Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group: Rhysida

Discovered by ransomware.live: 2024-04-12

Estimated attack date: 2024-04-12

Country: US

Description:

Oki Golf Oki Golf is a collection of 11 Seattle area golf courses, including The Golf Club at Newcastle, providing championship golf course layouts and outstanding course conditions to players of all skill levels.

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 23

Third Party Employee Credentials: 1


External Attack Surface: 9



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • okigolf-com.mail.protection.outlook.com.
TXT Records
  • v=spf1 a ip4:216.176.177.51 ip4:208.115.112.178 ip4:199.119.226.196 include:spf.protection.outlook.com include:dayforcehcm.com include:20284617.spf07.hubspotemail.net include:amazonses.com ~all
  • _nk742b6774l2wdv0y4pq2wtg2dfsiew
  • _qy31loltjl3rnl94kl6flkrdnkky170
  • amazon-business-verification=61a344d3160cdf2d7511cf63bac94390db6656528547139d9a6cf4955011e45d
  • google-site-verification=GXm0ROr7Q2oCW5Y4ht8Ci5vRqOcbYN4RtVR-OFWLNGc
  • google-site-verification=nF8-ekEumxH7Z0qUioRjH14a2R52dm9OjwQwWWB48Wo
Cloud / SaaS Services Detected
Amazon SES/WorkMail HubSpot