Group:
Blackbasta
Discovered by ransomware.live: 2023-03-19
Estimated attack date:
2023-03-19
Country:
Description:
Tri Counties Bank provides a unique brand of Service With Solutions® offering a breadth of personal, small business and commercial banking services to communities throughout California.Established in 1975 and with assets of $10 billion, Tri Counties Bank is a wholly-owned subsidiary of TriCo Bancshares (NASDAQ:TCBK) headquartered in Chico, California.In addition to an extensive California branch network, Tri Counties Bank provides convenient access to its products and services with locations throughout California, advanced online and mobile banking, and a nationwide network of over 37,000 surcharge-free ATMs.SITE: www.tcbk.com Address 63 Constitution Dr, ChicoCalifornia, 95973United States
DNS Records:
The following DNS records were found for the victim's domain.
- c77c8857-72d1-4ef2-b45a-e1674dee4e3b@identity-protect.org
- trustandsafety@support.aws.com
- mxb-00427001.gslb.pphosted.com.
- mxa-00427001.gslb.pphosted.com.
- facebook-domain-verification=ujoe1lec34fk31d4pbxvi5csydqrqy
- google-site-verification=RZ3yFI503hNybPd38Y6XVXkfeTposnkPSkeW-es8tN8
- google-site-verification=bEoczJsRtois8ud6QCvvNbOna7nRExKxEUBWKgGFCtQ
- openai-domain-verification=dv-uM2zZBeNmXkUanmVgSgxvsft
- smartsheet-site-validation=9wIx4uCPTbea-aPCHSFrKpQSdvn6-OCP
- v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
- /yTOrFnFxQ2ehtA+EdxYFXv4rGuuOmeB1qJPJmLb2SKSuJ/1LU4GPAmc762zhit+kfYQox9tFWlTKVoXQ9RaDA==
- 4kNtOvgthwemi9hIS/XIwuZ1ey4Mvxtp5KzD9MlAH5W6KAjbkdBTjNqTjdNOUyYrCjKEw7QxfDPdxrgjmd/ScQ==
- 5qzrdtpf3j8h0bm6y6g9rdznrrwrhxnw
- MS=ms39819811
- TAILSCALE-BO5gj8wiuAosD2WSWQP0
- anthropic-domain-verification-1c774z=c7l8l0U8MzEumprzHr1MLoMdk
- apple-domain-verification=DubTXclRL1JGj4yy
- ca3-5d720bfbfec44b628f075ed679aa6bd6
- ciscocidomainverification=7dce13296e33c0b2f9a9bf8f582796e91dadd0531a062dc27df3d2a39de240e3
- docusign=55ebb024-cf82-4be6-8762-bd2f4720789a
- docusign=7f752e29-40df-4c8b-bb63-a8030237fc61
Cloud / SaaS Services Detected
Apple
Microsoft 365
DocuSign
Proofpoint
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.