Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo robson.com

Group: blackbasta

Discovered by ransomware.live: 2024-06-06

Estimated attack date: 2024-05-13

Country: US

Description:

The Robson Companies, are a group of family-owned companies headquartered in Arizona that develop and build luxury active adult resort communities for those aged 55 and over. Their primary business is creating master-planned retirement communities that combine world-class amenities like golf courses, recreation centers, and social clubs with high-end homes designed for active retirees.SITE: www.robson.com Address : 9532 E Riggs Rd, Sun Lakes, Arizona, 85248, USAALL DATA SIZE: ≈600gb 1. Company data (HR, Accounting, Payroll…) 2. Employees personal documents & folders (tax forms, passports scan, DL, ID, SS…) 3. Clients data… & etc…



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • mx1-us1.ppe-hosted.com.
  • mx2-us1.ppe-hosted.com.
TXT Records
  • v=spf1 a:dispatch-us.ppe-hosted.com include:spf.protection.outlook.com include:_netblocks.envisionoptions.com include:aspmx.pardot.com a:swmail.showare.com ~all
  • 6g58rn0edr464nolvpvvcfbmkm
  • MS=ACD825ADF2CEFD6EEAC48D938E02FC228499D062
  • google-site-verification=cbg4vVPkUGbbucPzWGqrT-B5JM84BGBJK9hR3gqxVLU
  • k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC1Jui8x3QvmFPYkkpRh6KYbRMAvy/hswDIgsLWcvWOa4tGK2aCeCPR9W0ogQncnmFCN2TDLq5kvYF6XKAe/zCKDAr3w5HeT3lSfe21AVY7riGlom2b9dgYVarm0D5YIw20snxVMMEETZtxq9wn83XAU9UbJl3QXyF5y4gk5wT7fQIDAQAB;
  • kcgvrep7rv8llho80eoi00cd33
  • la4fado3g1okkhrlh5m2fldoop
  • m7eo2gdbdh2dtbinsmhhe6r00p
  • ocKm/I2tYyfgU7O+VHz/fZBYsYdiP/PY2mWtJHHcVleBABdnQD/6WN/tNVK84QC9Z2OsLnt2iN9w+ptbt40lUw==
  • pardot1005822=efc0456c5efacbe2e876000a6a6408b74cb62487ec44c2e85db5974a5a48d2e8
  • pinterest-site-verification=70f1e939cc81682232b9abdb0f33c557
  • ppe-066ba752fd5c3163e58b791fad2207d0fd42816f
Cloud / SaaS Services Detected
Salesforce Proofpoint Essentials

Leak Screenshot:

Leak Screenshot