Group:
Clop
Discovered by ransomware.live: 2025-02-27
Estimated attack date:
2025-02-27
Country:
Description:
[AI generated] TIMKEN.COM belongs to The Timken Company, a global manufacturer of bearings and related components and assemblies. Based in the USA, it offers engineered bearings and power transmission products used in various industries, including automotive, aerospace, and energy. Besides, it provides services like lubrication management and powertrain rebuild. With over a century of experience, Timken's innovative solutions are designed to improve efficiency and reliability.
Infostealer activity detected by HudsonRock
Compromised Employees: 9
Compromised Users: 159
Third Party Employee Credentials: 8
External Attack Surface:
90
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- mxa-0058d601.gslb.pphosted.com.
- mxb-0058d601.gslb.pphosted.com.
- webexdomainverification.4C675B8AFB06B136E053AB06FC0A3F65=0de9914f-6b9f-4ef1-8a7a-8d825099a442
- globalsign-domain-verification=AD0CC15FEEC993038513E9F39D8FCEE8
- 314A-21F9-1FD4-7F30-4004-AF88-38DE-1BC1
- google-site-verification=yhX_bLUreG4I9oPFcQ9FXCOaXng6S0tGm7nTw8K7jAA
- globalsign-domain-verification=4541d5c62333364a85542184093d1d6d
- smartsheet-site-validation=LqvS91_Wq_vIZ4RAMCy2WjJKE6jW2tHn
- zYAOmZ3n4dLLNkGlD9cHHip9Oit8hkdD46+PVj1ap/CS0Q/u3svQuJG4KnniqaR4cDIA49Vy03g9CRDQCsgNXA==
- ms-domain-verification=21ecbaad-f15e-43b9-975e-a031d5043ee8
- amazonses:DQ7rmlS9nKRdSlwQvZoc+CBycBp0D77YfQTbJb6aRIs=
- atlassian-domain-verification=59ahFzKk8Dp/5NudffwOabVN0RLYn1ZYUrGdPOvraJyBhXv/SpuVm2ai2uSlScTr
- H8azwsnjILbbKkqXAV/RSNkL4uPYwE6GAPP/+lxAF2mkX/cO8QDCgJQSeDGnt7b5K8um+nJ2xSdg3OsTnuxHrA==
- apple-domain-verification=9E9sCGzHF0ptw0zX
- W1SPuzgLbXkLF7QiMy371u443USsaF5BKCtrxQFRqVaXoj+0hC+WOWuA5aZ6elXt6o4+99BhzsQzHesWKgBVlg==
- globalsign-domain-verification=65DB3831C5B7838D880D271C273A2523
- v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
- e2ma-verification=1it
- globalsign-domain-verification=10EAB77377470E2E7E810FDE8EA2C7A1
- MS=ms48258293
- globalsign-domain-verification=11963F891D99A5B0DF57AE1FC8264B58
- globalsign-domain-verification=11963f891d99a5b0df57ae1fc8264b58
- cisco-ci-domain-verification=5bdb9c2eeec34d71522a1131909bae2cd7e9c3390021d06150454d5682a7f7ba
- traction-guest=afbee9d5-af3d-4351-a9ed-883b1ffaba6a
- globalsign-domain-verification=681F34A6DE7837ACC112C268663A090B
Cloud / SaaS Services Detected
Apple
Atlassian
Amazon SES/WorkMail
Microsoft 365
Cisco
Proofpoint
Cisco Webex
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.