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo otrwheel.com

Group: blackbasta

Discovered by ransomware.live: 2024-03-27

Estimated attack date: 2024-03-02

Country: US

Description:

OTR’s product portfolio includes tires, wheels, assemblies, tracks, tubes, ballast and more. Our tire lineup comprises over 1,700 models and 300+ distinctive treads, with bias and radial pneumatic (directional and non-directional); semi-pneumatic; solid (directional and non-directional); non-marking; and airless. The portfolio also includes over 1,000 wheels, with single- and multi-piece versions in steel and aluminum, as well as cast disc units. In total, there are over 100,000 standard items, many of which can be customized for unique applications.SITE: www.otrwheel.com Address : 195 Chatillon Rd NE Ste 4, Rome, Georgia, United StatesALL DATA SIZE: ~700gb 1. Human Resources 2. Engineering 3. Finance 4. Customers 5. Confidential personal documents employees & etc…


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 1


External Attack Surface: 1



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • mxb-006f7001.gslb.pphosted.com.
  • mxa-006f7001.gslb.pphosted.com.
TXT Records
  • fgudmh6cb9knlst2ci8i934b8q
  • pp58laqjd7al61qvmad9svl4i
  • openai-domain-verification=dv-pPDWGtCx5yO6EH92P1OLgnJ2
  • atlassian-sending-domain-verification=1a355a19-dac3-46e2-9c1d-ff08a2ace271
  • ZAC9465
  • qfe2n28upusvpd2ik6iagcq9bl
  • o1jfi0qjhi5a9mem2172g195ae
  • atlassian-domain-verification=2LQaSTm6akX54SyEoAeuuZvEnkk/4bBzf2GggyRDxaSVx/ObWavfmyray5K0hawd
  • facebook-domain-verification=gfzk217p214dtlweg0zddy2hhn6485
  • 5lk2vv3dp3gcvpmd6ihpfbi2l0
  • ppe-9d57a4274974c30db3aa
  • de6lj2no2bd34t5c8sgh3c2fu7
  • fk9r1l8fohvu0rqqffo7gv0q6r
  • apple-domain-verification=tPM1zGqF3XSJl5Pa
  • google-site-verification=42CHPaOslq49D-UmsuVypqtCIbgArBL8KVu5w0zmOH0
  • v=spf1 a:relays.digitalhill.com a:servers.digitalhill.com include:spf-006f7001.pphosted.com include:_spf.psm.knowbe4.com include:21790164.spf10.hubspotemail.net ~all
Cloud / SaaS Services Detected
Apple Atlassian HubSpot KnowBe4 Proofpoint

Leak Screenshot:

Leak Screenshot