Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo rosenbauer.com

Group: lockbit3

Discovered by ransomware.live: 2023-02-27

Estimated attack date: 2023-02-27

Description:

rosenbaueramerica.comRosenbauer is the world's largest producer of custom fire trucks worldwide with 14 factory locations and more than 150 years of experience.rosenbauer\veeam_admin:R%senbau3r2017!administrator@vsphere.local R0s3nb@u3r232GB



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse united-domains.de
  • whois united-domains.de
MX Records
  • mx1.hc152-99.eu.iphmx.com.
  • mx2.hc152-99.eu.iphmx.com.
TXT Records
  • msfpkey=3xk2ilmz1zelpiwfyizkspwix
  • MS=68EA1C1DFF218D06D92708B2388EE5E2DBB1AEA2
  • rlzzb0lgz1p4ln1d09pzgkhh52hql6hd
  • v=spf1 a mx ip4:193.104.82.0/24 ip4:62.218.36.75 ip4:62.218.36.76 ip4:85.31.2.169 ip4:85.31.2.171 ip4:85.31.2.172 ip4:46.4.19.104 ip4:207.54.69.26 include:_spf.odoo.com include:spf.protection.outlook.com include:spf.rosenbauer.siwa.cloud include:_spf.itan" "dtel.at exists:%{i}.spf.hc152-99.eu.iphmx.com -all
  • autodesk-domain-verification=idRW14lWA-2ozqOv2A_7
  • apple-domain-verification=TztCY3i7QCmd8ciR
  • google-site-verification=wMmGB4cj488PuftrOTM4ZFGUtnVTvfh2r9n_zTszthY
  • swisssign-check=wXelzjzwDsvgE9N-CG6OIVoYqWw
  • _59c8404521989ede874f596eaab0c56c.nhsllhhtvj.acm-validations.aws.
  • d365mktkey=cMvwwOgfhsJbIggTXzxhwAyo9sOcNohBjH2x2dgmdz0x
  • atlassian-domain-verification=0a8B2KLTNL4QsJYo2NbTQ9BGuayT6C1UFJSfgXGFKoOqSiRnnOGAqaAwdaQmy8Uk
  • _d260a043e00c89bbeac63658c8d324f5.nhsllhhtvj.acm-validations.aws
  • zWViCTCosuRRcWy79qB9DEZYwJIDMPIYHSSPcXP5TUeJncOt5XX0ogHpOUJJp8w0mnW82uStrkumQaGpXkpynQ==
  • MS=ms44479298
  • docusign=03b1cf66-6540-4f6c-92b2-f22676795efe
  • atlassian-domain-verification=O3FClZ7ONSKyqanfyLetasgMeJm9rUquUB1chVho9LdpMTkVdGOSEiWgBNvVKvGN
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Autodesk DocuSign